Privacy
Last updated: September 2026
MyBookCat is a catalogue of your own bookshelves. This page says what it keeps, who else sees it, and how to get rid of it. It is written to be read, not to be survived.
What we hold
Your account. Your email address and your name. Signing in is handled by Clerk, so your password lives with them and never with us; if you sign in with Google, we receive the email address and name on that Google account and nothing else from it.
Your library. Everything you catalogue: titles, authors, editions, volume numbers, languages, tags, categories, shelves and where on them a book sits, your notes, ratings and the page you are on.
Cover photographs. Covers you photograph, and cover images fetched from public book databases, stored as files alongside your catalogue.
Lending records. When you lend a book you write down who has it: a name, usually an email address, the date it went out and the date it is due. That is information about somebody else, and the section below on borrowers matters.
People in your library. Invitations, join codes, who is a member of which catalogue and what each of them may do.
Requests to borrow. If you turn on a public link and leave borrowing requests enabled, a visitor can send you their name, a way to reach them, and a short message.
How the app is used. Events like a book added, a scan run, an upgrade opened, with your account's internal id and which platform you were on. Also a record of each AI scan: which model ran, how many tokens it used and what it cost, which is how your scan allowance is counted.
Your plan. Which plan a library is on, how many bought scans it has left, and the identifiers Polar gives us so a payment can be matched to the right library.
Where it lives
Your account and your catalogue are stored in a Supabase database and file store hosted in Canada (Montreal). The app itself is served by Vercel from the United States, so requests you make pass through there. Everything below processes data in its own regions, which are generally the United States and the European Union.
Who else is involved
Five companies handle some part of this, and one of them handles your money. None of them are advertisers, and none of them are paid in data.
Clerk — signing in. Holds your email address, your name and your sign-in record, and sends the email that verifies your address.
Polar — payments. Polar is the merchant of record: they sell the plan, take the card, handle the tax and run any trial. They receive your email address, an identifier for the library being upgraded, and which plan or scan pack you chose. Card details never reach MyBookCat and we could not show them to you if you asked.
PostHog — product analytics, so we can see which parts of the app people actually use. It is sent your account's internal id and what happened, such as a book added or a scan run. It is never sent your name, your email address, your books' titles, or anything about a borrower. It is loaded through our own domain, so no third-party analytics domain is contacted from the page.
Resend — the reminder emails. Receives the borrower's name and email address, the book, and the due date, in order to deliver the message.
Anthropic, and OpenRouter for some foreign-language covers — reading a photographed cover. The photograph and nothing else is sent, it is used to extract the book's details, and it is not used to train models. Scanning a barcode or looking up an ISBN never sends a photograph anywhere.
Google Books and Open Library — looking up a book. They receive the ISBN and nothing about you.
We do not sell data, and there is no advertising anywhere in the app.
Cover images are not secret
Cover images are stored so that anyone holding the exact web address of a file can open it. The addresses contain long random identifiers and are not listed or guessable, and nothing links a cover to your name — but they are not locked behind your sign-in either. It is a fair thing to know before photographing the inside of a book that has your name written in it.
Borrowers, who never signed up
When you record a loan you are storing another person's name and email address, and MyBookCat will email them about the book without them ever having used it. They did not agree to anything with us; they lent or borrowed with you.
So: only enter a borrower's email address if it is reasonable to write to them about the book, tell them the app will do it if they would not expect it, and delete the loan when you want it to stop. Reminders can be switched off entirely for a library in Settings, under Lending and reminders. If somebody asks us directly to stop emailing them, we will remove their address.
Sharing, which is off until you turn it on
A library is private. Nobody sees it but you and anyone you invite into it.
You can publish a read-only page for a library and choose what appears on it: covers, authors, where a book sits, whether it is out on loan, a search box, your wishlist, and whether visitors may ask to borrow. Turning the page off removes access immediately. While it is on, the fields you ticked are visible to anyone with the link, which is what publishing means.
Getting your data out, and deleting it
Out: Settings has an export. Your whole catalogue comes down as Excel or CSV, with every title, author, shelf and note, at any time, on any plan.
Gone: Settings has a delete, and it deletes rather than deactivates. Every library you own goes with it — its books, shelves, loans, wishlist, invitations, its members' access, and its cover images. So do your own records everywhere else: your profile, your memberships in other people's libraries, your reading progress.
Two things survive, and it is fair to say so. Books you added to somebody else's library belong to that library and stay, as do libraries other people own. And the usage and AI-cost records are kept with the link to you removed, so we still know what the app costs to run without knowing whose scan it was.
If you own a library other people use, deleting your account removes it for them too. The app says so, in those words, before it accepts the confirmation.
How long it is kept
Your catalogue is kept until you delete it or delete your account: it is the thing you came here to keep. Usage and AI-cost records are kept as long as they are useful for running the service, with any link to a person removed once that account is gone. Payment records are Polar's and follow their retention and whatever the tax rules require of them.
Children
MyBookCat is not built for children and is not directed at them. An account is meant for someone aged 13 or over. A family or a school might well catalogue books that children read, which is a shelf rather than a child's account, but the account holder should be an adult or an older teenager.
Your rights
You can see your data (it is the app), correct it (edit it), take it away (export), and have it erased (delete your account). Depending on where you live you may also have the right to object to some processing or to complain to a data-protection regulator. Ask us and we will do it rather than make you cite a law.
Changes, and how to reach us
When this page changes the date at the top changes with it. If a change means we would do something materially different with data already collected, we will say so in the app rather than quietly amend this page.
Questions, or a request about your data: Support.