BookShelfy — Privacy Policy
Last updated: 2026-08-14
1. Overview
BookShelfy is a personal book library app for cataloguing the books you own, want, have lent out or have borrowed, with optional cloud sync via Microsoft OneDrive, barcode scanning, and book metadata lookup via the Google Books API. This privacy policy explains what personal data the app processes, for what purposes, on which legal bases, and what rights you have.
2. Controller
Stonemiller
Föttingerweg 13
90431 Nürnberg, Germany
Email: info@stonemiller.eu
3. Data We Process
3.1 Data stored locally on your device
By default, BookShelfy stores all of your data exclusively on your device in a local SQLite database. This includes:
- Book entries (title, author and co-authors, ISBN, series, genre, publisher, page count, publication date, description, tags, notes, list type — bookshelf, wishlist, lent, borrowed or archive)
- Your personal entries about a book (your own rating, favourite and read markers, start and finish reading dates, location, condition, price, place and date of purchase)
- Cover images, cached in a folder inside the app's own storage
- App settings (theme, list or grid layout, sort order, crash reporting preference, OneDrive connection state)
This local data is never transmitted to our servers. BookShelfy does not operate any backend of its own.
3.2 Cloud sync via Microsoft OneDrive (optional, opt-in)
If you connect a Microsoft account in the settings, BookShelfy can synchronise your book database with your personal OneDrive. Sync uses OAuth 2.0 — you sign in directly with Microsoft; we never see or store your Microsoft password.
- The long-lived refresh token issued by Microsoft is stored on your device only, in the platform's secure storage (Keychain on iOS and macOS, Keystore-backed encrypted storage on Android, DPAPI on Windows). The short-lived access token is kept in the app's own preference storage inside the app sandbox. Neither is transmitted to us.
- Your book database is uploaded as a file to the app folder of your own OneDrive account. Only you (and apps you authorise) can access that folder.
- Before each sync, the previous state of the database is written to that same folder as a dated backup file. These backups are not deleted automatically; you can remove them in OneDrive at any time.
- Sync merges changes from all your devices rather than overwriting them.
Cloud sync is fully optional. The app is fully functional offline without a Microsoft account.
3.3 Book lookup via the Google Books API
When you search for a book or scan a barcode, BookShelfy sends the search
term — a title, an author or an ISBN — directly from your device to the
Google Books API (www.googleapis.com) and displays the
results. This happens only when you actively search or scan; the app
makes no such request on its own. These requests are not routed through
our servers, and Google receives standard request metadata (such as
your IP address) as with any normal web request. We do not receive or
store your search terms.
3.4 Barcode scanning
The barcode scanner uses your device camera together with the platform's native barcode recognition (Apple Vision on iOS, Google ML Kit on Android). Recognition runs entirely on your device; no camera images are transmitted to us or to third parties. Only the ISBN read from the barcode is used, for the lookup described in §3.3. Camera access is requested only when you open the scanner.
3.5 Photo library access
You can pick an image from your photo library to use as a book cover. The selected image is stored on your device only and is not uploaded. Access is requested only at the moment you choose an image.
3.6 Error reports and user feedback
We use Sentry (see §5) to detect and fix crashes and errors. Crash reporting is switched on by default and can be switched off at any time under Settings → Privacy; when it is off, the reporting SDK is not started at all on the next launch and nothing is transmitted. While it is on, an error transmits:
- Timestamp and error message
- App version, operating system version, device model
- Stack trace
- A randomly generated installation identifier, created on the device, not linked to your identity or to any account, and reset when the app is reinstalled
- Breadcrumbs (a log of recent actions). The app deliberately disables log-based breadcrumbs, so book data, search terms and OneDrive responses are not included.
- A sample of performance and profiling data (roughly one in ten sessions) covering timings of app operations
sendDefaultPii is disabled, so the SDK attaches neither
your IP address nor your device name; Sentry processes the connection
IP only transiently at ingest.
If you submit the in-app Feedback form, we transmit:
- Your message
- Your email address
- Your name (optional)
The feedback form is delivered through Sentry and is therefore available only while crash reporting is switched on.
