Privacy Policy

Last updated: 23 August 2026

Carrel is a bookshelf app. You keep a list of books you have read, are reading, or want to read, and you can publish that shelf as a public page. This policy explains what we collect, why, where it lives, and how to get rid of it.

Carrel is made by Aleksandr Lobov, an individual developer in Serbia. Under the GDPR we are the controller of your data; under the Serbian Personal Data Protection Act we are the rukovalac. For anything on this page, write to lobovlabs@proton.me.

The short version

What we collect

From Google, when you sign in. We ask for the standard sign-in scopes: your email address, your name, and the account identifier Google gives us. Google's response also carries the address of your profile picture and your locale, and those are stored alongside your account because they arrive with it. Carrel does not display or use them. Your Google password never reaches us. Signing in with Google is the only way in: without it we cannot give you an account, because there would be nothing to attach your shelf to.

What you put into the app.

A record of your own edits. Each change you make to your shelf leaves a short technical line: what kind of change it was and when. It exists so that a change sent twice over a bad connection is applied once. It holds no book data and no text you typed.

Crash reports. We use Sentry to find out when the app breaks. Personal data collection is switched off in the SDK: a report contains the device model, the operating system and app version, and a technical description of the failure. It is not tied to your name or your email.

App updates. We can fix a bug in the app by sending the corrected code to your phone, without waiting for a store review. The app asks Expo whether a newer version exists: the question carries the platform, which build is asking, and the version it already has. Expo's servers see your device's IP address, as they would for any website your phone opens. Your books, your name and your email are not part of it. When there is nothing newer, nothing is downloaded.

Technical logs. Our providers keep ordinary server logs (IP address, time, address requested) for security and troubleshooting. Supabase also records the IP address of each sign-in in its authentication log. We run no log storage of our own.

What we never collect: your location, your contacts, your photos or files, an advertising identifier, or any record of how you move around the app screen by screen.

Why we use it

What Why Legal basis (GDPR)
Email, name, account ID So you can sign in and your shelf follows you to a new phone Performance of a contract, Art. 6(1)(b)
Books, settings, handle This is the service itself Performance of a contract
Publishing your shelf To show the page you asked us to show Performance of a contract; you switch it on, and you can switch it off
Record of your edits So a change sent twice is applied once Performance of a contract
Crash reports To keep the app from breaking Legitimate interests, Art. 6(1)(f)
App updates To fix a bug without waiting for a store review Legitimate interests, Art. 6(1)(f)
Logs, complaint records To keep the service safe and to answer complaints about public shelves, which includes writing back to whoever sent one, at the address on their account Legitimate interests; legal obligation where the law requires it

We make no automated decisions about you that have legal or similarly significant effects. The word list described in the Content & Moderation Policy is the only automatic step in Carrel, and all it does is hide a title from public pages.

What becomes public when you publish

Publishing is off by default. You turn it on yourself, and you can turn it off at any moment.

Visible to anyone who opens your page: your display name, your handle, your books marked read or reading (title, author, cover colour, and the month and year you added each one), how many books you keep and how many you have finished, and what you are reading now.

Not shown on your page: your wishlist — unless you switch it on. That switch sits next to the one that publishes, and it starts off.

Never visible to anyone: your email address, anything about your Google account.

Search engines. A published shelf is open to search engines unless you switch that off, and the switch sits next to the one that publishes it. Switching it off asks search engines not to list the page; it does not hide the page from anyone holding the link.

Two more things worth knowing. Unpublishing stops the page from working, but a page that has already been seen may sit in a search engine's or a messaging app's cache for a while, and we cannot clear those. And if you change your handle, links to your old address stop working. We do not redirect them, because a redirect would make the old handle impossible to release; the old one stays reserved for you for 30 days, so a change of mind and a typo both have a way back. A handle you have held for less than a day is the exception: it is released at once, and nothing about it is recorded.

