Privacy Policy
Short version: BookHoard does not sell your data, does not use your data for advertising, and does not share your reading information with third parties beyond what is strictly necessary to operate the app. Your library is yours.
1. Who we are
BookHoard is a personal library app available on Android and iOS. This policy explains what data we collect, why we collect it, and how it is used and protected.
If you have questions or requests about your data, contact us at support@bookhoardapp.com.
2. Data we collect and why
Account information
When you create a BookHoard account, we collect your email address. This is used solely to authenticate your account, send you password-reset emails, and deliver essential transactional messages. We do not use your email address for marketing.
Library data
BookHoard stores the library data you choose to add: book titles, authors, ratings, personal notes, tags, reading format (physical, digital, or audiobook), and location tags. This data is synced to a secure cloud database so you can access your library across devices. It is never shared with third parties, never used for advertising, and never sold.
Genre preferences
During onboarding, you may select genre preferences. These preferences are stored with your account and used only to improve your in-app recommendations.
Camera
BookHoard uses your device camera for two purposes: scanning ISBN barcodes and scanning bookshelf photos. Images captured during these scans are never stored on our servers and are never transmitted beyond the scanning process. Shelf photos are processed on-device or passed directly to our AI provider (see Section 3) for recognition and are immediately discarded.
Approximate location
The bookstore finder feature uses your device's approximate location to show nearby independent bookstores. Location access is requested only when you use this feature. Your location is never stored and never shared — it is used in real time to query a map service, then discarded.
Purchase and subscription data
If you subscribe to Hoard+, purchase validation data (receipt information) is handled by our subscription provider, RevenueCat. This data is used solely to confirm your subscription status. It is not used for advertising and is not sold.
Crash and error data
We collect anonymised crash reports and error logs to help us fix bugs and improve stability. These reports contain no personal information, no reading data, no book titles, and no user identifiers. See Section 3 for details on our crash monitoring provider.
3. Third-party services (vendors)
BookHoard uses the following third-party services to operate. Each vendor is listed with a description of what data they receive and why.
Supabase — Database & Authentication
Supabase stores your account information (email address) and your library data. All data is stored in a secure, access-controlled database. Supabase acts as our data processor and does not use your data for any purpose other than providing database services to BookHoard. → supabase.com/privacy
Anthropic — AI Recommendations
BookHoard uses Anthropic's AI models to generate personalised reading recommendations and to power the "Find Similar Books" feature. For recommendations, we send anonymised library patterns — genre breakdown, rating distributions, and tag patterns. For "Find Similar Books", the title of the book you are viewing is sent. We never send personal notes, your email address, or any other personally identifiable information to Anthropic. Data sent to Anthropic is used only to generate your response and is not used to train AI models. → anthropic.com/privacy
Google Places API — Bookstore Finder
When you use the bookstore finder, your approximate location is sent to the Google Places API to return nearby bookstore results. Google receives only the location coordinates — no account information, no library data. Location data is not stored by BookHoard after the query completes. → policies.google.com/privacy
Resend — Transactional Email
Resend delivers transactional emails on our behalf, including password-reset emails and authentication messages. Resend receives your email address solely for the purpose of delivering these messages. → resend.com/privacy
Sentry — Crash Monitoring
We use Sentry to monitor app stability. Error reports are anonymised — they contain no personal data, reading history, book titles, or user identifiers. We do not use Sentry's Session Replay feature. Error data is retained for 30 days. → sentry.io/privacy
RevenueCat — Subscription Management
We use RevenueCat to manage subscriptions. RevenueCat may collect purchase history solely for receipt validation and subscription management. This data is not used for advertising and is not sold. → revenuecat.com/privacy
Google Books API — Book Metadata
When you scan a barcode or search for a title, BookHoard queries the Google Books API to look up book details (title, author, cover image, description). Only the ISBN or search term is sent — no personal data, no account information, no library contents. → policies.google.com/privacy
New York Times Books API — Bestseller Lists
The Discover section displays NYT Bestseller lists sourced from the New York Times Books API. No personal data is sent to the NYT API — requests contain only the list name being fetched. → developer.nytimes.com
OpenStreetMap / Overpass API — Little Free Libraries
The Nearby tab uses the OpenStreetMap Overpass API to find Little Free Libraries near you. Your approximate location coordinates are sent to perform the search. No personal data or account information is transmitted. Map data is © OpenStreetMap contributors, available under the Open Database Licence.
PEN America — Banned Books Data
BookHoard's banned books feature uses publicly available data from PEN America's Index of School Book Bans. This data is downloaded to our servers periodically and is not a live API call from your device. No user data is sent to or received from PEN America. → pen.org/book-bans
4. Data we do not collect
- We do not collect or store shelf photos or barcode scan images.
- We do not track your location persistently or store it.
- We do not embed any advertising SDKs or third-party tracking libraries.
- We do not build advertising profiles or share data with ad networks.
- We do not sell your data — ever.
5. Data retention
Your account and library data are retained for as long as you have an active account. Crash and error data collected by Sentry is retained for 30 days. If you delete your account, your library data and account information are deleted from our systems.
6. Your rights and choices
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and all associated data.
- Export your library data (available in the app).
You can delete your account directly in the app via Settings → Account → Delete Account. This will permanently delete your library data and account information. For any other data requests, contact us at support@bookhoardapp.com.
7. Children's privacy
BookHoard is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
8. Changes to this policy
If we make material changes to this privacy policy, we will update the effective date at the top of this page and, where appropriate, notify you within the app. Continued use of BookHoard after changes take effect constitutes acceptance of the updated policy.
9. Contact
Questions, concerns, or data requests — please email us at support@bookhoardapp.com. We aim to respond within 5 business days.