Privacy Policy
The Realm — A bookshelf for your heart.
Effective Date: [LAUNCH DATE]
Last Updated: [LAUNCH DATE]
1. Who we are
This Privacy Policy explains how Allyoucanreserve Ltd ("we", "us", "our") collects, uses, shares and protects your personal data when you use The Realm mobile application and related services (the "Service" or "App").
Data Controller:
Allyoucanreserve Ltd
A private limited company registered in England and Wales (company number 10162791)
Registered office: 124 City Road, London, England, EC1V 2NX, United Kingdom
For any privacy question or request, contact: privacy@therealmshelf.app
We act as the data controller for the personal data described in this Policy. We have not appointed a Data Protection Officer because we are not required to; the email address above is monitored for privacy matters.
2. The laws this Policy is written for
- The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018;
- The EU General Data Protection Regulation (EU GDPR), for users in the European Economic Area;
- The Privacy and Electronic Communications Regulations (PECR);
- United States state privacy laws, including the California Consumer Privacy Act as amended by the CPRA ("CCPA") and comparable laws of Virginia, Colorado, Connecticut, Utah and other states (see Section 14);
- The Children's Online Privacy Protection Act (COPPA) (see Section 15);
- The privacy requirements of the Apple App Store and Google Play Store.
3. The short version
- We collect what we need to run the Service, and no more.
- No advertising. The App contains no third-party advertising and no ad tracking.
- We never sell your personal data, and we do not "share" it for cross-context behavioural advertising (as those terms are defined in the CCPA).
- Your reading notes, personal cover images and cover designs stay on your device. They are not uploaded, and we hold no copy of them. The one exception is an image you choose to put through the background remover, which has to be sent off to be processed (Section 7).
- Your ratings and reviews are private by default. Other readers see them only if you explicitly choose to share them when publishing a shelf.
- Payments are handled by Apple and Google. We never see your card details.
- You can delete your account — and all server-side data — inside the App (Settings → Manage Account → Delete Account & All Data).
The rest of this Policy is the detail behind that summary.
4. The data we collect
4.1 Data you give us directly (stored on our servers)
| Category | Examples |
|---|---|
| Account data | Email address; or the identity from Sign in with Apple / Google Sign-In (see Section 4.4 — Apple lets you hide your real email); display name; handle; bio; avatar photo; favourite genre; the books you choose to feature on your profile (currently reading, all-time favourite); Instagram/TikTok handles if you add them |
| Your library | Books on your lists (Read, TBR, Currently Reading, DNF, Favourites, custom lists), formats, when you added them |
| Ratings & reviews | Star ratings, short reviews ("The Verdict") and extended reviews — private by default; shared only if you opt in when publishing a shelf |
| Shelves | Shelf names, book arrangements, decor placements, rendered shelf images, captions, publish status |
| Social activity | Follows, likes, saves, comments (including @mentions), users you block, reports you submit |
| Spine photo submissions | A photo you add as your own spine for a book. The App uploads it when you add it and queues it for review by our staff (see Section 8.3 — after review, approved spines can appear on other users' shelves) |
| Background-remover results | The cut-out image produced when you use the background remover (Section 7) |
| Notification data | Your notification preferences and device push tokens |
| Support & feedback | Messages you send us; feedback you type into the App's feedback box (delivered to us through Sentry — see Section 4.3) |
4.2 Data that stays on your device only (never uploaded)
- Reading notes, including any photos you add to notes;
- Personal cover images you set for books (other users always see the original cover);
- Cover designs created in the Covers studio, including their edit history;
- Local preferences and caches (for example your last-open shelf).
This data lives only in the App's storage on your device, and we have no copy. It is deleted when you delete it or the App (or clear the App's data in your device settings), when you delete your account, and when a different account signs in on the same device — in that last case the App tells you what would be removed and asks first, and nothing is removed if you go back. Logging out on its own keeps it, so think twice before lending a signed-out device to someone who will sign in with their own account.
The one exception to "never uploaded": if you put one of these images through the background remover, that image is sent for processing as described in Section 7. If we ever add an optional cloud backup for this data, the App will say so clearly before anything is uploaded.
