Tales & Tails app
Tales & Tails Privacy Policy
Effective 1 October 2026Version 1.1.0
The Ukrainian version is authoritative. Translations are provided for information.
Diese Fassung ist nur auf Englisch verfügbar.
This version is available in English only.
Contents
Informational translation. The Ukrainian version of this document is the authoritative text. In case of any discrepancy, the Ukrainian text prevails.
Current version. Version 1.1.0, in force as of 1 October 2026.
The Ukrainian version is authoritative. Translations into other languages are informational; in case of any discrepancy, the Ukrainian text applies.
This Policy explains what personal data Tales & Tails processes, on what legal basis, to whom it is disclosed, how long it is retained, and how you can control it.
1. Who processes your data
Data controller:
| Name | Individual entrepreneur (ФОП) Hombosh Tomash Zoltanovych |
|---|---|
| Taxpayer registration number (РНОКПП) | 3461006118 |
| Address | 15 Lomonosova St., Vynohradiv, Zakarpattia Oblast, 90300, Ukraine |
| privacy@sgat.me |
Use of this address. The address is published only to meet legal disclosure requirements and is intended solely for official correspondence. Using it to cause harm, to harass or threaten anyone, for fraud, or for any other unlawful purpose is prohibited and entails liability under the law of Ukraine.
No separate data protection officer (DPO) has been appointed: the scope and nature of the processing do not meet the criteria for mandatory appointment. All requests are handled personally by the controller at the address above.
Applicable law. Processing is carried out in accordance with the Law of Ukraine "On Personal Data Protection" No. 2297-VI. If you are located in the European Economic Area (EEA), Regulation (EU) 2016/679 (GDPR) additionally applies to the processing of your data to the extent it covers this processing.
Response time. We respond to any request concerning personal data within 30 calendar days from the date of receipt. If a request is complex, we will notify you of the extension of the deadline and the reason for it before the initial 30 days expire.
Right to lodge a complaint. You may contact the Ukrainian Parliament Commissioner for Human Rights. If you are located in the EEA — the supervisory authority in the place of your residence, place of work, or place of the alleged infringement.
2. What this Policy covers
This Policy covers the Tales & Tails web application, the Tales & Tails apps for iOS and Android, and the Book Diary backend services that support them, including the Keycloak authentication system operating under our control.
This Policy does not cover third-party sites and services that you may reach via links from the application, in particular sources of book metadata and cover images, or third-party apps you share material to from the application (for example, Instagram Stories).
3. What data we process
| Category | Examples | Source | Mandatory |
|---|---|---|---|
| Identity | email, name, username, sub (account UUID) |
you, via Keycloak SSO (including sign-in with Google, if you choose it) | mandatory to create an account |
| Reading | books in your library, reading sessions, progress, goals, reviews, notes | you, via Book Diary services | you decide what to add |
| Technical (web app) | page URL, User-Agent, error stack trace, screen orientation, IP address at the network connection level | your browser → Sentry | automatically |
| Crash reports (iOS and Android) | device model, operating system and app versions, error stack trace, the pseudonymous sub identifier, the screens you moved through before the crash |
the app on your device → Sentry | automatically |
| Device and notifications | the device push token (APNs or FCM), platform (iOS / Android), device language and IANA time zone, which the app sends when it registers for push notifications; notification preferences; history of notifications sent | push token, platform, language and time zone — your device, after you allow notifications in the operating system; preferences — you, in your profile | push token — only if you allow notifications; preferences and history — automatically |
| Server logs and sign-in events | IP address, User-Agent and request path in API access logs; sign-in, sign-out, registration and password-change events in Keycloak | your browser or app, with every request | automatically |
| Consent | the analytics and sessionReplay flags |
you, via consent settings in the web app | your choice is stored automatically |
| Product analytics | de-identified page views and interaction events, session recordings | your browser → Google Tag, Microsoft Clarity (web app only) | only with your consent |
| Images | photographs of book covers, profile avatar, photographs in notes | your camera or gallery | optional |
| Moderation | text of the report and metadata of the submission | you, when you submit a report | optional |
| Payments | the email the subscription is taken out under, plan and billing frequency, amount, order number; from WayForPay — the masked card number, card expiry date, payment system, transaction ID, payment status and recurring-payment token. We do not receive the full card number | you — when subscribing in the web app; WayForPay — after payment | only if you take out Nine Tails |
Product analytics (Google Tag, Microsoft Clarity) runs only in the web app. The iOS and Android apps contain no analytics SDK.
