1. Introduction
Booktail is a reading-tracker mobile application provided by Khatsiur Vasyl, a sole proprietor (ФОП) registered in Ukraine ("we", "us", "our"). This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have.
As of v2.0, Booktail synchronises your reading data across your devices using a cloud backend. Version 2.1 adds a description of the data processed in connection with the paid Booktail Premium subscription (Section 3.6).
2. Data Controller
For the purposes of the EU General Data Protection Regulation ("GDPR") and Ukrainian Law No. 2297-VI on Personal Data Protection, the data controller is:
Khatsiur Vasyl, sole proprietor (ФОП) registered in Ukraine.
Contact (email only): contact.booktail@gmail.com
We have not appointed a Data Protection Officer; for any privacy question, write to the email above.
3. What Data We Collect
3.1 Account data
When you create an account using Sign in with Apple or Google, we receive from the identity provider:
- A stable user identifier;
- Your email address;
- Your display name (if the SSO provider shares it);
- Your avatar URL (if available).
3.2 Reading content
Everything you create inside the app is stored locally and synchronised to our backend so that it is available on all your devices:
- Books you add (title, authors, metadata, cover image);
- Reading shelves and collections;
- Reading journeys, sessions, and history events;
- Notes (text and attached photos);
- Reading goals and personal settings.
3.3 Attachments
Custom book covers and photos you attach to notes are uploaded to our cloud object storage so they remain available across your devices.
3.4 Crash diagnostics
When the app crashes or hits an unexpected error, an automatic diagnostic report is generated containing:
- Device model and operating system version;
- App version and build number;
- Stack trace and error message;
- Anonymised navigation breadcrumbs (which screens were visited; no content).
This report does not contain your books, notes, or other reading content.
3.5 Authentication artefacts
Short-lived access tokens and refresh tokens are stored locally on your device using the platform secure store (iOS Keychain, Android Keystore).
3.6 Subscription data
If you purchase Booktail Premium, we process information about the state of your subscription:
- Your Booktail account identifier, which we pass to the subscription-management provider so that the purchase is linked to your account;
- Your Premium access status, the plan you chose, and the start, renewal, or expiry dates;
- Transaction identifiers and the country of the store where the purchase was made;
- Platform, app version, and interface language — so that we can show you the subscription screen with the right prices and language.
We do not process your payment details. Payment is taken by Apple or Google; card number, bank details, and billing address are not passed to us and are not accessible to us.
3.7 What we do NOT collect
- Your location;
- Payment details — card numbers, bank data, billing address;
- Advertising identifiers;
- Behavioural analytics or screen-recording data;
- Your contacts;
- Microphone audio (the microphone permission may be requested by Android as part of the camera-permission group; the microphone is never accessed by the app);
- Biometric data.
4. Purposes and Legal Basis
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Account data | Account creation, authentication, multi-device sync | Performance of contract — Art. 6(1)(b) |
| Reading content | Sync, durability, display across your devices | Performance of contract — Art. 6(1)(b) |
| Attachments | Display book covers and note images on all your devices | Performance of contract — Art. 6(1)(b) |
| Subscription data | Providing paid access, restoring purchases, subscription support | Performance of contract — Art. 6(1)(b) |
| Crash diagnostics | Identify and fix bugs, improve stability | Legitimate interest — Art. 6(1)(f) |
Legitimate-interest balancing test (crash diagnostics). The data is technical and minimised, does not include your reading content, is not used for profiling or marketing, and is retained for 30 days. Our interest in app stability outweighs the limited privacy impact, and you can object at any time (see Section 8).
5. Sub-processors
We share personal data with the following categories of processors:
- Identity providers — for SSO and account management.
- Cloud infrastructure providers — for hosting our API in the European Union.
- Database hosting providers — for storing your reading data in the European Union.
- Object storage providers — for book covers and note images.
- Error monitoring services — for crash diagnostics.
- Subscription-management providers — for verifying subscription status and reconciling purchases with the stores.
When you choose to sign in, your data is also shared with the SSO provider you select:
The purchase itself is taken by Apple Inc. or Google LLC — with respect to your payment details they act as independent controllers, not as our processors.
