Privacy Policy of Bookgeist
Last modified: 2026-10-06
1. Introduction
This Privacy Policy explains how Bookgeist processes information when you use the app or the bookgeist.app and bookgeist.art websites.
Bookgeist is designed for personal use and works primarily with local storage on the device. Core library and reading features can be used offline. Connected features use external services for accounts, purchases and subscriptions, cloud backup, public book and author metadata, cover images, optional technical diagnostics, and AI or vision features.
2. Controller
Controller: Luis González López
Contact: [email protected]
Website: https://bookgeist.app
Privacy policy published at: https://bookgeist.app/privacy
3. Data Bookgeist may process
Bookgeist may process books and their metadata, ISBNs, reading status, reviews, ratings, private notes, reading sessions, objectives, collections, sagas, loans, app preferences, images, imported or exported files, structured author data when available or confirmed by the user, public bibliographic identifiers, RevenueCat customer identifiers, purchase and transaction data including tips and Stamp Packs, access status (Classic as the free base tier, Lifetime as a one-time purchase, or Studio as a monthly or annual subscription), AI credits, and the limited technical data needed to provide and protect connected services. RevenueCat, App Store, and Google Play are involved when a purchase, subscription, refund, restoration, or associated historical record exists. Tips do not require a Bookgeist account, but their purchase generates technical transaction records with the store and RevenueCat. Before an account is linked, RevenueCat may use its own customer identifier without a Bookgeist account; after sign-in, it may be associated with the pseudonymous Bookgeist account identifier. Tips do not change your access status or Stamp balance.
When you search for books, ISBNs, covers, or public bibliographic data, Bookgeist may process the query, approximate language, platform, app version, and other minimum technical data needed to provide and protect the service. These data do not include your name, email address, or library contents.
Connected features such as AI, credits, linked purchases, or cloud backup need an account and may depend on the active plan. Bookgeist uses Supabase Auth for verified-email, Apple, and Google sign-in and may process your email or Apple private-relay email, display name, provider user identifier, authentication data, and the data you explicitly send to a connected feature.
Cloud backups may include your library, sessions, notes, notebooks, attachments, scan history photos, and preferences. Their content is strongly encrypted on the device before upload and stored through Cloudflare services so it can be restored on authorized devices. This system is not described as end-to-end or zero-knowledge encryption. You can delete your account and associated service data as described in section 12 and in the account-deletion document.
If the user expressly enables technical diagnostics, Bookgeist may send anonymous technical data to Sentry to diagnose crashes, errors, and slow or failed flows: app version, build number, platform, operating system, sanitized stack trace, technical error message, limited technical breadcrumbs, and aggregate performance or flow-outcome metrics such as durations, retries, or completion states. Bookgeist does not send aliases, email, name, library contents, book titles, ISBNs or queries in clear text, notes, quotes, contacts, local files, full URLs, or personal content entered by the user in technical diagnostics.
When the user chooses to report a problem from the app, Bookgeist may send a user-initiated bug report. It may include a written description, a screenshot of the app that the user optionally attaches, and technical device context (app version, build number, platform, and operating system). Sending is voluntary and started by the user. Unlike the anonymous technical diagnostics above, a screenshot may contain personal content visible at that moment (book titles, notes, library) and, where applicable, third-party data shown on screen, so the user decides whether to attach it and what it shows. The report is sent through a Bookgeist service hosted by Cloudflare so the issue can be diagnosed and fixed.
When the user uses the bookgeist.app website, Bookgeist may process data from the contact form (name, email, and message, sent voluntarily to receive a response) and from the Android beta waitlist (email only, sent voluntarily to receive a Google Play testing invitation). Both forms are protected with Cloudflare Turnstile to prevent automated submissions; the verification result is not linked to the user’s identity beyond confirming the submission is not automated. This data is received through Bookgeist services hosted by Cloudflare. Submitting the form also records the date and time you accepted this Privacy Policy, as a record of your consent. The legal basis for this processing is your consent (Art. 6.1.a GDPR), given expressly by ticking the Privacy Policy acceptance checkbox before submitting the form. You can withdraw your consent at any time by writing to [email protected]; withdrawal does not affect the lawfulness of processing carried out before it. This data is kept for a maximum of 6 months from submission, after which it is automatically deleted.
