Effective October 3, 2026 · Version 1.33
Privacy Policy
ShelfLife is operated by Fisherbird LLC ("Fisherbird", "we", "us", or "our"). This Privacy Policy explains what personal information we collect when you use ShelfLife (the "Service") — through our iOS app, Android app, web app, or marketing website — how we use it, who we share it with, how long we keep it, and the rights you have over it.
By using the Service you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Service.
1. Who we are and how to reach us
The data controller for personal information processed through the Service is Fisherbird LLC. You can reach our privacy team at admins@theshelflifeapp.com.
We have not appointed a statutory Data Protection Officer because we are not required to under GDPR Article 37, but the privacy mailbox above is monitored and we respond to rights requests within the timelines described in Section 9.
2. Information we collect
We collect personal information in three ways: you give it to us, it is generated by your use of the Service, and a small amount is generated automatically when your device connects to our servers.
For California residents, this Section together with Section 3 ("How we use personal information") and Section 5 ("Disclosure of personal information") constitutes our Notice at Collection under the California Consumer Privacy Act, as amended by the California Privacy Rights Act.
2.1 Information you provide
- Account information — email address, password (stored only as a hash managed by Amazon Cognito; we never see the plaintext), display name, and chosen handle.
- Profile information — optional avatar, bio, and links to your Instagram and TikTok profiles.
- Reading data — the books you add to shelves, your ratings, written reviews, reading status, dates started and finished, and the books you pin to your Top 12.
- Spine images — photos you upload of book spines so the Service can render them on the shelf canvas. These are processed to extract a silhouette, palette, and (where permitted) a stylized render.
- Catalog contributions — details and cover images you add for public books and editions, and changes you make to their details. New public books, editions, covers, and edits are visible to other readers immediately and are reviewed afterwards. For each edit we keep what the details were before and what you changed them to, and which account made it, so we can review abuse and undo mistakes.
- Library import files — if you import a library from another service (for example a Goodreads, StoryGraph, or LibraryThing CSV export), we keep the file you uploaded for a short time, not only the books we read out of it. The file is stored privately; it is what we read your ratings, dates, and reviews from when you confirm the import, and it lets us investigate if you report a problem with the import. It is deleted automatically about ten days after upload, and immediately if you delete your account. See Section 7.
- Feedback you send us — when you use Send Feedback, we receive your message and, only if you choose to add them: up to three photos, a link to your most recent library import, and diagnostic information about your device. Photos are checked for malware and re-saved without their embedded metadata (including location) before anyone at ShelfLife can view them. Linking an import does not copy the file; it lets us look at the file you already uploaded while we still keep it (see Library import files above). Diagnostic information is sent only when you tick "Device info" under "Also send", and is limited to your device platform and model, operating-system version, app version and build, language, time zone, the app features enabled for you, and on the web your browser's user-agent and window size. It never includes a device or advertising identifier, your IP address, or your location. See Section 7.
- Photos you add as a Box Seat member — a photo you put in a picture frame on one of your shelves, or upload as your profile photo. Photos are checked for malware and re-saved without their embedded metadata (including location) before they appear. Moderators review new photos after they appear. See Sections 5.2 and 7.
- Peanut Gallery posts — the takes and quotes you post about a book, and your reactions to other readers' posts. See Sections 5.2 and 7.
- Book Signals — when you ask for recommendations, the note you write and the books or shelf you attach; when you answer another reader's Book Signal, your note and the books you recommend.
- Reading goals — the goals you set, the books and countries that count toward them, community goals you publish or join, and cheers you give other readers.
- Month in Books posts — if you post your monthly recap to your feed, the books you finished that month, your favorite, and the card style you chose.
- Social graph — the accounts you follow and the accounts that follow you, pending follow requests, and the accounts you block.
- Reports and book requests — if you report a profile, post, shelf, photo, or other content, we keep what you reported, the reason you chose, and any note you add. We do not tell the other reader who reported them. If you ask us to add a missing book, we keep what you searched for and any title, author, and ISBN you give us.
- Exit survey — if you answer the optional question shown before you delete your account, we keep the reason you chose and any comment you write. The answer is stored under the derived identifier described in Section 2.3, never your name, email address, or handle. See Section 7.
- Terms acceptance — the version of our Terms of Service you accepted and when.
- Support correspondence — messages you send us by email and any attachments you choose to include.
- Newsletter opt-in — if you tick the optional newsletter box at sign-up (or during onboarding), we record that choice — your email address, the answer, and when and where you gave it — so we can send you the occasional ShelfLife newsletter. The box is never pre-ticked, saying no changes nothing about your account, and you can withdraw at any time using the unsubscribe link in any newsletter or by emailing us.
