Privacy Policy

Last updated: August 16, 2026

What We Collect

Our Book Nook collects the minimum data needed to provide the book club experience:

  • Account information (email, name) for authentication
  • Reading progress, captures, and passages you share with your club
  • Book ratings and reviews you choose to save
  • Voice notes you record — the audio itself, and the transcript made from it
  • Photographs you take of a page, and of the night, when you add them
  • Optional: Readwise API token for highlight sync
  • Optional: Kindle highlights and notes you choose to bring in from one book through the Safari extension included with the iPhone app
  • Optional: Push notification device token for meeting reminders
  • Usage of the app itself — which screens are opened and which features are used — when product analytics is switched on for the build you are using. See below.

Kindle import opens Amazon's Kindle Notebook in Safari. You sign in to Amazon there, not with us: the extension does not collect your Amazon password or copy your Amazon cookies. It uses the visible book titles and authors only to let you choose an edition, then reads annotations only for the one book you confirm. The preview stays on your phone, and its highlights and notes come to us only after you confirm it. They arrive private. Disconnecting Kindle keeps material you already imported; removing imported Kindle data deletes it while keeping any separate OBN notes you wrote from it.

How We Use Your Data

  • Your captures and passages are shared only with members of your book club
  • AI features process what you and your club wrote — to build discussion guides and questions, to recap a meeting for whoever missed it, to recommend a next book, to read the text off a photograph of a page, to sort a spoken note into the right kind of note, and to define a word
  • Usage data tells us which parts of the app are worth keeping
  • We never sell your data or share it with advertisers
  • Reading data is never shared outside your club without your explicit action

AI & Third-Party Services

Our Book Nook uses AI (via Anthropic's Claude) in six places: discussion guides and questions built from your club's notes, a recap of a meeting for the members who missed it, a recommendation for what to read next, reading the words off a photograph of a page you have snapped, sorting a spoken note into the right kind of note, and defining a word you asked about. Whichever of those you use, the material it needs — your notes, the meeting's notes, the photograph — is sent to Anthropic for that one request. It is not stored by them and not used for training.

Voice notes are transcribed by OpenAI. When you record one, the audio file is uploaded to us, stored with your club's library, and sent to OpenAI's Whisper service, which sends back the words. That is the only thing OpenAI receives — the audio, and only to turn it into text. It is not stored by OpenAI or used for training. On iPhones running iOS 26, the app also makes a rough first transcript on the device itself so you can see your sentence right away; those words never leave the phone and are replaced by the real transcript when it arrives. The app asks before your first recording, and you can decline and still use everything else.

Authentication is provided by Supabase, and by Apple or Google if you choose to sign in that way. Uploaded audio and photographs are stored on DigitalOcean Spaces.

One thing worth knowing about that choice: if you sign in with Google, Google's own sign-in component collects rather more than we ask for — it declares your name, email, phone number, an approximate location, and a device identifier, some of it for Google's analytics — under Google's privacy policy rather than this one. Signing in with Apple, or with an email and a password, avoids it entirely. We receive only your name, email, and the account identifier.

Book data comes from Open Library, which is the catalogue we work from and the source of the cover images your device loads. When you search for a book, the words you typed go to Open Library. If Open Library is down, and only then, the same search may be repeated against Google Books — so a search you typed can reach Google. Nothing else about you is sent with it: not your name, not your email, not what you are reading.

Analytics & Diagnostics

Our Book Nook uses PostHog for product analytics — which screens are opened, which features are used, and a sampled replay of what happened on screen, with every text field masked so what you type is never captured. It is tied to your account, and it is used for one thing: knowing which parts of the app are worth keeping. PostHog is not an advertising network, we do not sell what it collects, and nothing here is used to follow you into other apps or websites. There is no advertising identifier anywhere in the app.

Imported passages and Kindle notes are excluded from session replay and analytics. We record only content-free facts such as whether an import completed or stopped.

Analytics is configured per deployment rather than compiled in: where it is not configured — which is the case for ourbooknook.com as this is written — the analytics code never starts and nothing at all is sent.

Sentry receives crash reports and a small, fixed vocabulary of technical failures from the website and the shipping iPhone app so we can repair something that broke. The iPhone configuration does not send your account identity, notes, book titles, highlights, screenshots, view hierarchy, network requests or bodies, interaction history, performance traces, logs, or screen recordings. A recent failure may leave a diagnostic code in Settings; choosing to email it lets support find that event.

Who Can Be Here

You must be at least 13 years old to have an account, and older if the law where you live sets a higher age for agreeing to something like this on your own. Our Book Nook is not directed at children, and we do not knowingly collect anything from anyone under 13. If you believe a child has made an account, write to [email protected] and we will remove it and everything attached to it.

Data Storage & Security

Your data lives in a managed Postgres database whose disks the provider encrypts at rest, and every connection to it requires TLS. That is the whole of the encryption story, and it is worth being exact about what it does and does not mean: your notes, your recordings and your integration tokens are stored as ordinary values in that database. We do not encrypt them a second time with a key of our own, so anyone with access to the database can read them — which is us, and nobody else. If you would rather a token were not there at all, disconnect the integration from Settings and it is deleted.

Your Rights

You can delete your account at any time from Settings. That removes your captures, your recordings, your uploaded photos and your sign-in itself. Work the club made together — the books, the meetings, the volumes — remains for the other members, with your name removed from it. You can also disconnect integrations and remove individual captures, and club owners can delete a club and everything in it.

Contact

Questions about privacy? Contact us at [email protected]. The rules everyone here agreed to are in the Terms of Use. For anything else — including reporting something a member wrote — see Support.