We do not collect:
- Advertising identifiers (IDFA, AAID)
- Precise location data
- Contacts, microphone data or camera images
- Your book data, in any error report or analytics event
4. Purposes and Legal Bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Local app functionality | Art. 6(1)(b) — contract performance |
| OneDrive cloud sync (when enabled) | Art. 6(1)(a) — consent / Art. 6(1)(b) — contract |
| Book lookup via the Google Books API | Art. 6(1)(a) — consent (by searching or scanning) |
| Error monitoring | Art. 6(1)(f) — legitimate interest in reliable software |
| User feedback | Art. 6(1)(a) — consent (by submitting the form) |
5. Third-Party Processors
We use the following processors under Art. 28 GDPR data processing agreements (or, where indicated, as services you separately contract with):
-
Microsoft Corporation — OneDrive storage and Microsoft account authentication, used only when you enable cloud sync. Data is stored in your own OneDrive account.
Privacy: https://privacy.microsoft.com/privacystatement -
Sentry (Functional Software EMEA) — error monitoring and user feedback.
Endpoint:ingest.de.sentry.io(Germany).
Privacy: https://sentry.io/privacy/ -
Google LLC (Google Books API) — book metadata lookup, only when you search for or scan a book.
Privacy: https://policies.google.com/privacy -
Apple Inc. — iOS / iPadOS app distribution via the App Store.
Privacy: https://www.apple.com/legal/privacy/ -
Google LLC — Android app distribution via Google Play.
Privacy: https://policies.google.com/privacy -
Microsoft Corporation — Windows app distribution via the Microsoft Store.
Privacy: https://privacy.microsoft.com/privacystatement
6. International Data Transfers
Some processors (notably Microsoft, Sentry, and Google) are based in the United States and may process data outside the EU/EEA. For such transfers we rely on the EU-US Data Privacy Framework and/or the EU Standard Contractual Clauses (SCCs) where applicable.
7. Retention
- Local device data: until you delete it or uninstall the app.
- OneDrive-synced data and the dated backup files: stored in your OneDrive account until you delete them.
- OAuth tokens: stored on your device until you disconnect or uninstall.
- Error reports: retained by Sentry for up to 90 days, then deleted.
- User feedback: retained for up to 24 months after submission.
8. Your Rights (GDPR Art. 15–22)
You have the right to:
- Access the personal data we hold about you (Art. 15)
- Have inaccurate data corrected (Art. 16)
- Request deletion of your data (Art. 17)
- Restrict processing (Art. 18)
- Receive your data in a portable format (Art. 20) — the app can export and share your full database at any time
- Object to processing based on legitimate interest (Art. 21) — crash reporting can be switched off under Settings → Privacy
- Withdraw consent for cloud sync at any time (via the in-app settings — “Disconnect”)
- Lodge a complaint with a supervisory authority
To exercise these rights, contact us at info@stonemiller.eu.
9. Supervisory Authority
You may lodge a complaint with the data protection authority of your EU member state. For the controller's place of residence (Germany), the competent authority is the State Commissioner for Data Protection of the respective federal state.
10. Security
All network traffic (OneDrive sync, Google Books lookups, Sentry) is transmitted via HTTPS/TLS. Microsoft account authentication is handled by Microsoft in a system browser session; we never see or store your password. The long-lived refresh token is kept in the platform's secure storage (Keychain, Keystore or DPAPI, depending on your system); the short-lived access token is kept in the app's own preference storage inside the app sandbox, which the operating system shields from other apps. Your book database stays on your device unless you enable cloud sync.
11. Children's Privacy
BookShelfy is a general-audience library app and is not directed at children under 13. It does not collect personal information from children. Parents who allow a child to use the app act as the controller for any data entered by the child.
12. Changes to This Policy
We may update this policy as the app evolves. Material changes will be announced in the app or on this page. The “Last updated” date above reflects the current version.
13. Contact
For any privacy-related questions, please contact info@stonemiller.eu.
BookShelfy — Datenschutzerklärung
Zuletzt aktualisiert: 14.08.2026
1. Überblick
BookShelfy ist eine persönliche Bücherverwaltung, um die eigenen Bücher zu katalogisieren — was im Regal steht, auf der Wunschliste bleibt, verliehen oder ausgeliehen ist — mit optionaler Cloud-Synchronisation über Microsoft OneDrive, Barcode-Scanner und Buchdaten-Abruf über die Google-Books-API. Diese Datenschutzerklärung beschreibt, welche personenbezogenen Daten die App verarbeitet, zu welchen Zwecken, auf welcher Rechtsgrundlage und welche Rechte Ihnen zustehen.