- How you heard about us — during onboarding we ask, once, how you heard about ShelfLife, and record your answer: one option from a short list (including "Prefer not to say", which is always available and is recorded as your answer), plus a short note if you choose "Something else". We use it only to understand which channels reach readers. It is included in your data export and deleted with your account.
- Box Seat membership — if you buy Box Seat, we keep which plan you chose, where you bought it (the App Store, Google Play, or our website through Paddle), whether it renews, when your current period ends, and whether the store has reported a billing problem, so we can unlock Box Seat and show your membership. Changes to your membership are also recorded as usage events, as described under "App usage events" below; billing problems are not. Apple, Google or Paddle takes your payment; we never see your card details.
2.2 Information generated by your use of the Service
- Activity events — when you add a book, change reading status, finish a book, post a review, update your Top 12, create a shelf, start or complete a reading goal, post your Month in Books, or are the first to post about a book in the Peanut Gallery, we record an activity event. These events are used to build your home feed and the home feeds of accounts that follow you.
- In-app notifications — a record of each notification we show you (for example, a new follower or a response to your Book Signal).
- Aggregate review statistics — per-book averages and rating distributions are derived from individual reviews.
2.3 Information collected automatically
- Operational metadata — IP address and basic request metadata (user-agent, timestamp, route) are processed transiently by our hosting providers for rate-limiting, abuse prevention, and to deliver the response. We do not retain raw access logs containing IP addresses for longer than 14 days.
- Local storage on your device — we store an authentication token (Amazon Cognito refresh token) in your device's secure storage (iOS Keychain, Android Keystore, or the browser's
localStorage) so that you stay signed in. We do not use third-party advertising cookies or cross-site tracking pixels. - Push notification token — if you allow notifications, the token your device gives us so we can send them. See the Expo entry in Section 5.1.
- Account platform history — when you use the Service while signed in, your requests identify the ShelfLife platform making the request: iOS, Android, or web. We keep the set of platforms observed on your account so we can operate and support the Service. We do not use this record to identify a physical device, and it does not include a device identifier, model, manufacturer, device name, or operating-system version. This account-linked record is separate from the random per-install mobile usage events described below.
- Account activity days — while you are signed in, we record the most recent day you used the Service, so we can operate and support it — for example, to tell whether an account is still in use, to time the reminders we send new readers, and to choose which active readers see a Book Signal. We also keep anonymous daily totals — how many readers who joined on a given day used the Service on each later day. Those totals contain no account identifier, cannot be traced back to you, and are not removed when an account is deleted.
- Crash and error diagnostics — when the app hits an unexpected error or crash, a diagnostic report is sent to our error-monitoring provider so we can fix it. It contains the error message and stack trace, the app version, your device or browser type and operating-system version, and the screen or route where the error happened. We configure this provider not to collect your IP address and do not attach your account identity to these reports. See the Sentry entry in Section 5.1.
- App usage events. In our mobile and web apps we record which features are used (for example, completing an import, scanning a spine, or tapping a tip card) together with device type, operating system version, and app version. We never record what you are reading, what you write, or what you search for — no book titles, no review or comment text, no search terms.
While you are signed in, these events are linked to your account through an identifier we derive from your account by a one-way calculation. We can reverse that link from our side — and we must be able to, so that deleting your account also deletes this data — but our analytics provider holds only the derived identifier and cannot connect it to you, your name, or your email. Signed out, the events carry only a random identifier.
If you are in the EU/EEA (including its overseas territories), the UK (including Gibraltar, Jersey, Guernsey, and the Isle of Man), Switzerland, Canada, South Korea, or China, the mobile app asks you first — once, before any usage analytics starts — and nothing is stored on your device or sent to our analytics provider for this purpose until you say yes. We tell whether to ask from your device's region and time-zone settings, not from your location. Everywhere else, usage analytics runs by default on our legitimate interest in understanding how ShelfLife is used. In every case you can turn it on or off at any time under Privacy → Share usage data. In the mobile app your answer is saved to your account, so it follows you to every phone or tablet you sign in on. In the web app the setting applies only to the browser you set it in.
When your Box Seat membership changes at the App Store, Google Play, or Paddle — it starts, renews, is canceled or turned back on, ends, is refunded, or switches plan — our servers record that change as a usage event too, with the plan, the store, and a general reason for a cancellation, but no price, no payment details, and nothing about billing problems. It carries the same derived identifier and follows the answer saved to your account from the mobile app: where the mobile app asks first, nothing is sent unless you said yes there, and nothing is sent once you have turned off Share usage data in the mobile app. Turning it off only in a web browser does not stop these events; email the privacy contact in Section 1 and we will turn them off for your whole account.
