Booqly
  • Features
  • Privacy
  • Cookies
  • Imprint
Get the app DE
Legal

Privacy Policy

Last updated · 3 September 2026

Data controller

Dr. Sven-Eric Molzahn
Lommelstrasse 1, 85101 Lenting, Germany
Email: sven-eric@molzahn-software.de

The short version

Booqly respects your reading. We don't sell your data. We don't run third-party analytics SDKs. We don't show ads. Your library lives in our Supabase backend (EU region) and on your device.

From your account

When you sign in we store: your email address (used for magic-link sign-in), a generated user UUID, your handle and optional display name, and an optional avatar image if you upload one.

Legal basis: performance of contract (Art. 6(1)(b) GDPR) — we need this data to provide the service you signed up for.
Retention: kept while your account exists. Deleted immediately when you delete your account in the app (Settings → Delete account); encrypted backups roll off within 90 days.

From your reading

The books you've added, started, and finished, plus any highlights or notes — so the library syncs across your devices and so social features (the feed, read-together sessions) can work. Export at any time as CSV or JSON from Settings → Export your library.

Legal basis: performance of contract (Art. 6(1)(b) GDPR).
Retention: same as account data above.

Shelf scanning (optional)

If you use the shelf-scan feature, the photo you took is sent to Anthropic (Claude API, USA) via our Supabase Edge Function to identify the books in it. Anthropic does not retain the image beyond the request. We log a timestamp + a thumbnail (stored only on your device) + a scan counter (server-side, to enforce the per-user quota). We never retain the original photo on our server.

Legal basis: consent (Art. 6(1)(a) GDPR) — you actively choose to scan.
Retention: the image is not stored. The scan counter is kept while your account exists.

Cover photos (optional, shared)

If you switch on Share cover photos (Settings → Privacy), the covers you photograph help other readers see the right edition. What leaves your device is only the straightened crop of the cover itself — at most 1200 pixels on the long edge, with all photo metadata (location, device, time) removed. The rest of the photo — hands, table, room — is never uploaded. A shared cover is stored with your account id (not shown to anyone) and can be seen by every Booqly reader who has that edition. You can turn sharing off at any time; covers you already shared stay until you delete your account or ask us to remove them.

Legal basis: consent (Art. 6(1)(a) GDPR) — sharing is off until you switch it on.
Retention: while your account exists. Removed with the account, or on request — see Rights holders in the Terms.

Recommendations

To suggest books you don't have yet, a summary of your shelf — titles, authors, reading status and ratings, never your notes — is sent to Booqly's server and from there to Anthropic (Claude API, USA), which proposes titles. Without an account this happens under an anonymous id (see below); nothing that identifies you goes along. Suggestions are kept for seven days so the same shelf isn't sent twice. Switch this off in Settings → Recommendations → Personalised picks; your shelf then stays on your device.

Legal basis: performance of contract (Art. 6(1)(b) GDPR) — personalised picks are part of the service, and you can object at any time in Settings.
Retention: the shelf summary is replaced whenever your shelf changes; suggestions expire after seven days.

Without an account

You can use Booqly without signing in. To keep recommendations working, the app then creates an anonymous account: a random id with no email, name or handle, holding only the shelf summary above. It is invisible to other readers. When you later sign in, its contributions move to your real account and the anonymous one is deleted; anonymous accounts unused for 180 days are deleted automatically.

Legal basis: performance of contract (Art. 6(1)(b) GDPR).
Retention: 180 days after last use, or until you sign in.

Push notifications (optional)

If you allow notifications, we store the device token Apple issues, together with the app language and whether the app is a test or App Store build, so we can tell you when a friend invites you to read together or joins your session. The token and the short notification text go to Apple (Apple Push Notification service, USA). Nothing else is sent through notifications.

Legal basis: consent (Art. 6(1)(a) GDPR) — the system permission dialog.
Retention: while your account exists; tokens Apple reports as invalid are removed immediately.

Reading together and friends

Friends — readers you are mutually connected with — see your handle, display name, avatar, and what you've chosen to show of your shelf (Settings → Privacy). When you invite a friend to read a book together, or accept an invitation, the other person sees whether you already have that book. Notes you write in a reading session are visible to its members.

Age range

Booqly's social features — the feed, profiles, comments and reading together — are for readers 13 and up. To check, the app asks Apple's Declared Age Range service, which answers only with a bracket such as "13 or older" or "under 13", from what you or a parent declared to Apple. Booqly never learns a birthday. The answer is kept on your device and is never sent to us. Readers under 13 keep the whole reading app: library, scanning, import and recommendations.

