Privacy Policy of BookGeist
Last modified: 2026-07-30
1. Introduction
This Privacy Policy explains how BookGeist processes information when you use the app or the bookgeist.app website.
BookGeist is designed for personal use and works primarily with local storage on the device. Core library and reading features can be used offline. Connected features use external services for accounts, purchases and subscriptions, cloud backup, public book and author metadata, cover images, optional error telemetry, and AI or vision features.
2. Controller
Controller: Luis Gonzalez Lopez
Contact: contact@bookgeist.app
Website: https://bookgeist.app
Privacy policy published at: https://bookgeist.app/privacy
3. Data BookGeist may process
BookGeist may process books and their metadata, ISBNs, reading status, reviews, ratings, private notes, reading sessions, objectives, collections, sagas, loans, app preferences, images, imported or exported files, structured author data when available or confirmed by the user, public bibliographic identifiers, RevenueCat customer identifiers, purchase or subscription status, AI credits, and the limited technical data needed to provide and protect connected services.
When you search for books, ISBNs, covers, or public bibliographic data, BookGeist may process the query, approximate language, platform, app version, and other minimum technical data needed to provide and protect the service. These data do not include your name, email address, or library contents.
Connected features such as AI, credits, linked purchases, or cloud backup need an account and may depend on the active plan. BookGeist uses Supabase Auth for verified-email, Apple, and Google sign-in and may process your email or Apple private-relay email, display name, provider user identifier, authentication data, and the data you explicitly send to a connected feature.
Cloud backups may include your library, sessions, notes, notebooks, attachments, and preferences. Their content is strongly encrypted on the device before upload and stored through Cloudflare services so it can be restored on authorized devices. This system is not described as end-to-end or zero-knowledge encryption. You can delete your account and associated service data as described in section 12 and in the account-deletion document.
If the user expressly enables error reports, BookGeist may send anonymous technical data to Sentry to diagnose crashes and errors: app version, build number, platform, operating system, sanitized stack trace, technical error message, and limited technical breadcrumbs. BookGeist does not send aliases, email, name, library contents, book titles, notes, quotes, contacts, local files, full URLs, or personal content entered by the user in error telemetry.
When the user chooses to report a problem from the app, BookGeist may send a user-initiated bug report. It may include a written description, a screenshot of the app that the user optionally attaches, and technical device context (app version, build number, platform, and operating system). Sending is voluntary and started by the user. Unlike the anonymous error telemetry above, a screenshot may contain personal content visible at that moment (book titles, notes, library) and, where applicable, third-party data shown on screen, so the user decides whether to attach it and what it shows. The report is sent through a BookGeist service hosted by Cloudflare so the issue can be diagnosed and fixed.
When the user uses the bookgeist.app website, BookGeist may process data from the contact form (name, email, and message, sent voluntarily to receive a response) and from the Android beta waitlist (email only, sent voluntarily to receive a Google Play testing invitation). Both forms are protected with Cloudflare Turnstile to prevent automated submissions; the verification result is not linked to the user’s identity beyond confirming the submission is not automated. This data is received through BookGeist services hosted by Cloudflare. Submitting the form also records the date and time you accepted this Privacy Policy, as a record of your consent. The legal basis for this processing is your consent (Art. 6.1.a GDPR), given expressly by ticking the Privacy Policy acceptance checkbox before submitting the form. You can withdraw your consent at any time by writing to contact@bookgeist.app; withdrawal does not affect the lawfulness of processing carried out before it. This data is kept for a maximum of 6 months from submission, after which it is automatically deleted.
4. Purposes
Data are used to operate the app, record reading progress, save notes and statistics, import and export data, personalize the app, download covers or metadata, consult public sources to improve cataloguing, protect BookGeist services and prevent abuse, diagnose crashes if optional error reporting is enabled, manage Classic and Lifetime purchases and monthly or annual Studio subscriptions, restore purchases, authenticate and manage accounts, create and restore encrypted cloud backups, provide connected services included in the plan, process AI/OCR/vision features with prior consent, diagnose user-initiated bug reports, respond to website contact messages, and manage Android beta invitations. Error telemetry is not used for advertising, tracking, or profiling.
