Privacy Policy
Last updated: 14 July 2026
Overview
Book Assembly is a personal book tracking application built with privacy at its core. We are committed to protecting your privacy and being transparent about how we handle your data. This policy explains what information we collect, how we use it, your rights regarding your data, and how we protect it.
Who We Are (Data Controller)
Book Assembly is the data controller responsible for your personal data, which means we decide how and why it is processed. We are a small service based in the United Kingdom. If you have any questions about how your data is handled, or wish to exercise your rights, you can reach us at privacy@bookassembly.co.uk.
Your Privacy Rights (GDPR)
As a service based in the United Kingdom, we comply with the UK General Data Protection Regulation (UK GDPR). You have the following rights:
- Right of access: Request a copy of your personal data
- Right to rectification: Correct inaccurate personal data
- Right to erasure: Request deletion of your personal data ("right to be forgotten")
- Right to data portability: Receive your data in a portable format
- Right to object: Object to processing of your personal data
- Right to restrict processing: Request limitation of how we process your data
- Right to withdraw consent: Withdraw consent at any time where processing is based on consent
To exercise these rights, use the tools in your account Settings or contact us via the details at the end of this policy.
Legal Basis for Processing
We process your personal data under the following legal bases:
- Contract performance: To provide the Book Assembly service you've signed up for (account management, book tracking features, data synchronisation)
- Legitimate interests: To improve and secure the service, prevent fraud and abuse (including processing your IP address for rate limiting and security), and fix bugs
- Consent: Where you've given explicit consent - such as enabling public profile features, or opting in to non-essential updates and announcements by email (which you can withdraw at any time in Dashboard → Preferences, or via the unsubscribe link in any such email)
You can withdraw consent at any time through your account Settings without affecting the lawfulness of processing based on consent before withdrawal.
Data We Collect
We collect only the data necessary to provide the service:
Account Information
- Email address: Used for account creation, login, and essential service communications
- Password: Encrypted and never stored in plain text
Book Data
- Books you add: Titles, authors, ISBNs, genres, ratings, notes, reading dates, and progress
- Book covers: Sourced from external APIs or uploaded by you
- Custom organisation: Custom genres, series, and collections you create
Wishlist Data
- Books you want to read: Including priority levels and personal notes
Preferences
- Display settings: Theme preferences, view options, and layout choices
- Widget configurations: Dashboard widget arrangement and settings
Profile Data (Optional)
- Username: A unique identifier for your profile URL (if you enable public profile)
- Display name: An optional name shown on your profile
- Bio: An optional description about yourself
- Profile photo: An optional image (you can show or hide it independently of your profile)
Technical Data
- IP address: Your IP address is processed to keep the service secure - rate limiting sign-in and other requests, preventing abuse and automated attacks, and delivering the site. We do not use it to track your activity across the web or build a profile of you. It is handled by our infrastructure providers (Cloudflare and Netlify) and our rate-limiting provider (Upstash) - see External Services below.
Beta Testing Data
As Book Assembly is currently in beta, we may occasionally collect:
- Error logs and crash reports: Anonymised where possible to help identify and fix bugs
- Feature usage statistics: Aggregated data not linked to individual users
- Performance metrics: To optimise the service
This information helps us improve the service. No personal reading data or identifiable information is included in these logs beyond what's necessary for debugging.
How We Store Your Data
Your data is stored securely using Google Firebase:
- Authentication: Firebase Authentication handles login securely with industry-standard encryption
- Database: Cloud Firestore stores your books, settings, and library data
- Image storage: Firebase Storage stores book cover images you upload
- Location: Data is stored on Google Cloud servers, which may be located in various regions
Local Storage:We also use your browser's local storage to cache data for faster loading and offline access. This cached data never leaves your device and is under your control.
International Data Transfers
Your data is stored on Google Cloud servers via Firebase. While we are based in the UK, your data may be transferred to and stored in countries outside the UK/EEA as part of Google's global infrastructure.
Google provides appropriate safeguards for these transfers through:
- Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office
- Data Processing Agreements
- Compliance with international data protection standards
For more information, see Google Cloud's data processing terms (opens in new tab).
