Privacy Policy
Last updated: July 30, 2026
1. Introduction
Shelfies ("we," "our," or "us") is a book tracking app. This policy explains what we collect, why, who we share it with, and what you can do about it. It covers the Shelfies mobile app and website.
We do not sell your personal data, we do not show you ads, and we do not use your reading history for advertising or share it with advertising networks.
2. Information We Collect
- Account information: your email address and authentication credentials. If you sign in with Google or Apple, we receive your email address and basic profile details from them.
- Profile: display name, username, avatar, and bio, if you add them.
- Library and reading data: books you add, shelves, tags, series, reading progress and sessions, ratings, reviews, notes, quotes and highlights, reading goals, and streaks.
- Social activity: follows, activity posts, comments, reactions, book letters, and reports or blocks you submit.
- Purchase information: your subscription and entitlement status. Payments are handled by Google Play or Stripe — we never receive or store your card details.
- App preferences: theme, language, notification and reminder settings, and your time zone (used to calculate streaks in your local time).
- Diagnostic and usage events: a small set of first-party product events (for example, that a paywall was opened or onboarding was completed) used to find broken flows. These are not sold or shared with advertising networks.
3. What Is Public and What Is Not
Shelfies has social features, so some information is visible to others by design. This is the part worth reading twice:
- Private by default: your library, reading progress, notes, quotes, highlights, goals, and account details.
- Visible to other users when you enable a public profile: your username, display name, avatar, bio, and the reading statistics shown on your profile. A public profile is reachable on the web by anyone with the link, and may be indexed by search engines.
- Visible to people who follow you: activity you post to the feed, such as finishing a book, milestones, and your companion's progress — subject to your notification and sharing settings.
- Visible to everyone in that context: comments and reactions you leave on other people's activity, and your entry in any leaderboard you join.
You can turn the public profile and activity sharing off at any time in Account settings. Turning them off stops future sharing; content others have already seen or copied cannot be recalled.
4. Device Permissions
- Camera: requested only when you scan a book barcode. Frames are processed on your device to read the barcode and are not uploaded or stored.
- Notifications: requested only when you choose to turn on reading reminders. Reminders are scheduled on your device.
You can decline either permission and keep using the app, and you can revoke both at any time in your device settings.
5. How We Use Your Information
- To provide the service and sync your library across your devices.
- To operate the social features you choose to use.
- To process purchases and determine what your subscription unlocks.
- To generate AI recommendations, summaries, and reading plans (Pro).
- To send the reminders and notifications you have enabled.
- To keep the service secure, prevent abuse, and handle reports.
- To fix defects and understand which flows are failing.
If you are in the EEA or UK, we rely on: performance of a contract for running the service and your purchases; consent for notifications, the public profile, and optional AI features; and legitimate interests for security, abuse prevention, and fixing defects. You may withdraw consent at any time.
6. Service Providers
We share data with a small number of providers who process it on our behalf, only as needed to run the app:
- Supabase: database, authentication, file storage, and backend hosting.
- Google Play Billing and RevenueCat: purchases and subscription status in the Android app.
- Stripe: payments and subscription management on the web.
- Lovable AI Gateway: powers AI features. When you use one, the relevant book titles, authors, and your related library context are sent to generate a response. Do not put anything into notes or reviews you would not want processed this way.
- Open Library: queried for book metadata and cover images. Your search terms reach them as part of the lookup; your account is not identified to them.
We also disclose information where we are legally required to, or to protect the rights and safety of our users.
7. International Transfers
Our providers may process data outside your country, including in the United States. Where personal data is transferred out of the EEA or UK, it is covered by the transfer mechanisms those providers offer, such as the European Commission's Standard Contractual Clauses.
8. Data Storage & Security
Your data is stored on managed cloud infrastructure, encrypted in transit and at rest, with per-user access rules enforced at the database level so one account cannot read another's private data. No system is perfectly secure, and we cannot guarantee absolute security — but if a breach affects your personal data, we will notify you and the relevant authority where the law requires it.
9. Retention & Deletion
We keep your data while your account is active. You can delete your account from Account settings in the app, or at /delete-account on the web.
When you delete your account, your personal data and library are removed within 30 days, except where we must keep records to meet a legal obligation — for example, purchase and tax records, which payment providers retain under their own statutory periods. Backups are purged on their normal rotation. Content you posted publicly, such as a comment on another reader's activity, may be shown as being from a deleted account rather than removed from their view.
10. Your Rights
Depending on where you live, you have the right to:
- Access the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Delete your account and your data.
- Export your library in a portable format (Account → Export data).
- Object to or restrict certain processing.
- Withdraw consent at any time, without affecting what was done beforehand.
- Complain to your local data protection authority.
We respond to requests within 30 days. We do not discriminate against you for exercising any of these rights.
11. Children's Privacy
Shelfies is not intended for children under 13, and we do not knowingly collect their personal information. In parts of the EEA where the minimum age for consent to online services is higher than 13, that higher local age applies. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes to This Policy
We may update this policy. We will change the "Last updated" date above, and for changes that materially affect your rights we will tell you in the app before they take effect.
13. Contact Us
For any privacy question or to exercise the rights above, use Account → Report a problem in the app. It reaches us directly and we reply to the email address on your account.