Privacy Policy
The short version. Shelvanize has no accounts and no sign-in. Your book collection is stored on your device and nowhere else. When you scan or type a book's barcode, the app sends that ISBN, and nothing about you, to our catalog service to look up the book's details, and when you search that catalog it sends what you typed and nothing about you. Book covers are fetched by your device from Open Library rather than from us, so their servers see your device's address and which cover it asked for. If the app crashes, or something inside it fails without crashing, a technical report goes to Google so we can fix it, and it never includes your books or anything you typed. There are no ads, no tracking, and nothing to sell, because we hold nothing about you.
You can export everything you have entered at any time, for free, and deleting the app deletes your data with it.
Who we are
Shelvanize is made by Laughter Consulting LLC. You can reach us at nic@laughterconsulting.com about anything in this policy.
What the app stores, and where
Shelvanize is a catalog of the physical books you own. Everything you put into it is written to a database on your own device. That includes the books you add, the shelves you create, the physical locations you name, any notes, ratings or measurements you enter, your lending records, and the arrangement passes you run.
None of it is uploaded. There is no Shelvanize account, so there is nothing for us to hold. We cannot see your collection, and we have no way to recover it for you if you lose your device, which is why the app makes exporting free and always available. What the app does send, and the one thing it fetches from someone else, are the subject of the next three sections.
What leaves your device
When you scan a book's barcode, or type one in, the app sends the 13-digit ISBN to our catalog service to look up the book's details. The service runs on Google Cloud Run in the us-central1 region. The request carries the ISBN and nothing else about you. There is no account, no device identifier, and no name, because none of those exist in the app to send.
When you open the app, it may also send the ISBN of a book already in your collection that has no classification yet, to check whether one has turned up since, at most about once a day for each such book and carrying nothing else about you. Those checks are not added to the count of look-ups described below.
You can also search that same catalog for a book by title, author or ISBN. The app sends what you typed, and which page of results it wants, to the same service, and gets back a list of matching books. Nothing else rides along. There is no account, no sign-in, no cookie and no device identifier on the request, and the app identifies itself only by its name and version number. It does not say what kind of device you are using or what version of the operating system it is running.
Our service does not record what you searched for. The log it keeps of a request holds the method, which endpoint was called, the response status and how long the work took, and never the words in the request itself.
Our service keeps a count of how often each ISBN has been looked up and when it was last requested. Those records carry no identity, and the table they live in has no user column at all. They are kept for a limited period and then deleted. Searching keeps no record of any kind. There is no row and no counter anywhere for the words you type, so there is nothing about a search for us to keep, to hand over, or to delete.
As with any cloud service, our provider records standard request logs for the API, which include IP addresses and the requested URL, for security and reliability. The URL of a barcode lookup contains the ISBN, and the URL of a search contains the words you typed. That log belongs to the platform our service runs on rather than to the service itself, and we do not use it to identify you.
When the app crashes or hits an error
If the app crashes, or if something inside it fails without crashing (a save that does not complete, a scanned book it cannot match, a book lookup that comes back wrong), a technical report goes to Google's Crashlytics service so we can find and fix the problem. The report says what the app was doing internally, drawn from a fixed set of technical event names we wrote ourselves, along with your device model, its operating system version, and an identifier for that installation of the app. The identifier is not tied to you. There is no account, so there is nothing to tie it to.
The same service also records that the app started, each time it starts, so it can tell how many sessions ended in a crash. That record carries a session identifier, the same installation identifier and device details as a crash report, and nothing about what you do in the app.
These reports never contain your books, your shelves, your searches, your notes, the names of anyone you have lent a book to, or anything you typed. The code that builds a report has no way to include them.
Google keeps crash reports for 90 days and then begins removing them. That number is Google's, from Google's Crashlytics disclosure, which also describes what Crashlytics collects.
Book cover images
Cover images do not come from our catalog service. When a book needs one, the app asks Open Library for it directly, at covers.openlibrary.org. Open Library is the project our book records come from, and it is run by the Internet Archive.
