← Athenaeum

Privacy Policy

Effective date: 2026-05-10  ·  Developer: Embersquire  ·  Contact: hello@embersquire.com

1. Overview

Athenaeum is a personal book library app that lets you scan ISBNs, catalog your books, and track your reading. This policy explains what data we collect, why we collect it, who we share it with, and what rights you have over it.

We do not collect your name, email address, phone number, location, or any other personally identifiable information. We do not create user accounts. We do not sell your data.

2. Data We Collect

2.1 Device Token

When you first open Athenaeum, the app generates a random 32-character identifier (a “device token”) and stores it on your device. This token is:

Your device token is stored locally on your device and sent to our backend server only when you submit a rating, a metadata correction, or a survey response.

2.2 Book Ratings

If you assign a star rating to a book, Athenaeum sends the following to our backend:

This data is stored in our database and used to compute community average ratings. It is not linked to your identity.

2.3 Book Metadata Corrections

If you edit a book’s title, author, publisher, page count, description, language, or genres, Athenaeum may submit those corrected values to our backend to improve the shared book database. If you scan a barcode that is not found in any public database, you may also submit a complete book record (title, author, and other fields) for community review. All submissions include:

This data is stored in our database and used to improve metadata accuracy for all users. It is not linked to your identity.

2.4 Cover Image Uploads

If you choose to share a cover photo with the community, Athenaeum uploads the image to our backend. Before storage, the image is passed through Google Cloud Vision API’s SafeSearch feature to screen for inappropriate content. Images that pass moderation are stored in Cloudflare R2 and served publicly at a URL tied to the book’s ISBN — they are not linked to your device token or identity. You initiate this action explicitly; no cover images are uploaded without your consent.

2.5 Crash and Diagnostic Data (Optional)

If you enable “Share crash data” in Settings → Diagnostics, the app will send anonymous crash reports to Sentry (sentry.io) when an unhandled error occurs. Each report includes:

Crash reports do not include your name, email, book library contents, or any personally identifiable information. IP addresses are scrubbed by Sentry before storage. This setting is off by default and can be changed at any time in Settings.

2.6 Anonymous Usage Statistics (Optional)

If you enable “Share anonymous stats” in Settings → Community, the app periodically sends an anonymous snapshot of your reading activity to our backend. This snapshot includes:

This data is stored in aggregate and used to compute community reading statistics (such as percentile comparisons shown in the Stats screen). It is linked only to your device token and contains no personally identifiable information. This setting is off by default.

2.7 Survey Responses (Optional)

Athenaeum may occasionally display an in-app survey asking a single question about how you use the app. If you choose to respond, the following is sent to our backend:

No free-text responses are collected. Survey participation is entirely voluntary — you can dismiss any survey without responding. Responses are stored anonymously and used only to inform product decisions.

2.8 Google Drive Backup (Optional)

If you enable Google Drive backup, Athenaeum uses your Google account to write a backup file to your personal Google Drive storage. This backup:

We do not receive, store, or have access to your Google credentials or Drive contents. This feature requires you to sign in with Google; that authentication is handled entirely by Google. Refer to Google’s Privacy Policy for details on how Google handles sign-in data.

2.9 Camera

Athenaeum uses your device camera to scan ISBN barcodes. Camera images are processed entirely on your device. No images or video are stored, transmitted, or shared with any third party. Only the ISBN number extracted from the barcode is used by the app.

2.10 Your Book Library and Settings

Your book library, reading progress, collection names, and app settings are stored entirely on your device in a local database. This data is never transmitted to our servers and is not accessible to us.

3. Data We Do Not Collect

4. Third-Party Services

Athenaeum queries external book databases to retrieve cover images, descriptions, author names, and other metadata. When you scan or look up a book, the book’s ISBN is sent to some or all of the following services. No personal information is included in these requests.

ServicePurposePrivacy
Google BooksBook metadata lookuppolicies.google.com/privacy
Open LibraryBook metadata lookuparchive.org/about/terms
Library of CongressBook metadata lookuploc.gov/legal
British National BibliographyBook metadata lookupbl.uk/legal-information
Library Hub Discover (Jisc)Book metadata lookupjisc.ac.uk/website/privacy-notice
WikidataSeries and genre datafoundation.wikimedia.org
ISBNdb (via our backend)Book metadata lookupisbndb.com/privacy-policy
Sentry (sentry.io)Crash reporting (opt-in only)sentry.io/privacy
Google Cloud Vision APICover image moderation (SafeSearch)policies.google.com/privacy
Google Drive / Google Sign-InOptional library backup to your own Drivepolicies.google.com/privacy

4.1 Our Backend Infrastructure

Our backend service is hosted on Cloudflare Workers. Ratings, corrections, and other community data are stored in a database hosted on Supabase. Cover images are stored in Cloudflare R2. These services act as data processors on our behalf and are contractually bound to handle your data only as directed by us.