5. User control
The user controls most content because they enter, import, edit, export, or delete it manually. Core local features do not require an account or connection.
Metadata lookups may run automatically during ISBN imports, book searches, or author enrichment. If there is no connection or no reliable source is found, the user can enter or correct data manually.
AI or visual-recognition features show a notice before sending content to an external service and allow cancellation. If the user cancels, no content is sent and no credits are consumed.
When an AI feature is accepted for the first time, BookGeist may store the consent date and policy version locally so the notice does not need to appear before every request. Consent can be withdrawn from Settings > AI & Privacy; the next AI request will ask again before sending content.
Anonymous error telemetry is optional and disabled by default. It can be enabled or disabled from Settings > Security > Send error reports. Disabling it blocks new telemetry submissions.
6. Storage model
BookGeist stores most information locally on the device. No BookGeist account is required for core local features and there is no mandatory sync to BookGeist-owned servers.
Protection of that local data at rest depends on the operating system and device safeguards, such as the device passcode and storage encryption. BookGeist does not apply an additional BookGeist-managed encryption layer to the local database.
BookGeist offers optional accounts. Classic and Lifetime purchases and monthly or annual Studio subscriptions are managed through the stores and RevenueCat. Studio and Lifetime include optional automatic encrypted cloud backup; local core features continue to work without mandatory cloud sync. Connected AI features depend on the plan, available Stamps, and service availability.
When you use account features, the necessary information described in section 3 is stored in BookGeist account, AI, or backup services and linked to a pseudonymous account identifier. Core local features continue to work without an account.
7. Internet connections, purchases, and third parties
BookGeist may connect to external services to download covers; search book or ISBN metadata; find alternative covers based on title and author; enrich author data; process optional error telemetry with Sentry; manage purchases and subscriptions with RevenueCat, Apple App Store, and Google Play; process user-selected content with an AI provider after consent; authenticate through Supabase Auth using verified email, Apple, or Google; create or restore encrypted backups for eligible plans; share, import, or export files; or send a user-initiated bug report with an optional screenshot and technical context.
Processors or providers include RevenueCat; Apple App Store and Google Play; Supabase Auth; Apple and Google identity services; Sentry; Cloudflare, which provides, protects, and stores BookGeist connected services; AI providers that may include Cloudflare, Google, OpenRouter, or OpenAI; and Open Library, Google Books, ISBNdb, DILVE, Wikidata/Wikipedia, Serper.dev, metadata APIs, and cover services.
Some of the providers above, including Cloudflare, operate with globally distributed infrastructure. Where this involves a data transfer outside the European Economic Area, that transfer is carried out under the safeguards provided by the GDPR (such as the European Commission’s standard contractual clauses or another recognized transfer mechanism).
BookGeist does not control the privacy policies of external sites or providers outside the controller’s responsibility.
8. AI, consent, and retention
Before sending content to an AI feature, the app informs the user what will be sent, why it will be used, that the user can cancel, that the feature may consume credits, and that consent can be revoked in Settings.
For AI visual reference, BookGeist sends the visual description written by the user, selected style, optional settings, and the minimum data needed to manage the plan, credits, and abuse prevention. For Studio Scan or another visual-recognition feature, BookGeist sends the cover, spine, or shelf image expressly selected by the user and the minimum technical data needed to process it. BookGeist does not send the full library, full notebook, contacts, backups, exports, or unrelated local files.
Temporary AI files and results managed by BookGeist are deleted after delivery or, if abandoned, normally within 24 hours. AI providers may apply their own operational retention under their processor terms.
BookGeist retains content sent to AI only for the minimum time needed to process the request, diagnose failures, and prevent abuse. BookGeist does not use that content to train its own models. AI providers apply their own processing and retention terms.
