Readendar

Legal

Privacy policy

2026-08-01

This policy applies to readendar.com, the Readendar app for iOS and Android, public sharing pages and support or moderation contacts.

Controller and contact

The controller is Daniel Balastegui Julian, an individual operator established in Barcelona, Spain. Privacy requests may be sent to hello@readendar.com. No data protection officer has been appointed because Readendar’s present processing does not require one.

If a competent authority makes a valid request under applicable law, only the additional data strictly necessary to comply will be provided, after verifying the authority’s competence, the scope of the request and its legal basis.

What we process, why and for how long

PurposeDataLegal basisRecipientsRetention
Create and secure an accountEmail, opaque account ID, authentication method, magic-link and refresh-token records, login security eventsPerformance of the contract; legitimate interest in preventing abuseHetzner infrastructure, Brevo for magic-link email, Google or Apple when that sign-in method is chosenWhile the account is active. Short-lived login credentials expire automatically; security records are retained only as needed to investigate abuse
Provide the reading serviceProfile name, language, timezone, avatar, library, progress, plans, events, quotes, reminders, clubs, memberships, polls, votes, custom fields, community ratings and reviews, and settingsPerformance of the contractHetzner hosting, database and object storageWhile the account is active; deleted from the live service when the account or relevant content is deleted
Display content you choose to shareRevocable share tokens, public club profile, public Social profile when published to Everyone, public poll content and aggregate results, according to the visibility selectedPerformance of the contract and your deliberate publication choiceCloudflare, Hetzner and visitors to the public URLUntil you revoke sharing, make the content private or delete it
Process uploadsAvatars, covers and poll imagesPerformance of the contractHetzner object storageUntil replaced or deleted. Unsaved poll media is staged for no more than 24 hours
Search and import booksSearch terms, ISBNs and book metadata; data you choose to import from a file or an in-app browserPerformance of the contractHetzner-hosted Redis cache, ISBNdb and Open Library; the external Goodreads, StoryGraph, Bookmory, Babelio or Amazon page when you choose its web importRaw search terms are cached without an account ID for up to 30 days and are not added to your profile. Imported books or quotes follow account retention
Send local reminders and provide capture toolsEvent and quote data used for local notifications; images used for OCR; microphone audio used for dictationPerformance of the contractOperating-system services on your deviceNotifications and OCR are on-device. Dictation is unavailable unless the OS confirms genuine on-device recognition; audio and OCR images are not uploaded
Optional product analyticsOpaque account ID, app-instance/device identifiers, screen names and selected feature events; version, time and state of the consent choiceConsent; legal obligation/accountability for the consent evidenceGoogle Firebase Analytics; Hetzner stores the consent recordEvents: no more than 2 months. The latest choice and its evidence remain until account deletion or as long as needed to establish compliance
Diagnose failures and performanceCrash information, stack traces, app/device version, technical context and a 5% sample of request performance traces. No session replay; request bodies, headers, cookies and query strings are not sent, and secret-bearing path segments are redactedLegitimate interest in service reliability and performanceSentryNo more than 90 days
Protect the service and keep access logsIP address, timestamp, HTTP method, route, response status and durationLegitimate interest in security, abuse prevention and availabilityCloudflare and HetznerCloudflare necessarily processes the complete request URL at the edge. Workers Logs are disabled in deployment configuration and Readendar does not configure a Logpush destination. Origin logs redact secret tokens and queries and rotate within 30 days
Prevent deleted accounts being restoredAccount ID and deletion-request timestamp in a private suppression marker outside the databaseLegal obligation and legitimate interest in honouring erasureHetzner object storage35 days, covering the maximum backup lifetime plus a safety margin
If you joined an early-access listEmail, form language, source page and signup timeConsentSlack as the internal work channelUntil access is offered, you withdraw consent or the list is closed, whichever occurs first
Answer feedback and supportMessage, feedback category, account ID and technical context you deliberately sendLegitimate interest in answering and improving the serviceSlack; Sentry when a linked error is investigatedUp to 12 months, unless needed longer for an active request or legal claim
Review reports and illegal-content noticesReported URL/content, reasons, evidence, reporter contact details and moderation outcomeLegal obligation and legitimate interest in maintaining a safe serviceSlack and the providers needed to investigate or comply with a lawful requestUp to 12 months after closure; longer only where required for proceedings or by law

We do not sell personal data, use it for advertising or track you across other companies’ apps. Firebase Analytics is disabled by default. Accepting the Terms or reading this policy does not enable it; enabling it is a separate optional choice that can be withdrawn at any time in Settings.