We do not request or collect: the full payment card number (you enter card details on the WayForPay page), location data (the apps do not request access to geolocation; on photo metadata, see §14), contacts from your device, or biometric data. If you turn on sign-in with Face ID, Touch ID or a fingerprint, the check is performed by your device's operating system, and the app receives only a "yes" or "no" answer from it.
4. Why we do this and on what basis
| Purpose | Legal basis |
|---|---|
| Creating and maintaining an account, authentication | performance of a contract (Art. 6(1)(b) GDPR; Art. 11 of Law No. 2297-VI) |
| Providing reading diary features: library, sessions, progress, goals, statistics | performance of a contract |
| Publishing your content (reviews, posts) within the scope you have chosen | performance of a contract |
| Device registration, notification preferences and service emails | performance of a contract |
| Sending push notifications to your device | consent — the notification permission you grant in the operating system and can withdraw in its settings |
| Taking out the Nine Tails subscription, accepting payments, recurring charges and refunds | performance of a contract |
| Monitoring errors and stability (Sentry) | legitimate interest — keeping the service operational; scope minimised (see §6) |
| Product analytics (Google Tag) and session recording (Microsoft Clarity) in the web app | consent — neither SDK is loaded until consent is given |
| Personalised book recommendations based on reading history | performance of the contract — the recommendation engine is one of the Service's core features (see §5); on the right to object, see §5 and §10 |
| Automatic sentiment scoring of reviews as a signal for recommendations | performance of the contract (see §5) |
| Automatic background removal from cover photographs | performance of a contract |
| Content moderation and handling of reports | legitimate interest — community safety; where applicable — compliance with a legal obligation |
| Protection against abuse, spam and unauthorised access, including server logs and the sign-in event log | legitimate interest — service security |
| Keeping payment and accounting records | compliance with a legal obligation (Art. 44.3 of the Tax Code of Ukraine) |
Where the basis is legitimate interest, we have balanced it against your rights and freedoms. You have the right to object to such processing — see §10.
Manage consent for analytics and session recording.
5. Reading history — a sensitive context
What a person reads may reveal religious or philosophical beliefs, health status, political opinions, ethnic origin or sexual orientation. For this reason, information about your library may in certain circumstances fall under special categories of personal data (Art. 9 GDPR; Art. 7 of Law No. 2297-VI).
We treat this data accordingly:
- We do not analyse your reading history in order to infer beliefs, health status, opinions or any other special categories of data.
- Your library, reading sessions, progress and private notes are private by default. Only you can see them.
- Other users see only what you deliberately publish: reviews, posts, comments. By publishing such material, you make it publicly available by your own decision (Art. 9(2)(e) GDPR).
- On our side, access is limited to those Book Diary services that are technically necessary for the feature to work, and to the controller — when needed for support or to investigate an incident.
- We do not sell or transfer reading history to advertisers, data brokers or any third parties for their own purposes.
Book recommendations
The recommendation engine is one of the Service's core features. It runs by default for every user and computes personalised selections on the server from your reading history. The legal basis is performance of the contract: this feature is, among others, why you came to the Service.
Recommendations cannot currently be switched off in the application. We regard this as a shortcoming and plan to add the corresponding setting.
Until then, the following applies. Article 8 of Law No. 2297-VI gives you the right to submit a reasoned demand objecting to the processing of your data. We honour such a demand in respect of recommendations regardless of the legal basis and without requiring justification: write to privacy@sgat.me and within 30 calendar days we will stop using your reading history for personalisation and delete the derived recommendation profile. You will still see the catalogue — just not personalised.
We constrain this processing as follows:
- the model works with genres, authors, series, themes and behavioural signals (progress, completion, ratings), and not with inferences about your beliefs, health, views or any other protected attributes;
- we do not derive, label or store any special-category data attributes;
- recommendation profiles are not shared with third parties and are not used for advertising or for any purpose beyond showing you book selections;
- recommendations have no legal or similarly significant effects on you (see §13).
Language models. To build vector descriptions of books and short
explanations of why a book is recommended, the recommendation service may call
Amazon Bedrock (the Amazon Titan and Anthropic Claude Haiku models) in the AWS
eu-north-1 region (Stockholm, Sweden). The models receive only the genres and
subgenres of books and the list of your favourite genres. We do not send
them your account identifier, name, email, notes, reviews or reading history.