We also rely on a small number of other service providers that may process limited data outside the UK/EEA, each under appropriate safeguards such as Standard Contractual Clauses or equivalent agreements:
- Cloudflare (United States / global) - content delivery, security and traffic protection; processes your IP address and request metadata as the network in front of the site
- Netlify (United States) - hosting and content delivery
- Upstash (United States / global) - rate limiting, which briefly stores counters keyed to your IP address to prevent abuse
- Sentry (United States) - error monitoring, when enabled
- Resend (United States) - sending transactional emails
- Gravatar (United States) - displaying profile images, using a one-way hash of your email address
You can read more about what each of these services does in the "External Services" section below.
Cookies and Local Storage
Cookies
Book Assembly does not use cookies for tracking or analytics. We set a single, strictly necessary cookie:
| Name | Purpose | Duration | Type |
|---|---|---|---|
| session | Keeps you logged in and authenticates requests to the server | 7 days | Strictly necessary (HTTP-only, secure) |
This cookie is strictly necessary for the service to function and cannot be disabled while using Book Assembly. It is not used for tracking or advertising. We set no third-party cookies for tracking or advertising; our network provider Cloudflare may set a strictly necessary security cookie - see Third-Party Cookies below.
Local Storage
We use your browser's local storage to:
- Cache your library data for faster loading
- Enable offline access to your books
- Store your preferences and settings
This locally stored data never leaves your device and is completely under your control. You can clear it at any time from Settings or by clearing your browser data.
IndexedDB
We also use IndexedDB (a browser storage mechanism similar to local storage) for authentication token persistence via the Firebase Auth SDK. This is strictly necessary for keeping you signed in between visits and is cleared when you sign out or clear your browser data.
Third-Party Cookies
Cloudflare Web Analytics does not use cookies or track you across sites. Because Cloudflare also protects and delivers the site as our network provider, it may set a strictly necessary security cookie (for example to tell genuine visitors from automated bots). This is exempt from consent under the cookie rules and is not used to track you or for advertising.
Public Profile
You can optionally create a public profile to share your library with others. Profile data includes:
- Username: A unique identifier for your profile URL
- Display name: An optional name shown on your profile
- Bio: An optional description about yourself
- Profile photo: An optional image (you can show or hide it independently of your profile)
Visibility Settings
You control who can see your profile:
- Only you: Your profile is completely private. Only you can see it when logged in, and it won't appear on search engines.
- Anyone with the link: Your profile is accessible to anyone you share your profile link with. Other users cannot find you by browsing or searching Book Assembly, and search engines won't list it.
- Anyone: Your profile can be found when browsing or searching for users within Book Assembly, and may be listed by search engines like Google.
You can change these settings at any time from Settings after logging in.
Important Note About Search Engines
Public and "People I share with" profiles may be indexed by external search engines like Google. We use technical measures (such as robots.txt directives and meta tags) to discourage indexing of private profiles, but we cannot guarantee complete prevention of search engine indexing. If privacy is important to you, we strongly recommend using the "Just me" visibility setting.
Sharing Books, Lists and Reviews
Separately from your profile, you can choose to make individual books, lists, and reviews public. Each has its own visibility setting, and everything is private unless you turn it on. When you make something public:
- Other people can see it - a public book, list, or review is visible to anyone who visits your profile or the book's page, and public content may appear in search engines.
- Some details always stay private, even on a public book: your private notes, exact reading dates, ownership, and your exact reading progress. You choose which optional details (such as your rating or reading status) are shown.
- If your profile is public, you may be named to other users on the pages of books you share - for example, listed among the readers who have a book. If your profile is private or link-only, you are counted anonymously but never named this way.
Community Statistics
To show community context on a book's page - such as how many readers have a book and its average rating - we keep an anonymised, aggregated record for each book across all users. This record holds counts and totals only (for example, the number of readers who have the book and the sum of their ratings) and does not identify individual users. Your contribution to these totals is removed automatically when you make the book private, delete the book, or delete your account.