2. Verantwortlicher
Stonemiller
Föttingerweg 13
90431 Nürnberg, Deutschland
E-Mail: info@stonemiller.eu
3. Verarbeitete Daten
3.1 Lokale Daten auf Ihrem Gerät
Standardmäßig speichert BookShelfy alle Daten ausschließlich lokal auf Ihrem Gerät in einer SQLite-Datenbank. Dazu gehören:
- Bucheinträge (Titel, Autor und Co-Autoren, ISBN, Reihe, Genre, Verlag, Seitenzahl, Erscheinungsdatum, Beschreibung, Schlagwörter, Notizen, Listentyp — Bücherregal, Wunschliste, Verliehen, Ausgeliehen oder Archiv)
- Ihre persönlichen Angaben zu einem Buch (eigene Bewertung, Favoriten- und Gelesen-Markierung, Lesebeginn und -ende, Standort, Zustand, Preis, Ort und Datum des Kaufs)
- Coverbilder, zwischengespeichert in einem Ordner im App-eigenen Speicher
- App-Einstellungen (Design, Listen- oder Rasteransicht, Sortierung, Einstellung zu Absturzberichten, OneDrive-Verbindungsstatus)
Diese lokalen Daten werden niemals an unsere Server übertragen. BookShelfy betreibt kein eigenes Backend.
3.2 Cloud-Synchronisation über Microsoft OneDrive (optional, Opt-in)
Wenn Sie in den Einstellungen ein Microsoft-Konto verbinden, kann BookShelfy Ihre Buchdatenbank mit Ihrem persönlichen OneDrive synchronisieren. Die Synchronisation erfolgt per OAuth 2.0 — Sie melden sich direkt bei Microsoft an; wir sehen oder speichern Ihr Microsoft-Passwort zu keinem Zeitpunkt.
- Das langlebige, von Microsoft ausgestellte Refresh-Token wird ausschließlich auf Ihrem Gerät im sicheren Speicher der Plattform abgelegt (Keychain unter iOS und macOS, Keystore-gestützter verschlüsselter Speicher unter Android, DPAPI unter Windows). Das kurzlebige Access-Token liegt im App-eigenen Einstellungsspeicher innerhalb der App-Sandbox. An uns wird keines von beiden übermittelt.
- Ihre Buchdatenbank wird als Datei im App-Ordner Ihres eigenen OneDrive-Kontos abgelegt. Nur Sie (und von Ihnen autorisierte Apps) haben Zugriff.
- Vor jeder Synchronisation wird der vorherige Stand der Datenbank als datierte Sicherungsdatei im selben Ordner abgelegt. Diese Sicherungen werden nicht automatisch gelöscht; Sie können sie jederzeit in OneDrive entfernen.
- Die Synchronisation führt Änderungen von allen Ihren Geräten zusammen, statt sie zu überschreiben.
Die Synchronisation ist vollständig optional. Die App funktioniert auch vollständig offline ohne Microsoft-Konto.
3.3 Buchdaten-Abruf über die Google-Books-API
Wenn Sie nach einem Buch suchen oder einen Barcode scannen, sendet
BookShelfy den Suchbegriff — Titel, Autor oder ISBN — direkt von Ihrem
Gerät an die Google-Books-API (www.googleapis.com) und
zeigt die Ergebnisse an. Das geschieht ausschließlich dann, wenn Sie
aktiv suchen oder scannen; von sich aus stellt die App keine solche
Anfrage. Diese Anfragen werden nicht über unsere Server geleitet;
Google erhält dabei die üblichen Anfrage-Metadaten (etwa Ihre
IP-Adresse) wie bei jeder normalen Web-Anfrage. Wir erhalten und
speichern Ihre Suchbegriffe nicht.
3.4 Barcode-Scanner
Der Barcode-Scanner nutzt die Kamera Ihres Geräts zusammen mit der nativen Barcode-Erkennung der Plattform (Apple Vision unter iOS, Google ML Kit unter Android). Die Erkennung läuft vollständig auf Ihrem Gerät; Kamerabilder werden weder an uns noch an Dritte übermittelt. Verwendet wird nur die aus dem Barcode gelesene ISBN, für den in §3.3 beschriebenen Abruf. Der Kamerazugriff wird erst angefragt, wenn Sie den Scanner öffnen.