Data stored in Supabase is hosted on servers located in the United States (West region). If you are located in the European Economic Area, this represents a transfer of data outside the EEA. This transfer is governed by Standard Contractual Clauses approved by the European Commission, incorporated into Supabase’s Data Processing Addendum. Given that the data transferred consists solely of pseudonymous identifiers and publicly available bibliographic information, the privacy risk of this transfer is minimal.

4.2 In-App Purchases

In-app purchases (such as world theme unlocks) are processed entirely by Google Play or the Apple App Store. We do not receive or store your payment information.

4.3 Affiliate Links

Athenaeum may display links to purchase books through third-party retailers. These are affiliate links — if you make a purchase after tapping a link, we may earn a small commission at no additional cost to you.

Current affiliate partners:

Tapping an affiliate link opens the retailer’s website in your browser. Any data you provide to the retailer is governed by the retailer’s own privacy policy, not this one.

5. How We Use Your Data

DataPurposeLegal Basis (GDPR)
Device tokenDeduplicate ratings, corrections, and survey responsesLegitimate interest
Book ratingsCompute community average ratingsLegitimate interest
Metadata corrections and full-record submissionsImprove shared book database accuracyLegitimate interest
ISBN (in lookup requests)Retrieve book metadataLegitimate interest
Cover image uploadsProvide community cover photos linked to ISBNsConsent (user-initiated)
Crash reports (opt-in)Identify and fix software defectsConsent
Anonymous usage statistics (opt-in)Compute aggregate community reading benchmarksConsent
Survey responses (opt-in)Inform product decisionsConsent

We do not use your data for advertising, profiling, or any automated decision-making that affects you.

6. Data Retention

DataRetention Period
Device token (local)Until you uninstall the app or clear app data
Device token (server)Until you request deletion
Book ratingsIndefinitely, to maintain community rating accuracy
Metadata corrections and full-record submissionsIndefinitely, to maintain database quality
Cover image uploadsIndefinitely (publicly served); deleted on request
Crash reports90 days (Sentry default retention on free tier)
Anonymous usage statisticsIndefinitely in aggregate; individual snapshots not retained
Survey responsesIndefinitely in aggregate; not linked to identifiable individuals
Camera imagesNot retained — deleted immediately after barcode extraction
Book library and settingsUntil you uninstall the app or clear app data
Google Drive backupUntil you delete it from your own Google Drive

7. Your Rights

7.1 All Users

You may request:

To make a request, email hello@embersquire.com with the subject line “Privacy Request.” Because your data is linked only to a pseudonymous device token, we may ask you to provide your token so we can locate your records. You can find your device token in Settings → About within the app. We will respond within 30 days.

7.2 European Economic Area — GDPR

If you are located in the EEA, you have the following additional rights under the General Data Protection Regulation:

Our legal basis for processing pseudonymous device tokens, ratings, and corrections is legitimate interest (Article 6(1)(f) GDPR): improving the accuracy and quality of the shared book database benefits all users and involves minimal privacy risk given the pseudonymous nature of the data. Opt-in features (crash reporting, usage statistics, surveys) are processed on the basis of consent (Article 6(1)(a) GDPR).

7.3 California — CCPA

If you are a California resident, you have the following rights under the California Consumer Privacy Act:

We do not sell or share your personal information as defined under the CCPA. Categories of personal information collected: device identifiers (pseudonymous device token); user-submitted content (ratings, metadata corrections, cover image uploads, survey responses); diagnostic data (crash reports, if opted in); usage statistics (if opted in).

To exercise your California rights, email hello@embersquire.com with the subject line “California Privacy Request.”

8. Children’s Privacy

Athenaeum is not directed at children under the age of 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has submitted data through the app, please contact us at hello@embersquire.com and we will delete it promptly.

9. Data Security

We implement reasonable technical measures to protect data in transit and at rest:

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we take reasonable steps to protect your data.

10. Changes to This Policy

We may update this policy from time to time. When we do, we will update the effective date at the top of this page. If the changes are significant, we will notify you within the app. Continued use of Athenaeum after changes are posted constitutes your acceptance of the updated policy.

11. Contact

Embersquire
Email: hello@embersquire.com
For privacy-specific requests, use the subject line “Privacy Request” so we can route your message correctly.