A current list of named sub-processors is available on request via contact.booktail@gmail.com.
6. International Transfers
Most of your data is physically stored within the European Union (Frankfurt, Germany). Some sub-processors are US-based legal entities whose engineers may have access from the United States. Subscription data (Section 3.6) is processed and stored by the subscription-management provider on infrastructure in the United States. Where such transfers occur, we rely on:
- Standard Contractual Clauses approved by the European Commission, and/or
- EU-US Data Privacy Framework certification, where the processor participates.
For users in Ukraine, your data is processed in the European Union, which Ukrainian law recognises as providing an adequate level of protection.
7. How Long We Keep Your Data
| State | Retention |
|---|---|
| Active account | For as long as you keep the account |
| Account deletion request | 30-day grace period before hard deletion |
| Database backups | Up to 30 days after deletion (rolling backup window) |
| Crash diagnostics | 30 days |
| Attachments after account deletion | Removed together with your account |
| Subscription data | For as long as you keep the account; transaction history under the subscription-management provider's own policy |
End-to-end deletion. In the worst case, your data may persist in rolling backups for up to 30 days after the grace period expires, for a total of approximately 60 days. After that, no copy remains.
Deleting your account does not cancel your subscription. The subscription is held with the App Store or Google Play and keeps renewing until you cancel it in the settings of the relevant platform — see Section 7.5 of the Terms & Conditions.
8. Your Rights
If you are in the EU, EEA, or UK, you have the rights below under the GDPR. If you are in Ukraine, equivalent rights apply under Law No. 2297-VI.
- Right of access — request a copy of your personal data by emailing contact.booktail@gmail.com. You can also view most of your data directly in the app.
- Right to rectification — edit your data directly in the app; for fields you cannot edit, write to us.
- Right to erasure — Settings → Delete Account, or write to us.
- Right to restriction of processing — write to us.
- Right to object — write to us, in particular to object to crash diagnostics processing on legitimate-interest grounds.
- Right to data portability — request an export of your data by email; we will provide it in a structured, machine-readable format (e.g. JSON) within one month.
- Right to withdraw consent — sign out and delete your account.
To exercise any right, email contact.booktail@gmail.com. We respond within one month.
Right to lodge a complaint:
- EU/EEA residents: with the data-protection authority of your country of residence (e.g., the Irish Data Protection Commission, the German BfDI, the Polish UODO).
- Ukrainian residents: with the Ukrainian Parliament Commissioner for Human Rights (Ombudsperson) — https://www.ombudsman.gov.ua/
9. Security
- All API traffic uses TLS 1.2 or higher.
- Data at rest on our infrastructure is encrypted using the default encryption of the underlying providers (managed-database encryption, object-storage encryption).
- Authentication tokens are stored on your device in the platform secure store (iOS Keychain, Android Keystore).
- The local SQLite database on your device is not separately encrypted by the app; it relies on the device-level encryption provided by your operating system (FileVault, Android File-Based Encryption). For maximum security, use a device passcode and keep your operating system updated.
No method of electronic storage is 100% secure, and we cannot guarantee absolute security.
10. Children's Privacy
You must be at least 13 years old to use Booktail.
If you are located in the European Economic Area or the United Kingdom, you must be at least 16, or such lower age (down to 13) as your national law permits with verifiable parental consent.
We do not knowingly collect personal data from children below these thresholds. If you believe a child has created an account, contact us and we will delete it.
11. Third-Party Links
The app may contain links to external websites (book information sources, your SSO provider's privacy pages). We are not responsible for the privacy practices of those sites; we encourage you to read their policies.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The Effective Date at the top of this page reflects the most recent version, and we encourage you to review this policy periodically.
If we make a change that significantly affects how we handle your personal data, we will use reasonable efforts to inform you in advance — for example by displaying a notice in the App or by another appropriate means available to us at the time.
Earlier versions are available on request.
13. Contact
For privacy questions, requests, or complaints:
Email: contact.booktail@gmail.com
We respond within a reasonable time, and within one month for formal data-subject requests.