Because that request does not go through our service, it travels from your device straight to theirs. Their servers therefore see your device's IP address and which cover it asked for, and a cover identifies a book. We send it directly on purpose. Putting every user's covers through one of our servers is the pattern Open Library asked us not to build, and it would also stand our entire user base behind a single address.
Each cover is fetched at most once per device. The first time a book needs its cover the image is saved on your device, and after that it is read from there, so opening the same shelf again never asks for it a second time. If Open Library answers that it has no cover for a book, the app remembers that answer and never asks again.
The request carries nothing about you. There is no account, no cookie and no device identifier on it, and the app identifies itself only by its name and version number. The covers saved on your device are erased along with everything else by the delete-all option in Settings, and by uninstalling the app.
What we collect about you
We collect no analytics and no telemetry beyond the error and crash reports described above. Apart from those reports, the catalog lookups and the searches described above, nothing you do in the app is reported to us, and your collection and your reading activity stay on your device. Book covers are fetched by your device from Open Library rather than from us, which is described above in full. There are no advertising identifiers, no third-party advertising or marketing software development kits, no location tracking, and no contact list access. We do not build a profile of you, and we do not sell or share personal information with anyone, because we do not have any.
On Android, the third-party library that reads barcodes and cover text (Google's ML Kit) may report its own technical diagnostics, such as device and app information and performance metrics, to Google, as described in Google's ML Kit disclosure.
Your reading and lending records
What a person reads, and who they lend books to, is sensitive. We treat it that way. Your reading history, your lending records, and the names of anyone you have lent a book to stay on your device, are never transmitted to us or to anyone else, and are deliberately excluded from the app's diagnostic logs. Asking Open Library for a cover does tell them which book's cover was needed, as described above, and it carries none of these records with it.
The app never generates commentary about your taste, your habits, or what your collection says about you. That is a deliberate product decision, not an oversight.
Permissions the app asks for
- Camera, to scan barcodes and read the text on a book's cover. All recognition happens on your device, and camera frames are never sent anywhere. On iOS, a captured still exists only in memory and is discarded when you leave the screen. On Android, captured stills live in the app's private cache and are removed when you leave the screen, and by Delete All Data.
- Notifications, only if you set a return date on a book you have lent out. The reminder is scheduled by your device and fires locally, with no server involved. If you decline the permission, lending still works in full and the app simply tells you it cannot remind you.
- Files, only when you choose to export or import. The app writes to the location you pick and reads the file you pick, and nothing else.
Each permission is asked for at the moment the feature needs it, and declining any of them never blocks the rest of the app.
Children
Shelvanize is not directed at children under 13, and since the app collects nothing that identifies anyone, it collects nothing that identifies a child.
Your data, and your control over it
Because everything lives on your device, you already have complete control. Export your entire collection to CSV or JSON at any time, at no cost and with no subscription required, including while offline. Delete everything from inside the app with the delete-all option in Settings. Uninstalling the app removes its database from your device.
None of these are paid features and none of them will ever become paid features. If you subscribe and then cancel, everything you entered stays readable, editable and exportable.
Payments
If Shelvanize offers a paid feature, the purchase is handled entirely by Apple or Google. We never see or store your payment details. We receive only whether your purchase is active.
Where the book information comes from
Book records shown in Shelvanize come from Open Library, a project of the Internet Archive, which publishes its catalog into the public domain. We host our own copy of that catalog, built from Open Library's published data files, so your lookups and your searches go to our service rather than to Open Library. For books our catalog cannot classify, our service asks the Library of Congress about the ISBN on its own schedule, from our servers rather than from your device, carrying nothing about you. Cover images are the exception and are fetched from Open Library directly, which is described above. Looking up a book by its barcode tells us which book was looked up, as described above, and nothing about you. A search tells us nothing that we keep.
Changes to this policy
If we change this policy, we will change the version number and effective date at the top. If a change affects what leaves your device, we will say so in the app rather than only here.
The website
shelvanize.com is a static site with no analytics, no advertising, and no tracking cookies. Our host keeps standard server request logs, which include IP addresses, for security and reliability. We do not use them to identify you.
Contact
Questions about privacy go to nic@laughterconsulting.com.