Skip to content

Privacy policy

BookPocket keeps your reading life and the people behind it. This page says what we store, who can see it, who helps us run the service, and how to delete it all.

Last updated 29 September 2026.

Who runs BookPocket?

BookPocket is run by one person, R.J. LaCount. "We" on this page means R.J. For any question about your data, email privacy@bookpocket.app.

BookPocket is in early testing. We may change this policy as it grows. If a change affects what we do with your data, we email you before it takes effect.

What do we store about you?

  • Your account: your email address, your name if you give one, your picture if you add one, your time zone and your preferred format. We store your password only as a one-way hash, so nobody can read it.
  • Your books: what is on your shelf, statuses, reading dates, ratings, reviews, private notes, pause notes, tags and the sources you credit.
  • Your imports: the Goodreads or StoryGraph file you upload, and what we read from it. We keep the file in private storage that is not publicly readable, until you delete your account.
  • Where you are signed in: for each signed-in device, the IP address and browser it signed in from, so the session can be checked and ended.
  • Your phone, if you turn on notifications in the iOS app: a device token Apple gives us, which is how a notification finds your phone. Turning notifications off in iPhone Settings stops them.
  • Your friends: who you are friends with, and friend requests you have sent or received.
  • The waitlist: your email address and your name if you give one.

We count how many times each page of this website is opened each day, and which website linked to it. The count holds nothing about you: no IP address, no browser details and no cookie.

We use no advertising or tracking tools, and we do not sell or rent your data to anyone.

What do we store about other people?

Recording who recommended a book is the point of BookPocket. So you can store details about people who have not signed up and have not agreed to anything. We treat that data with extra care.

  • Sources you record: a name, what kind of source it is, how you know them, your note about them, a link and a picture. Only you can see them.
  • Pictures of sources are kept in private storage that is not publicly readable. Your own picture is in public storage, at an address nobody can guess.
  • Email addresses you send books or invitations to. The person gets one email, which names you, the book and your note. They can accept it or ignore it.

A source is only connected to someone's BookPocket account if that person agrees. Nobody can link your account to their source without you.

Who can see your data?

  • Anyone: book pages are public. They show the reviews readers write, with the reader's name, and an average of readers' ratings with how many there are. To hide your review of a book, press the lock on it.
  • Only you: your shelf, reading dates, private notes, pause notes, tags and sources.
  • Your friends see your name and that you are friends. Nothing else on your account is shown to them. If you decline a friend request, the person who sent it is not told.
  • People you send a book to see your name and your note. You see whether they accepted it and whether they have finished it, and nothing more.
  • Support: if you ask for help, a support account can look up counts and states on your account, such as how many books you have or whether an import failed. It cannot see titles, notes, reviews, tags or sources, and every lookup is logged.
  • R.J. can reach the database to keep the service running and fix problems, and only does so for that.

Who else handles your data?

We use a few services to run BookPocket. Each one gets only what it needs.

  • Hetzner hosts the servers and the database.
  • Cloudflare R2 stores pictures, book covers, import files and nightly database backups.
  • Apple delivers notifications to the iOS app, so it receives the device token and the notification's text.
  • Resend delivers our emails, so it receives the address and the message.
  • Open Library and the Library of Congress receive the words you search for and book identifiers such as ISBNs. They never receive your name or email address.
  • A cover address you paste is fetched once by our server. That website sees a request from BookPocket, never from you.

What do we keep in your browser?

  • A cookie that keeps you signed in.
  • A cookie that tells this site you have signed in before, so a button can say "Dashboard". It cannot sign you in.
  • A cookie that remembers whether you view My Books as a list or a grid.
  • Your theme and motion choices, stored in your browser only.

None of these track you across other websites.

How long do we keep it, and how do you delete it?

  • Your account stays until you delete it. To delete it, open your profile and use Delete your account. Everything goes, including the sources you recorded and their pictures.
  • Books you typed into the catalogue stay for everyone else, without your name on them.
  • Deleted data can remain in nightly backups for a short time, until those backups are replaced.
  • An unconfirmed waitlist signup is deleted once its confirmation link expires. To leave the waitlist, use the link in the email that confirmed your signup.
  • To get a copy of your data, or to ask us to correct or delete something, email privacy@bookpocket.app.