Your requests to our servers also carry your device's region setting (country level) and time zone, which we keep on your account so we know which countries our readers are in. This is not precise location data.
See Section 9 for your right to object.
- Marketing-site usage events — marketing site only. This bullet applies only to our public marketing website (theshelflifeapp.com) and nothing else. On the marketing site we record the page visited, referring site, campaign source, medium, and campaign name, scroll milestones, and selected calls to action and outbound links. We also use PostHog's heatmap and autocapture features there: heatmaps aggregate click and mouse-movement locations across visitors; and autocapture records clicks and page interactions we have not individually coded an event for. Text typed into form fields is never included in an autocapture event. We do not use session replay: no screen-recording-style playback of your visit is made. Because these features need real browser storage to work, we ask for your consent first if you're visiting from the EU/EEA, the UK, or Switzerland — see "Opt-in consent banner" in Section 11. Everywhere else, this analytics runs by default, using PostHog's privacy-preserving server-side visitor identifier rather than the sale/advertising identifiers used by ad-tech cookies. If you decline (or opt out) where a banner is shown, we still count your visit using a cookieless, storage-free method, without heatmaps or autocapture.
Our iOS app, Android app, and web app never do any of this. Heatmaps and autocapture are used on the marketing website only. The mobile and web app usage events described above remain deliberate, individually-coded events — no click heatmaps and no automatic capture of interactions we haven't explicitly chosen to track. Nothing we operate records your screen.
Our web app (the signed-in product at app.theshelflifeapp.com) still writes nothing to cookies or browser storage for analytics: the identifier described above is derived from your sign-in session each time, not stored in your browser. The only thing we save there is your own choice if you turn usage data off, so that we can keep honoring it.
We do not knowingly collect precise geolocation data, contacts, or microphone audio. We do not collect biometric data; see Section 2.4 below for the specific way biometric unlock works on your device.
2.4 Biometric authentication
ShelfLife offers an optional biometric-unlock feature on devices that have Face ID, Touch ID, fingerprint, or another on-device biometric method enrolled with the operating system. You can turn this on or off at any time from Account in the app; it is off by default.
When the feature is enabled, biometric verification is performed entirely by your device's operating system — Apple's Local Authentication framework on iOS, and the Android BiometricPrompt API on Android. We receive only a yes/no result from the operating system, indicating whether verification succeeded.
We do not collect, receive, transmit, or store any biometric identifier or biometric information about you. Specifically, we do not have access to any fingerprint scan, facial geometry, voiceprint, retina or iris scan, hand-geometry scan, or any other unique biological pattern or characteristic. No biometric template ever leaves your device. Nothing biometric is transmitted to our servers, to Amazon Web Services, or to any third party.
The only thing the app stores in connection with this feature is a boolean preference, kept in your device's secure storage, that records whether you opted in. Disabling the feature deletes that preference; deleting the app removes it along with everything else the app stored locally.
Because no biometric identifier or biometric information ever reaches us, we do not engage in conduct regulated by the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act, the Washington Biometric Privacy Act, or the biometric provisions of comprehensive state privacy laws — all biometric handling occurs in your device's secure enclave under the operating system's policies, not ours.
3. How we use personal information
We use personal information to:
- Operate, maintain, and improve the Service, including rendering your shelves, delivering your home feed, and showing profiles of accounts you follow.
- Understand aggregate feature use, marketing traffic, and download conversion so we can improve the Service and its public website.
- Authenticate you and keep your account secure.
- Operate and support the Service across iOS, Android, and web, including understanding which ShelfLife platforms an account has used.
- Detect, investigate, and prevent fraudulent, abusive, or unlawful activity, and enforce our Terms of Service.
- Send transactional communications such as account verification, password reset, security alerts, and confirmations of actions you took (for example, account deletion).
- Send you a reminder email if an import you started is waiting for your review and we can't reach you with a push notification. You can turn these off with the link in the email or in Settings.
- Send Box Seat members the renewal reminders and confirmations that consumer law requires before and after an annual membership renews.
- Review reports, moderate content, and answer requests to add a missing book.
- Send the ShelfLife newsletter to readers who opted in (consent, which you can withdraw at any time).
- Respond to your support requests, rights requests, and other correspondence.
- Comply with our legal obligations, including responding to lawful requests by public authorities and preserving evidence where required.
We do not use your personal information to serve third-party advertising, to build cross-site advertising profiles, or to sell it to data brokers.
