Privacy Policy

Reading Journey · Updated 16 September 2026

Who is responsible

Reading Journey is provided by Vinh P. Dinh, the controller responsible for the personal information described here. Contact us at [email protected] about privacy or your data.

This policy covers the Reading Journey app and its supporting services. You can use the app without creating an account. Some features, including book recognition, imports, subscriptions, analytics and crash reporting, communicate with external services even when you are signed out.

When you sign in, your library synchronizes automatically with your Reading Journey account. This can include an existing library already on your device, along with its notes, reading history, saved photos and saved locations. Signing out or uninstalling the app does not delete information already stored by our services.

Accounts, sign-in and service emails

We use Supabase to create and authenticate accounts. Account information includes your account identifier, email address, linked sign-in providers, profile information supplied by those providers, and authentication and session records. Apple or Google may supply a name, email address, provider identifier and profile details; Apple may supply a private relay email address. Names supplied during Apple sign-in may be saved as your full, given and family name.

If you use email and password, Supabase processes your credentials. Session credentials are also stored on your device so that you can remain signed in. Linking a sign-in method associates that provider identity with your account; it does not make your reading library public.

Supabase and Cloudflare Email Service process email addresses, message content and delivery information to send account confirmation, password recovery and other account-related messages. Authentication links contain information needed to complete the requested action. Apple and Google also process sign-in information under their own policies.

Your library, photos and location

Your library is stored on your device. When signed in, account synchronization also stores library information with Cloudflare: books and their identifiers, reading progress and dates, history, ratings, reviews, private notes, shelves and collections, goals, imported records, and the technical identifiers and change records needed to synchronize devices.

Saved custom covers and reading-journal photos can be uploaded to private Cloudflare storage as part of synchronization. Camera and photo-library access is used when you choose the relevant feature. Images can contain people or other personal information, so consider what is visible before uploading them.

Location is optional. If you allow location access and save a location to your reading journal, a location label and precise latitude and longitude may be stored with that entry and synchronized with your account. You can manage camera, photos and location permissions in iOS Settings. Revoking permission prevents future access through that permission; it does not remove information you previously saved.

Book searches, scans and imports

Book searches send search terms, titles, authors or ISBNs through our Cloudflare services to book-information providers such as ISBNdb and, where enabled, Google Books. Search results and bibliographic information are cached to provide the service efficiently.

Cover scans and image imports send the selected images to Google Gemini for book recognition. Processing may produce extracted text and book suggestions. Images can contain information beyond the intended book cover. Google's handling of these requests depends on the Gemini service and account settings in use.

If you import a library file, our services process the records it contains, which can include ratings, reviews, private notes, shelves and reading dates. Social-media imports process the URL you provide and may download and send the associated media to our extraction service and Google Gemini. Those URLs may identify a social-media account or post.

Plus subscriptions and your membership number

Apple processes App Store payments. RevenueCat processes purchase, transaction, subscription and entitlement information so that Reading Journey can provide and restore Plus access. We do not receive your full payment-card details from Apple.

RevenueCat uses a customer identifier even when you are signed out. When you sign in, we use your stable Reading Journey account identifier with RevenueCat to associate subscription access with your account. RevenueCat may retain related customer aliases and purchase history. Restoring purchases is also subject to Apple and RevenueCat's purchase-transfer behavior.

The library-style membership number is a decorative identifier. It is stored by our membership service and may be associated with your RevenueCat customer; it is separate from your sign-in credentials.

Usage information, diagnostics and support

Amplitude processes app usage events, such as feature interactions, scan or search outcomes, selected book identifiers and some error information, together with SDK-generated identifiers and device/app information. Firebase Crashlytics processes crash and nonfatal error reports, app/build and device information, and diagnostic details. These records help us understand usage, diagnose problems and improve reliability. Identifiers and diagnostic records are not necessarily anonymous, even when they do not contain your name or email.

Our hosting and service providers also process connection and security information, which may include IP addresses, request details, timestamps and device or browser information, to deliver and protect the services.