The generated explanation is stored in our database.
6. Who we share data with
The table has been reconciled with the source code of the apps and backend
services. The web app loads Google Tag only after analytics consent and when
a measurement or container id is configured. Microsoft Clarity is not
injected by the web app; it runs only if it is configured as a tag in a Google
Tag Manager (GTM-) container loaded after that same consent. The iOS and
Android apps load neither Google Tag nor Microsoft Clarity.
| Processor | Purpose | What data | Place of processing | Retention at the processor |
|---|---|---|---|---|
| Amazon Web Services (Amazon Web Services EMEA SARL) | hosting of all Book Diary services and the Keycloak authentication system: AWS Lambda, Amazon API Gateway, Amazon EventBridge and Amazon SQS, Amazon RDS for PostgreSQL, Amazon S3, Amazon CloudFront, Amazon ECS with Elastic Load Balancing (Keycloak), Amazon ElastiCache, Amazon CloudWatch | account and Keycloak credentials, reading and profile data, notes, reviews, images, request logs (IP address, User-Agent) | EU — Stockholm, Sweden (eu-north-1 region); delivery through the global CloudFront edge network; the web app's CloudFront access logs — USA (us-east-1), see §7 |
see §9 |
| Amazon SES (Amazon Web Services EMEA SARL) | sending emails, including Keycloak emails | email address, subject and body of the email | EU — Stockholm (eu-north-1) |
delivery records — up to 90 days |
| Amazon SNS (Amazon Web Services EMEA SARL) → Apple Push Notification service (Apple Inc.) and Firebase Cloud Messaging (Google LLC) | delivering push notifications on iOS and Android | device push token, notification text | SNS — EU, Stockholm (eu-north-1); Apple and Google — see §7 |
delivery records — up to 90 days |
| Amazon Bedrock (Amazon Web Services EMEA SARL), Stability AI model | automatic background removal from a cover photograph | the cover photograph, downscaled to 1024 px; no account identifier | USA (AWS regions in the USA), see §7 | not retained after processing (Amazon Bedrock terms) |
| Amazon Bedrock (Amazon Web Services EMEA SARL), Amazon Titan and Anthropic Claude Haiku models | vector descriptions of books and explanations of recommendations (§5) | book genres and subgenres, the list of your favourite genres; no account identifier | EU — Stockholm (eu-north-1) |
not retained after processing (Amazon Bedrock terms) |
| Amazon Comprehend (Amazon Web Services EMEA SARL) | automatic sentiment scoring of a review | review text; no account identifier | EU — Ireland (eu-west-1 region) |
under AWS terms |
| WayForPay (Ukraine) | payment operator: card payments, recurring charges, refunds, fiscal receipts | email, order number, amount, plan name; the card details you enter on the WayForPay page | Ukraine | under WayForPay's terms and Ukrainian law |
| Sentry (Functional Software, Inc.) | error monitoring in the web app and the iOS and Android apps | error stack trace, page URL or app screen, browser data or device model, OS and app versions, sub UUID; no Authorization header, no email or name (sendDefaultPii: false) |
EU — Frankfurt, Germany (de.sentry.io region) |
30 days |
| Google (Google Ireland Limited) — independent controller | sign-in with a Google account in Keycloak — only if you choose it | email and name from your Google account; Google learns that you are signing in to Tales & Tails | Google; possible transfer to Google LLC (USA) | under Google's rules |
| Google Tag / Google Analytics 4 (Google Ireland Limited) | product analytics (page views) — web app only | page URL, referrer, browser data, pseudonymous client id; no account sub, email or name |
Google Cloud; transfer to Google LLC (USA) — see §7 | as configured on the GA4 property (2 months default; maximum 14 months) |
| Microsoft Clarity (Microsoft Ireland Operations Ltd) | product analytics, session recording — web app only | masked interaction events, pseudonymous Clarity identifier, sub |
Microsoft Azure; transfer to Microsoft Corporation (USA) — see §7 | 30 days; sampled and saved recordings — up to 9 months (Microsoft limitation) |
Google Tag is not loaded at all until you give consent, and not until a
measurement id is configured. Until then, no request to Google is made and no
_ga cookie is set.
Microsoft Clarity is not injected by the web app. It loads only as a tag inside Google Tag Manager, and only after you give analytics consent. Until then, no request to Clarity is made and no Clarity cookie is set.
