Privacy Policy
Last Updated: 30 May 2026Bookmark ("we", "our", or "the app") is committed to protecting your privacy. This Privacy Policy explains what information Bookmark collects, how it is used, and what choices you have when using the Bookmark iOS and Android apps, website, account features, sync, and community features.
Bookmark can be used without an account. Core library data is stored on your device. If you sign in or use account, sync, social, or community features, some data is sent to our backend services so those features can work.
We do not sell your personal data. We do not run ads. We do not use third-party advertising identifiers or cross-app tracking.
Information We Collect
On-Device Library Data
Bookmark stores your library and reading data on your device. This may include:
- Books, titles, authors, ISBNs, descriptions, covers, publishers, formats, languages, categories, series, and page counts
- Reading status, progress, read-through history, reading sessions, streaks, daily goals, notes, ratings, reviews, and timestamps
- Tags, shelves, wishlist items, preorders, subscriptions, renewal details, release guesses, loans, and purchase details you enter
- Custom book covers, book spine or edge images, book photos, subscription images, preorder images, and other images you add
- App preferences, widget data, notification settings, import/export state, and cached metadata
On iOS, this data is stored in the app container and, where needed for widgets, the app group container. On Android, this data is stored using app-local databases, preferences, and files. Authentication, app attestation, and integrity tokens are stored using platform secure storage where supported.
Android device backup or device transfer may include some non-authentication app preferences. Authentication and integrity-token preferences are excluded from Android backup. Bookmark does not use iCloud or CloudKit for library sync.
Account Sign-In
An account is optional for core library features.
On iOS, Bookmark uses Sign in with Apple. On Android, Bookmark uses Google Sign-In through Android Credential Manager. Depending on the provider and your choices, Bookmark may receive an app-specific account identifier, email address, name or display name, profile photo URL, and authentication token.
Bookmark uses these provider tokens to authenticate with Supabase, our backend account provider. Your Supabase account links account-only features such as cloud sync, social profiles, book clubs, remote notifications, and feature requests.
Cloud Sync and Backup
When you are signed in, Bookmark syncs supported app data to Supabase so your data can be backed up, restored, and used across devices.
Synced data may include:
- Library metadata such as titles, authors, ISBNs, descriptions, publishers, formats, languages, categories, series, covers, and page counts
- Reading status, current page, percent complete, read dates, read-through records, notes, ratings, reviews, reading sessions, daily progress, streaks, and goals
- Tags, shelves, shelf layouts, wishlist items, preorders, subscriptions, renewal records, release guesses, loans, and book-related reminders
- Purchase or order details you choose to enter, such as price, currency, purchase date, purchase location, retailer, order links, tracking numbers, subscription cost, and subscription contact email
- Custom covers, spine images, sprayed-edge images, book photos, preorder images, subscription images, and release-guess images
- Sync metadata, deleted-state markers, and timestamps needed to keep devices consistent
Synced images are stored in private Supabase Storage areas such as the user-data bucket. Signed URLs may be used so the app can download your private images. If you do not sign in, this cloud sync data is not sent to Supabase, except for other network requests described in this policy.
Social Profiles and Community Features
If you create a social profile, use social discovery, join book clubs, submit feature requests, or use community features, Bookmark stores the information needed to provide those features in Supabase.
This may include:
- Profile details such as username, display name, avatar, invite code, profile visibility, favorite genres, aggregate reading stats, reading heatmap data, and currently reading books
- Follow relationships, follow requests, blocks, mutes, activities, likes, comments, replies, mentions, and notification records
- Book club details, membership, roles, proposed books, votes, schedules, discussions, messages, reading progress, milestones, invitations, join requests, and club notification preferences
- Feature requests, votes, and moderation or report records
For profile matching, books-in-common, and social discovery features, Bookmark may sync book hashes and supporting metadata for books in your library, including ISBNs where available, titles, authors, reading status, cover URL, rating, finish date, series details, published date, and shared custom cover paths. Visibility is controlled by profile privacy settings, relationship status, feature rules, and backend access controls.
