Privacy Policy
Last updated: 23 August 2026
Carrel is a bookshelf app. You keep a list of books you have read, are reading, or want to read, and you can publish that shelf as a public page. This policy explains what we collect, why, where it lives, and how to get rid of it.
Carrel is made by Aleksandr Lobov, an individual developer in Serbia. Under the GDPR we are the controller of your data; under the Serbian Personal Data Protection Act we are the rukovalac. For anything on this page, write to lobovlabs@proton.me.
The short version
- We do not sell your data, and we do not share it for advertising.
- No ads, no advertising ID, no behavioural analytics, no tracking across other apps or sites.
- We never see your password. Sign-in goes through Google.
- Your shelf is private until you publish it, and publishing leaves your wishlist out unless you choose to include it.
- You can delete your account, and everything in it, at any time.
What we collect
From Google, when you sign in. We ask for the standard sign-in scopes: your email address, your name, and the account identifier Google gives us. Google's response also carries the address of your profile picture and your locale, and those are stored alongside your account because they arrive with it. Carrel does not display or use them. Your Google password never reaches us. Signing in with Google is the only way in: without it we cannot give you an account, because there would be nothing to attach your shelf to.
What you put into the app.
- Your display name and your handle, the part of your public address,
trycarrel.app/{handle}. - Your books: title, author, status (read, reading, wishlist), the date you added the book, the date you finished it, the cover colour, and, if you found the book in the Open Library catalogue, a reference to its cover image there.
- Your shelf display settings, and whether your shelf is published.
A record of your own edits. Each change you make to your shelf leaves a short technical line: what kind of change it was and when. It exists so that a change sent twice over a bad connection is applied once. It holds no book data and no text you typed.
Crash reports. We use Sentry to find out when the app breaks. Personal data collection is switched off in the SDK: a report contains the device model, the operating system and app version, and a technical description of the failure. It is not tied to your name or your email.
App updates. We can fix a bug in the app by sending the corrected code to your phone, without waiting for a store review. The app asks Expo whether a newer version exists: the question carries the platform, which build is asking, and the version it already has. Expo's servers see your device's IP address, as they would for any website your phone opens. Your books, your name and your email are not part of it. When there is nothing newer, nothing is downloaded.
Technical logs. Our providers keep ordinary server logs (IP address, time, address requested) for security and troubleshooting. Supabase also records the IP address of each sign-in in its authentication log. We run no log storage of our own.
What we never collect: your location, your contacts, your photos or files, an advertising identifier, or any record of how you move around the app screen by screen.
Why we use it
| What | Why | Legal basis (GDPR) |
|---|---|---|
| Email, name, account ID | So you can sign in and your shelf follows you to a new phone | Performance of a contract, Art. 6(1)(b) |
| Books, settings, handle | This is the service itself | Performance of a contract |
| Publishing your shelf | To show the page you asked us to show | Performance of a contract; you switch it on, and you can switch it off |
| Record of your edits | So a change sent twice is applied once | Performance of a contract |
| Crash reports | To keep the app from breaking | Legitimate interests, Art. 6(1)(f) |
| App updates | To fix a bug without waiting for a store review | Legitimate interests, Art. 6(1)(f) |
| Logs, complaint records | To keep the service safe and to answer complaints about public shelves, which includes writing back to whoever sent one, at the address on their account | Legitimate interests; legal obligation where the law requires it |
We make no automated decisions about you that have legal or similarly significant effects. The word list described in the Content & Moderation Policy is the only automatic step in Carrel, and all it does is hide a title from public pages.
What becomes public when you publish
Publishing is off by default. You turn it on yourself, and you can turn it off at any moment.
Visible to anyone who opens your page: your display name, your handle, your books marked read or reading (title, author, cover colour, and the month and year you added each one), how many books you keep and how many you have finished, and what you are reading now.
Not shown on your page: your wishlist — unless you switch it on. That switch sits next to the one that publishes, and it starts off.
Never visible to anyone: your email address, anything about your Google account.
Search engines. A published shelf is open to search engines unless you switch that off, and the switch sits next to the one that publishes it. Switching it off asks search engines not to list the page; it does not hide the page from anyone holding the link.
Two more things worth knowing. Unpublishing stops the page from working, but a page that has already been seen may sit in a search engine's or a messaging app's cache for a while, and we cannot clear those. And if you change your handle, links to your old address stop working. We do not redirect them, because a redirect would make the old handle impossible to release; the old one stays reserved for you for 30 days, so a change of mind and a typo both have a way back. A handle you have held for less than a day is the exception: it is released at once, and nothing about it is recorded.
Who else touches your data
We use a small number of services to run Carrel. They process data on our instructions and are not allowed to use it for their own purposes. Google is the exception: when you sign in, Google handles that sign-in for its own purposes as well as ours, under its own privacy policy, and we have no say in what it does with it.
| Service | What it does | Where |
|---|---|---|
| Supabase | Database and sign-in | Database in the European Union; the company is in the United States |
| Cloudflare | Website hosting, and encrypted backups in a bucket restricted to the EU | European Union, on Cloudflare's global network |
| Sign-in | Google's own infrastructure, under Google's privacy policy | |
| Sentry | Crash reports | Reports stored in the European Union; the company is in the United States |
| Expo | App updates | United States |
| GitHub | Runs the nightly job that makes the backup | United States |
Open Library is different: it is not our processor. When you search for a book, or when a real cover is displayed, your device talks to openlibrary.org directly. We send them nothing about your account, but their servers see your device's IP address, as they would for any website your phone opens. If you never search, and your shelf shows only drawn covers, your device never contacts them.