Disclosure required by law. We may disclose data upon a substantiated request from a competent state authority made in accordance with the law. We review every such request for lawfulness and scope and, where legally permitted, notify you.
A data processing agreement (DPA) limiting processing to our instructions is concluded with each third-party processor. We do not begin transferring data to a processor before such an agreement is in force.
7. International data transfers
Amazon Web Services — data hosted in the EEA. The Book Diary services,
Keycloak, databases and files are hosted in the AWS eu-north-1 region
(Stockholm, Sweden), and review sentiment is scored in the eu-west-1 region
(Ireland). Both countries are part of the EEA and parties to Council of Europe
Convention No. 108. Content is delivered through the global Amazon CloudFront
edge network, so the technical data of a request is processed by the edge
location nearest to you. The web app's CloudFront access logs (IP address,
User-Agent, URL) are kept for 30 days in the AWS us-east-1 region (USA) on
the basis of the EU Standard Contractual Clauses (SCCs) in our agreement
with Amazon Web Services EMEA SARL.
Sentry — no transfer outside the EEA. Our Sentry project is created in the European region, and error data is stored in Frankfurt (Germany). Germany is part of the EEA and a party to Council of Europe Convention No. 108; accordingly, under Art. 29 of Law No. 2297-VI such a state ensures an adequate level of protection. We note separately: the administrative data of our own developer account in Sentry (organisation settings, DSN keys) is stored in the USA — this is our account data, not your personal data.
Google Tag / Google Analytics — transfer to the USA. We contract with Google Ireland Limited, which transfers data to Google LLC (USA) on the basis of the EU Standard Contractual Clauses (SCCs) and, where applicable, the EU–US Data Privacy Framework. This processing takes place only with your consent, and you may withdraw consent at any time.
Microsoft Clarity — transfer to the USA. Microsoft does not offer a choice of storage region for Clarity. As an EEA customer, we contract with Microsoft Ireland Operations Limited, which transfers data to its affiliate Microsoft Corporation (USA) on the basis of the EU Standard Contractual Clauses (SCCs), supplemented by Microsoft's technical and organisational measures. In addition: this processing takes place only with your consent, data is masked on the client, and you may withdraw consent at any time.
If you do not want your interaction data to be transferred to the USA, do not give consent to analytics — the service is fully functional without it.
Amazon Bedrock — transfer of cover photographs to the USA. To remove the background from a cover photograph, we send a downscaled image to the Stability AI model in Amazon Bedrock in AWS regions in the USA. No account identifier is sent with the image. The transfer takes place under our agreement with Amazon Web Services EMEA SARL on the basis of the EU Standard Contractual Clauses (SCCs) and, where applicable, the EU–US Data Privacy Framework. If you do not want this transfer, do not upload your own cover photograph: a book can be added without one.
Push notifications — Apple and Google. To deliver a push notification, Amazon SNS passes your device's push token and the notification text to Apple Push Notification service (Apple Inc., USA) or Firebase Cloud Messaging (Google LLC, USA). Notifications arrive only after you have allowed them in the operating system, and you can turn them off at any time in your device settings. The basis for the transfer is that permission, together with the EU Standard Contractual Clauses (SCCs) and, where applicable, the EU–US Data Privacy Framework.
8. Cookies and storage on your device
Subsections 8.1, 8.3 and 8.4 concern the web app, 8.2 concerns signing in to any of the apps, and 8.5 concerns the iOS and Android apps.
8.1. Web app: on our domain
| Key | Mechanism | Purpose | Lifetime | When it appears |
|---|---|---|---|---|
bd-telemetry-consent |
localStorage |
Art. 7(1) GDPR record of consent: policy version (v), decision time (t), and two flags analytics (a) and sessionReplay (r). Both flags stay false until you actively choose |
until the browser is cleared or the choice is changed | after the first decision (banner or profile). A record stored against an earlier policy version is treated as absent |
bd-locale |
localStorage |
preferred language for legal documents (uk / en / de / es / fr); synced from the Keycloak locale claim after sign-in |
until the browser is cleared or the IdP account language changes | after the first resolution or a successful sign-in |
tt-theme |
localStorage |
saved colour scheme (light / dark / system) |
until the browser is cleared or the theme is changed | after the first theme change in the profile |
tt-force-desktop |
cookie (first party) | remembers that you chose to open the web app on a screen narrower than supported, so the warning page does not appear again | 30 days | when you choose to open the web app on a narrow screen |
bd-account-deletion-hand-off |
sessionStorage (this tab only) |
a marker that you started deleting your account: the start time (startedAt) and whether you were signed in at the time (startedSignedIn), so that the outcome of the deletion can be shown when you come back from the sign-in page |
until you come back from the sign-in page (the marker is then removed) or close the tab | when you start deleting your account |
| access token | tab memory (not localStorage, not a cookie) |
authorisation of API requests | until sign-out or tab reload | after a successful sign-in |
bd-telemetry-consent, bd-locale, tt-theme, tt-force-desktop and
bd-account-deletion-hand-off are strictly necessary — for enforcing your
privacy settings, legal-document language, appearance, your choice of the full
web app and completing an account deletion you started, respectively; no
consent is required for them.