Contact from the app
Settings > Contact lets you submit questions, issues, suggestions and missing-book requests without signing in. We send your name, reply email, the fields you complete and, if you choose it for a book request, an ISBN CSV. Language, app version, platform and a random reference to prevent duplicates are also included. These forms do not automatically attach your library, screenshots or logs.
The Bookgeist service hosted by Cloudflare stores the request and the time you accepted the consent checkbox. The team receives a reference-only notification and accesses the content in a restricted panel. Submission is voluntary and used to answer your question, investigate an issue, consider a suggestion or review adding a book to the search catalogue. Requests and their CSVs are retained for a maximum of six months. You can request deletion or withdraw consent by writing to [email protected]. IP and capacity limits prevent abuse; these native forms do not use Turnstile. Do not include other people’s personal data in the CSV.
Website analytics
Public pages on bookgeist.app and bookgeist.art use Cloudflare Web Analytics for aggregate statistics about visits, pages viewed, referral sources, country, browser, device and loading performance. When you visit these pages, your browser sends technical measurements to Cloudflare. According to its documentation, this service does not use cookies or local storage to measure usage and does not fingerprint individuals. We do not send form contents, your email or your library to this analytics service, or link its metrics to a Bookgeist account. The sign-in callback page is excluded. These statistics help improve the websites and are not used for personalized advertising. More information: Cloudflare Web Analytics.
In addition, openings of the /app link printed on bookmarks are recorded in a Cloudflare database to measure the initial campaign. Each record contains a random opening identifier, the campaign, the server date and time, and the /app path. This record does not store IP addresses, browser information, URL parameters, or account or visitor identifiers, and does not use cookies or local storage. We retain the opening history to compare campaign trends. An opening does not prove an installation or identify a person; repeat visits may count again.
4. Purposes
Data are used to operate the app, record reading progress, save notes and statistics, import and export data, personalize the app, download covers or metadata, consult public sources to improve cataloguing, protect Bookgeist services and prevent abuse, diagnose crashes, errors, and slow or failed flows if optional technical diagnostics are enabled, manage Lifetime purchases, voluntary tips, Stamp Packs, monthly or annual Studio subscriptions, purchase and subscription restoration where applicable, and historical Classic records needed for support or restoration, authenticate and manage accounts, create and restore encrypted cloud backups, provide connected services included in the plan, process native text recognition (OCR) on the device without sending the image to an AI provider for that local processing, process external AI features such as Studio Scan or image generation with explicit consent before transferring content, diagnose user-initiated bug reports, respond to website contact messages, and manage Android beta invitations. Technical diagnostics are not used for advertising, tracking, or profiling.
4a. Legal basis for processing
| Processing | Legal basis |
|---|---|
| Using the app, metadata and cover lookups, and managing the account and the connected services of your plan, including cloud backup | Performance of a contract, that is, the terms of use you accept (Art. 6(1)(b) GDPR) |
| Purchases, subscriptions, Stamp Packs, tips, and purchase restoration | Performance of a contract (Art. 6(1)(b) GDPR) |
| Sending content to external AI features | Your consent (Art. 6(1)(a) GDPR), which you can withdraw in Settings |
| Optional technical diagnostics | Your consent (Art. 6(1)(a) GDPR); off by default |
| Bug reports, contact forms, and the Android waitlist | Your consent (Art. 6(1)(a) GDPR), given by sending them voluntarily |
| Service security, fraud and abuse prevention, usage limits, and technical logs | Our legitimate interest in protecting the service and its users (Art. 6(1)(f) GDPR) |
| Aggregate website statistics and campaign measurement | Our legitimate interest in improving the websites (Art. 6(1)(f) GDPR) |
| Handling your requests to exercise your rights, including account deletion, and being able to show that we handled them | Compliance with legal obligations (Art. 6(1)(c) GDPR) |
| Technical record after deletion | Our legitimate interest (Art. 6(1)(f) GDPR); see below |
Where the basis is your consent, you can withdraw it at any time without affecting the lawfulness of earlier processing. Where it is our legitimate interest, you can object by writing to [email protected].
