Who this policy covers
This policy applies to MyBookShelf, a library and lending tracker that lets users add books, scan barcodes or ISBNs, store notes, save cover images, and track lending records. The app creates an anonymous Firebase guest account on first use to store account-scoped data. You may later link or sign in to that account with Google or Apple.
This page is intended to serve as the public privacy policy URL for Apple App Store and Google Play submissions.
Data we collect or access
Depending on how you use the app, MyBookShelf may collect, access, or store the following categories of data:
- Library content you create: book titles, authors, ISBNs or barcodes, categories, notes, purchase dates, quantities, and other library metadata you enter.
- Lending records you create: borrower names, optional borrower phone numbers, optional borrower email addresses, dates lent, return dates, quantities, and notes.
- Account data: Firebase user ID and basic sign-in information returned by Google Sign-In, Apple Sign In, or Firebase anonymous authentication.
- Uploaded media: book cover images you choose to upload for syncing across devices.
- Guest migration cache: when a guest library is merged into an existing Google or Apple account, a temporary on-device copy of the guest books, lending records, and managed cover images is kept until the import succeeds or you clear the associated account data.
- Barcode lookup input: barcode or ISBN values sent to Google Books when you request a book lookup, including batch barcode scanning.
- Imported library files: CSV export files (for example from Goodreads) that you explicitly choose to import. The file is read on your device to create book entries; the file itself is not uploaded.
- Subscription status: whether MyBookShelf Pro is active on the device and store account, including the selected monthly or yearly plan when available.
- Advertising-related data for free users: device and app information processed by the Google Mobile Ads SDK to serve ads.
- Operational logs and diagnostics: Firebase user ID, app, platform, version, and device information, timestamps, request or feature outcomes, error details, crash stack traces, and limited transaction identifiers (such as hashed purchase identifiers) used to diagnose failures, prevent abuse, and operate subscription validation.
MyBookShelf does not claim that all data categories are collected for every user. Collection depends on which features you use.
How we use data
- To create, display, edit, and organize your personal library.
- To store and sync your guest or signed-in library and lending records under an account-scoped Firebase identity.
- To upload and retrieve your chosen cover images from cloud storage.
- To look up book details (title, author, cover, category) using Google Books after a scan, batch scan, or manual identifier entry.
- To create book entries from a library export file you choose to import.
- To pre-fill an optional borrower reminder message that you can send yourself through your device's share sheet — the app does not send messages on your behalf.
- To validate and restore an active MyBookShelf Pro subscription on eligible devices and store accounts.
- To show ads to free users and remove ads for users with an active MyBookShelf Pro subscription.
- To support account deletion and other user-requested account actions inside the app.
- To diagnose crashes and service failures, secure the service, prevent abuse, and monitor backend operations.
Ads and purchases
Free users may see banner and occasional interstitial ads. The app uses Google Mobile Ads for ad delivery. Premium features are unlocked through MyBookShelf Pro monthly and yearly auto-renewing subscriptions. Purchase transactions, billing, renewals, cancellations, and restoration are handled by Apple App Store or Google Play.
Subscription status may also be validated through Firebase Functions using store-provided purchase data so the app can confirm current entitlement status more reliably across devices.
Users may cancel their subscription at any time in their store account settings. If canceled, access to Pro features continues until the current billing month or year ends.
Where required by regional law or platform policy, the app presents ad consent choices and provides an in-app privacy choices entry point so users can review or update those selections later.
Users can report inappropriate or age-inappropriate ads through the in-app support flow or by contacting bilalmanisa@gmail.com.
MyBookShelf itself does not store your payment card number or direct billing credentials.
Security practices
MyBookShelf uses Firebase services and authenticated per-user access controls to limit access to synced data. Storage and Firestore rules are designed so users can access only their own cloud records.
No system can guarantee absolute security, but reasonable technical measures are used to protect synced data and account-scoped access.
Retention
Library records, lending records, and uploaded cover images are retained until you delete them, delete your account or guest library through the app, or otherwise remove the associated cloud content.
If you sign in with a permanent account, synced data may remain associated with that account until you delete it. If you use a guest or anonymous account, the guest library remains stored until it is removed through the app’s delete action. Uninstalling the app does not delete the anonymous Firebase account or its cloud data and may make that guest account harder to identify later.
A temporary guest-migration cache remains only while an interrupted account merge is pending. It is removed after a successful import or when the associated source or destination account is deleted. App uninstallation normally removes this on-device cache.
Crash reports and Firebase or Google Cloud operational and security logs are retained according to the configured or standard retention periods of those services. Previously collected diagnostics and logs may remain after account deletion until they age out or are de-identified, and some records may be retained longer when required for security, fraud prevention, or legal compliance.
After account deletion, MyBookShelf retains a minimal server-side deletion marker containing the Firebase UID and deletion time, plus hashed subscription ownership claims when applicable. These records contain no library, lending, cover-image, email, or raw store-token content. They are retained to block still-valid stale login tokens from recreating deleted data and to authorize an explicit restore of a still-paid store subscription into a recreated account.
Account and data deletion
MyBookShelf provides an in-app deletion path in Settings & Privacy.
- Signed-in users can delete the account and synced library data from inside the app.
- Guest users can delete the guest library and associated cloud data from inside the app.
- Deletion is intended to remove synced books, lending records, and uploaded cover images tied to that account.
- Purchase entitlements are store-managed and may remain restorable under the relevant store account even after app data is deleted.
In-app deletion starts when you confirm the request and ordinarily completes promptly. Wait for the app to show a success result; if it reports an error, some data may remain and you should retry or contact support. Verified email deletion requests are processed within 30 days.
Users who no longer have access to the app can also use the hosted deletion-request page at /delete-account.html. An anonymous guest account may not be identifiable from an email address alone, so guest users should use the in-app deletion flow before uninstalling whenever possible.
Account deletion does not remove store-managed purchase records. Previously collected Crashlytics diagnostics and operational or security logs may remain for the retention periods described above.
Children
MyBookShelf is not designed as a children’s data product and is not intended to knowingly collect personal information from children in violation of applicable law. Users should avoid storing personal information about others beyond what is necessary for optional lending tracking.
Changes to this policy
This Privacy Policy may be updated to reflect feature changes, operational changes, legal requirements, or updated platform expectations. The “Last updated” date at the top of this page will change when material revisions are made.
Privacy contact
For privacy questions, account-related support, or deletion-related requests, contact bilalmanisa@gmail.com.
This same contact should also be used in Apple App Store Connect and Google Play Console so users and review teams see a consistent privacy contact path.