CatShelf does not sell personal data, show ads, or track you across other companies’ apps or websites. Shelf-photo processing is disclosed before the first upload. Optional analytics and optional photo quality review are off by default. You can delete your CatShelf data in the app.
1. Overview and scope
CatShelf is an iPhone app operated by Bryan Lin (“CatShelf,” “we,” “us,” or “our”). It helps readers identify books on a shelf, receive reading recommendations, maintain a personal library, and revisit earlier scans. This policy applies to the CatShelf app, the CatShelf service, and this website.
The public website does not use advertising cookies or product analytics. Basic hosting and security logs may be created by our hosting provider when you visit it.
2. Data we process
Account and identity data
When account access is available and you sign in with Apple or Google, we receive an account identifier and any limited profile information you choose to share through that provider, such as an email address or display name. Before sign-in, CatShelf uses a random installation identifier and a protected device credential to secure the onboarding flow and prevent abuse.
Shelf photos and scan data
If you choose to scan, CatShelf processes the shelf photo you take or select, derived crops, detected book titles and authors, scan results, corrections, scan timing and error information, and the books you choose to locate on the shelf. Successfully completed shelf scans keep a private server copy of the source photo as part of scan history so you can reopen results, use Find on shelf, and troubleshoot that scan.
Reader profile and library data
CatShelf processes the books you save, reading status, ratings, ownership and want-in-print choices, recommendation feedback, search activity, and related profile signals. These signals let CatShelf remember your library and make future shelf results more useful.
Library imports
If you import a Goodreads or StoryGraph export, CatShelf processes the book rows, shelf names, ratings, and reading status needed to build your library. Raw CSV uploads are removed after parsing in ordinary operation. CatShelf ignores review text and private notes. When you use the connected Goodreads flow, your Goodreads password and browser cookies stay inside the isolated browser on your device and are not sent to CatShelf servers.
Optional analytics and optional quality review
If you turn on product analytics, CatShelf may collect interaction events such as onboarding steps, scans, saves, status changes, and feature outcomes. If you separately turn on photo quality review, future shelf photos and related diagnostic artifacts may be reviewed to improve scan quality. Both choices are off by default and can be changed later in the app.
Notifications, purchases, and support
If you allow notifications, we process an Apple Push Notification service token, notification preferences, delivery outcomes, and in-app notification read state. Apple processes App Store purchases and billing. CatShelf reads limited product and entitlement information needed to unlock subscribed features; we do not receive your payment-card number. If you contact support, we process your message, email address, and any information you choose to include.
Security and operational data
We process IP address, request timestamps, device and app version information, authentication and integrity signals, rate-limit records, error details, and service logs as needed to operate and protect CatShelf. We do not need precise location data. A photo may nevertheless contain incidental information visible in the scene, so avoid including people, addresses, payment information, or other sensitive material in a shelf photo.
3. How we use data
We use the data described above to:
- provide shelf recognition, recommendations, Find on shelf, scan history, imports, and library features;
- create and secure accounts, transfer onboarding data into an account, and restore signed-in state;
- verify subscription access and help you restore or manage purchases;
- send the scan, import, and reminder notifications you allow;
- detect abuse, enforce limits, prevent cross-user access, and investigate service failures;
- respond to support requests and complete deletion requests; and
- improve product or scan quality only when the relevant optional setting permits it.
4. Cloud and AI processing
Before CatShelf uploads the first shelf photo, the app explains that the photo will be sent to CatShelf’s cloud service and Google Vertex AI to identify books. CatShelf may send a shelf image or a limited row crop to Vertex AI for recognition and location. Google states that it does not use customer data to train or fine-tune its managed models without the customer’s permission or instruction, though limited provider logging or in-memory caching may apply under Google Cloud’s service terms.
CatShelf may use OpenRouter and its configured model providers to produce text recommendations from limited book and taste context. These recommendation requests do not require your payment details and are designed not to include your account credentials. AI and book-metadata results can be incomplete or wrong; CatShelf lets you correct books and does not treat model output as authoritative.
5. When data is shared
We share data only as needed to provide, secure, or support CatShelf, or when law requires it. Our service providers and platform partners may include:
- Apple for Sign in with Apple, App Store purchases, device services, and push notifications;
- Google for Google Sign-In, Google Cloud infrastructure, and Vertex AI processing;
- Supabase for account authentication and database services;
- Cloudflare R2 for private object storage;
- OpenRouter and configured model providers for text recommendation processing;
- Open Library, Google Books, and Hardcover where configured for public book metadata and cover lookup; and
- Vercel for hosting and delivering this public website, including routine request and security logging.
Public book-metadata services receive the search or book identifiers needed for a lookup; they do not need your CatShelf password or Apple payment information. CatShelf does not sell personal data, use it for third-party advertising, or share it for cross-app tracking.
6. Retention and deletion
- Account, profile, library, and scan history: kept while your CatShelf data remains active, then deleted when you use Delete all my data, subject to limited legal and security exceptions.
- Completed shelf photos: kept privately with the associated scan history so the scan can be reopened and Find on shelf can work; deleted with your CatShelf data.
- Temporary scan uploads: normally removed after a scan finishes or is canceled. Backup lifecycle controls bound orphaned uploads that cannot be linked or cleaned up normally.
- Import files: raw server uploads are removed after parsing in ordinary operation. A protected retry copy may remain on your iPhone until the import safely finishes, then it is removed.
- Optional quality-review artifacts: may remain with the associated scan until they are deleted. Turning the setting off stops future optional review collection but does not by itself delete earlier scan history.
- Operational records and logs: kept only as long as reasonably needed for reliability, security, fraud prevention, dispute handling, and legal obligations, then deleted or de-identified under applicable schedules.
In the app, open Me → Data → Delete all my data. CatShelf deletes server-side reader data and then clears local CatShelf data from that device. Deleting CatShelf data does not cancel an Apple subscription; billing must be managed separately through Apple. If a network or service error interrupts deletion, CatShelf keeps a protected deletion record and attempts to finish safely.
7. Your choices and controls
- Decline shelf-photo processing and use non-scan onboarding paths where available.
- Turn optional analytics and optional photo quality review on or off in Me.
- Control camera, photo, and notification permissions in iOS Settings.
- Change notification categories in CatShelf and visible-alert permission in iOS.
- Delete CatShelf data in the app or contact us for help with a deletion request.
- Manage or cancel Apple billing from iOS Settings → your name → Subscriptions.
8. Security and other details
Security
CatShelf uses encrypted network connections, protected device credentials, account authentication, access controls, private storage, rate limits, and deletion barriers. No system is perfectly secure, but we design the service so identifiers alone are not treated as authorization.
Children
CatShelf is not directed to children under 13, and we do not knowingly collect personal data from a child under 13. If you believe a child has provided personal data, contact us so we can investigate and delete it.
United States service
CatShelf’s initial service is offered in the United States. Data may be processed in the United States and other places where our service providers operate, subject to their contractual and legal safeguards.
Policy changes
We may update this policy as CatShelf changes. We will post the updated date here and provide an additional notice in the app when a material change calls for one. A new use that requires consent will not rely on an old consent choice.
9. Contact
For privacy questions, deletion help, or access and correction requests, email support@catshelfapp.com or visit CatShelf Support.