Privacy
What we do with your data.
Last updated 17 May 2026
Short version. We collect what's needed to run your shelf — nothing for advertising. We don't sell your data. You can export or delete it any time from Profile → Data & privacy.
The short version
MyBooks stores what's needed to keep your library working and to personalise recommendations. We do not sell your data. We do not use it for ad targeting. You remain in control — you can export everything we have, or delete it outright, at any time.
What we collect
- Account info — your email, plus an optional display name and avatar.
- Your library — the media you add, ratings, reviews, reading status, and anything else you save.
- Chat history — your conversations with the assistant, so it can remember them next time.
- Technical — IP address, browser, and error logs, used only for debugging.
How we use it
- To personalise recommendations from the chat assistant.
- To keep your library in sync across devices.
- To send transactional email (magic-link login, account deletion confirmations).
- To debug errors and keep the service working.
We do not profile you for advertising. We don't run any ad network, analytics broker, or behavioural tracker.
Who else sees it
To run the service we share data with a small number of providers, each only for a specific purpose:
- Google — if you choose to sign in with Google.
- Our LLM provider — when the chat runs, your messages (and relevant parts of your library) are sent so the assistant can respond.
- Stripe — if you buy a subscription or top-up, Stripe processes the payment. We receive a confirmation and a transaction reference; we never see or store your card details.
- Our cloud host — where your data lives and the app runs.
- Our email provider — to deliver magic-link emails and account notifications.
Some of these providers may process your data outside the EU/EEA (for example in the United States). When they do, they rely on standard contractual clauses or equivalent safeguards approved under EU law.
No one else. No data brokers, no advertising networks, no analytics resellers.
Legal basis
Under the GDPR we rely on the following bases to process your data:
- Performance of a contract — to run your account, your library, and any subscription you've taken out.
- Legitimate interest — to keep the service secure, debug errors, and prevent abuse.
- Consent — for anything optional you turn on yourself. You can withdraw it at any time.
- Legal obligation — to keep payment and tax records for as long as the law requires.
Age requirement
MyBooks is not intended for children. You must be at least 16 years old to use the service. If you learn that a child under 16 has created an account, please email us and we'll remove it.
Your rights
- Export. Download everything we have about you from Profile → Data & privacy → Export.
- Delete. Remove your account and all associated data from Profile → Data & privacy → Delete account. We keep backups for up to 30 days before they are purged.
- Correct or ask questions. Email [email protected] and we'll respond within 30 days.
Security & retention
Data is encrypted in transit (HTTPS) and at rest. We keep your data for as long as your account is active. If you delete your account, everything is removed within 30 days.
Changes
If we change how we handle your data in a way that matters, we'll email you before the change takes effect. Minor clarifications just get a new "last updated" date on this page.
Contact
- Data controller
- Daniel Stokke
- [email protected]
- Last updated
- 17 May 2026