4. Legal bases for processing (UK and EEA users)
If you are in the United Kingdom, the European Economic Area, or Switzerland, we rely on the following legal bases under the UK GDPR and EU GDPR:
- Performance of a contract (Article 6(1)(b)) — to provide the core Service to you under our Terms of Service. We cannot operate your account without processing the data described in Section 2.1 and Section 2.2.
- Legitimate interests (Article 6(1)(f)) — to keep the Service secure, prevent abuse, debug operational problems, protect our rights, and understand how the Service is used where the law does not require consent for that (see Section 2.3). Where we rely on legitimate interests, we have weighed those against your privacy interests; you can object at any time (see Section 9).
- Consent (Article 6(1)(a)) — where required by law for cookies and similar technologies that are not strictly necessary, for usage analytics in the mobile app (which asks you first), and for any optional marketing communications. You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Legal obligation (Article 6(1)(c)) — when we must process data to comply with a legal requirement, such as responding to a valid court order.
We do not engage in solely automated decision-making with legal or similarly significant effects on you (Article 22).
5. Disclosure of personal information
We disclose personal information only in the following circumstances:
5.1 Service providers (sub-processors)
We use a small number of vendors to operate the Service. They process personal information on our behalf under written agreements that bind them to confidentiality and security obligations.
- Amazon Web Services, Inc. — cloud infrastructure and platform services, such as application hosting, database (DynamoDB), object storage (S3), authentication (Cognito), email delivery (Simple Email Service), and serverless compute (Lambda). Processing region:
us-east-2(Ohio, United States). - 650 Industries, Inc. (d/b/a Expo) — push-notification delivery. When we send you a notification (such as a Book Signal response or a new follower), we pass a device push token and the notification's contents to Expo's push service, which relays it to Apple (APNs) or Google (FCM).
- Cloudflare, Inc. — Cloudflare Turnstile, an anti-bot challenge used on our web app's signup form, and Cloudflare Web Analytics, a cookie-less pageview/referrer analytics tool on our marketing site.
- Functional Software, Inc. (d/b/a Sentry) — application error and crash monitoring for our web and mobile apps. When the app encounters an error, a diagnostic report (error message, stack trace, app version, device/browser type, and the URL of the screen where it happened) is sent to Sentry so we can fix it. We configure Sentry not to collect your IP address and do not attach your account identity to these reports.
- PostHog EU B.V. (d/b/a PostHog) — product analytics for our mobile and web apps, and usage analytics, heatmaps, and autocapture for our marketing site only (theshelflifeapp.com — not the iOS app, Android app, or web app), hosted in the European Union. We do not use session replay anywhere. App feature-usage events never include heatmaps or autocapture. While you are signed in they are labelled with an identifier derived from your account by a one-way calculation, which PostHog cannot connect back to you; signed out, a random identifier is used. Changes to a Box Seat membership (started, renewed, canceled, ended, refunded, or switched plan) are sent from our servers under the same identifier, without price or payment details. Marketing-site visitors from the EU/EEA, UK, or Switzerland are asked for consent before any cookie-based tracking or heatmap/autocapture runs; everyone else gets it by default, tied to PostHog's privacy-preserving identifier rather than an advertising identifier; anyone who declines is still counted using a cookieless, storage-free method. We never send your name, email address, account identity, book titles, review or comment text, search terms, or the contents of form fields, and we do not use this data for advertising.
- RevenueCat, Inc. — subscription management for Box Seat in our iOS and Android apps and on our website. If Box Seat is offered to you in our apps or on our website, RevenueCat receives your ShelfLife account identifier, your store country, basic device and app details (such as app version and operating system) and your IP address, and, if you buy Box Seat, your purchase and subscription records from Apple, Google or Paddle (such as the plan, price, and renewal dates), and tells us whether your membership is active. If you buy Box Seat on our website, RevenueCat also receives your email address from Paddle as part of the purchase record. We do not send RevenueCat your reading activity, and it never receives your payment card details.
- MailerLite, Inc. — newsletter delivery. If you opt in to the ShelfLife newsletter, we give MailerLite your email address and when and where you opted in, and it sends the newsletter on our behalf. MailerLite records whether each newsletter was delivered, opened, or clicked, and handles unsubscribes. Nobody who has not opted in is added, and we do not send MailerLite your reading activity. MailerLite stores this data in the European Union (the Netherlands).
- Open Library / Internet Archive — public book metadata lookups. We send a book identifier (such as an OLID or ISBN). We do not send any data that identifies you to Open Library.