Required and optional data

Email, authentication data, a display name, preferred language, timezone, acceptance of the Terms and the minimum account/service records are required to complete onboarding and use the account service. Without them, Readendar cannot authenticate you, configure the service or identify your contributions to you and other club members. Uploads, public links, imports, feedback and moderation contact data are required only when you choose those functions. Avatar, reading goals and Firebase Analytics are optional; refusing or withdrawing analytics has no effect on core functionality.

Sources of data

Most data comes directly from you or your device. Club administrators and members may provide your displayed membership role, poll participation or content concerning shared club activity. A reporter may provide a URL, account reference or allegation concerning content. Book metadata comes from ISBNdb and Open Library, and sign-in identity data comes from Google or Apple only when that sign-in method is selected. Where Article 14 GDPR applies, this section identifies those source categories; we will provide additional individual information when required and not disproportionate or legally exempt.

Account deletion and backups

Deleting your account removes the account and associated live database records in one operation. Object-storage deletion jobs are recorded durably and retried until the relevant avatar and cover objects are removed. Encrypted database backups are kept for no more than 30 days and are then automatically pruned. A deleted account is not restored from a backup except where strictly necessary for disaster recovery; any restored deletion state must be reconciled again.

Processors and international transfers

Provider and serviceMain processing location / transfer mechanism
Hetzner — hosting, database, Redis and object storageEuropean Union
Brevo — transactional emailEuropean Union; approved sub-processors may use an adequacy decision or standard contractual clauses
Cloudflare — network delivery and securityGlobal edge network; transfers outside the EEA use the provider DPA, adequacy where applicable, or standard contractual clauses
Google — sign-in and optional Firebase AnalyticsEU/United States and global infrastructure; adequacy where applicable or standard contractual clauses
Apple: Sign in with AppleUnited States and global infrastructure; adequacy where applicable or standard contractual clauses
Sentry — error diagnosticsProvider infrastructure configured for the account; transfers outside the EEA use standard contractual clauses
Slack — restricted support/moderation workflowsEU/United States; adequacy where applicable or standard contractual clauses
ISBNdb and Internet Archive/Open Library — catalogue lookupUnited States; standard contractual clauses or another applicable Article 46 safeguard where personal data is transferred

Providers may use approved sub-processors. You may request information or a copy of the applicable transfer safeguard at hello@readendar.com, subject to redaction of confidential provisions.

The periods in the matrix are Readendar’s maximum controller retention limits. They must be enforced through each provider’s automated controls or scheduled deletion and evidenced in the provider register before production use. Firebase events are limited to two months, Sentry events to 90 days and Slack support/moderation records to 12 months. The controller reviews the applicable DPA, transfer mechanism, sub-processors, configured retention and dated evidence at least quarterly and whenever a provider or data flow changes.

Your choices and rights

You may:

  • change or withdraw optional analytics consent in Settings;
  • download a copy of your account data from the app;
  • correct profile data or revoke public sharing;
  • delete individual content or your entire account;
  • request access, rectification, erasure, restriction or portability, and object to processing based on legitimate interests.

Contact hello@readendar.com. We may need to verify that the request concerns your account. Withdrawing consent does not affect processing already carried out lawfully. You may complain to your local supervisory authority; in Spain, this is the Spanish Data Protection Agency.

Children

Readendar is not intended for children under 16 and does not knowingly allow them to create accounts. See the Age and minors policy.

Changes

We will give reasonable advance notice of material changes. A new purpose that requires consent will not be activated without a new choice.

Social

If you activate Social, Readendar processes your unique handle, bio, discovery and approval settings, privacy tiers and per-book overrides, follow requests and accepted connections, blocks and mutes, activity components, reactions, inbox entries, reports and push installations to provide the feature. Everyone means publication on the public Internet. Searchable profiles may be included in our sitemap and indexed by external search engines; non-searchable profiles remain available by direct handle link with noindex instructions. Search-engine caches can persist after content is restricted or removed, and blocking cannot prevent anonymous viewing of content published to Everyone.

Social activity is retained for up to 12 months and Social inbox entries for up to 90 days. Profile-view statistics count each signed-in viewer at most once per profile and UTC day using a keyed, non-reversible HMAC token; tokens are deleted after 35 days and viewer identities are never shown. Firebase Cloud Messaging processes encrypted-at-rest installation tokens to deliver optional Social notifications. Raw push tokens are not logged or exported. Reports retain the reporter, reason, optional note, target snapshot, decision and audit timestamps as moderation evidence under the existing legal-retention policy.

A Social reset requires recent authentication and typed-handle confirmation. It removes the Social profile, graph, privacy and book overrides, activity, reactions, inbox, push installations and profile-view totals, while preserving personal ratings, reviews and private notes and any moderation evidence that lawfully must be retained. Full account deletion removes all live Social data immediately except that same minimal moderation evidence. Public-library links are a separate link-only channel and can bypass Social relationship tiers.