The same goes for anyone visiting a public shelf. Looking at the shelf itself contacts no one else, but opening a book that has a real cover loads that cover from Open Library, so their servers see the visitor's IP address. The page does not tell them whose shelf it came from.
We do not sell your data, do not share it with advertisers, and do not give it to data brokers.
Where your data lives
The database sits in the European Union, and so do the backups. Some of the companies above are based in the United States, so some data reaches them there.
- Cloudflare, Google, GitHub, Sentry and Expo are certified under the EU–US Data Privacy Framework, and transfers to them rely on that certification.
- Supabase is not certified under the Framework. Transfers to Supabase rely on the European Commission's standard contractual clauses, which are part of the data processing agreement we have with them.
The nightly backup is made by a job running on GitHub's servers in the United States. The dump is encrypted there before it is stored, and the encrypted copy is kept in the European Union.
How long we keep it
- Your account and your books: for as long as your account exists.
- After you delete your account: removed from the live database straight away. The public page stops working immediately.
- Backups: deleted data stays in daily backups for up to 14 days and in monthly backups for up to 12 months. Backups are encrypted and used only to restore the whole service after a failure, never to bring one account back.
- A record that an account was deleted: the account identifier and the date, for one year. No name, no email. It exists so that if we ever have to restore the whole database from a backup, accounts that were deleted are deleted again rather than quietly restored.
- A handle you released: the handle, the date, and which account released it, for 30 days, so nobody else can take an address you have just left and so you can take it back. The record is deleted after that. A handle you held for less than a day is not recorded at all.
- The handle of an account you deleted in the app: the handle and the date only, not linked to you or to anything else, for 30 days, so nobody can take over links you shared. A handle held for less than a day is not kept. If we delete your account at your request by email, or for breaking the rules, the handle is released at once.
- Crash reports: 90 days.
- Records of a complaint about a public shelf: 12 months.
- A record of a moderation action: if we ever hide something on your public page, or reserve a handle for you, we keep what was done, when and why for 12 months. It can include the title of the book concerned.
- Server logs: Supabase keeps database and authentication logs for one day. Cloudflare keeps request logs for its own security purposes, under its own retention. Expo keeps a record of update requests, under its own retention.
If Carrel ever charges for anything
Carrel is free today, and we take no payments at all. If paid features arrive, Google Play handles the payment: we never see your card, and Google does not give it to us. What we would receive and store is the fact of the purchase (which plan, the Google Play order and purchase identifiers, and the dates it starts, renews and ends), on the basis of our contract with you.
Two consequences we would rather state now than explain later. Google Play's billing service would become one of the services listed above. And a record of a purchase has to outlive the account it belonged to: accounting law in Serbia requires financial records to be kept for years, so deleting your account would remove your profile and your books but leave the purchase record, stripped down to the order identifier, the amount and the date. This page and the Subscription terms will say exactly which years and which fields before a single payment is taken.
Your rights in the EEA and the UK
You can ask us to:
- give you a copy of your data, in a machine-readable file;
- correct anything that is wrong;
- delete your account and its contents;
- restrict what we do with your data, or object to processing we base on legitimate interests;
- withdraw consent, where we ever rely on it.
Write to lobovlabs@proton.me. We answer within one month. There is no charge. If you are unhappy with the answer, you can complain to the data protection authority in the country where you live.
Carrel is a one-person service, and the point of contact for everything on this page is the address above. We answer in English.
If you are in the United States
We do not sell or share personal information, and we have never done so. We do not offer financial incentives for data.
The categories we collect are: identifiers (email address, name, account identifier), internet and network activity (technical logs and crash reports), and the content you create in the app (your books and shelf settings). We collect them for the purposes in the table above and keep them for the periods listed above.
Depending on where you live, you may have the right to know what we hold, to get a copy, to correct it, to delete it, to opt out of sale or sharing (there is nothing to opt out of), and not to be treated differently for exercising any of these. Write to lobovlabs@proton.me.
We do not collect sensitive personal information. If we turn a request down, you can reply and ask us to look at it again.
Children
Carrel is not for children under 16. We do not knowingly collect data from anyone younger. If you believe a child has an account, write to lobovlabs@proton.me and we will remove it.
Security
Everything travels over HTTPS. We store no passwords. Database rules make an unpublished shelf unreadable to other users, and keep the wishlist unreadable to the public on a published shelf until you ask for it to be shown. The developer can open any shelf, published or not, in order to answer a complaint; nobody else can. That rule lives in the database, not in the app, so a broken client cannot get around it. Backups are encrypted as they are made, and are only ever stored encrypted. Access is limited to the developer. No system is perfectly secure, and we do not pretend otherwise.
Changes
If this policy changes, the new version appears here with a new date at the top. If a change matters to you, we will say so in the app before it takes effect.
Contact
Aleksandr Lobov lobovlabs@proton.me