Privacy policy

Keep your data close.

This policy explains what TomeHoard handles when you use the mobile app, tomehoard.com, or a shared wishlist page. It is written to match the way the product currently works.

Last updated: September 17, 2026

01 / The basics

Who we are

TomeHoard is the service provider responsible for the app, website, account features, and shared wishlist pages described here. For privacy questions or requests, contact admin@tomehoard.com.

This policy applies to information handled through the hosted TomeHoard service. A self-hosted, development, or modified build may use different infrastructure and may have its own privacy notice.

02 / What we handle

Information we handle

The information depends on which features you choose. You can use the core library without creating an account.

Library and reading data

The app can store book identifiers such as ISBNs, titles, authors, formats, condition, acquisition details, prices and currencies, dates, ratings, notes, custom series and genre information, reading history, shelves, goals, and visibility choices. This also includes metadata and cover images cached for offline use.

This information is kept in the app’s local database and app-owned files until you remove it or uninstall the app. A Goodreads CSV import is parsed on your device; the CSV is not uploaded by the import feature.

Account and profile data

If you create an account, we handle your email address, an account identifier, username, display name, and authentication information. In the hosted app, Supabase Auth manages the password, confirmation email, password recovery, and session lifecycle. We do not receive or store your plaintext password. Some self-hosted or test builds can use local authentication; those builds store a password hash and session-token hashes on their configured server.

Optional sync and social features

When you sign in and enable sync, the supported library rows are copied to the TomeHoard API so the library can be restored on your other devices. These rows can include books, reading events, shelves, shelf membership, goals, settings, visibility choices, and user-entered book details. Provider metadata and device-local cover paths remain on the device; a custom cover you choose can be uploaded to private storage so your other devices can use it.

If you use friends, we handle the usernames, display names, and friendship or request status needed to connect people. Friends only receive the library fields allowed by your visibility settings. Private notes and local file paths are not included in friend views.

Public wishlist links

You can create an unlisted share link for your wishlist. Anyone who has that link can view the owner’s display name or username, wishlist titles, authors, ISBNs, and cover images, plus links to search for those books at retailers. The link is not indexed by search engines, but it is a bearer link: treat it like an invitation. Links stay active until you revoke them. Opening a link updates its last-accessed time; we do not identify the visitor through the wishlist feature itself.

Book metadata and cover lookups

When the app looks up a book, it may send an ISBN or title and author search terms to the metadata provider you have enabled. Depending on your settings and the lookup, providers can include Hardcover, Goodreads, Google Books, bibliotek.dk, Open Library, Amazon, and Audible. Their own privacy notices apply to requests they receive. Optional Google Books and Hardcover API keys are stored in secure storage on your device and are not included in TomeHoard issue reports.

Permissions and device information

  • Camera access is used only when you scan an ISBN barcode or take a custom book-cover photo. Photo or file access is used only when you choose an existing cover.
  • Low-accuracy foreground location may be requested once per app session to suggest a country and default currency. TomeHoard does not track your location in the background or store your coordinates. You can deny the permission and choose a currency yourself.
  • Normal technical information, such as IP address, request time, user agent, device model, operating-system version, app version, and error details may be processed by hosting and monitoring infrastructure when you connect to the service.

03 / The website

What happens on the website

The informational pages do not require an account and do not use advertising cookies or analytics trackers. The shared wishlist page stores your selected shopping region in browser local storage so it can remember that preference. It sends the chosen market as part of the request that loads the wishlist.

Wishlist pages load book covers and, when configured, optional Google Books purchase or information links. If you follow a retailer link, the retailer receives the search URL and ordinary browser connection data under its own privacy policy.

Account confirmation and password-reset pages use Supabase’s browser library, delivered through jsDelivr. That CDN and the browser may process normal technical request information needed to deliver the script.

04 / Use and sharing

Why we use information

We use information to:

  • provide the library, reading, sync, friend, and wishlist features;
  • authenticate accounts, recover access, and protect the service;
  • look up book metadata and cache it for your chosen device;
  • respond to support requests, diagnose errors, and improve reliability;
  • prevent abuse, enforce visibility choices, and comply with legal obligations.

Who receives information

We do not sell your personal information and do not use it for advertising. We may share or make information available to:

  • Supabase, which provides hosted authentication, database, and private file storage for the hosted app;
  • GlitchTip/Sentry, when configured, for website, app, and API error monitoring. Reports can include technical diagnostics, an account identifier, and any text you choose to include in an issue report. The app does not enable session tracking and does not send default personal data;
  • the metadata providers you choose, for the ISBN or search terms needed to return book details and covers;
  • hosting, networking, and security providers that operate the website, API, database, or storage; and
  • friends or anyone with a wishlist link, but only the information made visible through your settings or that explicit link.

Authorized TomeHoard administrators may access account and library information when necessary to operate, secure, support, or administer the service.

05 / Reliability

Diagnostics and support

When monitoring is enabled for a deployment, the app can send uncaught errors, platform errors, and limited performance information to GlitchTip/Sentry. The website removes query strings and fragments from reported page URLs. The API may also capture server errors with request method, URL, account context, and technical timing information.

The in-app “Report an issue” form sends the title, description, optional reproduction steps, and device/app diagnostics. Please do not include passwords, API keys, access tokens, private addresses, or other sensitive information in a report.

For short-term troubleshooting, the API may keep up to 100 recent completed non-admin request summaries in application memory. These can include bounded response payloads. Authentication response bodies are omitted, sensitive fields are redacted, and this history is cleared when the API process restarts.

06 / Control

Retention and deletion

Local library data remains on your device until you delete it, clear the app’s data, or uninstall the app. The app’s “Delete local library” action affects the device only; it does not delete a synced account copy.

We keep account, profile, synced library, friendship, and share link data while it is needed to provide the service. You can revoke wishlist links from the app. To request access, correction, export, restriction, or deletion of account or server-side data, email admin@tomehoard.com. We may retain limited information where necessary for security, fraud prevention, legal claims, or legal obligations.

Diagnostic data is retained according to the monitoring and hosting configuration for the relevant deployment and only for as long as it is useful for reliability, security, or support. Copies in backups, logs, or legal records may take longer to disappear.

07 / Your choices

Your rights

Depending on where you live and the law that applies, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information. You can also change visibility settings, decline device permissions, disable metadata providers, use the app without an account, and revoke public wishlist links.

We will respond to a privacy request within the time required by applicable law. We may need to verify your identity before fulfilling a request. You may also complain to your local data protection authority; for people in the EU/EEA, national data protection authorities handle GDPR complaints.

08 / Safeguards

Security and international use

We use access controls, authenticated requests, private storage for custom covers, redaction of sensitive request fields, and encrypted connections for the hosted API. No online service can guarantee absolute security, so keep your account credentials and wishlist links private.

TomeHoard and its service providers may process information in countries different from your own. Where required, we use appropriate safeguards for those transfers. The privacy practices of third-party providers are governed by their own notices.

09 / Age

Children’s privacy

TomeHoard is not directed to children and we do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us so we can review and remove it where appropriate.

10 / Updates

Changes to this policy

We may update this policy when TomeHoard’s features, providers, or legal obligations change. The latest version will always be posted on this page with a new “Last updated” date. If a change is material, we will provide additional notice when appropriate.

This page describes TomeHoard’s current product behavior and is not legal advice. Have local counsel review it before relying on it for a particular jurisdiction or business structure.