3.5 Zugriff auf die Fotomediathek
Sie können ein Bild aus Ihrer Fotomediathek als Cover für ein Buch auswählen. Das gewählte Bild wird ausschließlich auf Ihrem Gerät gespeichert und nicht hochgeladen. Der Zugriff wird erst in dem Moment angefragt, in dem Sie ein Bild auswählen.
3.6 Fehlerberichte und Nutzer-Feedback
Wir setzen Sentry (siehe §5) ein, um Abstürze und Fehler zu erkennen und zu beheben. Absturzberichte sind standardmäßig aktiviert und können jederzeit unter Einstellungen → Datenschutz abgeschaltet werden; ist die Funktion aus, wird das Melde-SDK beim nächsten Start gar nicht erst gestartet und es werden keinerlei Daten übermittelt. Solange sie aktiv ist, werden im Fehlerfall übermittelt:
- Zeitpunkt und Fehlermeldung
- App-Version, Betriebssystem-Version, Gerätemodell
- Stacktrace
- Eine zufällig erzeugte Installations-Kennung, die auf dem Gerät entsteht, mit keiner Identität und keinem Konto verknüpft ist und bei einer Neuinstallation zurückgesetzt wird
- Breadcrumbs (Protokoll der letzten Aktionen). Die App deaktiviert protokollbasierte Breadcrumbs bewusst, sodass Buchdaten, Suchbegriffe und OneDrive-Antworten nicht enthalten sind.
- Eine Stichprobe von Performance- und Profiling-Daten (etwa jede zehnte Sitzung) zu den Laufzeiten von App-Vorgängen
sendDefaultPii ist deaktiviert; das SDK übermittelt daher
weder Ihre IP-Adresse noch Ihren Gerätenamen. Sentry verarbeitet die
Verbindungs-IP lediglich kurzzeitig bei der Annahme der Daten.
Wenn Sie das In-App-Formular Feedback verwenden, werden zusätzlich übermittelt:
- Ihre Nachricht
- Ihre E-Mail-Adresse
- Ihr Name (optional)
Das Feedback-Formular läuft über Sentry und steht daher nur zur Verfügung, solange Absturzberichte aktiviert sind.
Wir erheben keine:
- Werbe-IDs (IDFA, AAID)
- Genauen Standortdaten
- Kontakte, Mikrofondaten oder Kamerabilder
- Buchdaten in Fehlerberichten oder Analyse-Ereignissen
4. Zwecke und Rechtsgrundlagen (Art. 6 DSGVO)
| Zweck | Rechtsgrundlage |
|---|---|
| Lokale App-Funktionen | Art. 6 Abs. 1 lit. b — Vertragserfüllung |
| OneDrive-Cloud-Synchronisation (bei Aktivierung) | Art. 6 Abs. 1 lit. a — Einwilligung / lit. b — Vertrag |
| Buchdaten-Abruf über die Google-Books-API | Art. 6 Abs. 1 lit. a — Einwilligung (durch Suche oder Scan) |
| Fehler-Monitoring | Art. 6 Abs. 1 lit. f — berechtigtes Interesse an zuverlässiger Software |
| Nutzer-Feedback | Art. 6 Abs. 1 lit. a — Einwilligung (durch Absenden des Formulars) |
5. Auftragsverarbeiter
Wir setzen folgende Auftragsverarbeiter nach Art. 28 DSGVO ein (bzw., wo angegeben, Dienste, die Sie selbst mit dem Anbieter vereinbaren):
-
Microsoft Corporation — OneDrive-Speicher und Microsoft-Konto-Authentifizierung, nur bei aktivierter Cloud-Synchronisation. Die Daten werden in Ihrem eigenen OneDrive-Konto gespeichert.
Datenschutz: https://privacy.microsoft.com/privacystatement -
Sentry (Functional Software EMEA) — Fehler-Monitoring und Nutzer-Feedback.
Endpunkt:ingest.de.sentry.io(Deutschland).
Datenschutz: https://sentry.io/privacy/ -
Google LLC (Google-Books-API) — Abruf von Buchdaten, nur wenn Sie nach einem Buch suchen oder einen Barcode scannen.
Datenschutz: https://policies.google.com/privacy -
Apple Inc. — Vertrieb der iOS- / iPadOS-App über den App Store.
Datenschutz: https://www.apple.com/legal/privacy/ -
Google LLC — Vertrieb der Android-App über Google Play.