4.3 Data collected automatically
| Category | Details |
|---|---|
| Crash and error data | Collected via Sentry when the App crashes or errors: a pseudonymous user id, device model, OS version, App version and the technical state of the error. It is linked to your account only through that id. Session replay is disabled. Your name and email are never sent to Sentry. Feedback you send from the App's feedback box reaches us through the same service and contains the text you typed. |
| Technical data | Device type, OS version, App version, language and time zone. Your IP address is inherently visible to servers when the App makes requests; we do not use it to track you. |
| Bot check on the sign-in screen | When the sign-in screen opens, Cloudflare Turnstile checks that the request comes from a real device and not a script. Cloudflare receives your IP address and technical signals about your device and the embedded browser view the check runs in; we receive only a pass-or-fail token (see Section 11). |
| Aggregate product signals | Non-identifying counts used to rank the book catalogue (for example how often a book is added across all users). |
| Fair-use counters | Per-account counts that enforce limits on costly features (book search, cover analysis, background removals): how many times you used the feature in a period — not what you searched for or uploaded. |
| App usage | A few events linked to your account, stored in our own database: that you opened the App (at most once a day), that you reached a free-tier limit (and which one), that the upgrade screen was shown (and from where), and that you subscribed (and to which plan). We use them only to set fair free-tier limits and to see whether the paid tier is worth offering — never for advertising, and they are never shared or sold. |
We do not collect: precise location, contacts, calendars, microphone audio, browsing history or advertising identifiers. We use no third-party analytics SDKs — the usage events above never leave our own database.
4.4 Data we receive from others
| Source | What we receive |
|---|---|
| Apple (sign-in) | Your email address — or the private relay address Apple creates if you choose to hide it — and Apple's identifier for your account. The App asks Apple for your name but does not keep it or send it to our servers. |
| Google (sign-in) | Your name, email address and the web address of your Google profile picture, as contained in Google's sign-in token. Our authentication provider stores them with your account; the App itself does not use the name or picture. |
| Apple / Google / RevenueCat (purchases) | Confirmation a purchase was made, plan type and renewal status — never your card details |
| Google Books API, Open Library | Book metadata (titles, authors, covers, page counts) — data about books, not about you (see Section 8.5 for what these services receive) |
We never share sign-in data with advertising platforms or data brokers, and we do not combine an Apple private relay address with information from elsewhere to work out who you are.
5. Payments — we never see your card
All purchases are processed by Apple (App Store) or Google (Google Play). We never receive your card number, CVV or billing address. Subscription status is managed for us by RevenueCat, Inc., which receives store receipts and tells the App whether your account has the paid tier (revenuecat.com/privacy). So that your purchase follows your account across devices, your Realm account id is used as the RevenueCat customer id.
6. Why we use your data, and our lawful bases
Under UK and EU GDPR every use of personal data needs a lawful basis. Ours:
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating your account, signing you in, running the Service | Account data | Contract (Art. 6(1)(b)) |
| Core features: library, shelves, reviews, Covers, Browse | Library, shelves, reviews, social activity | Contract |
| Showing your published content to other users | Published shelves, shared reviews, comments, profile | Contract — publishing is always your explicit action |
| Ranking the Browse feed and book search | Aggregate signals, follows, likes and saves | Contract, plus legitimate interests (a useful feed) |
| Processing your subscription | Purchase confirmations | Contract |
| Push notifications about activity on your account | Push tokens, notification preferences | Consent — withdraw any time in Settings or device settings |
| Safety: moderation of submissions and comments, blocks, reports | Submissions, comments, reports | Legitimate interests (a safe service) and legal obligation where applicable |
| Protecting sign-in from automated abuse (bot check) | IP address and device signals, processed by Cloudflare | Legitimate interests (a secure service that scripts cannot misuse) |
| Fixing crashes and defects | Crash and error data | Legitimate interests (a working product) |
| Setting free-tier limits and deciding what the paid tier offers | App usage events | Legitimate interests (a fair free tier and a sustainable service) |
| Complying with the law | As required | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests we have balanced them against your rights, and you may object (Section 13). We make no automated decisions with legal or similarly significant effects, and we do not deliberately process special-category data (what you reveal in free-text content is your choice).