Who else touches your data

We use a small number of services to run Carrel. They process data on our instructions and are not allowed to use it for their own purposes. Google is the exception: when you sign in, Google handles that sign-in for its own purposes as well as ours, under its own privacy policy, and we have no say in what it does with it.

Service What it does Where
Supabase Database and sign-in Database in the European Union; the company is in the United States
Cloudflare Website hosting, and encrypted backups in a bucket restricted to the EU European Union, on Cloudflare's global network
Google Sign-in Google's own infrastructure, under Google's privacy policy
Sentry Crash reports Reports stored in the European Union; the company is in the United States
Expo App updates United States
GitHub Runs the nightly job that makes the backup United States

Open Library is different: it is not our processor. When you search for a book, or when a real cover is displayed, your device talks to openlibrary.org directly. We send them nothing about your account, but their servers see your device's IP address, as they would for any website your phone opens. If you never search, and your shelf shows only drawn covers, your device never contacts them.

The same goes for anyone visiting a public shelf. Looking at the shelf itself contacts no one else, but opening a book that has a real cover loads that cover from Open Library, so their servers see the visitor's IP address. The page does not tell them whose shelf it came from.

We do not sell your data, do not share it with advertisers, and do not give it to data brokers.

Where your data lives

The database sits in the European Union, and so do the backups. Some of the companies above are based in the United States, so some data reaches them there.

The nightly backup is made by a job running on GitHub's servers in the United States. The dump is encrypted there before it is stored, and the encrypted copy is kept in the European Union.

How long we keep it

If Carrel ever charges for anything

Carrel is free today, and we take no payments at all. If paid features arrive, Google Play handles the payment: we never see your card, and Google does not give it to us. What we would receive and store is the fact of the purchase (which plan, the Google Play order and purchase identifiers, and the dates it starts, renews and ends), on the basis of our contract with you.

Two consequences we would rather state now than explain later. Google Play's billing service would become one of the services listed above. And a record of a purchase has to outlive the account it belonged to: accounting law in Serbia requires financial records to be kept for years, so deleting your account would remove your profile and your books but leave the purchase record, stripped down to the order identifier, the amount and the date. This page and the Subscription terms will say exactly which years and which fields before a single payment is taken.

Your rights in the EEA and the UK

You can ask us to:

Write to lobovlabs@proton.me. We answer within one month. There is no charge. If you are unhappy with the answer, you can complain to the data protection authority in the country where you live.

Carrel is a one-person service, and the point of contact for everything on this page is the address above. We answer in English.

If you are in the United States

We do not sell or share personal information, and we have never done so. We do not offer financial incentives for data.

The categories we collect are: identifiers (email address, name, account identifier), internet and network activity (technical logs and crash reports), and the content you create in the app (your books and shelf settings). We collect them for the purposes in the table above and keep them for the periods listed above.

Depending on where you live, you may have the right to know what we hold, to get a copy, to correct it, to delete it, to opt out of sale or sharing (there is nothing to opt out of), and not to be treated differently for exercising any of these. Write to lobovlabs@proton.me.

We do not collect sensitive personal information. If we turn a request down, you can reply and ask us to look at it again.

Children

Carrel is not for children under 16. We do not knowingly collect data from anyone younger. If you believe a child has an account, write to lobovlabs@proton.me and we will remove it.

Security

Everything travels over HTTPS. We store no passwords. Database rules make an unpublished shelf unreadable to other users, and keep the wishlist unreadable to the public on a published shelf until you ask for it to be shown. The developer can open any shelf, published or not, in order to answer a complaint; nobody else can. That rule lives in the database, not in the app, so a broken client cannot get around it. Backups are encrypted as they are made, and are only ever stored encrypted. Access is limited to the developer. No system is perfectly secure, and we do not pretend otherwise.

Changes

If this policy changes, the new version appears here with a new date at the top. If a change matters to you, we will say so in the app before it takes effect.

Contact

Aleksandr Lobov lobovlabs@proton.me