Technical record after deletion
After you delete your account, we keep a minimal technical record so that an operation started before deletion cannot store data for the account again. It contains a pseudonymous account identifier, a reference to the deletion operation, and its status. It does not include your name, email, or library content, and is not used for any other purpose.
Our legitimate interest is that deletions are complete and verifiable. We have assessed its necessity and its impact on the people concerned, which is minimal. The record may be kept for more than 30 days: we delete it once no operation started before deletion can store data for the account again, or once another verified mechanism achieves the same result without keeping it. We review the need at least once a year.
You can object to this processing on grounds relating to your particular situation by writing to [email protected]. We will stop processing the record unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or it is needed to establish, exercise, or defend legal claims. We will tell you the decision and the reasons.
5. User control
The user controls most content because they enter, import, edit, export, or delete it manually. Core local features do not require an account or connection.
Metadata lookups may run automatically during ISBN imports, book searches, or author enrichment. If there is no connection or no reliable source is found, the user can enter or correct data manually.
Camera or photo-access permission allows you to capture or select images; it does not by itself authorize sending them to AI services. Native OCR is processed on the device. Studio Scan and other external AI features require separate consent before content is transferred. If you do not accept, that transfer is not authorized and you can continue using the local features included in your plan.
Bookgeist may store the consent date and policy version locally so the notice does not need to appear before every request. You can withdraw consent from the AI and privacy section in Settings. After withdrawal, your consent is required again before new transfers to AI can be authorized. Withdrawal does not undo transfers already made or automatically delete content already sent; its processing and retention are described in section 8.
With valid consent, Studio Scan may prepare and preload a selected photo to Bookgeist services before you press the final button to start recognition. Cancelling the analysis does not necessarily mean the photo has stayed on the device. Transfer, starting analysis, and confirming books are separate steps, as explained in section 8.
Anonymous technical diagnostics are optional and disabled by default. They can be enabled or disabled from Settings > Privacy & permissions > Share technical diagnostics. Disabling them blocks new telemetry submissions.
6. Storage model
Bookgeist stores most information locally on the device. No Bookgeist account is required for core local features and there is no mandatory sync to Bookgeist-owned servers.
Protection of that local data at rest depends on the operating system and device safeguards, such as the device passcode and storage encryption. Bookgeist does not apply an additional Bookgeist-managed encryption layer to the local database.
Bookgeist offers optional accounts. Classic is the current free base tier. Lifetime purchases, tips, Stamp Packs, and monthly or annual Studio subscriptions are managed through the stores and RevenueCat. Historical Classic purchase records may remain in those systems for restoration, support, refunds, or product transition. Studio and Lifetime include optional automatic encrypted cloud backup; local core features continue to work without mandatory cloud sync. Connected AI features depend on the plan, available Stamps, and service availability.
When you use account features, the necessary information described in section 3 is stored in Bookgeist account, AI, or backup services and linked to a pseudonymous account identifier. Core local features continue to work without an account.
7. Internet connections, purchases, and third parties
Bookgeist may connect to external services to download covers; search book or ISBN metadata; find alternative covers based on title and author; enrich author data; process optional technical diagnostics with Sentry; manage purchases, including tips and Stamp Packs, and subscriptions with RevenueCat, Apple App Store, and Google Play; transfer user-selected content for an external AI feature with prior consent, including preparation or preloading of Studio Scan images (native local OCR does not require that transfer); authenticate through Supabase Auth using verified email, Apple, or Google; create or restore encrypted backups for eligible plans; share, import, or export files; or send a user-initiated bug report with an optional screenshot and technical context.
Processors or providers include RevenueCat for purchases (including tips and Stamp Packs), subscriptions, and restoration where applicable; Apple App Store and Google Play; Supabase Auth; Apple and Google identity services; Sentry; and Open Library, Google Books, ISBNdb, DILVE, Wikidata/Wikipedia, Serper.dev, metadata APIs, and cover services.
For connected infrastructure and AI:
- Cloudflare provides infrastructure, protection, and storage for Bookgeist connected services, including receiving and preloading AI images, encrypted backups, bug reports, and cover delivery.
- Google provides book recognition and image generation through its AI services, directly or through OpenRouter.