The interface language is fixed as Ukrainian, so no separate UI-language key is written.
Controls: Profile → Cookie and analytics preferences.
8.2. Authentication provider domain
Keycloak sets SSO session cookies on its own domain, not on the application's domain. They are strictly necessary for sign-in and are retained according to the identity provider's session settings.
8.3. Microsoft Clarity — only after consent
If you give consent to analytics, Clarity will set the following cookies:
| Cookie | Type | Purpose |
|---|---|---|
_clck |
first party | stores the Clarity user identifier for this site |
_clsk |
first party | groups page views into a single recording session |
CLID |
third party | identifies the first observation of a user in the Clarity network |
MUID |
third party | browser identifier across Microsoft services; per Microsoft's own description, also used for advertising and site analytics |
ANONCHK, MR, SM |
third party | service flags for synchronising Microsoft identifiers |
As long as consent is absent, none of these cookies is set.
8.4. Google Tag — only after consent
If you give consent to analytics and a measurement id is configured, Google Tag
(gtag.js) will set the following cookies:
| Cookie | Type | Purpose |
|---|---|---|
_ga |
first party | distinguishes users |
_ga_* |
first party | persists the GA4 session state |
_gid |
first party | distinguishes users (typically 24 hours) |
_gat |
first party | throttles request rate |
As long as consent is absent, none of these cookies is set.
Open cookie and analytics settings
8.5. iOS and Android apps
The apps set no cookies of their own and create no advertising or analytics identifiers.
| What | Where it is stored | Purpose | Lifetime |
|---|---|---|---|
| refresh token and a flag for whether sign-in is protected by biometrics | the operating system's secure storage (Keychain on iOS, Keystore on Android), available only on this device while it is unlocked | signing in without entering your password again | until you sign out or delete the app |
| access token | app memory only | authorisation of API requests | until the app is closed or the token is refreshed |
| settings, caches and note drafts | the app's local storage on the device | appearance, your last choices in the interface, a cache of the genre list, unsaved note drafts | until the app is deleted or its data is cleared |
| current reading session data and the book cover (iOS) | the app's shared storage on the device (App Group), which the widget and Live Activity read | showing the reading timer and the book's title and cover on the lock screen and in the widget | session data — until the session ends; covers — until the app is deleted |
| ongoing reading-timer notification (Android) | the device's notification shade | showing the book title and reading time while the session lasts | until the reading session ends |
9. How long we retain data
| Category | Retention period |
|---|---|
| Account (Keycloak) | until the account is deleted |
| Reading data in the API: library, sessions, progress, goals, notes and photographs in notes | until deleted by you or until the account is deleted |
| Your reviews, comments, votes on reviews and the reports you have submitted | until deleted by you or until the account is deleted — they are then deleted, not de-identified |
| Profile avatar | until the account is deleted |
| Cover photographs | the processed cover — together with the book's record in the catalogue; the original uploaded for processing — 7 days |
| Device push tokens and notification preferences | until the account is deleted |
| History of notifications sent | 6 months |
| Delivery records for emails and push notifications (recipient address, push token) | up to 90 days |
| API access logs (IP address, User-Agent, request path) | 30 days |
| Service and Keycloak logs | 7 days |
| Account activity log (including sign-in, sign-out, password changes) | until the account is deleted; the entries are then de-identified |
| Automated database backups | 7 days |
| Previous and deleted file versions in storage | 30 days |
| Error events in Sentry | 30 days |
| Google Analytics 4 data (web app) | as configured on the property (2 months default; maximum 14 months) |
| Microsoft Clarity data (web app) | 30 days; sampled and saved recordings — up to 9 months (Microsoft technical limitation) |
| Moderation reports | 6 months after the submission is closed; reports you submitted are deleted together with your account, and reports about deleted content — together with that content |
Record of your consent (localStorage, web app) |
until withdrawn or the browser is cleared |
| Payment and accounting records | 1095 days (Art. 44.3 of the Tax Code of Ukraine); after the account is deleted — without any link to you |
After an account is deleted, the Keycloak account and all your sessions are deleted immediately. Every Book Diary service erases your data asynchronously — normally within minutes, with retries if something fails, and within 30 days at most. Your data disappears from automated database backups within 7 days, and deleted file versions within 30 days. Data that the law obliges us to keep longer is retained solely to the extent of that obligation and is not used for any other purposes.