If you contact support, we process your email address, message and attachments. If you choose to send the app's diagnostic export, it can include a copy of your full library database, including notes, reviews and saved coordinates, as well as logs, device details and your RevenueCat identifier. The diagnostic exporter does not copy the photo files themselves. Review what you share before sending it.

Why we process information

We use information to provide the features you request, authenticate and protect accounts, synchronize your library, recognize and find books, process imports, provide subscriptions, send service messages and respond to support requests. Where applicable under data protection law, processing necessary to provide those services is based on performing our agreement with you.

We also process information for our legitimate interests in operating a secure, reliable service and understanding and improving its use, subject to your rights. Where consent is required for a particular activity, we rely on that consent and you may withdraw it. We may retain or disclose information when required to comply with legal obligations or to establish, exercise or defend legal claims. This notice does not make use of the app blanket consent to every form of processing.

Service providers and processing locations

The services described above receive information needed for their functions; information sent to them can be personal or linked to an account or device. The principal providers are:

Processing is not limited to your country. Our current Supabase account project is hosted in Ohio, United States. Private synchronized media storage and account backups are configured in the eastern United States. Other Cloudflare services and our other providers may process information in the United States, Europe and other locations where they operate. Provider privacy and data-processing information explains their international operations and transfer safeguards. Contact us for information about safeguards applicable to your data.

Retention and deletion

Local library information remains on your device until removed. Synced account and library information is retained to provide your account and synchronization until you delete it or request deletion, subject to necessary security and legal records. Signing out, removing the app or cancelling Plus does not by itself delete your account or cloud library.

Account backups. While you are signed in, we keep automatic backups of your synchronized library and private media in private Cloudflare storage so that your library can be restored if it is lost or damaged. A backup is taken about once a day when your library has changed. Backups are kept on a rolling schedule: one for each of the last seven days, one for each of the last four weeks and one for each of the last twelve months, plus the most recent backup. A book, note, photo or other record you delete from your library can therefore remain in an earlier backup for up to a year before that backup expires.

You can request account deletion in the app's account settings or contact [email protected]. The account deletion process removes the account's synchronized library and private media, requests deletion of the associated identified RevenueCat customer, and deletes the Supabase account. A minimal account-deletion marker is retained to prevent old sessions or devices from restoring deleted cloud data. The deleted account's backups are kept in private storage for 30 days after deletion and are then deleted. If deletion cannot finish, it may need to be retried or completed with support.

Deleting your Reading Journey account does not cancel an Apple subscription. Manage or cancel subscriptions in your Apple account settings.

Other information follows separate retention processes. Scan sessions normally expire after a short period of inactivity, and library-import sessions are scheduled for cleanup after 24 hours. Some lookup caches expire after one or seven days. These schedules do not cover every copy or service: some search and social-media import records, catalog/cache records and older diagnostic archives currently have no automatic deletion period. Support messages and diagnostic attachments also have no single automatic expiry. Contact us to request review and deletion of information associated with you.

Account deletion is not an immediate purge of all vendor logs, analytics, purchase records, backups, support correspondence or historical copies. Those records may remain under the applicable provider's retention processes or where needed for security, legal obligations or claims. We assess deletion requests across the relevant services. We do not promise one fixed retention period for all data.

Your choices and rights

You can choose whether to create an account, use scans and imports, save photos or locations, or send support attachments. Signing out stops synchronization for that account on that device, while previously uploaded information remains until deleted. Device permissions can be changed in iOS Settings.

Depending on applicable law, you can request access to, correction or deletion of your personal information, a portable copy, restriction of processing, or object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it without affecting earlier lawful processing. You may also complain to your local data protection authority. Contact [email protected] to exercise your rights; we may need to verify that the request relates to your account.

Children, security and policy changes

Reading Journey is not directed to children under 13, and we do not knowingly solicit their personal information. If you believe a child has provided personal information, contact us so that we can investigate and address it.

We use access controls, authenticated account requests and private media storage to protect information. No system can guarantee absolute security. Keep your account credentials and exported files secure.

We update this page when our practices change and show the update date above. Where required, we will provide additional notice or obtain consent for a material change.

Contact

Vinh P. Dinh · Reading Journey
[email protected]