MyBookList

Privacy policy

Last updated 16 August 2026

Template — not legal advice. This describes how the app currently behaves, but it has not been reviewed by a lawyer. Have counsel check it before you launch publicly, especially if you take users in the EU (GDPR) or California (CCPA).

What we store

An account holds your email address, a username, an optional display name, avatar and bio. Authentication is handled by Supabase Auth; we never see or store your password.

Everything else is what you record: the books on your lists, your page counts, ratings and reviews, the reading groups you join, your daily page logs, and your friendships.

What other people can see

MyBookList is deliberately open about reading. Your profile, your book lists and your reviews are readable by anyone with an account. Inside a reading group, every member sees every other member’s declared book, daily page counts and streak — including the days you missed. That visibility is the point of the product; if you would rather it were private, do not join a group.

Your email address is never shown to other users.

Where it lives

Data is stored in Supabase (PostgreSQL). Row Level Security policies are applied to every table so the database itself enforces who can read and write what, rather than relying on the application alone.

Cookies

One session cookie keeps you signed in. There is no advertising, no third-party analytics, and no tracking pixels.

Deleting your account

Ask and your account is removed. Deletion cascades: your lists, logs, reviews, group memberships and friendships go with it. Aggregate counts that no longer identify you may remain.

Contact

Questions about any of this go through the feedback form.