Your data, plainly explained
Privacy Policy
Effective August 31, 2026
Read & Rec'd is local-first. You can manage a reading library without an account. If you create an account, the app uses account data to protect your library in the cloud, deliver private book Rec'ds, and provide optional connections and friend-library sharing. We do not sell personal information, serve third-party ads, or track you across other companies' apps or websites.
Information on Your Device
Your reading library is saved on your device first. It can include book titles and authors, cover links, formats, reading status and order, dates, reactions, recommendation drafts, tags, notes, reading goals, imported source information, and local profile preferences. This information remains on the device unless you choose an app feature that sends it elsewhere, such as signed-in cloud protection, a private Rec'd, an optional friend shelf, book search, Spotify import, export, or support contact.
Account and Profile Information
An account is optional. If you create one, we process your email address, an internal account identifier, authentication session information, display name, username, profile description, format preferences, Rec'd delivery preference, and friend-library visibility choice. Supabase provides authentication and database services. Supabase handles your password authentication; Read & Rec'd does not receive or store your plaintext password.
Cloud Library Protection
When you sign in and protect a library, Read & Rec'd stores an account-linked backup with Supabase. The backup can contain the device-library information described above, including books, notes, tags, goals, reading order, reactions, dates, and recommendation provenance. This is a backup and deliberate restore service, not public sharing or live community activity. Database access controls restrict a backup to its owner.
Private Book Rec'ds
If you send or receive a private Rec'd, Supabase stores the participants' account identifiers and sender profile snapshot, book title and author, optional cover and publication details, format and source, your optional recommendation note, delivery status, and timestamps. A Rec'd is available only to its sender and recipient. Exact-username lookup returns only a matching reader who has chosen to receive Rec'ds; the app does not provide public profile browsing or partial-username discovery.
Friends, Blocking, and Shared Shelves
Signed-in readers can connect only by entering another reader's exact Rec'd username. Supabase stores the two participants' account identifiers, request or accepted status, and timestamps. The app does not provide partial-username search, suggested friends, contact uploads, followers, or public profile browsing. Removing a friend deletes the connection. Blocking stores the blocker and blocked account identifiers so requests, shared shelves, and private Rec'd delivery remain unavailable in both directions; a block list is visible only to the reader who created it.
Friend-library sharing is off by default. If you choose Reading activity or Full reading stack, Read & Rec'd stores a separate account-linked snapshot containing only the book title, author, optional cover and publication year, selected genres, format, reading section, and Loved or Liked state. It does not include email, private notes, personal tags, goals, Rec'd notes or provenance, cloud-backup contents, or exact stack order. Only currently accepted, unblocked friends can request the snapshot. Choosing Nothing deletes the snapshot; removing or blocking a friend immediately ends that reader's access.
Optional Push Notifications
If you explicitly turn on notifications, Read & Rec'd stores an account-linked Expo push token, device platform, enabled status, and registration timestamps with Supabase. Expo's push service and Apple Push Notification service process the token to deliver an alert when another reader sends you a private Rec'd or when a friend request is received or accepted. The lock-screen alert may identify the other reader but does not include a book title, private recommendation note, or shared-library contents. Declining, canceling, removing, or blocking a connection does not send a friend alert.
Turning notifications off stops delivery but may retain the disabled registration so you can turn it back on. Signing out removes that account's registration for the phone, account deletion removes its registered devices, and invalid tokens may be disabled automatically. You can also change notification permission in iOS Settings.
Book Search and Imports
Open Library
When you search for a book, the search text is sent directly to Open Library so it can return book metadata and cover images. We do not intentionally attach your Read & Rec'd account identity to those searches. Open Library may receive ordinary request information such as your IP address and device or browser details under its own privacy policy.
Spotify
Spotify connection is optional. If you connect it, Spotify authenticates you and Read & Rec'd requests access to view your saved audiobooks so you can choose titles to import. The app does not ask for Spotify playback control and does not sync listening progress. The Spotify access token is used for the active connection and is not included in your Read & Rec'd library. Imported audiobook metadata becomes part of your device library and, if cloud protection is active, your account backup.
Files You Choose
Import uses the system file picker for a Read & Rec'd JSON export or Goodreads CSV that you select. Export uses the system share sheet and sends the file only to the destination you choose. The app does not request unrestricted access to your files.
Support and Service Messages
Google email services deliver account confirmation and password-recovery messages and receive support mail you choose to send. A support message may include your email address and whatever details you provide. Do not send passwords, authentication codes, access tokens, or sensitive reading notes in a support request.
Technical Information
Our hosting and service providers may process standard connection and security information—such as IP address, device or browser type, request timestamps, and diagnostic logs—to deliver and protect their services. Read & Rec'd does not include an advertising SDK, cross-app tracking SDK, or a third-party product analytics SDK in this release.
How We Use Information
- Provide the reading library, account, backup, private Rec'd, Friends, optional shared-shelf, search, and import features you request.
- Authenticate accounts, confirm email ownership, recover passwords, and keep sessions secure.
- Prevent unauthorized access, investigate failures, and maintain service reliability.
- Respond to support, privacy, and deletion requests.
Service Providers and Disclosure
We use service providers only as needed to operate these features: Supabase for authentication, database, cloud backup, and server functions; Expo and Apple for optional push-notification delivery; Google for account/support email delivery; Open Library and the Internet Archive for book search and covers; Spotify for optional audiobook import; and Cloudflare for these public pages. Their processing is governed by their own terms and privacy policies.
We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising. We may disclose information when required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards and notice where required.
Retention and Deletion
Device-library data remains until you delete it, erase the device library, remove the app, or the operating system removes app data. Account, profile, cloud backup, private Rec'd, friendship, block, and optional shared-shelf data remain while needed to provide the account. In the app, open Profile → Library & backup → Delete account to permanently delete the account and associated cloud profile, backup, Rec'd, friendship, block, shared-shelf, and device-registration records. You separately choose whether to keep the reading library on that device or erase it too.
Service-provider backups and security logs may persist for a limited period under provider retention schedules and are not used to recreate a deleted account. Support correspondence may be retained as reasonably needed to resolve the request, maintain security records, and meet legal obligations.
Your Choices
- Use the core local reading library without creating an account.
- Choose whether readers with your exact username can send private Rec'ds.
- Send, accept, decline, or cancel friend requests by exact username; remove friends; and block or unblock readers.
- Keep your friend library private or share only Reading activity or your Full reading stack with accepted friends.
- Choose whether this phone receives Rec'd and friend-request notifications, and change notification permission in iOS Settings.
- Disconnect Spotify by ending the app connection and revoke access from your Spotify account settings.
- Edit or delete library items, export a portable copy, or erase the device library.
- Delete your cloud account in the app or contact support if you cannot access it.
Depending on where you live, you may have additional rights to access, correct, delete, or restrict use of personal information. Contact us to make a request. We may need to verify that you control the relevant account.
Security
We use platform security features, encrypted network connections, authenticated access, and database access controls designed to protect account data. No storage or transmission method is completely secure, so we cannot guarantee absolute security.
Children
Read & Rec'd is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Contact us if you believe a child provided personal information so we can investigate and delete it as appropriate.
Changes to This Policy
We may update this policy as the app changes. We will post the revised policy here with a new effective date. Material changes may also be communicated in the app or through another appropriate channel.
Contact
For privacy questions or data requests, email readandrecd.support@gmail.com.