7. AI features — what leaves the App
Two features use external AI services, both narrowly:
- Generated book spines and cover colours. To draw a book's spine in your shelf's style, the book's public cover image (from the book catalogue — not your photos) and the book's title may be analysed by Anthropic's Claude API. No personal data about you is included.
- Magic background remover (a paid Covers feature). This is the one case where one of the device-only images in Section 4.2 leaves your device: the first time you use it, the App tells you where the image goes and asks for your permission; after that, the image you explicitly choose is sent to our server and on to Replicate, Inc., an AI service, which removes its background and returns the result. We do not store the original image. The finished cut-out is stored on our servers until you delete your account, at an unlisted web address — it is not shown to other users, but it is not password-protected, so anyone who had the exact address could open it. Only submit photos you have the right to use.
Both providers process images solely to provide the feature. We do not use your content to train AI models.
8. Who we share data with
We do not sell personal data. We share it only as described here.
8.1 Service providers (processors)
| Provider | Role | Location |
|---|---|---|
| Supabase, Inc. | Our backend: database, authentication, file storage, server functions. Project hosted in the United Kingdom (London) | USA (company); your data is stored in the United Kingdom (London) |
| Apple Inc. | App distribution, payments, sign-in, push delivery (APNs) | USA |
| Google LLC | App distribution, payments, sign-in, push delivery (FCM), Google Books API | USA |
| RevenueCat, Inc. | Subscription management | USA |
| Resend, Inc. | Delivery of sign-in codes and email-change confirmation codes: receives your email address and the message containing the code | USA (EU sending region) |
| Cloudflare, Inc. | Bot check on the sign-in screen (Turnstile — Sections 4.3 and 11); routing of email you send to our support and privacy addresses; our domain and website | USA (global network) |
| Proton AG | The mailbox that receives messages you send to our support and privacy addresses (Cloudflare forwards them there) | Switzerland |
| Functional Software, Inc. (Sentry) | Crash and error reporting, and delivery of in-app feedback — EU data residency, pseudonymous ids only | USA, EU ingest |
| Expo (650 Industries, Inc.) | Push notification delivery (receives the device push token and the notification text, which can include another user's display name); delivery of App updates — the App checks Expo's servers for a newer version of its code | USA |
| Anthropic, PBC | AI analysis of public book cover images (Section 7) | USA |
| Replicate, Inc. | Background removal of images you submit to the background remover (Section 7) | USA |
8.2 Other users — what they can and cannot see
Your profile can be viewed by other signed-in users. It shows: your display name, handle and avatar; your bio, favourite genre and follower/following counts; your Instagram/TikTok handles if you added them; and the books you chose to feature (currently reading, all-time favourite).
When you publish a shelf, other users can also see: the shelf's name, caption, image, books and decor; and — only if you opted in — your shared ratings and reviews for its books. Comments you write are visible to anyone who can see that shelf. Your public profile lists your published shelves and shared reviews, including via your profile link.
Your profile link (therealmshelf.app/your-handle) also works for people who are not signed in. Without signing in, a visitor can see: for a public account, your display name, handle, avatar, bio and how many published shelves and followers you have; for a private account, only your display name and avatar.
If you set your account to private, people have to ask before they can follow you. Anyone signed in can send a follow request; you see who is asking and accept or decline it, and declining tells the other person nothing. Until you accept, they see only your display name and avatar — not your bio, counts, featured books, shelves or reviews. Your shelves, featured books and shared reviews are shown only to followers you have approved. You can remove a follower at any time (they are not told), and blocking someone also removes them. Followers you already had when you switched to private stay; if you switch back to public, requests still waiting are accepted, because what they asked to see is public by then.
Other users can never see: your reading notes, personal cover images, cover designs, your library lists (apart from the books you choose to feature on your profile), ratings or reviews you have not shared, your email address, or your unpublished shelves.
8.3 Spine submissions
When you add your own spine photo for a book, the App uploads it to our servers and places it in a review queue — this happens automatically when you add the photo. Our staff look at it, and if they approve it as the canonical spine for that book, it will render on any user's shelf containing that book. Your name is not displayed with it.
Until then it is used only on your own shelves — which includes the picture of any shelf you publish, so other users can see it there.