10. Your rights
You have the right to:
- know exactly what data of yours we process and receive a copy of it;
- rectify inaccurate or incomplete data;
- delete your data and your account;
- receive your data in a machine-readable format and transfer it to another service;
- restrict processing;
- object to processing — both to processing based on legitimate interest and to the personalisation of recommendations (§5), which we disable upon your reasoned demand;
- withdraw consent at any time — this does not affect the lawfulness of processing before withdrawal;
- lodge a complaint with a supervisory authority (see §1).
How to exercise them. Exporting your data and deleting your account are available in the app (see below). For any other request — or if you cannot use the app — write to privacy@sgat.me from the address linked to your account. We respond within 30 calendar days. If a request comes from a different address, we will ask you to verify your identity — to no greater extent than necessary for verification.
Consent to analytics can be withdrawn with one click in the web app — just as easily as it is given: consent settings.
Exporting your data. In the web app or in the iOS or Android app, open
Profile → Account → Export data («Профіль → Обліковий запис → Експортувати
дані»). The app assembles a single JSON file,
tales-and-tails-export-YYYY-MM-DD.json, on your device with your account
details, profile and settings, library, reading sessions, goals, notes
(including those in the trash), reviews, subscription status and the account
activity log for the last 90 days. Reading sessions and reviews are included
only for books that are still in your library, and reviews only if they are
published and visible to everyone. Photographs in notes appear in the file as
file identifiers, without the images themselves. Book ratings, comments, votes
on reviews and the reports you have submitted are not in the file. We provide
these and any other data we process (for example, logs) on request by email.
Deleting your account. Open Profile → Account → Delete account («Профіль → Обліковий запис → Видалити акаунт») in the web app or in the iOS or Android app. The app opens the sign-in page: sign in again and confirm the deletion by typing the confirmation word. The sign-in page reports that the deletion succeeded, and if you go back to the app from it, the app shows the message «Акаунт видалено» ("Account deleted"). If you do not have the app, open the «Видалення акаунта» ("Account deletion") page and press «Увійти та видалити акаунт» ("Sign in and delete account"). If you cannot sign in, write to privacy@sgat.me from the address linked to your account — we will verify your identity. Deletion is irreversible, so export your data first.
What happens when an account is deleted. The Keycloak account and all your sessions are deleted immediately. Every Book Diary service erases your data asynchronously — normally within minutes, with retries, and within 30 days at most. Your published reviews, comments, votes and reports are deleted, not de-identified; moderation reports attached to the deleted content are deleted with it. If you have an active Nine Tails subscription, its recurring WayForPay charge is cancelled. Payment accounting records are kept for 1095 days (Art. 44.3 of the Tax Code of Ukraine) without any link to you. Your data disappears from automated database backups within 7 days, and deleted file versions within 30 days.
11. Security
- All traffic between your browser or the app on your device and our API is transmitted exclusively over HTTPS.
- Passwords never reach our apps: authentication is performed by Keycloak using the OpenID Connect protocol. The iOS and Android apps open the sign-in page in the system browser.
- In the web app, the access token is stored in tab memory, not in
localStorageand not in a cookie — this reduces the risk of it being stolen through cross-site scripting. - In the iOS and Android apps, the refresh token is stored in the operating system's secure storage (Keychain / Keystore) and is available only on that device, and the access token only in app memory. If you wish, you can protect sign-in with biometrics; the check is performed by the operating system.
- Sentry is configured with
sendDefaultPii: false: we do not send emails, names or authorisation headers there. - Access to production data is limited to persons who need it to operate the service.