- OpenRouter acts as an intermediary for book recognition and image generation routes. It forwards the necessary content to the provider processing the request. Configured OpenRouter recognition routes may use OpenAI or Microsoft (Azure); image generation routes may use Google, OpenAI, Microsoft (Azure), Sourceful, Krea, or Black Forest Labs.
- OpenAI moderates descriptions and text settings for image generation features to detect disallowed content. This review may take place even if no image is subsequently generated and no Stamps are consumed. This text moderation is separate from recognition or generation that its services may perform through OpenRouter.
The requested feature and available route determine which providers are involved. If a route fails, an alternative may receive the content needed to retry the request; a single request may therefore pass through more than one provider. Not every listed provider receives every request.
Some of the providers above, including Cloudflare, operate with globally distributed infrastructure. Where this involves a data transfer outside the European Economic Area, that transfer is carried out under the safeguards provided by the GDPR (such as the European Commission’s standard contractual clauses or another recognized transfer mechanism).
Bookgeist does not control the privacy policies of external sites or providers outside the controller’s responsibility.
8. AI, consent, and retention
Sending content to external AI requires your prior consent. This policy describes the content that may be sent, its purposes, and the recipients involved. AI features may consume Stamps depending on the feature and plan. Camera or photo-access permission is separate from that consent. You can refuse or withdraw it in Settings; the local features in your plan remain available.
AI features may send selected images, written descriptions, style and other settings, and the technical or account identifiers needed to authenticate the request, manage the plan and Stamps, provide the service, and prevent abuse. Bookgeist services and the external providers involved may process these data according to their role; the content is not presumed anonymous, nor is every recipient presumed to receive the same fields.
For AI visual reference, Bookgeist sends the visual description written by the user, selected style, optional settings, and the minimum data needed to manage the plan, credits, and abuse prevention. Bookgeist does not send the full library, full notebook, contacts, backups, exports, or unrelated local files.
Cover, spine, or shelf photos you select for Studio Scan are sent to Bookgeist services and external AI providers to recognize books. This is not exclusively local processing: images used by these features leave the iPhone or other device running the app. Recipients are identified in section 7.
Studio Scan distinguishes three steps:
- Image transfer: with valid consent, preparation and preloading may upload the selected photo to Bookgeist services before you press the final recognition button. This transfer is part of the authorized submission; camera permission alone does not authorize it.
- Starting analysis: requesting recognition starts AI analysis of the prepared images. Cancelling before this step does not undo a transfer already made.
- Library confirmation: reviewing and confirming recognized books is a later step. Uploading an image or starting its analysis does not mean confirming those books in your library.
On your device, the app keeps a copy of your Studio Scan photos and their results for 7 days from the scan, so you can review failed scans and add books by hand. After that period, the local copy is deleted automatically. It is private and under your control: it is only included in the backups you make or turn on to recover your data, such as the encrypted cloud backup described in section 3, and it is not used for any other purpose. A restored backup keeps each scan’s original deadline, so scans that are already older than 7 days are deleted during the next automatic cleanup.
Temporary AI files and results managed by Bookgeist are deleted after delivery or, if abandoned, normally within 24 hours. AI providers may apply their own operational retention under their processor terms.
Bookgeist retains content sent to AI only for the minimum time needed to process the request, diagnose failures, and prevent abuse. Bookgeist does not use that content to train its own models. AI providers apply their own processing and retention terms.
For image generation, Bookgeist deletes the description and temporary files after delivering the result or, if processing does not complete, normally within 24 hours. Technical data that does not contain the submitted content may be kept for the time needed to manage credits, security, and abuse prevention.
When a user reports an image, the pseudonymous identifier, reason, and user-written detail are retained to record and investigate the incident. These data are scheduled for automatic deletion 180 days after the report; temporary failures are retried. We may delete them earlier when no longer needed, and they are deleted when the account is deleted. Do not include unnecessary personal information in a description or report.
9. Device permissions
Depending on platform and user choices, Bookgeist may request camera, photos/gallery, contacts, files/documents, microphone (to dictate or record voice notes), and notifications permissions. Notifications are local reminders generated on the device and are not sent through Bookgeist-owned servers. Granting permissions is optional, but some features will not work without them. Granting camera or photo access does not mean consenting to send images to external AI. That transfer requires the separate consent described in sections 5 and 8.
10. Data sharing
Bookgeist does not sell personal data and does not automatically share the user’s library or reading history with advertising networks. In the app and forms, data leave the device when the user initiates an action that requires it or uses a documented feature requiring an external lookup, such as exporting or sharing a file, downloading a cover, searching external metadata, enriching author data, making purchases including tips and Stamp Packs, restoring purchases where applicable, managing a subscription, transferring content to an external AI feature with prior consent including Studio Scan image preloading (native OCR is processed locally), sending a user-initiated bug report with a screenshot the user chooses to attach, or submitting the contact form or joining the Android beta waitlist.
Browsing public website pages also sends Cloudflare the technical measurements described under Website analytics in section 3.
11. Retention
Local data are kept while the app remains installed or until the user deletes them manually from the app or by clearing app data. As an exception, the local copy of Studio Scan photos and results is kept for 7 days from the scan and then deleted automatically, as section 8 explains. Exported files may remain wherever the user stores or shares them. Purchase data, including tip transactions, are retained according to Apple, Google, and RevenueCat policies. AI data are retained only for the operational periods described in section 8. Account data, backup metadata, and encrypted backup objects are retained while the account exists or until account deletion under the service’s operational policy. Loss or expiry of an eligible plan may block backup access without causing immediate deletion, subject to minimum legal, security, and transaction-retention obligations.
Technical data used to provide and protect metadata services are retained only for the minimum time needed to prevent abuse and diagnose errors.
User-initiated bug reports (description, attached screenshot, and technical context) are kept only as long as needed to reproduce, diagnose, and fix the issue, and are deleted once no longer useful for that purpose.
Account data and synced data are kept while the account is active and are deleted when the account is deleted, except the minimal records described in the account deletion document, including the technical record in section 4a and the record of your request for up to 24 months. Apple, Google, and RevenueCat keep transaction records under their own obligations and policies.
After a deletion request, your data may remain for up to 30 days in the technical recovery history of our databases, which is not used for ordinary activity. If we ever had to restore it, we would re-apply the recorded deletions. Technical operating logs are kept for short periods, normally 7 days at most.
Contact messages submitted through the website and Android beta waitlist signups are kept for a maximum of 6 months from submission, after which they are automatically deleted.
12. User rights
The user can access, modify, or delete content they have entered, export their data, delete the app and local data, delete their Bookgeist account and associated server data from Settings, restore purchases, and manage or cancel subscriptions through App Store or Google Play.
You can also exercise your rights of access, rectification, erasure, objection, restriction of processing, and portability, and withdraw any consent you have given, by writing to [email protected]. If your request concerns a deleted account and you still have the deletion reference the app displayed, include it to help us find it. We respond without undue delay and within one month of receipt at the latest; if its complexity or the number of requests means we need up to two more months, we will tell you, with the reason, within the first month.
If you believe the processing of your data does not comply with applicable law, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es, without prejudice to any other administrative or judicial remedy.
13. Children
Bookgeist is intended for people aged 13 and over and is not intended for children under 13. Bookgeist does not request a date of birth or perform documentary age verification. Most reading tracking remains on the device; accounts, purchases, reports, and AI or connected features process the data described in this policy when the user chooses to use them.
People aged 13 to 17 must use the app with any authorization or supervision required by applicable law and the rules of their family account or store. In all cases, a person under 18 may use connected or AI features that rely on providers requiring parental authorization only when that authorization has been obtained. In Spain, where processing is based on consent, users under 14 require consent from the holder of parental responsibility or guardianship under Article 7 of the LOPDGDD. We recommend that a responsible adult review purchases, connected features, and AI image generation. See the Age Suitability Policy. If a legal guardian believes that a minor’s data has been processed inappropriately, they can contact [email protected] to request review or deletion.
14. Security
Bookgeist uses a local-storage-centered architecture and strong safeguards to protect communications, accounts, and backups. Cloudflare provides and protects the connected services. No system can guarantee absolute security.
15. Changes to this policy
This Privacy Policy may be updated to reflect functional, technical, or legal changes. The last-modified date is shown at the beginning of the document.
16. Contact
For privacy questions, support, or requests to exercise your rights, contact [email protected].
This English text is a translation of the binding Spanish version and is provided for convenience.