External Services
We use the following external services to provide Book Assembly's functionality:
Cloudflare (Delivery, Security and Analytics)
- Purpose: Cloudflare sits in front of the site as our network provider - delivering pages quickly, and protecting the service from automated abuse and attacks. It also provides privacy-focused website analytics measuring page views and performance
- Data processed: As the network provider, Cloudflare processes your IP address and request metadata (such as the page requested and your browser type) to route and protect traffic. Its analytics collect only aggregated, anonymous statistics
- Privacy features: The analytics do not use cookies, do not track individuals across sites, and do not collect personal information. Cloudflare may set a strictly necessary security cookie (see Cookies above)
Cloudflare Privacy Policy (opens in new tab)
Upstash (Rate Limiting)
- Purpose: Rate limiting - counting recent requests to protect the service from abuse, spam, and automated attacks
- Data shared: Short-lived counters keyed to your IP address. No account details, reading data, or email content are shared
- When used: On security-sensitive requests such as sign-in, password reset, contact, and search
Upstash Privacy Policy (opens in new tab)
Google Firebase
- Purpose: Secure infrastructure for authentication, data storage, and file hosting
- Data collected: Data you enter into Book Assembly (stored securely)
Google Privacy Policy (opens in new tab) | Firebase Data Processing Terms (opens in new tab)
ISBNdb API
- Purpose: Book metadata and cover images when searching or scanning barcodes
- Data shared: Only ISBN or search terms you enter, not your personal information
ISBNdb Privacy Policy (opens in new tab)
Gravatar
- Purpose: Default profile image for users who haven't uploaded a photo
- Data shared: An MD5 hash of your email address is sent to Gravatar's servers to check if you have a profile image. Your actual email address is not shared - only a one-way hash
- When used: Only when displaying profile photos (e.g. in the header or on public profiles)
Automattic Privacy Policy (opens in new tab) (Gravatar is operated by Automattic)
Open Library API
- Purpose: Fallback source for additional book data
- Data shared: Only ISBN or search terms, not your personal information
Open Library Privacy (opens in new tab)
Sentry (Error Monitoring)
- Purpose: Detecting and diagnosing application errors to improve reliability
- Data shared: Error messages, stack traces, browser type, and the page URL where the error occurred. No personal reading data, book titles, or account details are included
- When used: Automatically when an application error occurs
Sentry Privacy Policy (opens in new tab)
Resend (Transactional and Broadcast Email)
- Purpose: Sending account-related emails (password resets, email verification, contact form replies, account deletion confirmations, import notifications) and - where you have opted in - non-essential broadcast emails such as product updates, tips and recommendations, and surveys
- Data shared: Your email address and the email content. Account emails only go out when triggered by your actions; broadcast emails only go to addresses you have explicitly opted in for under Dashboard → Preferences → Email Notifications
- When used: Triggered by your actions for account emails; periodically (and only with your opt-in) for the broadcast categories. Every broadcast email has a one-click unsubscribe in both the email client's header and the footer of the message
Resend Privacy Policy (opens in new tab)
Netlify (Hosting)
- Purpose: Hosting the Book Assembly website and serving all pages and API requests
- Data processed: Your IP address and request metadata (URL, headers, timestamps) are processed by Netlify's servers as part of delivering the site to your browser. This is standard for any web host
- Data retention: Netlify retains server logs for a limited period for security and debugging purposes
Netlify Privacy Policy (opens in new tab)
Important: When you search for books, we send only your search terms or ISBN to these services. We do not share your account information, reading history, or any personal data with these services.
