Privacy Policy

The Realm — A bookshelf for your heart.

Effective Date: [LAUNCH DATE]
Last Updated: [LAUNCH DATE]


1. Who we are

This Privacy Policy explains how Allyoucanreserve Ltd ("we", "us", "our") collects, uses, shares and protects your personal data when you use The Realm mobile application and related services (the "Service" or "App").

Data Controller:
Allyoucanreserve Ltd
A private limited company registered in England and Wales (company number 10162791)
Registered office: 124 City Road, London, England, EC1V 2NX, United Kingdom

For any privacy question or request, contact: privacy@therealmshelf.app

We act as the data controller for the personal data described in this Policy. We have not appointed a Data Protection Officer because we are not required to; the email address above is monitored for privacy matters.


2. The laws this Policy is written for


3. The short version

The rest of this Policy is the detail behind that summary.


4. The data we collect

4.1 Data you give us directly (stored on our servers)

Category Examples
Account data Email address; or the identity from Sign in with Apple / Google Sign-In (see Section 4.4 — Apple lets you hide your real email); display name; handle; bio; avatar photo; favourite genre; the books you choose to feature on your profile (currently reading, all-time favourite); Instagram/TikTok handles if you add them
Your library Books on your lists (Read, TBR, Currently Reading, DNF, Favourites, custom lists), formats, when you added them
Ratings & reviews Star ratings, short reviews ("The Verdict") and extended reviews — private by default; shared only if you opt in when publishing a shelf
Shelves Shelf names, book arrangements, decor placements, rendered shelf images, captions, publish status
Social activity Follows, likes, saves, comments (including @mentions), users you block, reports you submit
Spine photo submissions A photo you add as your own spine for a book. The App uploads it when you add it and queues it for review by our staff (see Section 8.3 — after review, approved spines can appear on other users' shelves)
Background-remover results The cut-out image produced when you use the background remover (Section 7)
Notification data Your notification preferences and device push tokens
Support & feedback Messages you send us; feedback you type into the App's feedback box (delivered to us through Sentry — see Section 4.3)

4.2 Data that stays on your device only (never uploaded)

This data lives only in the App's storage on your device, and we have no copy. It is deleted when you delete it or the App (or clear the App's data in your device settings), when you delete your account, and when a different account signs in on the same device — in that last case the App tells you what would be removed and asks first, and nothing is removed if you go back. Logging out on its own keeps it, so think twice before lending a signed-out device to someone who will sign in with their own account.

The one exception to "never uploaded": if you put one of these images through the background remover, that image is sent for processing as described in Section 7. If we ever add an optional cloud backup for this data, the App will say so clearly before anything is uploaded.

4.3 Data collected automatically

Category Details
Crash and error data Collected via Sentry when the App crashes or errors: a pseudonymous user id, device model, OS version, App version and the technical state of the error. It is linked to your account only through that id. Session replay is disabled. Your name and email are never sent to Sentry. Feedback you send from the App's feedback box reaches us through the same service and contains the text you typed.
Technical data Device type, OS version, App version, language and time zone. Your IP address is inherently visible to servers when the App makes requests; we do not use it to track you.
Bot check on the sign-in screen When the sign-in screen opens, Cloudflare Turnstile checks that the request comes from a real device and not a script. Cloudflare receives your IP address and technical signals about your device and the embedded browser view the check runs in; we receive only a pass-or-fail token (see Section 11).
Aggregate product signals Non-identifying counts used to rank the book catalogue (for example how often a book is added across all users).
Fair-use counters Per-account counts that enforce limits on costly features (book search, cover analysis, background removals): how many times you used the feature in a period — not what you searched for or uploaded.
App usage A few events linked to your account, stored in our own database: that you opened the App (at most once a day), that you reached a free-tier limit (and which one), that the upgrade screen was shown (and from where), and that you subscribed (and to which plan). We use them only to set fair free-tier limits and to see whether the paid tier is worth offering — never for advertising, and they are never shared or sold.

We do not collect: precise location, contacts, calendars, microphone audio, browsing history or advertising identifiers. We use no third-party analytics SDKs — the usage events above never leave our own database.