For image generation, BookGeist deletes the description and temporary files after delivering the result or, if processing does not complete, normally within 24 hours. Technical data that does not contain the submitted content may be kept for the time needed to manage credits, security, and abuse prevention.
When a user reports an image, the pseudonymous identifier, reason, and user-written detail are retained to record and investigate the incident. These data are scheduled for automatic deletion 180 days after the report; temporary failures are retried. We may delete them earlier when no longer needed, and they are deleted when the account is deleted. Do not include unnecessary personal information in a description or report.
9. Device permissions
Depending on platform and user choices, BookGeist may request camera, photos/gallery, contacts, files/documents, microphone (to dictate or record voice notes), and notifications permissions. Notifications are local reminders generated on the device and are not sent through BookGeist-owned servers. Granting permissions is optional, but some features will not work without them.
10. Data sharing
BookGeist does not sell personal data and does not automatically share the user’s library or reading history with advertising networks. Data only leave the device when the user initiates an action that requires it or uses a documented feature requiring an external lookup, such as exporting or sharing a file, downloading a cover, searching external metadata, enriching author data, restoring purchases, managing a subscription, sending content to an AI/OCR/vision feature with prior consent, sending a user-initiated bug report with a screenshot the user chooses to attach, or submitting the contact form or joining the Android beta waitlist.
11. Retention
Local data are kept while the app remains installed or until the user deletes them manually from the app or by clearing app data. Exported files may remain wherever the user stores or shares them. Purchase data are retained according to Apple, Google, and RevenueCat policies. AI data are retained only for the operational periods described in section 8. Account data, backup metadata, and encrypted backup objects are retained while the account exists or until account deletion under the service’s operational policy. Loss or expiry of an eligible plan may block backup access without causing immediate deletion, subject to minimum legal, security, and transaction-retention obligations.
Technical data used to provide and protect metadata services are retained only for the minimum time needed to prevent abuse and diagnose errors.
User-initiated bug reports (description, attached screenshot, and technical context) are kept only as long as needed to reproduce, diagnose, and fix the issue, and are deleted once no longer useful for that purpose.
Account data and synced data are kept while the account is active and are deleted when the account is deleted, except information that must be retained by legal obligation or that is managed by Apple, Google, or RevenueCat.
Contact messages submitted through the website and Android beta waitlist signups are kept for a maximum of 6 months from submission, after which they are automatically deleted.
12. User rights
The user can access, modify, or delete content they have entered, export their data, delete the app and local data, delete their BookGeist account and associated server data from Settings, restore purchases, and manage or cancel subscriptions through App Store or Google Play. To exercise legal rights with the controller, use the contact listed in this policy.
If you believe the processing of your data does not comply with applicable law, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es, without prejudice to any other administrative or judicial remedy.
13. Children
BookGeist is intended for people aged 13 and over and is not intended for children under 13. BookGeist does not request a date of birth or perform documentary age verification. Most reading tracking remains on the device; accounts, purchases, reports, and AI or connected features process the data described in this policy when the user chooses to use them.
People aged 13 to 17 must use the app with any authorization or supervision required by applicable law and the rules of their family account or store. In all cases, a person under 18 may use connected or AI features that rely on providers requiring parental authorization only when that authorization has been obtained. In Spain, where processing is based on consent, users under 14 require consent from the holder of parental responsibility or guardianship under Article 7 of the LOPDGDD. We recommend that a responsible adult review purchases, connected features, and AI image generation. See the Age Suitability Policy. If a legal guardian believes that a minor’s data has been processed inappropriately, they can contact contact@bookgeist.app to request review or deletion.
14. Security
BookGeist uses a local-storage-centered architecture and strong safeguards to protect communications, accounts, and backups. Cloudflare provides and protects the connected services. No system can guarantee absolute security.
15. Changes to this policy
This Privacy Policy may be updated to reflect functional, technical, or legal changes. The last-modified date is shown at the beginning of the document.
16. Contact
For privacy questions, support, or requests to exercise your rights, contact contact@bookgeist.app.
This English text is a translation of the binding Spanish version and is provided for convenience.