Choosing "Revert to original spine" removes the photo from your device and your shelves, and deletes the uploaded copy from our servers as long as our staff have not approved it yet. A photo that has already been approved stays in use for other users; email privacy@therealmshelf.app if you want it removed. All your submissions, including approved ones, are deleted when you delete your account.
8.4 Legal, safety and business transfers
We may disclose personal data where necessary in good faith to comply with law or a binding order; to protect the rights, property or safety of our users, ourselves or the public; to investigate fraud or abuse; or to enforce our Terms. If we are involved in a merger, acquisition or asset sale, personal data may transfer to the successor, who must honour this Policy; we will notify you of any such change.
8.5 Book data sources your device contacts directly
To find books and show their covers, the App on your device talks directly to two independent services:
- Open Library (run by the Internet Archive, USA): the App sends the search text or ISBN you entered and downloads cover images.
- Google Books: the App sends an ISBN to look for a better cover and downloads cover images. Text searches of Google Books go through our servers instead, without your account details.
As with any internet request, these services can see your IP address. They do not receive your account details. They are not our service providers: they act independently, under their own privacy policies.
9. International transfers
Some providers process data in the United States, and Cloudflare operates a global network, so its bot check may be handled in a data centre near you. Where personal data leaves the UK or EEA we rely on: adequacy decisions (including the EU–US Data Privacy Framework and UK–US Data Bridge where the provider is certified); the European Commission's Standard Contractual Clauses and/or the UK International Data Transfer Addendum; and additional safeguards where appropriate. You can request a copy of the relevant safeguards via the privacy email above.
10. How long we keep data
| Data | Retention |
|---|---|
| Account, library, shelves, reviews, social data | While your account exists |
| Push tokens | Removed on sign-out and on account deletion |
| Follow requests to or from a private account | Until the request is accepted, declined or cancelled, or either account is deleted or blocks the other |
| Notifications in your activity list | Deleted automatically after 180 days (90 days once read) |
| Push delivery log (who was notified about which kind of event — used only to stop notification spam) | Deleted automatically after 7 days |
| Books you remove from your library | Marked as removed so your other devices learn of it, then deleted for good after 180 days |
| Books and decor you remove from a shelf | Marked as removed so your other devices learn of it, and kept in that state until you delete your account |
| Spine photo submissions and background-remover cut-outs | Until you delete your account |
| Fair-use counters | Deleted automatically after 90 days; the monthly background-removal count is kept while your account exists |
| Crash and error data (Sentry) | Deleted automatically per Sentry retention (typically 90 days) |
| App usage events | Deleted automatically after 24 months, and at once when you delete your account |
| Purchase records | Per the stores' and RevenueCat's retention; our accounting records up to 6 years (UK law) |
| Device-only data (notes, cover designs, personal covers) | Entirely under your control — deleted when you delete them or the App; Section 4.2 lists the other cases |
| Backups | Rotated and overwritten in the ordinary course |
Account deletion is built into the App (Settings → Manage Account → Delete Account & All Data). It deletes your server-side data — profile, library, shelves, reviews, comments, follows and uploaded images including spine submissions and background-remover cut-outs — subject only to records we are legally required to keep and short-lived backups. It also clears the App's data on the device you delete from, including the device-only data in Section 4.2.
11. How we protect your data
- All traffic between the App and our servers is encrypted in transit (TLS); data is encrypted at rest by our hosting providers.
- Passwordless sign-in: one-time email codes or Apple/Google sign-in — we never store a password for your account. (The only account with a password is a demonstration account we provide to the app stores' reviewers.)
- A bot check (Cloudflare Turnstile) on the sign-in screen, so that scripts cannot use it to send sign-in emails in bulk.
- Row-level security on our database, so an account can only read what it is allowed to see.
- Least-data design: feed and profile queries fetch only what the screen needs.
- Human review of submitted spine photos before they can be used as a book's spine on other users' shelves.
- Regular security audits of the codebase and its dependencies.
Access by our staff. A small number of authorised staff can access user data where their job requires it: to review reports (including who made a report), to review spine submissions, to find an account by its email address or handle when handling a support or safety matter, and to unpublish a shelf that breaks our rules. Changes staff make through our admin tools are recorded in an internal log, which we keep even after a staff member's own account is closed.
No system is perfectly secure. If a personal data breach is likely to put your rights and freedoms at risk, we will notify the UK Information Commissioner's Office within 72 hours and affected users without undue delay, as the law requires.