Datenschutz: https://policies.google.com/privacy -
Microsoft Corporation — Vertrieb der Windows-App über den Microsoft Store.
Datenschutz: https://privacy.microsoft.com/privacystatement
6. Drittlandübermittlung
Einige Auftragsverarbeiter (insbesondere Microsoft, Sentry und Google) haben ihren Sitz in den USA und verarbeiten Daten gegebenenfalls außerhalb der EU/EWR. Für solche Übermittlungen stützen wir uns auf das EU-US Data Privacy Framework und/oder die EU-Standardvertragsklauseln (SCC).
7. Speicherdauer
- Lokale Gerätedaten: bis Sie die Daten löschen oder die App deinstallieren.
- OneDrive-synchronisierte Daten und die datierten Sicherungsdateien: in Ihrem OneDrive-Konto, bis Sie sie löschen.
- OAuth-Tokens: auf Ihrem Gerät, bis Sie die Verbindung trennen oder die App deinstallieren.
- Fehlerberichte: bis zu 90 Tage bei Sentry, danach Löschung.
- Nutzer-Feedback: bis zu 24 Monate nach Absenden.
8. Ihre Rechte (Art. 15–22 DSGVO)
Sie haben das Recht auf:
- Auskunft über die zu Ihrer Person gespeicherten Daten (Art. 15)
- Berichtigung unrichtiger Daten (Art. 16)
- Löschung Ihrer Daten (Art. 17)
- Einschränkung der Verarbeitung (Art. 18)
- Datenübertragbarkeit (Art. 20) — die App kann Ihre vollständige Datenbank jederzeit exportieren und teilen
- Widerspruch gegen die Verarbeitung aufgrund berechtigten Interesses (Art. 21) — Absturzberichte lassen sich unter Einstellungen → Datenschutz abschalten
- Widerruf der Einwilligung zur Cloud-Synchronisation (jederzeit in den App-Einstellungen — „Trennen“)
- Beschwerde bei einer Aufsichtsbehörde
Zur Ausübung dieser Rechte wenden Sie sich bitte an info@stonemiller.eu.
9. Aufsichtsbehörde
Sie haben das Recht, Beschwerde bei einer Datenschutz-Aufsichtsbehörde einzureichen. Zuständig für den Sitz des Verantwortlichen (Deutschland) ist der Landesbeauftragte für den Datenschutz des jeweiligen Bundeslandes.
10. Datensicherheit
Sämtlicher Netzwerkverkehr (OneDrive-Synchronisation, Google-Books- Abfragen, Sentry) wird per HTTPS/TLS übertragen. Die Authentifizierung am Microsoft-Konto erfolgt direkt bei Microsoft in einer System-Browser-Sitzung; wir sehen oder speichern Ihr Passwort zu keinem Zeitpunkt. Das langlebige Refresh-Token wird im sicheren Speicher der Plattform abgelegt (Keychain, Keystore oder DPAPI, je nach System); das kurzlebige Access-Token liegt im App-eigenen Einstellungsspeicher innerhalb der App-Sandbox, den das Betriebssystem gegenüber anderen Apps abschirmt. Ihre Buchdatenbank bleibt auf Ihrem Gerät, solange Sie die Cloud-Synchronisation nicht aktivieren.
11. Kinder
BookShelfy ist eine Bücherverwaltung für ein allgemeines Publikum und richtet sich nicht an Kinder unter 13 Jahren. Sie erhebt keine personenbezogenen Daten von Kindern. Eltern, die ihrem Kind die Nutzung erlauben, sind für die vom Kind eingegebenen Daten Verantwortliche.
12. Änderungen dieser Erklärung
Wir können diese Datenschutzerklärung anpassen, wenn sich die App weiterentwickelt. Wesentliche Änderungen werden in der App oder auf dieser Seite bekannt gegeben. Das oben genannte Datum „Zuletzt aktualisiert" spiegelt die aktuelle Fassung wider.
13. Kontakt
Bei Fragen zum Datenschutz wenden Sie sich bitte an info@stonemiller.eu.
14. Impressum (TMG §5)
Stonemiller
Föttingerweg 13
90431 Nürnberg, Deutschland
E-Mail: info@stonemiller.eu
Verantwortlich für den Inhalt nach § 55 Abs. 2 RStV: Stonemiller, Anschrift wie oben.