← All apps

BookShelfy — Privacy Policy

Last updated: 2026-08-14

1. Overview

BookShelfy is a personal book library app for cataloguing the books you own, want, have lent out or have borrowed, with optional cloud sync via Microsoft OneDrive, barcode scanning, and book metadata lookup via the Google Books API. This privacy policy explains what personal data the app processes, for what purposes, on which legal bases, and what rights you have.

2. Controller

Stonemiller
Föttingerweg 13
90431 Nürnberg, Germany
Email: info@stonemiller.eu

3. Data We Process

3.1 Data stored locally on your device

By default, BookShelfy stores all of your data exclusively on your device in a local SQLite database. This includes:

This local data is never transmitted to our servers. BookShelfy does not operate any backend of its own.

3.2 Cloud sync via Microsoft OneDrive (optional, opt-in)

If you connect a Microsoft account in the settings, BookShelfy can synchronise your book database with your personal OneDrive. Sync uses OAuth 2.0 — you sign in directly with Microsoft; we never see or store your Microsoft password.

Cloud sync is fully optional. The app is fully functional offline without a Microsoft account.

3.3 Book lookup via the Google Books API

When you search for a book or scan a barcode, BookShelfy sends the search term — a title, an author or an ISBN — directly from your device to the Google Books API (www.googleapis.com) and displays the results. This happens only when you actively search or scan; the app makes no such request on its own. These requests are not routed through our servers, and Google receives standard request metadata (such as your IP address) as with any normal web request. We do not receive or store your search terms.

3.4 Barcode scanning

The barcode scanner uses your device camera together with the platform's native barcode recognition (Apple Vision on iOS, Google ML Kit on Android). Recognition runs entirely on your device; no camera images are transmitted to us or to third parties. Only the ISBN read from the barcode is used, for the lookup described in §3.3. Camera access is requested only when you open the scanner.

3.5 Photo library access

You can pick an image from your photo library to use as a book cover. The selected image is stored on your device only and is not uploaded. Access is requested only at the moment you choose an image.

3.6 Error reports and user feedback

We use Sentry (see §5) to detect and fix crashes and errors. Crash reporting is switched on by default and can be switched off at any time under Settings → Privacy; when it is off, the reporting SDK is not started at all on the next launch and nothing is transmitted. While it is on, an error transmits:

sendDefaultPii is disabled, so the SDK attaches neither your IP address nor your device name; Sentry processes the connection IP only transiently at ingest.

If you submit the in-app Feedback form, we transmit:

The feedback form is delivered through Sentry and is therefore available only while crash reporting is switched on.

We do not collect:

4. Purposes and Legal Bases (GDPR Art. 6)

PurposeLegal basis
Local app functionalityArt. 6(1)(b) — contract performance
OneDrive cloud sync (when enabled)Art. 6(1)(a) — consent / Art. 6(1)(b) — contract
Book lookup via the Google Books APIArt. 6(1)(a) — consent (by searching or scanning)
Error monitoringArt. 6(1)(f) — legitimate interest in reliable software
User feedbackArt. 6(1)(a) — consent (by submitting the form)

5. Third-Party Processors

We use the following processors under Art. 28 GDPR data processing agreements (or, where indicated, as services you separately contract with):

6. International Data Transfers

Some processors (notably Microsoft, Sentry, and Google) are based in the United States and may process data outside the EU/EEA. For such transfers we rely on the EU-US Data Privacy Framework and/or the EU Standard Contractual Clauses (SCCs) where applicable.

7. Retention

8. Your Rights (GDPR Art. 15–22)

You have the right to:

To exercise these rights, contact us at info@stonemiller.eu.

9. Supervisory Authority

You may lodge a complaint with the data protection authority of your EU member state. For the controller's place of residence (Germany), the competent authority is the State Commissioner for Data Protection of the respective federal state.

10. Security

All network traffic (OneDrive sync, Google Books lookups, Sentry) is transmitted via HTTPS/TLS. Microsoft account authentication is handled by Microsoft in a system browser session; we never see or store your password. The long-lived refresh token is kept in the platform's secure storage (Keychain, Keystore or DPAPI, depending on your system); the short-lived access token is kept in the app's own preference storage inside the app sandbox, which the operating system shields from other apps. Your book database stays on your device unless you enable cloud sync.

11. Children's Privacy

BookShelfy is a general-audience library app and is not directed at children under 13. It does not collect personal information from children. Parents who allow a child to use the app act as the controller for any data entered by the child.

12. Changes to This Policy

We may update this policy as the app evolves. Material changes will be announced in the app or on this page. The “Last updated” date above reflects the current version.

13. Contact

For any privacy-related questions, please contact info@stonemiller.eu.