β Back to Bookplate
Privacy Policy
Bookplate (bookplateapp.com) Β· Last updated July 30, 2026
Bookplate is a personal reading tracker. This policy says exactly what data the app
handles, where it goes, and how to delete it. The short version: your reading data is
yours, we don't run ads or analytics, we never sell your data or share it for
advertising, and you can delete your account and its data from inside the app. We share data with the service
providers listed below only as needed to run the app.
What we store
- Your library: books, to-be-read entries, reading progress, start/finish
dates, ratings, notes, and reading history.
- Your shelf identity: the shelf name you choose, an optional username and
friend code, and your cup/shelf designs (including painted cup art).
- Your account: if you sign in, your email address and sign-in provider,
managed by Firebase Authentication (Google). When you create an account we
ask your birth date once to check eligibility β it's checked on your device and
immediately discarded, never stored or sent to us. Signing back in never asks
again, on any device.
- Social data, only if you use those features: friend connections, blocked
users, reviews and comments you publish, and notifications.
- Sync bookkeeping: timestamps on your items so your devices can agree which
edit is newest.
- Support & safety records: messages you send through Help &
feedback (your message text, the email you enter, and your account id if you're
signed in), and reports you file about content or readers (your account id, what
you reported, and the reason). These are operational records kept separately from
your shelf.
We do not collect analytics, advertising identifiers, location, contacts, or
anything from your device beyond what you type into the app.
Where it lives
- Signed out (guest mode): your shelf data β books, designs, notes β stays in
your browser's local storage on your device and is not synced or uploaded to
Bookplate's database. Features that look things up (search, barcode scan, covers,
discovery) still make network requests to the services below, which, like any web
request, see your IP address and the query.
- Signed in: your data syncs to Cloud Firestore (Google Cloud), tied to your
account, so it follows you across devices.
Services the app talks to
- Firebase / Google Cloud β sign-in and the synced database.
- Open Library (openlibrary.org, covers.openlibrary.org) β when you search for
a book, scan a barcode, or the app fetches cover art and ratings, the book's
title/author/ISBN is sent as a query. The discovery features (mood search, taste
test, βFor youβ) also send subject, genre, and author queries derived from your
mood picks, quiz answers, and highly-rated authors/genres β for example
subject:"fantasy" or a favorite author's name. Bookplate attaches no
account identifier to any of these queries, but like any web request the provider
sees your IP address, and the queries themselves can reflect your tastes.
- Apple iTunes Search API β same idea, for additional book ratings. Query
only, no account identifier.
- Script hosting (CDNs): the app loads open-source libraries from Google,
Cloudflare, and jsDelivr. Like any web request, those servers see your IP address in
standard server logs; no app data is sent to them.
That is the complete list. No ad networks, no analytics services, no data brokers.
What other people can see
- Profiles are private by default. Your shelf is visible to a friend only if
you connect with them, and appears in the public directory only if you turn
Discoverable on.
- Reviews and comments you publish are visible to other Bookplate readers under your
shelf name.
Data retention
- Your shelf and account data are kept for as long as your account exists,
so your shelf is there when you come back, and are deleted when you delete your
account (see below).
- Support messages and reports are operational records, kept as long as
they're needed to handle support and keep the community safe β they are not tied
to your account's lifetime. Support messages are deleted on request (see
below).
- Messages from the retired messaging feature: Bookplate no longer offers
direct messages. Conversations from that feature are no longer accessible in the
app but remain stored in shared conversation records. Ask us to delete yours via
Help & feedback β best done while your account still exists, since
those records are found by account id; after account deletion we can investigate
but may not be able to locate yours.
- Local guest data stays on your device until you clear it, sign in (see
the in-app explanation of what happens then), or sign out (signing out wipes the
device's local copy for privacy on shared devices).
Deleting your data
In-app account deletion: Account sheet β βDelete my accountβ¦β. After you
confirm (twice) and re-verify your sign-in, the app immediately deletes from
Bookplate's servers, and from the device you're on:
- your library, TBR, reading history, and painted cup art;
- your profile, directory listing, username, and friend code;
- your friend requests (sent and received) and notifications;
- every review and comment you published;
- your sign-in account itself, and the local copy on this device.
The honest fine print:
- Other devices: a device that was signed in keeps its local copy. Its
session stops working when its sign-in token expires β within about an hour β
after which it can no longer sync; signing out there wipes that local copy. We
cannot reach into an offline device to erase it remotely.
- If something fails: the app deletes your sign-in account only
after every server-side purge above has succeeded. If any step fails, it
stops, tells you, and leaves your sign-in intact so you can retry β it never
deletes your account while data remains behind.
- If your account is deleted from another device while this device is
still signed in, this device ends its session and keeps a local recovery copy
of whatever was on it (never uploaded), so nothing is silently destroyed. You
can download or delete that copy yourself under Support β Data history β
Recovery copies; if it can't be saved (storage full), nothing is erased and
the app tells you to export instead.
- Support & safety records (Help & feedback messages and reports
you filed) are not automatically removed by account deletion β after deletion your
account id in them no longer links to any profile. To have your support messages
deleted, ask through Help & feedback β ideally before deleting your account,
or mention the email you used in them so we can find them.
- Friends' copies: your profile and shared shelf disappear for your friends
because the data behind them is gone. The entry naming you in a friend's own list
may linger on their side until they remove it, but it leads nowhere.
- Messages you sent through the retired messaging feature live in shared
conversation records and are not removed by account deletion. Ask us to delete
them before deleting your account (they're found by account id); after
deletion we can investigate but may not be able to locate yours.
- Backups you exported yourself are files on your device and are yours to
keep or delete. Residual copies in the database provider's infrastructure backups
expire on Google Cloud's standard deletion timelines.
Children
Bookplate is not directed at children under 13, and we do not knowingly collect
personal information from them.
Changes and contact
If this policy changes, the date above changes with it β check this page for the
current version. Questions or requests: use Help & feedback inside the app,
or email bookplateapp@gmail.com β the
developer reads every message.
Terms of Service Β· Community
Guidelines