12. Push notifications and your choices
Notifications (new followers and follow requests, likes, saves, comments, milestones, release reminders) are optional. You can switch each category on or off in the App's Settings, or disable notifications entirely in your device settings. Release-day reminders are scheduled locally on your device.
13. Your rights (UK & EEA)
You have the right to: access the personal data we hold about you; have it rectified or erased; restrict or object to processing (including any based on legitimate interests); data portability; and to withdraw consent at any time without affecting prior processing. We respond within one calendar month, free of charge (unless a request is manifestly unfounded or excessive).
To exercise them: use the in-App tools (edit profile, delete account) or email privacy@therealmshelf.app.
You may complain to the Information Commissioner's Office (ico.org.uk · 0303 123 1113 · Wycliffe House, Water Lane, Wilmslow, SK9 5AF) or, in the EEA, to your local supervisory authority. We would welcome the chance to resolve your concern first.
14. Additional information for US residents
State privacy laws (including the CCPA/CPRA) give residents of certain states specific rights. In the 12 months before the date above we collected these categories of personal information: identifiers (email, name, handle, Apple or Google account identifiers if you sign in that way, device push tokens); user content you provide (library, shelves, reviews, comments, photos you upload, feedback you send); commercial information (subscription status); internet or network activity limited to crash/error data and in-app usage events (opening the App, reaching a free-tier limit, seeing the upgrade screen, subscribing); and inferences limited to aggregate book-ranking signals.
- We do not sell personal information and have not done so. We do not "share" personal information for cross-context behavioural advertising, and we do not use it for targeted advertising. There is accordingly nothing to opt out of.
- We do not use or disclose sensitive personal information for purposes that would trigger a right to limit.
- You have the rights to know/access, delete, correct and portability, and the right to non-discrimination for exercising them. In-App: Settings → Manage Account → Delete Account & All Data. Otherwise email privacy@therealmshelf.app; we verify requests via your account email, and you may use an authorised agent with proof of authorisation. If we decline a request you may appeal by replying to our decision; we will explain the outcome.
- The App does not respond to "Do Not Track" or Global Privacy Control signals because it is not a website, does no cross-site tracking and does not sell or share data — there is nothing such a signal would switch off.
15. Children
The Service is for adults: it is rated 18+ on the app stores and is not directed at children or teenagers. We do not knowingly collect personal data from anyone under 18 (and never from children under 13, per COPPA). When you sign in, the App asks you to confirm that you are at least 18; we do not store that confirmation and we do not ask for your date of birth. If you believe someone under 18 has created an account, contact us and we will delete it.
16. Cookies and local storage
The App is a native mobile application and sets no browser cookies of its own. The bot check on the sign-in screen (Section 11) runs in a small embedded browser view, in which Cloudflare may store technical data strictly needed for that security check. The App uses local device storage to keep you signed in, remember preferences and cache content for speed. Our website at therealmshelf.app (these documents, the support pages and the pages behind profile links) sets no cookies and uses no analytics or advertising tools. It is hosted by Cloudflare, which — like any web host — processes your IP address and basic request data to deliver the pages and keep them secure. When you open a profile link in a browser, the page asks our backend (Supabase) for the public details of that profile described in Section 8.2; nothing about you is stored.
17. Third-party links and affiliate notice
"Get This Book" links open third-party retailers (Amazon, Kindle, Audible, Bookshop.org); they currently open the retailers' UK sites where one exists. Links to Amazon, Kindle and Audible are affiliate links — we may earn a commission on qualifying purchases at no extra cost to you — and links to other retailers may become affiliate links in future. Once you leave the App the retailer's own privacy policy applies; we do not receive personal data about what you buy there.
18. Changes to this Policy
We may update this Policy as the Service or the law changes. For material changes we will notify you in the App (and by email where appropriate) at least 14 days before they take effect. The "Last Updated" date shows the current version.
19. Contact
Allyoucanreserve Ltd, 124 City Road, London, England, EC1V 2NX, United Kingdom
Email: privacy@therealmshelf.app
If you need this Policy in another format (for example screen-reader friendly), contact us and we will provide one.
© Allyoucanreserve Ltd. All rights reserved.