Last Updated: September 23, 2026
Controller and contact
See the Contact page and the Legal Notice.
App (all platforms)
BookShelves stores your library locally on your device. Without sync enabled, no data leaves your device.
Sync and accounts (Pro). When you enable sync, we create an internal user ID on our servers to identify which devices belong together and route your encrypted data between them. On Apple devices, this happens automatically without additional sign-in. On other platforms, you sign in with Apple, Google, or Microsoft, or register with your email address. When you use a third-party sign-in provider, we receive your email address and an account identifier. When you register directly, we store your email address.
We use your email address for account identification, support, and service notifications related to features you use (such as wishlist alerts). We do not send marketing emails.
When sync is enabled, two kinds of data may leave your device:
(a) Book files may be stored in a cloud storage service you select (such as Apple iCloud Drive). These services are operated by their respective providers, not by us.
(b) Library metadata (titles, reading progress, annotations, settings) is synchronized using a platform-provided service (such as Apple CloudKit) or our own sync service.
When you sync through Apple iCloud, as the BookShelves apps for Mac, iPhone and iPad do, your library metadata is stored in your own iCloud account. We hold no keys to it and cannot access it; Apple’s privacy policy applies to that storage.
Where our own sync service is used, your data is encrypted on your device before transmission and stored in encrypted form at rest. Content synced through our sync service is protected as follows:
Standard Protection. Your encryption keys are secured on our servers so we can help you recover your data if you lose access to all your devices. Under Standard Protection, we have the technical ability to access your synced content in limited circumstances (for example, to assist with account recovery or to comply with a valid legal request). Standard Protection is the only level of protection currently offered for our sync service.
Enhanced Protection (planned, not yet available). We intend to offer an opt-in Enhanced Protection under which your devices retain sole access to your encryption keys, so that we cannot decrypt, read, or access your synced content, and under which your data cannot be recovered by anyone, including us, if you lose access to all your devices and your recovery key. Enhanced Protection is not yet available in the app. Until it is, all content synced through our sync service is protected under Standard Protection. We will update this policy when Enhanced Protection becomes available.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Push notifications. If you enable sync, we store a device push token to deliver sync notifications via Apple Push Notification service (APNS) or Google Firebase Cloud Messaging (FCM). These notifications contain no personal data – they are a signal for the app to check for updates. We store only a hashed user identifier, a device identifier, and the push endpoint. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Crash and error reports. The app sends anonymous crash and error reports to Sentry. You can disable this in Settings > Analytics Opt-Out. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in fixing bugs).
Install attribution (Apple platforms only). On first launch, the app requests anonymous install attribution data from Apple (Apple Search Ads campaign identifier, ad group, keyword, and region). This data does not identify you and is sent to Sentry for aggregate campaign analytics. It cannot be disabled separately. If you did not arrive via an ad, only empty placeholder values are recorded. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in measuring advertising effectiveness).
In-app issue reports
When you choose to submit a bug report or rendering issue report from within the app, we collect:
- Your description of the issue.
- A screenshot (automatically captured for rendering reports, optional for bug reports).
- For rendering issues: the full chapter text (HTML) and stylesheets of the page you are viewing, so we can reproduce the problem.
- Book title, author, and reading position.
- Reader settings (theme, font, layout).
- Device type, OS version, and app version.
- Your email address, only if you provide it (used solely to follow up on your report).
This data is sent to our feedback portal (hosted on AWS) and is only used to diagnose and fix the reported issue. No data is collected until you tap “Send Report.” Legal basis: Art. 6(1)(b) GDPR (you initiated the request).
Website (getbookshelves.app)
Google Analytics runs only after you accept the cookie banner. Consent stored for 365 days. Legal basis: Art. 6(1)(a) GDPR (consent).
Feedback portal (feedback.getbookshelves.app)
If you submit feedback, comment, vote, or sign in, we process:
- Your email address (not publicly visible).
- Your Apple or Google account identifier, if you choose social sign-in.
- Your IP address, used solely for spam rate-limiting (kept for 48 hours).
- The content you submit (titles, bodies, comments, votes – publicly visible).
- Functional cookies strictly necessary for sign-in and abuse defence. No advertising or cross-site tracking cookies.
Legal bases: Art. 6(1)(b) GDPR (you initiated the request) and Art. 6(1)(f) GDPR (preventing abuse).
Recipients
- Apple – App Store, iCloud, Sign in with Apple, Apple Push Notification service, Apple Search Ads attribution. Privacy Policy
- Google – Google Play Store (Android distribution), Firebase Cloud Messaging, website analytics, and Sign in with Google. Privacy Policy
- Microsoft – Sign in with Microsoft. Privacy Statement
- Cloudflare – Turnstile anti-bot challenge on the feedback portal. Privacy Policy
- Amazon Web Services – feedback portal hosting, infrastructure for our own sync service, and push notification delivery. Encryption keys for data synced through our sync service are secured on AWS infrastructure (Standard Protection). Privacy Notice
- Sentry – app crash reporting. Privacy Policy
- Open Library – book metadata (no personal data sent). Open Library
Retention
- App data: until you delete it from your device or your cloud storage account.
- Sync account (email or provider identifier), encrypted sync data, and push tokens: until you request deletion.
- Sentry error data: 90 days.
- In-app issue reports (including chapter text and screenshots): until the issue is resolved, then deleted.
- Feedback portal posts, comments, votes, and account identifier: until you request deletion.
Account deletion
To delete your sync account and all associated data (encrypted sync data, push tokens, email address, and account identifier), contact us via the Contact page. Deletion is permanent and cannot be undone.
Your rights (GDPR / CCPA)
You have the right to access, rectification, erasure, restriction of processing, data portability, objection, and to withdraw consent at any time. To exercise these rights, contact us via the Contact page. We respond within 30 days.
You can also lodge a complaint with a data protection authority (Germany: BfDI).
Children
We do not knowingly process data of children under 16.
Changes
Material changes will be reflected by updating the “Last Updated” date above.