What We Don't Do
We built Book Assembly around respect for your privacy. Here's what we explicitly don't do:
- ✗ No tracking: We don't track your browsing behaviour or reading habits beyond what you explicitly record in the app
- ✗ No advertising: We don't show advertisements or sell your data to advertisers
- ✗ No third-party sharing: Your personal data is never shared with or sold to third parties for marketing purposes
- ✗ No profiling or automated decisions: We don't build profiles, analyse your reading habits for targeting, or make any automated decisions that have legal or similarly significant effects on you (UK GDPR Art. 22)
- ✗ No unnecessary data collection: We only collect what's needed to provide the service you signed up for
- ✗ No dark patterns: We make it easy to export and delete your data - your data is truly yours
Your Rights and Controls
You have full control over your data at all times:
Access Your Data
- View all your data within the app at any time
- See exactly what information we store about you
Edit Your Data
- Edit any personal data we hold about you directly in the app at any time
- This includes your display name, email address, password, profile details, and every field on every book in your library
- Changes take effect immediately - you do not need to contact us to exercise your right to rectification
Export Your Data
- Download your library data as JSON or CSV from Settings
- Portable formats that you can use elsewhere or keep as backup
- Includes your books, ratings, reviews, notes, genres, series, lists, wishlist, reading progress, and reading goals, plus any images you uploaded
- Your account details (email, username, display name, bio, and preferences) are not part of this library export. To receive a complete copy of all personal data we hold about you (a Subject Access Request), email privacy@bookassembly.co.uk and we will respond within one month
Delete Your Data
- Permanently delete your account and all associated data from Settings
- See "Data Retention" section below for specific timelines
Clear Local Cache
- Remove locally stored data from your browser via Settings
- This doesn't affect your synced library, only local browser cache
Control Your Profile
- Enable or disable public profile at any time
- Change visibility settings instantly
- Control what information is displayed
Data Retention
Active Accounts
Your data is retained for as long as you maintain an active account. We do not automatically delete inactive accounts - your data remains available until you choose to delete your account.
Account Deletion
When you delete your account:
- All your personal data is permanently removed within 30 days
- Anonymised, aggregated usage statistics (not linked to you or your account) may be retained for service improvement
Admin Action Logs
We maintain internal audit logs that record administrative actions (such as account deletions) for legal compliance and security purposes. These logs:
- Are retained for a maximum of 2 years, then permanently deleted
- Are not accessible to users and contain only the minimum data needed for compliance
- Are processed under our legitimate interest in maintaining security and meeting legal obligations
Deleted Books
When you delete a book from your library:
- It moves to a bin where it can be restored for 30 days
- After 30 days, deleted books are permanently removed from all systems
- This gives you time to recover accidentally deleted books
Local Data
Cached data in your browser is retained until you:
- Sign out of your account
- Clear your browser data/cache
- Use the "Clear local cache" option in Settings
Data Breach Notification
Security is our priority, but in the unlikely event of a data breach that affects your personal information, we will:
- Report to the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, where required by UK GDPR
- Notify affected users without undue delay where the breach is likely to result in a high risk to your rights, using the email address on your account
- Explain what happened and what data was potentially affected
- Describe the steps we're taking to address the breach and prevent future incidents
- Provide guidance on how you can protect your account
We maintain security measures to prevent unauthorised access, but we encourage you to:
- Use a strong, unique password
- Enable any additional security features we offer
- Keep your email address up to date for critical notifications
Children's Privacy
Book Assembly is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately via the contact details below. We will promptly investigate and delete such information from our systems.
Security
We take the security of your data seriously:
- Password encryption: Your password is never stored in plain text. We use industry-standard hashing algorithms.
- HTTPS encryption: All data transmission between your device and our servers uses HTTPS encryption.
- Firebase security: Google Firebase provides enterprise-grade security for authentication and data storage, including encryption at rest and in transit.
- Access controls: Strict access controls ensure only authorised systems can access your data.
- Regular updates: We keep our systems and dependencies updated with the latest security patches.
While we implement strong security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but commit to following industry best practices.
Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
When we make changes:
- We will update the "Last updated" date at the top of this policy
- For material changes, we will notify you via email and/or a prominent notice in the service
- We will give you at least 30 days' notice before material changes take effect
We encourage you to review this policy periodically to stay informed about how we protect your data.
Your continued use of Book Assembly after changes take effect constitutes acceptance of the updated policy. If you don't agree with changes, you may delete your account and export your data before the changes take effect.
Contact Us
General Enquiries
If you have questions about this privacy policy or how your data is handled:
- Support page: Contact Support
- General email: support@bookassembly.co.uk
Data Protection Enquiries
As a small organisation that does not process personal data on a large scale, we are not required to appoint a Data Protection Officer under UK GDPR. For any data protection queries, please contact us at:
- Privacy email: privacy@bookassembly.co.uk
Response Times
We aim to respond to:
- General enquiries within 7 days
- Data protection requests within 30 days (as required by UK GDPR)
- Urgent security matters within 24 hours
Supervisory Authority
If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk/make-a-complaint (opens in new tab)
Telephone: 0303 123 1113
By using Book Assembly, you acknowledge that you have read, understood, and agree to this Privacy Policy.