Personal data breaches. If an incident occurs that creates a risk to your rights, we will notify the supervisory authority within 72 hours of becoming aware of it, and you — without undue delay, if the risk is high.
No system is absolutely secure. If you have discovered a vulnerability, write to privacy@sgat.me — we do not pursue anyone for good-faith vulnerability reports.
12. Age of users
The service is intended for persons aged 16 and over. We do not knowingly collect data of persons under 16 and do not direct the service at them.
If you believe that a person under 16 has created an account, write to privacy@sgat.me — we will verify this and delete the account and the related data.
13. Automated decision-making and profiling
We do not take decisions concerning you that produce legal effects or similarly significantly affect you based solely on automated processing (Art. 22 GDPR).
Personalised book recommendations constitute profiling. It runs by default for every user, but its effects are non-binding and insignificant: they are suggestions you are free to ignore, they do not restrict your access to any feature of the Service, do not affect any price, and determine none of your rights. Art. 22 GDPR therefore does not apply to them.
If you do not want your reading history used for personalisation, we will disable it for your account on request — the procedure is described in §5.
Content moderation may use automated filters for initial screening, but a decision to restrict access to or remove content is always reviewed by a human. You may appeal such a decision via the contact in §1.
14. Camera and photographs
Camera access is requested only at the moment you choose to scan an ISBN barcode or to photograph a cover or a page for a note. Declining blocks nothing: you can choose an image from your gallery or enter the book details manually.
ISBN scanning happens on your device — in the iOS and Android apps and in the web app alike: camera images do not leave the device, and only the recognised ISBN reaches us. If your browser has no built-in barcode detection, the web app loads a recognition module from the jsDelivr CDN; no camera images are sent there.
Gallery access is requested when you choose a cover photograph, a profile avatar or a photograph for a note. The chosen image is uploaded directly to our storage in Amazon S3 (§6).
EXIF metadata. The apps re-encode cover photographs and note photographs on your device before uploading them, and the server re-encodes covers once more, so stored covers and note photographs contain no EXIF metadata, including GPS coordinates. The iOS and Android apps upload a profile avatar as the file is stored on your device, so its metadata — including GPS coordinates, if the camera recorded them — may be kept. If you do not want that, choose an avatar image without geotags.
A cover photograph may be processed automatically to improve its appearance, in particular by removing the background: for this, a downscaled image is sent to Amazon Bedrock in the USA (§6, §7). The processed photograph becomes the cover of the book in the catalogue and is deleted together with that book's record; the original uploaded for processing is deleted automatically within 7 days.
15. Moderation reports
A report is submitted by a user in free form; it is read by people from the moderation team.
- The identity of the author of a report is not disclosed to the user the report is about.
- Submitting a report means a review, not a guarantee that content will be removed.
- Do not include unnecessary personal data in the text of a report — describe only what is needed to understand the violation.
- Reports are retained for 6 months after the submission is closed (§9); reports you submitted are deleted together with your account, and reports about deleted content — together with that content.
16. Error monitoring and session recording
Sentry operates for all users of the web app and the iOS and Android apps on the basis of legitimate interest. The Session Replay feature in Sentry is disabled. Technical data about the error is collected, not your content; in the iOS and Android apps, also the device model, OS and app versions, the screens you moved through before the crash, and sampled performance data.
Google Tag runs only in the web app and records page views only after consent. We do not send your account identifier, email or name to Google.
Microsoft Clarity runs only in the web app and records sessions only after consent. We do not enable this integration until masking is configured to exclude the following from recordings:
- the authentication screen and any credential input fields;
- the report submission form;
- the camera preview;
- the review, note and post editors.
If you withdraw consent: Google Tag and Clarity no longer load, the cookies listed in §8.3 and §8.4 are deleted, and data previously collected by those processors is erased according to the periods in §9.
The iOS and Android apps contain neither Google Tag nor Microsoft Clarity, nor any other analytics SDK.
17. Changes to this Policy
We notify you of material changes — new categories of data, new processors,
new purposes, a change of legal basis — in the application and, where available,
by email at least 14 days before they take effect. Such changes are
accompanied by an increase of the version in the document's metadata.
Editorial corrections that do not change the substance of the processing do not
change the version and do not require notification.
Previous versions are provided on request via the contact in §1.
18. Related documents
- Terms of Use
- Manage cookies and analytics