Paddle, for purchases on our website. Box Seat bought on the ShelfLife website is sold by our reseller Paddle (Paddle.com Market Limited, or Paddle.com Inc. for buyers in the United States and Paddle.com (Canada) Ltd. for buyers in Canada), the merchant of record for those orders. Paddle is not our sub-processor: it is an independent controller of the information it collects to sell to you, under its own Buyer Terms and Privacy Notice. When you buy Box Seat on the web, Paddle receives your name, email address, billing country and postcode, payment details and IP address, and we pass it your ShelfLife account identifier so the purchase unlocks your account. Paddle processes the payment, charges any applicable tax, and handles refunds.
We publish an up-to-date list of material sub-processors at theshelflifeapp.com/subprocessors and will give at least 30 days' notice of changes that materially affect the categories of data processed.
5.2 Publicly visible content
Some information you provide is, by design, visible to others:
- Your handle, display name, avatar, and bio are visible to anyone who views your profile. Anyone holding your profile's share link can open it without a ShelfLife account: if your account is public they see those details, your social links, your book, follower and following counts, your Top 12, and your Public shelves (never the lists of who follows you or whom you follow); if your account is private they see only your display name, handle, and avatar. Signed-in readers also see your bio and social links, even if your account is private.
- Reviews you post are publicly visible alongside the book.
- Peanut Gallery takes and quotes you post are shown to every signed-in reader who opens that book's gallery, with your display name and avatar, even if your account is private. We may also show one in the home feed of a reader who has finished the same book. Other readers can react to and report your posts.
- A Book Signal you send goes to your followers and to readers who read similar books, with your handle, display name, note, and books. While it is active, other signed-in readers can also come across it. A response you send is shown to the reader who asked.
- A community goal you publish can be browsed and joined by any signed-in reader. Members of a community goal can see each other's progress and the books counted toward it; if your account is private, members who don't follow you see that progress without your name, handle, or avatar. When you cheer a reader's goal activity, that reader can see that you did.
- A Month in Books recap you post is shown to your followers and can be opened by anyone who is allowed to see your reading activity.
- Shelves you create are visible to followers and, depending on your privacy setting, may be visible to other signed-in users. A shelf set to Public can also be opened by anyone holding its share link, including people without a ShelfLife account — this includes the title and author of any reader-created book on that shelf (its cover image is not shown until a moderator has reviewed it).
- Spine photos you upload may appear in the community spine pool for the same book, where other users can choose them for their own shelves.
- A photo in a picture frame is shown with its shelf, including through a public shelf's share link, and a profile photo is shown wherever your avatar appears. Each photo is stored at a public web address that is hard to guess, so anyone who has that link can view the photo until it is replaced, removed, or taken down, even if the shelf it sits on is private. Other readers can report a photo. If a moderator takes a photo down, it stops being shown and we tell you in the app, with the moderator's comment.
- Books and editions you add to ShelfLife's shared catalog, and their covers, are shown to all users as soon as you add them, without your name or handle. A moderator may later correct, merge, remove, or make one private; a book made private stays visible only to readers who already had it. Edits you make to a book's details are shown to all users as soon as you save them, also without your name or handle; a moderator may later change them back.
5.3 Legal disclosures
We may disclose personal information if we believe in good faith that disclosure is necessary to (a) comply with a subpoena, court order, or other valid legal process; (b) protect the safety of any person; (c) investigate, prevent, or respond to suspected fraud, security, or technical issues; or (d) enforce our Terms of Service.
5.4 Business transfers
If Fisherbird is acquired, merges with another entity, or sells substantially all of its assets, your information may be transferred as part of the transaction. We will notify you (by email and an in-app notice) before your information becomes subject to a different privacy policy.
We do not sell personal information for monetary or other valuable consideration, and we do not "share" personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act.
6. International data transfers
We are based in the United States and our servers are located in the United States (AWS us-east-2). If you access the Service from outside the United States, your personal information will be transferred to, stored, and processed in the United States. The sub-processors listed in Section 5.1 (including our error-monitoring provider, Sentry) are likewise located in the United States, with the exception of PostHog EU B.V., which stores and processes its analytics data in the European Union, and MailerLite, which stores newsletter subscriber data in the European Union.
For transfers from the United Kingdom, the European Economic Area, or Switzerland to the United States, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and, for transfers from the UK, the UK International Data Transfer Addendum to those clauses. Where required, we conduct transfer impact assessments and apply supplementary safeguards (encryption in transit and at rest, restricted access, no government data-sharing programs that we are aware of). You can request a copy of the relevant safeguards by emailing the privacy contact in Section 1.
7. Retention
We keep personal information only for as long as we need it for the purposes described in this Policy or as required by law.
- Account and reading data — kept until you delete your account. This includes your goals, Month in Books posts, blocks, the Book Signals you send, and your Terms acceptance record.
