Privacy Policy
Last updated: September 16, 2026
This policy explains how ITIME MARKETING INC handles information when you use Better Bookshelf. Your saved library is stored on your device. Optional online features—including AI shelf scanning, book lookup, purchases and backups—process information outside your device.
Your library and shelf photos
Book records, reading status, reviews and saved shelf photos are stored locally. You can export your data or back it up to your own Google Drive. A local library is separate from the scan account used to verify purchases and manage scan credits.
AI book identification
When you choose AI scanning, the selected photo is sent through our server, hosted on Railway, to OpenAI for book identification. We remove camera metadata before sending the image and do not attach your name, email, device identifier or Google credentials to the OpenAI request. The photo itself may contain personal information; photograph only content you want processed.
Our service records scan results, request identifiers and credit activity to deliver results, recover interrupted scans and prevent duplicate charges. A scan result can include recognized titles and positions. These records are separate from your complete local library.
OpenAI processes requests under its applicable API data controls. API data is not used for model training by default unless the account opts into sharing. Provider retention, security monitoring and legal obligations may apply; we do not promise that a submitted image is anonymous or never retained. See OpenAI data controls.
Purchases and scan accounts
Apple or Google handles checkout. RevenueCat and our server use purchase records and app-generated customer identifiers to verify Unlimited access, grant included scans, deliver scan packs and reconcile purchases. We do not receive your payment-card details. Scan accounts use device credentials and optional recovery codes; keep recovery codes private. Purchase and credit records are retained to maintain balances, prevent repeated grants and resolve transaction issues.
Optional Google Drive and other integrations
Connecting Google Drive uses Google authorization through our server. Tokens and account information support backup access; they are not sent to OpenAI. Ordinary customers do not need Google sign-in to use purchased scans. Special owner access requires separate verification of the connected owner account.
Book lookup sends ISBNs or title and author searches to metadata services, including Google Books, Open Library and ISBNdb. Cover images may be loaded from their providers. Optional Readwise integration uses your supplied token to retrieve highlights. Each provider handles requests under its own policies.
Analytics, attribution and service operation
We use Aptabase for product-usage events and AppsFlyer for installation and advertising measurement. RevenueCat also supports purchase measurement and Apple AdServices attribution. These services may process app events, purchase information, app or device identifiers and technical information according to their configuration and platform permissions. We do not include book titles or review text in our product-analytics event properties.
Our website uses Google Analytics and Google Ads to measure visits and store-button clicks. Store links use AppsFlyer to associate website referrals with app installs and purchases where attribution is available. We retain campaign tags, advertising click identifiers, the landing-page path and referring website hostname for the browsing session. These links can distinguish search engines, AI assistants and other referrals when a source is supplied. Purchase attribution is connected through app-generated identifiers shared with RevenueCat; a store-button click by itself is not a purchase.
Our hosting and service providers receive network information such as IP addresses when requests are made. We use service records and abuse-prevention controls to protect accounts, manage costs and troubleshoot failures. Protected backups preserve scan-account and credit records.
Your choices and deletion
You can decline camera access, avoid AI scanning, disconnect optional integrations, delete local books and photos, and delete your Google Drive backups. Removing the app does not delete server-side purchase records or copies held by other providers. To request help with server-held information, contact books@betterbookshelf.co. We may need to verify the request and retain records necessary for transaction, security or legal obligations. Never email a recovery code or password.
In version 1.8.0 or later, request scan-account deletion from Backup & Restore → Scan account → Delete scan account. Scanning stops immediately and cleanup completes within 30 days. Unused credits are forfeited; your local library and personal backups remain. Minimal one-way purchase and customer fingerprints remain to prevent duplicate grants. Protected backups rotate within seven days. See Delete Your Data for account-deletion requests, retention details, and local and backup instructions.
Children and policy changes
Better Bookshelf is not directed at children under 13. Contact us if you believe a child has provided personal information. We update this page when our practices change.
Contact
Questions about privacy: books@betterbookshelf.co.