Community Book Images
If you choose to share book images with the community or select a community image, Bookmark may upload cover, spine, or sprayed-edge images and thumbnails to Supabase Storage and store related image records.
Community image records may include the image type, book ISBN, title, author, dimensions, file size, storage path, moderation status, and timestamps. Approved community images may be shown to other authenticated users for matching books.
Analytics
Bookmark uses TelemetryDeck for privacy-focused product analytics. Analytics help us understand which features are used, diagnose product issues, and improve the app.
Analytics events may include feature usage, app launches, onboarding steps, tab or screen names, paywall events, purchase or restore events, sync outcomes, import/export outcomes, widget usage, barcode scanning outcomes, notification interactions, API error categories, app attestation or integrity outcomes, and bucketed counts or durations.
We do not use TelemetryDeck to collect your reading notes, free-form reviews, full library contents, payment card details, or advertising identifiers.
Crash Diagnostics
Bookmark uses Sentry on iOS and Android for crash and error diagnostics. Sentry may collect technical diagnostic information such as app version, device model, operating system version, stack traces, error messages, and breadcrumbs that help reproduce crashes.
Sentry is configured not to send default personally identifiable information. On Android, screenshot and view hierarchy attachment are disabled. Performance tracing is disabled.
Book Metadata, Currency, and App Configuration Requests
When you search for books, scan ISBN barcodes, import books, or request metadata, Bookmark may send the ISBN, search query, author name, or batch of ISBNs to our API at api.bookmarkapp.com.au. This API is hosted on Cloudflare Workers and may query ISBNdb or related metadata services.
When Bookmark converts purchase prices or displays currency information, it may request exchange-rate data from our API, which may use Open Exchange Rates.
On iOS, Bookmark may also fetch remote app configuration from our API.
These API requests may include app attestation or integrity authorization tokens so we can verify that requests are coming from a genuine app and reduce abuse. These requests do not include your full library unless you submit those ISBNs, titles, authors, or searches as part of a lookup, import, or metadata request.
App Attestation and Device Integrity
Bookmark uses Apple App Attest on iOS and Google Play Integrity on Android to protect backend APIs from abuse.
The app may request a challenge from our API, send Apple or Google attestation or integrity tokens to our API, and store returned authorization tokens or device integrity identifiers in platform secure storage. These tokens are used for API protection, not advertising or cross-app tracking.
Camera, Photos, and On-Device Scanning
Bookmark may request camera access for barcode scanning, book photos, and related book-management workflows. Bookmark may request photo or media access when you choose images for covers, avatars, books, preorders, subscriptions, or community sharing.
Barcode and text recognition are performed on device using platform tools such as Apple frameworks on iOS and Google ML Kit or CameraX on Android. Images remain local unless you sign in and cloud sync them, upload them as part of a profile or book club feature, or choose to share them with the community.
Imports, Exports, and Backups
Bookmark can import data from files such as CSV, Goodreads exports, spreadsheet files, or Bookmark backup files. Imported files are processed on your device. If metadata lookup is needed, related ISBNs, titles, authors, or search terms may be sent to our metadata API.
Exports and backup files are created on your device and are shared, saved, or stored only where you choose. If you are signed in, imported or restored library data may later sync to Supabase.
Notifications
Bookmark provides local reminders for app features such as daily goals, streaks, preorders, subscriptions, release guesses, weekly reports, and book club deadlines.
Bookmark also supports remote push notifications for account, social, and book club features. On iOS, remote notifications use Apple Push Notification service. On Android, remote notifications use Firebase Cloud Messaging.
When you are signed in and notifications are enabled, Bookmark may store a device push token, platform, app version, user ID, notification preferences, and muted club settings in Supabase. Remote notification payloads may include a notification type, title, body, and IDs needed to open the related screen.
You can manage notification permissions through your device settings and supported in-app notification preferences.