Legal basis: legal obligation and legitimate interest (Art. 6(1)(c), (f) GDPR) — keeping social features to readers of the age the platform requires.
Retention: on the device only, until the app is deleted.

Where to buy

Booqly links to bookshops so you can buy a book you want. Tapping a link opens the shop; only then does the shop learn anything about you, under its own privacy policy. Some links are affiliate links: as an Amazon Associate, Booqly earns from qualifying purchases. No purchase or browsing data comes back to us.

Newsletter (optional)

If you submit your email on the landing page, we store: your email address, which launch you asked to hear about (iOS or Android), a UUID confirmation token, a UUID unsubscribe token, the timestamp of signup and confirmation, and the IP + browser user-agent of the device that confirmed (for GDPR-compliant proof of consent). We use this only to send the one launch announcement you asked for. List storage: Supabase. Email sending: Brevo (EU-based, Paris). Every email contains an unsubscribe link.

Legal basis: consent (Art. 6(1)(a) GDPR), confirmed via double opt-in.
Retention: kept until you unsubscribe. Unsubscribed rows are flagged and deleted after 30 days.

Analytics (website only)

If you accept analytics via the cookie banner, we load Vercel Analytics in cookieless mode on thebooqly.com to count page views. No cookies, no advertising identifiers, no cross-site tracking. If you reject, no analytics script is loaded.

Legal basis: consent (Art. 6(1)(a) GDPR).
Retention: Vercel retains aggregated, non-personal page-view data for up to 12 months.

What we don't collect

  • No advertising identifiers, no fingerprinting.
  • No precise location, no contacts, no photo library access beyond what you actively pick.
  • No reading data shared with publishers, marketers, or model trainers.

Third-country transfers

Some sub-processors are based outside the EU:

  • Anthropic (USA) — receives shelf-scan images when you trigger a scan, and your shelf summary for recommendations. Not retained beyond the request, not used for training. Transfer safeguard: EU Standard Contractual Clauses (SCC) as part of Anthropic's Data Processing Agreement.
  • Apple (USA) — delivers push notifications: receives your device token and the notification text. Transfer safeguard: EU Standard Contractual Clauses (SCC) under Apple's developer terms.
  • Vercel (USA) — hosts the website and processes cookieless analytics if you consent. Transfer safeguard: EU Standard Contractual Clauses (SCC).

All other data processing (accounts, library, newsletter) occurs within the EU via Supabase (EU region) and Brevo (Paris, France).

Your rights (GDPR)

Under the GDPR you have the right to:

  • Access (Art. 15) — request a copy of your personal data.
  • Rectification (Art. 16) — correct inaccurate data.
  • Erasure (Art. 17) — request deletion of your data.
  • Restriction of processing (Art. 18) — request that we limit how we use your data.
  • Data portability (Art. 20) — receive your data in a structured, machine-readable format. Use Settings → Export your library to export as CSV or JSON at any time.
  • Object (Art. 21) — object to processing based on legitimate interest.
  • Withdraw consent (Art. 7(3)) — withdraw consent at any time without affecting the lawfulness of prior processing.

Account deletion: Settings → Delete account, in the app, immediately. It removes your profile, friendships, reading sessions, notes and shared cover photos; the books on your device stay. Encrypted backups roll off within 90 days. If you can't reach the app, email sven-eric@molzahn-software.de from your account's address.

Supervisory authority

You have the right to lodge a complaint with a data-protection authority. Our competent authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany — www.lda.bayern.de.

Where data lives

Supabase (EU region). All transport HTTPS. Backups encrypted at rest. Sub-processors: Supabase (storage), Brevo (newsletter and report emails), Vercel (website hosting & analytics), Anthropic (shelf-scan and recommendation requests), Apple (push notifications).

Contact

Questions about anything above: sven-eric@molzahn-software.de.

Booqly

A calm reading log for people who'd rather finish a chapter than refresh a feed.

Product

  • Features
  • Download
  • Support

Company

  • Contact

Legal

  • Privacy
  • Cookies
  • Terms
  • Imprint
© 2026 Dr. Sven-Eric Molzahn English · Deutsch Built with patience, not engagement metrics.

This site uses no tracking cookies. Accept to enable anonymous page-view analytics (Vercel, cookieless). Read the policy.