4.4 Data we receive from others

Source What we receive
Apple (sign-in) Your email address — or the private relay address Apple creates if you choose to hide it — and Apple's identifier for your account. The App asks Apple for your name but does not keep it or send it to our servers.
Google (sign-in) Your name, email address and the web address of your Google profile picture, as contained in Google's sign-in token. Our authentication provider stores them with your account; the App itself does not use the name or picture.
Apple / Google / RevenueCat (purchases) Confirmation a purchase was made, plan type and renewal status — never your card details
Google Books API, Open Library Book metadata (titles, authors, covers, page counts) — data about books, not about you (see Section 8.5 for what these services receive)

We never share sign-in data with advertising platforms or data brokers, and we do not combine an Apple private relay address with information from elsewhere to work out who you are.


5. Payments — we never see your card

All purchases are processed by Apple (App Store) or Google (Google Play). We never receive your card number, CVV or billing address. Subscription status is managed for us by RevenueCat, Inc., which receives store receipts and tells the App whether your account has the paid tier (revenuecat.com/privacy). So that your purchase follows your account across devices, your Realm account id is used as the RevenueCat customer id.


6. Why we use your data, and our lawful bases

Under UK and EU GDPR every use of personal data needs a lawful basis. Ours:

Purpose Data used Lawful basis
Creating your account, signing you in, running the Service Account data Contract (Art. 6(1)(b))
Core features: library, shelves, reviews, Covers, Browse Library, shelves, reviews, social activity Contract
Showing your published content to other users Published shelves, shared reviews, comments, profile Contract — publishing is always your explicit action
Ranking the Browse feed and book search Aggregate signals, follows, likes and saves Contract, plus legitimate interests (a useful feed)
Processing your subscription Purchase confirmations Contract
Push notifications about activity on your account Push tokens, notification preferences Consent — withdraw any time in Settings or device settings
Safety: moderation of submissions and comments, blocks, reports Submissions, comments, reports Legitimate interests (a safe service) and legal obligation where applicable
Protecting sign-in from automated abuse (bot check) IP address and device signals, processed by Cloudflare Legitimate interests (a secure service that scripts cannot misuse)
Fixing crashes and defects Crash and error data Legitimate interests (a working product)
Setting free-tier limits and deciding what the paid tier offers App usage events Legitimate interests (a fair free tier and a sustainable service)
Complying with the law As required Legal obligation (Art. 6(1)(c))

Where we rely on legitimate interests we have balanced them against your rights, and you may object (Section 13). We make no automated decisions with legal or similarly significant effects, and we do not deliberately process special-category data (what you reveal in free-text content is your choice).


7. AI features — what leaves the App

Two features use external AI services, both narrowly:

Both providers process images solely to provide the feature. We do not use your content to train AI models.


8. Who we share data with

We do not sell personal data. We share it only as described here.

8.1 Service providers (processors)

Provider Role Location
Supabase, Inc. Our backend: database, authentication, file storage, server functions. Project hosted in the United Kingdom (London) USA (company); your data is stored in the United Kingdom (London)
Apple Inc. App distribution, payments, sign-in, push delivery (APNs) USA
Google LLC App distribution, payments, sign-in, push delivery (FCM), Google Books API USA
RevenueCat, Inc. Subscription management USA
Resend, Inc. Delivery of sign-in codes and email-change confirmation codes: receives your email address and the message containing the code USA (EU sending region)
Cloudflare, Inc. Bot check on the sign-in screen (Turnstile — Sections 4.3 and 11); routing of email you send to our support and privacy addresses; our domain and website USA (global network)
Proton AG The mailbox that receives messages you send to our support and privacy addresses (Cloudflare forwards them there) Switzerland
Functional Software, Inc. (Sentry) Crash and error reporting, and delivery of in-app feedback — EU data residency, pseudonymous ids only USA, EU ingest
Expo (650 Industries, Inc.) Push notification delivery (receives the device push token and the notification text, which can include another user's display name); delivery of App updates — the App checks Expo's servers for a newer version of its code USA
Anthropic, PBC AI analysis of public book cover images (Section 7) USA
Replicate, Inc. Background removal of images you submit to the background remover (Section 7) USA

8.2 Other users — what they can and cannot see

Your profile can be viewed by other signed-in users. It shows: your display name, handle and avatar; your bio, favourite genre and follower/following counts; your Instagram/TikTok handles if you added them; and the books you chose to feature (currently reading, all-time favourite).

