Privacy Policy
Last updated
Shelf works without an account and doesn't track you. Your library lives on your devices and in your own iCloud. To find a book, Shelf looks it up in a public book catalogue; this policy explains what it sends and why.
In short
| What | Where it goes | Can the developer see it? |
|---|---|---|
| Your library, ratings and notes | Your devices and your private iCloud database | No |
| ISBNs, searches and book identifiers | Open Library | No |
| A link you paste | The website it points to, to find the book | No |
| Your shared library and recommendations (only if you share) | The Book Club members you invite, through iCloud | No |
| Book summaries, for “Because you liked” suggestions | Nowhere: worked out on your device | No |
| Camera images | Nowhere: only the barcode number is read, on your device | No |
Who is responsible
Shelf is developed by Marco Lüthi, the controller responsible for data processing under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).
Marco Lüthi
Gutstrasse 172
8055 Zürich
Switzerland
hi@luthi-mar.co
Your library
The books you add (title, subtitle, authors, ISBN, publisher, year, page count, summary, subjects, edition details, cover, the shelf it is on, the dates you added, started and finished it, your own rating, notes and the books you pair it with) and the recommendations you send and receive are stored in the app on your device. If you are signed in to iCloud, they sync between your devices through the app's private iCloud database (Apple CloudKit). That database belongs to your Apple Account: the developer has no access to it. Without iCloud, the library stays on the device.
The library is kept in a storage area shared with Shelf's iMessage app and its Share extension on the same device, so you can send a book from Messages and add one from Safari. Your settings, such as the name shown on your shared library, are stored on the device. Your data may also be included in your device backups, depending on your own backup settings.
Removing a book removes it on all your devices. Deleting the app deletes the data on that device; to delete the synced copy too, remove Shelf's data in the iOS Settings app under your Apple Account, iCloud, Manage Storage.
Camera
With your permission, Shelf uses the camera to read the barcode on the back of a book. The barcode is recognised on your device by Apple's VisionKit. No photos or video are recorded, stored or sent; only the ISBN is used. You can type it instead, and change the camera permission at any time in the iOS Settings app.
Finding a book
To identify a book and show its cover and details, Shelf sends requests directly from your device to:
- Open Library, the open book catalogue of the Internet Archive: the ISBN you scan or type, the searches you type, and Open Library's own edition and work IDs to fetch details, ratings and covers. See the Internet Archive's terms and privacy policy.
- The website of a link you paste, when the link itself doesn't name the book (for example a Goodreads page or a short link): Shelf opens that page, as a browser would, to find the book's ISBN or title. The website's own privacy policy applies.
When you share a page with Shelf from Safari or another app, Shelf's Share extension receives only the link or text you share, and looks it up the same way.
These requests are sent without an account or any identifier of yours, but like any internet request they reveal your device's IP address to the service. Shelf does not send your library or anything else about you.
Book Club
If you choose to share your library, Shelf places a read-only copy of it in a shared area of your private iCloud database and shares it, through Apple's iCloud sharing, with the people you invite (the members of your Book Club). They can see the name you choose for your library and, for each book, its title, subtitle, authors, ISBN, shelf, page count, year, cover, up to eight subjects, the date you added it, your star rating and the books you pair it with. They never see your notes or reading dates. The copy updates as your library changes. When you stop sharing, the copy is removed and members no longer see your books.
When you recommend a book, Shelf saves the recommendation (the book, the member it is for, their name and iCloud user identifier as iCloud reports them, your note of up to 280 characters and the date) in that same shared area. The app shows it in the recipient's For You, but every member who can see your library can see what you recommend. Take Back removes it.
When a member shares their library with you and you accept, Shelf reads it, and the recommendations meant for you, from iCloud to show them to you. You can remove a member's library at any time.
Notifications
So Shelf can notice a new recommendation while it is closed, iCloud sends the app a silent push (through Apple's push notification service) when a library shared with you changes. The app then fetches the change from iCloud. If you allowed notifications, it shows one on your device with the member's name, the book's title and their note. No server of the developer is involved. You can turn notifications off at any time in the iOS Settings app.
On your device
“Because you liked” suggestions and the suggested pairings are worked out on your device, from the summaries, subjects and authors of your books, with Apple's on-device language model. Shelf also reads the lettering on each cover on your device (with Apple's Vision), to print the book's spine in a serif or sans-serif face. Nothing is sent anywhere for either.
Sharing a book
When you send a book with Send to Anyone or from Shelf's iMessage app, the link carries only that book's ISBN, title, author and the address of its cover, and the message shows its cover, which Shelf attaches itself. The link opens the book in Shelf. For people without Shelf it opens the App Clip where available, or the book's page on this website, which reads the book from the link in the browser and makes no other requests. A book saved in the App Clip stays on that device until Shelf is installed, which then puts it on the chosen shelf.
Buying a book
Buy on Amazon opens the book in your country's Amazon store, in your browser or the Amazon app; your device's region picks the store. As an Amazon Associate, Shelf earns from qualifying purchases: the link may carry Shelf's Associates tag, so Amazon can credit a purchase to Shelf. Shelf sends Amazon nothing else, and the developer only sees Amazon's anonymous sales totals. On Amazon, Amazon's privacy policy applies.
Legal basis
Where the GDPR applies, the processing described above is necessary to provide the features you use (Art. 6(1)(b) GDPR). Camera access and notifications are based on your choice to allow them, which you can withdraw at any time in the iOS Settings app. Under the Swiss FADP, we process personal data only as described here and in line with its principles.
What Shelf does not do
- No account, sign-up or login.
- No advertising, analytics, crash-reporting or tracking SDKs.
- No tracking across apps or websites, and no selling or sharing of data with data brokers.
This website
This website is a static site without cookies, analytics or tracking. Fonts are served from this website itself, so your browser does not contact third-party font services. When you visit a page, the hosting provider Vercel Inc. (based in the United States, with data centres worldwide) automatically records technical access data in server logs: your IP address, date and time, the requested page, referrer and browser type. This is needed to deliver the site and keep it secure (legitimate interest, Art. 6(1)(f) GDPR). The logs are deleted after a short period. Links to the App Store take you to Apple, where Apple's privacy policy applies.
Your rights
You have the right to request access to your personal data and to have it corrected or deleted, to object to or restrict processing, and to data portability. Because the apps store your data on your device and do not identify you, the developer usually holds no personal data about you. Most of it you can delete yourself by deleting the app.
To exercise your rights, email hi@luthi-mar.co. You can also lodge a complaint with a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), in the EU the data protection authority of your country.
International transfers
Apple may process data in the United States and other countries. Apple describes the safeguards it uses for these transfers, such as the Data Privacy Framework and standard contractual clauses, in its privacy policy. This website is hosted by Vercel Inc., based in the United States; its server logs are transferred under the same kind of safeguards.
Children
Shelf is not directed at children and does not knowingly collect data from them.
Changes to this policy
If the app starts handling data differently, this page will be updated before the change ships, and the date at the top will change.