- Peanut Gallery posts — kept until you delete them or your account. When you delete your account, your takes and quotes are handled like public reviews (see the last item in this list) and your reactions are deleted.
- Community goals you published — the goal's wording and settings may remain after you delete your account, because other readers have joined it. You are no longer shown as a member.
- Cheers — deleted 90 days after you give them.
- In-app notifications — deleted 90 days after they are created, or sooner if you delete your account.
- Reports and book requests — kept for as long as we need them to moderate the Service and keep a record of what was reported and what we did, including after the account that filed them is deleted.
- Exit survey answers — kept after your account is deleted, so we can learn why readers leave. They are stored only under the derived identifier described in Section 2.3, never with your name, email address, or handle.
- Last-active day — kept until you delete your account. The anonymous daily totals derived from it contain no account identifier and are kept indefinitely.
- Spine images and stylized renders — private cropped images and their stylized renders are kept until you delete your account or we remove them. Non-private cropped images submitted for community review and their stylized renders may remain after account deletion, without a connection to your account. Temporary uploads in the
tmp/prefix that were never finalised are deleted seven days after upload. - Public catalog contributions — public book and edition details, covers, and edits may remain after you delete your account because other readers can use those entries. We remove their association with your account, including from the record of each edit. Private Custom Books and their covers are removed with your account.
- Record of catalog changes — a log, seen only by our team, of the public books and editions you add, the edits you make to public book details (what each edit changed), and when you add or change a Custom Book (never its title). We use it to review changes and undo harmful ones. Each entry is deleted automatically two years after it was made. When you delete your account, its connection to you is removed from every entry.
- Library import files you uploaded — kept for about ten days after upload so your import can be completed and, if you report a problem with it, investigated against the file you actually sent; then deleted automatically, or sooner if you delete your account. The books imported from the file remain in your library as ordinary reading data and are kept until you delete your account.
- Photos attached to feedback — deleted automatically 90 days after upload, whether or not the report was sent. Deleting your account does not delete them sooner; they expire on the same schedule. Uploads that fail the malware check are deleted within about two days. The feedback message itself and any diagnostic information are kept with your report.
- Frame and profile photos — kept until you replace or remove them, remove the picture frame or its shelf, choose a different avatar, or delete your account. Ending your membership does not remove them. If a moderator takes a photo down, it is removed from view straight away and a private copy is kept for 90 days for safety and legal reasons, then deleted automatically; deleting your account does not delete that copy sooner. If a photo appears to show the sexual abuse or exploitation of a child, we report it to the National Center for Missing & Exploited Children, as US law requires, and keep the photo and the information about the account that uploaded it for one year after the report, or longer if law enforcement asks us to. The file you upload is deleted within about two days, including one that fails the malware check. We keep a record of each upload (when you added it, where it is shown, and whether a moderator has reviewed it) for 30 days after the photo is replaced or removed, and for 30 days after an upload fails the malware check or can't be processed. The record of an upload whose check never finished is deleted after about two days. The record of a take-down, including the moderator's comment, is kept until you delete your account.
- Per-follower home-feed inbox copies — 90 days (the source-of-truth activity log on the actor is retained until the actor deletes their account).
- Book Signal delivery records — when a Book Signal is sent to you, a record of why it reached you (for example, that you follow the sender or read similar books), whether we sent you a notification about it, and whether it was shown in your feed, opened, or hidden. We use these records only to send future Book Signals to readers likely to want them. Deleted 180 days after the signal was sent, or sooner if you delete your account.
- Reader suggestion records — which readers we suggested to you and in what order, so we can avoid repeating them and tell whether suggestions help. Deleted 90 days after they were shown, or sooner if you delete your account.
- Reader suggestion pool — if your profile is public and you have been active recently, a short summary of that activity and of the kinds of books in your library, used to suggest you to other readers. Rebuilt daily, and deleted within a few days of your profile becoming private, your account being deleted, or two weeks passing without activity.
- Import reminder email records — when your library import is waiting for your review, a record of whether we sent you a reminder email and, if not, why (for example, that you turned reminder emails off). We use these records only to measure whether reminders help readers finish reviewing their import. Deleted 180 days after the decision was recorded, or sooner if you delete your account.
- Database point-in-time recovery backups — 35 days on a rolling basis.
- Daily database snapshots used for internal analysis — deleted automatically about three days after they are made.
- Access logs containing IP addresses — no more than 14 days.
- Crash and error diagnostic reports — retained by our error-monitoring provider for up to 90 days, then automatically deleted.