When you publish a shelf, other users can also see: the shelf's name, caption, image, books and decor; and — only if you opted in — your shared ratings and reviews for its books. Comments you write are visible to anyone who can see that shelf. Your public profile lists your published shelves and shared reviews, including via your profile link.

Your profile link (therealmshelf.app/your-handle) also works for people who are not signed in. Without signing in, a visitor can see: for a public account, your display name, handle, avatar, bio and how many published shelves and followers you have; for a private account, only your display name and avatar.

If you set your account to private, people have to ask before they can follow you. Anyone signed in can send a follow request; you see who is asking and accept or decline it, and declining tells the other person nothing. Until you accept, they see only your display name and avatar — not your bio, counts, featured books, shelves or reviews. Your shelves, featured books and shared reviews are shown only to followers you have approved. You can remove a follower at any time (they are not told), and blocking someone also removes them. Followers you already had when you switched to private stay; if you switch back to public, requests still waiting are accepted, because what they asked to see is public by then.

Other users can never see: your reading notes, personal cover images, cover designs, your library lists (apart from the books you choose to feature on your profile), ratings or reviews you have not shared, your email address, or your unpublished shelves.

8.3 Spine submissions

When you add your own spine photo for a book, the App uploads it to our servers and places it in a review queue — this happens automatically when you add the photo. Our staff look at it, and if they approve it as the canonical spine for that book, it will render on any user's shelf containing that book. Your name is not displayed with it.

Until then it is used only on your own shelves — which includes the picture of any shelf you publish, so other users can see it there.

Choosing "Revert to original spine" removes the photo from your device and your shelves, and deletes the uploaded copy from our servers as long as our staff have not approved it yet. A photo that has already been approved stays in use for other users; email privacy@therealmshelf.app if you want it removed. All your submissions, including approved ones, are deleted when you delete your account.

We may disclose personal data where necessary in good faith to comply with law or a binding order; to protect the rights, property or safety of our users, ourselves or the public; to investigate fraud or abuse; or to enforce our Terms. If we are involved in a merger, acquisition or asset sale, personal data may transfer to the successor, who must honour this Policy; we will notify you of any such change.

8.5 Book data sources your device contacts directly

To find books and show their covers, the App on your device talks directly to two independent services:

As with any internet request, these services can see your IP address. They do not receive your account details. They are not our service providers: they act independently, under their own privacy policies.


9. International transfers

Some providers process data in the United States, and Cloudflare operates a global network, so its bot check may be handled in a data centre near you. Where personal data leaves the UK or EEA we rely on: adequacy decisions (including the EU–US Data Privacy Framework and UK–US Data Bridge where the provider is certified); the European Commission's Standard Contractual Clauses and/or the UK International Data Transfer Addendum; and additional safeguards where appropriate. You can request a copy of the relevant safeguards via the privacy email above.


10. How long we keep data

Data Retention
Account, library, shelves, reviews, social data While your account exists
Push tokens Removed on sign-out and on account deletion
Follow requests to or from a private account Until the request is accepted, declined or cancelled, or either account is deleted or blocks the other
Notifications in your activity list Deleted automatically after 180 days (90 days once read)
Push delivery log (who was notified about which kind of event — used only to stop notification spam) Deleted automatically after 7 days
Books you remove from your library Marked as removed so your other devices learn of it, then deleted for good after 180 days
Books and decor you remove from a shelf Marked as removed so your other devices learn of it, and kept in that state until you delete your account
Spine photo submissions and background-remover cut-outs Until you delete your account
Fair-use counters Deleted automatically after 90 days; the monthly background-removal count is kept while your account exists
Crash and error data (Sentry) Deleted automatically per Sentry retention (typically 90 days)
App usage events Deleted automatically after 24 months, and at once when you delete your account
Purchase records Per the stores' and RevenueCat's retention; our accounting records up to 6 years (UK law)
Device-only data (notes, cover designs, personal covers) Entirely under your control — deleted when you delete them or the App; Section 4.2 lists the other cases
Backups Rotated and overwritten in the ordinary course

Account deletion is built into the App (Settings → Manage Account → Delete Account & All Data). It deletes your server-side data — profile, library, shelves, reviews, comments, follows and uploaded images including spine submissions and background-remover cut-outs — subject only to records we are legally required to keep and short-lived backups. It also clears the App's data on the device you delete from, including the device-only data in Section 4.2.