Widgets
Bookmark widgets read shared on-device app data so they can display your books or reading information. Widgets do not independently send your library data to our servers.
In-App Purchases
Bookmark uses Apple StoreKit on iOS and Google Play Billing on Android for subscriptions and one-time purchases. Apple or Google process payments and manage billing accounts.
Bookmark does not receive or store your payment card number, bank details, or platform billing credentials. Bookmark stores entitlement or premium-status information needed to unlock paid features. Purchase, product, entitlement, or revenue-related events may be reported to TelemetryDeck for product analytics and purchase diagnostics.
How We Use Information
We use information to:
- Provide the app's library, reading, sync, account, social, book club, notification, and community image features
- Back up and restore signed-in user data
- Authenticate accounts and protect backend APIs from abuse
- Fetch book metadata, covers, author information, and exchange-rate data
- Process subscriptions, lifetime purchases, and premium entitlements
- Improve app reliability, diagnose crashes, and understand feature usage
- Respond to support, legal, privacy, and safety requests
What We Do Not Do
Bookmark does not:
- Sell your personal data
- Run third-party ads
- Use advertising identifiers for cross-app tracking
- Use your reading data to build advertising profiles
- Give other users access to your private synced library unless you choose social, book club, or community features that share specific data
Third-Party Services
Bookmark uses the following services where needed:
- Supabase for authentication, database storage, file storage, realtime account features, and backend access controls
- TelemetryDeck for privacy-focused analytics
- Sentry for crash and error diagnostics
- Cloudflare Workers for Bookmark's API
- ISBNdb and related metadata services for book metadata
- Open Exchange Rates for currency exchange-rate data
- Apple Sign in with Apple for iOS account sign-in
- Google Sign-In and Android Credential Manager for Android account sign-in
- Apple StoreKit and the App Store for iOS purchases
- Google Play Billing for Android purchases
- Apple App Attest and DeviceCheck services for iOS app attestation
- Google Play Integrity for Android app integrity checks
- Apple Push Notification service for iOS push notifications
- Firebase Cloud Messaging for Android push notifications
- Google ML Kit and Android CameraX for on-device scanning workflows
- Apple and Google platform services for operating-system features such as notifications, secure storage, app review prompts, and device backup where enabled by the platform
These services process data according to their own privacy policies and terms.
Data Storage and Security
Local data is stored in app-controlled storage on your device. Sensitive authentication and integrity tokens are stored using platform secure storage where supported.
Remote account data is stored in Supabase and protected using authentication, backend authorization rules, private storage buckets, signed URLs, and HTTPS. Bookmark's API uses app attestation or integrity checks for protected endpoints.
No internet-based system can be guaranteed completely secure, but we limit collection, restrict access, and use technical controls appropriate to the type of data being handled.
Retention and Deletion
You can delete books, images, profile content, and other app data through supported app features. You can also delete local app data by uninstalling the app, subject to any device backups or platform restore features you have enabled.
Signing out removes local account state and attempts to remove device push tokens where supported. Account deletion and social-profile deletion flows remove local data and app-managed remote records where supported by the app. Some records may remain for a limited time in backups, logs, cached systems, purchase records managed by Apple or Google, or backend records that require manual deletion.
If you want us to delete remote account, sync, or social data associated with your account, contact us at legal@bookmarkapp.com.au from the email address associated with your account or include enough information for us to identify the account.
Active App Store or Google Play subscriptions must be cancelled through Apple or Google.
Children's Privacy
Bookmark is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us so we can delete it.
Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, or export personal information associated with your account. To make a privacy request, contact legal@bookmarkapp.com.au.
Changes to This Policy
We may update this Privacy Policy as Bookmark changes. When we make material changes, we will update the "Last Updated" date and, where appropriate, provide notice in the app or on the website.
Contact
For privacy questions or requests, contact:
legal@bookmarkapp.com.au
Questions? Email legal@bookmarkapp.com.au