- App usage events — retained by our analytics provider for the standard retention period of our plan with them, and in any case no longer than we keep your account. When you delete your account, the events linked to it and the derived identifier described in Section 2.3 are deleted as part of the deletion process. If you turn off Share usage data in the mobile app, no further events are recorded for your account from the mobile app or from our servers; if you turn it off in the web app, no further events are recorded from that browser (see Section 2.3).
- Support correspondence — up to two years from the date of the last message, then deleted.
- Publicly posted reviews, Peanut Gallery takes and quotes, and non-private community image submissions on a deleted account — the user identifier is replaced with
deleted_userand uploader lookup keys are removed so the content is no longer linked to your account. The content itself may remain available to preserve public book discussions and the shared community spine library.
If you would prefer that public reviews, takes, or quotes you posted be deleted rather than pseudonymized, you can ask us by emailing the privacy contact and we will honor the request within the timelines in Section 9.
8. Security
We protect personal information with technical and organizational measures appropriate to the risk, including:
- Encryption in transit (TLS 1.2 or higher) for all traffic between your device and our servers, and between our servers and our service providers.
- Encryption at rest for the database and object storage.
- Strict access controls. Only a small number of administrators have production access, gated by multi-factor authentication.
- Separation of password hashing (Cognito) from application logic.
- Continuous monitoring, automated patching of dependencies, and a dependency-scanning pipeline in continuous integration.
No service can guarantee perfect security. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority in line with Articles 33 and 34 of the GDPR.
9. Your rights
Subject to applicable law, you have the following rights over the personal information we hold about you.
9.1 Rights available to everyone
- Access — request a copy of the personal information we hold about you.
- Rectification — correct inaccurate information. Most fields are editable directly in the app (profile, reviews, reading data).
- Erasure — delete your account and the personal information associated with it. You can start the process in the app at Account → Data → Delete account. Some information may be retained in backups for up to 35 days, in access logs for up to 14 days, and as pseudonymized public content, reports, and exit survey answers as described in Section 7. If a moderator took down one of your photos, a taken-down photo's private copy is kept for up to 90 days after the take-down, even after you delete your account, or for longer if we have reported it to the authorities (Section 7).
- Portability — receive a copy of your data in a structured, machine-readable format. You can download it yourself at any time at Account → Data → Download your data, in the mobile app or the web app. If you need something the download does not include, email the privacy contact and we will provide it within 30 days.
- Objection — object to processing based on our legitimate interests. For usage analytics you can exercise this yourself at any time, without asking us: turn off Privacy → Share usage data. In the mobile app that applies to your whole account. In the web app it applies to the browser you set it in, so set it in each browser you use, or email the privacy contact and we will apply it for your whole account.
- Restriction — ask us to restrict processing while we consider an objection or rectification request.
- Withdraw consent — where we rely on consent, withdraw it at any time.
9.2 California residents
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the rights above and the additional right to know the categories of personal information we collect, the categories of sources, the business purposes for which we collect or share it, and the categories of third parties with which we share it (all described in this Policy).
We do not sell personal information and we do not share personal information for cross-context behavioral advertising. Because we do not sell or share in that sense, we are not required to offer a "Do Not Sell or Share My Personal Information" link, and we have no financial incentive program to offer.
Sensitive personal information. The only category of "sensitive personal information" as defined by Cal. Civ. Code § 1798.140(ae) that we collect is your account log-in credentials (your email address together with your hashed password). We use this category only for the purposes that the CCPA exempts from the right to limit — namely, performing the services you reasonably expect, verifying or maintaining the quality or safety of the Service, and detecting, preventing, or responding to security incidents (Cal. Civ. Code § 1798.121(a) and the corresponding regulations). We do not use sensitive personal information to infer characteristics about you. Because we use it solely for those exempt purposes, the right to limit the use of sensitive personal information does not apply.
You may exercise your rights by emailing the privacy contact in Section 1. You may use an authorized agent to make a request; we will verify the agent's authority and your identity before responding. We will not discriminate against you for exercising your rights.
9.3 Other jurisdictions
If you live in Colorado, Connecticut, Utah, Virginia, Texas, Oregon, Montana, or another US state with a comprehensive privacy law, you have substantially the same rights described above, exercised in the same way.
If you live in Canada, Australia, New Zealand, the United Kingdom, the European Economic Area, or Switzerland, the rights described in Section 9.1 apply to you under the law of your jurisdiction.
9.4 How to exercise your rights, and our timelines
Email admins@theshelflifeapp.com. We will respond within 30 days for GDPR/UK GDPR requests and within 45 days for CCPA requests, with one extension where the request is complex. We may need to verify your identity before acting.