11. How we protect your data

Access by our staff. A small number of authorised staff can access user data where their job requires it: to review reports (including who made a report), to review spine submissions, to find an account by its email address or handle when handling a support or safety matter, and to unpublish a shelf that breaks our rules. Changes staff make through our admin tools are recorded in an internal log, which we keep even after a staff member's own account is closed.

No system is perfectly secure. If a personal data breach is likely to put your rights and freedoms at risk, we will notify the UK Information Commissioner's Office within 72 hours and affected users without undue delay, as the law requires.


12. Push notifications and your choices

Notifications (new followers and follow requests, likes, saves, comments, milestones, release reminders) are optional. You can switch each category on or off in the App's Settings, or disable notifications entirely in your device settings. Release-day reminders are scheduled locally on your device.


13. Your rights (UK & EEA)

You have the right to: access the personal data we hold about you; have it rectified or erased; restrict or object to processing (including any based on legitimate interests); data portability; and to withdraw consent at any time without affecting prior processing. We respond within one calendar month, free of charge (unless a request is manifestly unfounded or excessive).

To exercise them: use the in-App tools (edit profile, delete account) or email privacy@therealmshelf.app.

You may complain to the Information Commissioner's Office (ico.org.uk · 0303 123 1113 · Wycliffe House, Water Lane, Wilmslow, SK9 5AF) or, in the EEA, to your local supervisory authority. We would welcome the chance to resolve your concern first.


14. Additional information for US residents

State privacy laws (including the CCPA/CPRA) give residents of certain states specific rights. In the 12 months before the date above we collected these categories of personal information: identifiers (email, name, handle, Apple or Google account identifiers if you sign in that way, device push tokens); user content you provide (library, shelves, reviews, comments, photos you upload, feedback you send); commercial information (subscription status); internet or network activity limited to crash/error data and in-app usage events (opening the App, reaching a free-tier limit, seeing the upgrade screen, subscribing); and inferences limited to aggregate book-ranking signals.


15. Children

The Service is for adults: it is rated 18+ on the app stores and is not directed at children or teenagers. We do not knowingly collect personal data from anyone under 18 (and never from children under 13, per COPPA). When you sign in, the App asks you to confirm that you are at least 18; we do not store that confirmation and we do not ask for your date of birth. If you believe someone under 18 has created an account, contact us and we will delete it.


16. Cookies and local storage

The App is a native mobile application and sets no browser cookies of its own. The bot check on the sign-in screen (Section 11) runs in a small embedded browser view, in which Cloudflare may store technical data strictly needed for that security check. The App uses local device storage to keep you signed in, remember preferences and cache content for speed. Our website at therealmshelf.app (these documents, the support pages and the pages behind profile links) sets no cookies and uses no analytics or advertising tools. It is hosted by Cloudflare, which — like any web host — processes your IP address and basic request data to deliver the pages and keep them secure. When you open a profile link in a browser, the page asks our backend (Supabase) for the public details of that profile described in Section 8.2; nothing about you is stored.


"Get This Book" links open third-party retailers (Amazon, Kindle, Audible, Bookshop.org); they currently open the retailers' UK sites where one exists. Links to Amazon, Kindle and Audible are affiliate links — we may earn a commission on qualifying purchases at no extra cost to you — and links to other retailers may become affiliate links in future. Once you leave the App the retailer's own privacy policy applies; we do not receive personal data about what you buy there.


18. Changes to this Policy

We may update this Policy as the Service or the law changes. For material changes we will notify you in the App (and by email where appropriate) at least 14 days before they take effect. The "Last Updated" date shows the current version.


19. Contact

Allyoucanreserve Ltd, 124 City Road, London, England, EC1V 2NX, United Kingdom
Email: privacy@therealmshelf.app

If you need this Policy in another format (for example screen-reader friendly), contact us and we will provide one.


© Allyoucanreserve Ltd. All rights reserved.