Shelfd
Privacy Policy
Last updated: 9 July 2026
Your reading data is yours. This policy explains exactly what we collect, why, and the control you have over it.
This Privacy Policy explains how Shelfd, a service operated by Cormac Berkery (“Shelfd”, “we”, “us”), collects, uses, and protects your personal data when you use https://shelfd.cormacberkery.com and related services (the “Service”).
We are the data controller for your personal data, established in the Netherlands. If you have any questions or wish to exercise your rights, contact us at cormacberkery@gmail.com. A postal address is available on request.
1. Who this applies to
This policy applies to everyone who uses Shelfd. The Service is not directed at children under 16, and we do not knowingly collect data from them. If you believe a child has provided us personal data, contact us and we will delete it.
2. What data we collect
Account data. When you create an account we collect your email address (for email/password sign-up), a display name, and any optional profile details you choose to add (avatar, bio, pronouns, location, website). Passwords are never stored in plain text — only a securely hashed digest.
Social login data. If you sign in with Google or TikTok, we receive a stable identifier from that provider plus basic profile information:
- Google: your email address, name, and profile picture.
- TikTok: your TikTok user ID (open_id), display name, and avatar — and, if you grant it, your TikTok username, bio, and verified status. TikTok does not share your email with us.
We store which provider you used and the provider’s identifier so you can log back in. We never receive or store your password for these providers.
Your library and activity. The books you add to your shelves (read, reading, want, did-not-finish), your ratings, reviews, reading progress, notes, lists, quotes, follows, and any posts you create.
Imported data. If you import a library from Goodreads, StoryGraph, or LibraryThing, we process the CSV file you upload to add those books to your shelves.
Shelf-scan photos. If you use the shelf scanner, the photo you upload is sent to a third-party vision-model provider (Groq, or OpenRouter) purely to detect the book spines in it, and the provider returns the detected text. Each provider handles the image under its own terms; we send only what is needed to run the scan and we do not keep the original photo after the scan is complete. Using the scanner is optional — if you would rather not have a photo processed this way, simply don’t use it.
Technical and usage data. To keep you logged in we set a strictly-necessary, httpOnly session cookie. If you consent to analytics, we collect limited product-usage events (such as pages viewed, features used, and searches) tied to a pseudonymous identifier, plus coarse information such as your country and device type. We do not store your IP address in the clear, or your full user-agent, for analytics.
3. How we use your data and our legal bases
We rely on the following legal bases under the GDPR (Article 6):
- Run your account and keep you logged in
- Performance of a contract.
- Store and show your library, reviews, and social activity
- Performance of a contract.
- Process imports and shelf-scan photos you submit
- Performance of a contract.
- Security, fraud prevention, and abuse moderation
- Our legitimate interests.
- Product analytics and improvement
- Your consent — which you can withdraw at any time.
- Marketing emails (if any)
- Your consent.
- Meeting legal obligations
- Legal obligation.
We ask for your consent before setting any non-essential (analytics or marketing) cookies or tracking, and you can change your choice at any time in settings.
4. Who we share it with
We do not sell your personal data. We share it only with service providers who process it on our behalf, under contract:
- Our hosting provider — application and database hosting.
- Cloudflare — DNS, content delivery, and security.
- Google — for Google Sign-In (only if you use it).
- TikTok / ByteDance — for TikTok Login (only if you use it).
- Groq / OpenRouter — vision-model processing of shelf-scan photos (only if you scan).
- Our email delivery provider — for transactional email, if we email you.
We may also disclose data where required by law.
5. Business transfers
If Shelfd is ever part of a merger, acquisition, reorganisation, or sale of assets — or if the Service winds down — your personal data may be transferred as part of that process. We will only allow this where the recipient agrees to protect your data consistent with this policy, and we will notify you (in the app or by email) of any change to who controls your data and of any choices you have.
6. International transfers
Our primary hosting is in the EU. Where a provider processes data outside the EEA (for example Google or TikTok), that transfer is covered by appropriate safeguards such as the EU Standard Contractual Clauses.
7. How long we keep it
We keep your account data for as long as your account is active. When you delete your account, we soft-delete it and then permanently erase or anonymise your personal data within 90 days, except where we must keep certain records to comply with the law. Analytics events, where collected, are retained for up to 14 months and then deleted or aggregated.
8. Automated decisions
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Features such as recommendations and the shelf scanner are assistive — they help you organise and discover books, and you stay in control of what ends up on your shelves.
9. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and the right to data portability — which is core to Shelfd: you can export your full library at any time. To exercise any right, email cormacberkery@gmail.com. To protect your account we may first need to verify your identity, usually by confirming the request comes from the email address on your account, and we aim to respond within one month as the GDPR requires. You also have the right to lodge a complaint with your data protection authority; in the Netherlands this is the Autoriteit Persoonsgegevens.
10. Notice for US residents
If you live in California or another US state with a privacy law (such as Virginia, Colorado, or Connecticut), this applies in addition to the rest of the policy. We do not sell your personal information, and we do not “share” it for cross-context behavioural advertising or use it for targeted advertising. Depending on your state, you may have the right to know what personal information we hold about you, to access, correct, or delete it, and not to be treated differently for exercising these rights. Use the same contact details above to make a request, and you may appeal a decision by replying to our response.
11. Cookies
We use a strictly-necessary session cookie to keep you logged in (no consent required). Any analytics or preference cookies are set only with your consent.
12. Security
We protect your data with measures including hashed passwords, httpOnly session cookies, encrypted transport (HTTPS), and access controls. No system is perfectly secure, but we work to protect your information and will notify you and the relevant authority of a breach where required.
13. Changes to this policy
We may update this policy from time to time. We will post the new version here and update the “Last updated” date; significant changes will be notified in the app or by email.
14. Contact
Shelfd, operated by Cormac Berkery in the Netherlands — cormacberkery@gmail.com. A postal address is available on request.