9.5 Right to complain
If you believe we have not handled your personal information properly, please contact us first so we can try to resolve the issue. You also have the right to lodge a complaint with your local data protection supervisory authority — for example, the UK Information Commissioner's Office or your country's national data protection authority in the EEA.
10. Children
ShelfLife is not directed at children under 13, and we do not knowingly collect personal information from children under 13 — within the meaning of the US Children's Online Privacy Protection Act or otherwise. Where local law sets a higher minimum age for using the Service (see Section 1 of our Terms of Service), we do not knowingly collect personal information from children under that higher age. If you become aware that a child below an applicable minimum age has provided personal information to us, please contact the privacy address and we will delete the information promptly.
11. Cookies and similar technologies
The web app uses localStorage to store an authentication token and a small number of UI preferences, and a session-scoped CSRF token cookie where required. These are strictly necessary to operate the Service and do not require consent under the EU ePrivacy Directive. The web app's signup form uses Cloudflare Turnstile, which sets a short-lived first-party cookie strictly necessary to perform the anti-bot challenge.
Our web app does not use analytics, advertising, or social-media-tracking cookies. It does use PostHog for product analytics (see Section 2.3), but that integration sets no cookies and writes nothing to localStorage or sessionStorage. While you are signed in, the identifier it uses is recalculated from your sign-in session on each visit rather than saved in your browser; signed out, it is a random identifier held in memory for a single page-load. This does mean that while you are signed in we can recognize you as the same reader across visits and devices, which we use to count how many people come back. That is why no consent banner appears in the web app: with no analytics storage on your device, the EU/UK/Swiss ePrivacy consent requirement described below does not apply.
The one exception is your own choice: if you turn off Share usage data, we save that preference in localStorage so we can keep honoring it. Storing a preference you have expressly asked us to remember is strictly necessary to provide what you requested, and needs no consent.
The marketing site uses Cloudflare Web Analytics, which operates without analytics cookies or cross-site tracking, and PostHog to measure pageviews, referral sources, on-page actions, heatmaps, and autocapture (see Section 2.3). Unlike Cloudflare Web Analytics, our marketing-site PostHog integration does use analytics cookies and browser storage for visitors who see it run by default or who explicitly accept it via the banner described below; visitors who decline, and visitors we never ask, are counted with a cookieless method that sets no cookies and uses no localStorage or sessionStorage. Our mobile app uses PostHog for product analytics only — no cookies, no session replay, no heatmaps. Usage events there are associated with an identifier derived from your account while signed in, or a random per-install identifier otherwise; never with your name or email address, and never used for advertising or shared for cross-app tracking. In the EU/EEA, the UK, Switzerland, Canada, South Korea, and China, the mobile app asks for your consent before this starts (see Section 2.3).
Opt-in consent banner (marketing site)
Because heatmaps and autocapture rely on browser storage, we show a consent banner on the marketing site to visitors we detect (by browser time zone, a heuristic — not precise geolocation) as likely being in the EU/EEA, the UK, or Switzerland. If you accept, we run marketing analytics with cookies as described in Section 2.3. If you decline, or before you answer, we fall back to the cookieless method described above: no cookies, no heatmaps, no autocapture — only an anonymous visit count. Visitors elsewhere are not shown this banner and get the cookie-based experience by default, consistent with US privacy law, which (unlike the EU/UK/Swiss ePrivacy rules) does not require opt-in consent for this kind of analytics cookie.
Opt-out preference signals (Global Privacy Control)
A growing number of US state privacy laws require businesses to honor universal opt-out preference signals — most commonly the Global Privacy Control (GPC) browser signal — as a valid request to opt out of the sale or sharing of personal information for cross-context behavioral advertising. Because we do not sell personal information and do not share personal information for cross-context behavioral advertising in the first place, a GPC signal does not change how we process your data. If we ever begin practices that would qualify as "sale" or "sharing" under those laws, we will treat a GPC signal from your browser as a valid opt-out without requiring any further action from you, and we will update this Policy first.
We do not respond to legacy "Do Not Track" signals because there is no industry consensus on what they require, but our practices already meet the common intent: we do not engage in cross-site tracking.
12. Third-party links
The Service may contain links to third-party websites (for example, Open Library pages for books). We are not responsible for the privacy practices of those websites. We encourage you to read their privacy notices before providing them with any personal information.
13. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will:
- Update the Effective date at the top of this document;
- Increment the version identifier; and
- Notify you with an in-app notice at least 30 days before the changes take effect.
Continued use of the Service after the new effective date constitutes acceptance of the updated Policy. If you do not agree, you may delete your account before the new date.
14. Contact
For any question, request, or concern about this Policy or our handling of personal information, contact: