← Back to Bookmark
Legal

Privacy Policy

Last Updated: 30 May 2026

Bookmark ("we", "our", or "the app") is committed to protecting your privacy. This Privacy Policy explains what information Bookmark collects, how it is used, and what choices you have when using the Bookmark iOS and Android apps, website, account features, sync, and community features.

Bookmark can be used without an account. Core library data is stored on your device. If you sign in or use account, sync, social, or community features, some data is sent to our backend services so those features can work.

We do not sell your personal data. We do not run ads. We do not use third-party advertising identifiers or cross-app tracking.

Information We Collect

On-Device Library Data

Bookmark stores your library and reading data on your device. This may include:

On iOS, this data is stored in the app container and, where needed for widgets, the app group container. On Android, this data is stored using app-local databases, preferences, and files. Authentication, app attestation, and integrity tokens are stored using platform secure storage where supported.

Android device backup or device transfer may include some non-authentication app preferences. Authentication and integrity-token preferences are excluded from Android backup. Bookmark does not use iCloud or CloudKit for library sync.

Account Sign-In

An account is optional for core library features.

On iOS, Bookmark uses Sign in with Apple. On Android, Bookmark uses Google Sign-In through Android Credential Manager. Depending on the provider and your choices, Bookmark may receive an app-specific account identifier, email address, name or display name, profile photo URL, and authentication token.

Bookmark uses these provider tokens to authenticate with Supabase, our backend account provider. Your Supabase account links account-only features such as cloud sync, social profiles, book clubs, remote notifications, and feature requests.

Cloud Sync and Backup

When you are signed in, Bookmark syncs supported app data to Supabase so your data can be backed up, restored, and used across devices.

Synced data may include:

Synced images are stored in private Supabase Storage areas such as the user-data bucket. Signed URLs may be used so the app can download your private images. If you do not sign in, this cloud sync data is not sent to Supabase, except for other network requests described in this policy.

Social Profiles and Community Features

If you create a social profile, use social discovery, join book clubs, submit feature requests, or use community features, Bookmark stores the information needed to provide those features in Supabase.

This may include:

For profile matching, books-in-common, and social discovery features, Bookmark may sync book hashes and supporting metadata for books in your library, including ISBNs where available, titles, authors, reading status, cover URL, rating, finish date, series details, published date, and shared custom cover paths. Visibility is controlled by profile privacy settings, relationship status, feature rules, and backend access controls.

Community Book Images

If you choose to share book images with the community or select a community image, Bookmark may upload cover, spine, or sprayed-edge images and thumbnails to Supabase Storage and store related image records.

Community image records may include the image type, book ISBN, title, author, dimensions, file size, storage path, moderation status, and timestamps. Approved community images may be shown to other authenticated users for matching books.

Analytics

Bookmark uses TelemetryDeck for privacy-focused product analytics. Analytics help us understand which features are used, diagnose product issues, and improve the app.

Analytics events may include feature usage, app launches, onboarding steps, tab or screen names, paywall events, purchase or restore events, sync outcomes, import/export outcomes, widget usage, barcode scanning outcomes, notification interactions, API error categories, app attestation or integrity outcomes, and bucketed counts or durations.

We do not use TelemetryDeck to collect your reading notes, free-form reviews, full library contents, payment card details, or advertising identifiers.

Crash Diagnostics

Bookmark uses Sentry on iOS and Android for crash and error diagnostics. Sentry may collect technical diagnostic information such as app version, device model, operating system version, stack traces, error messages, and breadcrumbs that help reproduce crashes.

Sentry is configured not to send default personally identifiable information. On Android, screenshot and view hierarchy attachment are disabled. Performance tracing is disabled.

Book Metadata, Currency, and App Configuration Requests

When you search for books, scan ISBN barcodes, import books, or request metadata, Bookmark may send the ISBN, search query, author name, or batch of ISBNs to our API at api.bookmarkapp.com.au. This API is hosted on Cloudflare Workers and may query ISBNdb or related metadata services.

When Bookmark converts purchase prices or displays currency information, it may request exchange-rate data from our API, which may use Open Exchange Rates.

On iOS, Bookmark may also fetch remote app configuration from our API.

These API requests may include app attestation or integrity authorization tokens so we can verify that requests are coming from a genuine app and reduce abuse. These requests do not include your full library unless you submit those ISBNs, titles, authors, or searches as part of a lookup, import, or metadata request.

App Attestation and Device Integrity

Bookmark uses Apple App Attest on iOS and Google Play Integrity on Android to protect backend APIs from abuse.

The app may request a challenge from our API, send Apple or Google attestation or integrity tokens to our API, and store returned authorization tokens or device integrity identifiers in platform secure storage. These tokens are used for API protection, not advertising or cross-app tracking.

Camera, Photos, and On-Device Scanning

Bookmark may request camera access for barcode scanning, book photos, and related book-management workflows. Bookmark may request photo or media access when you choose images for covers, avatars, books, preorders, subscriptions, or community sharing.

Barcode and text recognition are performed on device using platform tools such as Apple frameworks on iOS and Google ML Kit or CameraX on Android. Images remain local unless you sign in and cloud sync them, upload them as part of a profile or book club feature, or choose to share them with the community.

Imports, Exports, and Backups

Bookmark can import data from files such as CSV, Goodreads exports, spreadsheet files, or Bookmark backup files. Imported files are processed on your device. If metadata lookup is needed, related ISBNs, titles, authors, or search terms may be sent to our metadata API.

Exports and backup files are created on your device and are shared, saved, or stored only where you choose. If you are signed in, imported or restored library data may later sync to Supabase.

Notifications

Bookmark provides local reminders for app features such as daily goals, streaks, preorders, subscriptions, release guesses, weekly reports, and book club deadlines.

Bookmark also supports remote push notifications for account, social, and book club features. On iOS, remote notifications use Apple Push Notification service. On Android, remote notifications use Firebase Cloud Messaging.

When you are signed in and notifications are enabled, Bookmark may store a device push token, platform, app version, user ID, notification preferences, and muted club settings in Supabase. Remote notification payloads may include a notification type, title, body, and IDs needed to open the related screen.

You can manage notification permissions through your device settings and supported in-app notification preferences.

Widgets

Bookmark widgets read shared on-device app data so they can display your books or reading information. Widgets do not independently send your library data to our servers.

In-App Purchases

Bookmark uses Apple StoreKit on iOS and Google Play Billing on Android for subscriptions and one-time purchases. Apple or Google process payments and manage billing accounts.

Bookmark does not receive or store your payment card number, bank details, or platform billing credentials. Bookmark stores entitlement or premium-status information needed to unlock paid features. Purchase, product, entitlement, or revenue-related events may be reported to TelemetryDeck for product analytics and purchase diagnostics.

How We Use Information

We use information to:

What We Do Not Do

Bookmark does not:

Third-Party Services

Bookmark uses the following services where needed:

These services process data according to their own privacy policies and terms.

Data Storage and Security

Local data is stored in app-controlled storage on your device. Sensitive authentication and integrity tokens are stored using platform secure storage where supported.

Remote account data is stored in Supabase and protected using authentication, backend authorization rules, private storage buckets, signed URLs, and HTTPS. Bookmark's API uses app attestation or integrity checks for protected endpoints.

No internet-based system can be guaranteed completely secure, but we limit collection, restrict access, and use technical controls appropriate to the type of data being handled.

Retention and Deletion

You can delete books, images, profile content, and other app data through supported app features. You can also delete local app data by uninstalling the app, subject to any device backups or platform restore features you have enabled.

Signing out removes local account state and attempts to remove device push tokens where supported. Account deletion and social-profile deletion flows remove local data and app-managed remote records where supported by the app. Some records may remain for a limited time in backups, logs, cached systems, purchase records managed by Apple or Google, or backend records that require manual deletion.

If you want us to delete remote account, sync, or social data associated with your account, contact us at legal@bookmarkapp.com.au from the email address associated with your account or include enough information for us to identify the account.

Active App Store or Google Play subscriptions must be cancelled through Apple or Google.

Children's Privacy

Bookmark is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us so we can delete it.

Your Privacy Rights

Depending on your location, you may have rights to access, correct, delete, or export personal information associated with your account. To make a privacy request, contact legal@bookmarkapp.com.au.

Changes to This Policy

We may update this Privacy Policy as Bookmark changes. When we make material changes, we will update the "Last Updated" date and, where appropriate, provide notice in the app or on the website.

Contact

For privacy questions or requests, contact:

legal@bookmarkapp.com.au

Questions? Email legal@bookmarkapp.com.au