Privacy
What this site knows about you
Short version: your library, and almost nothing else. There is no advertising here, no analytics, no third-party scripts, and no email address on file — because the service was never asked to be anything other than a place to keep your reading.
Last updated 8 September 2026.
Who is responsible
BetweenBooks is run by Louis Røislie, who is the data controller for the purposes of the UK GDPR and the EU GDPR. Anything in this policy — a question, a request, a complaint — reaches a person at privacy@betweenbooks.net.
It is a small service run by one person. That is worth saying plainly, because it shapes everything below: there is no data team, no vendor list, and nothing being done with your reading that you would need a policy this long to discover.
What is stored
All of it is data you typed, chose or asked for. Nothing here is observed, inferred or bought.
| What | Specifically | Why |
|---|---|---|
| Your account | A username, a password (stored only as a scrypt hash, never as the password), which plan you are on and when it runs to, and the date you signed up. | To let you in, and to know which shelves are yours. |
| Your library | Every book you add and everything you record about it: title, author, ISBN, page count, year, which shelf it is on, your tags, reading status, progress, star rating and the four aspect ratings, the dates you started and finished, and the free text of your review, your thoughts and your notes. | It is the service. Without it there is nothing to show you. |
| How you like it to look | Display name, accent colour, shelf defaults, and — if you set them — a profile picture, a background image and any custom CSS you have written. Images are held as data URLs on your own account row, downscaled by your browser before they are sent. | So the app looks the way you left it, on any machine you sign in from. |
| Discovery and friends | The genres you have marked as interests or muted, suggestions you have dismissed, books you have excluded from recommendations, whether Friends is switched on, which shelves you have chosen to share, and any connections or blocks. | To make recommendations from your own shelves, and to run Friends if you turn it on. |
| Your session | A hash of your session token, the time it was created and the time it expires. Not the token itself, not your IP address, and not your browser's user agent. | To keep you signed in for fourteen days without asking again. |
What is never collected
This is the shortest section it can honestly be, and the list is exhaustive rather than reassuring:
- No email address. You are never asked for one, at sign-up or after. The trade is that a forgotten password cannot be emailed back to you — the price of not holding an address is that there is no address to send it to.
- No analytics. No Google Analytics, no Plausible, no Fathom, no page-view counter of any kind. Nobody, including the person running this, can see which pages you visited or how long you stayed.
- No advertising and no profiling. Your reading is not sold, rented, shared with data brokers, used to target anything at you, or used to train any machine learning model — not ours, because there isn't one, and not anyone else's.
- No third-party scripts. No trackers, no pixels, no embedded widgets, no tag manager. Every line of JavaScript on this site is served from this domain, and as of September 2026 the typefaces are too — they used to be fetched from Google's servers, which quietly handed Google your IP address before the page had painted. They are hosted here now, and that request no longer leaves this domain.
- No payment details. Every account starts with fourteen days of Pro and no card is asked for, so there is no card to store. If paid subscriptions open later, this policy will say who processes them before anyone is charged.
Why it is allowed to be stored
Under the UK and EU GDPR, holding data needs a lawful basis. There are three here:
- Performing our contract with you (Art. 6(1)(b)) — your account, your library, your settings, and the session that keeps you signed in. This is the service you asked for; it cannot run without them.
- Legitimate interests (Art. 6(1)(f)) — keeping the service standing up. Sign-in and sign-up attempts are rate limited, which needs a short-lived count against a username and an IP address. The interest is preventing password guessing and automated abuse; the impact on you is close to nil, and there is no way to run a sign-in form safely without it.
- Your consent (Art. 6(1)(a)) — Friends, and only Friends. It is off until you switch it on, and switching it off withdraws that consent without touching anything else.
Who else can see it
Two companies are involved in running this site. Neither is sent your library.
- Cloudflare hosts everything — the site, the code and the database — and processes data on our instructions as a processor. In the ordinary course of serving and protecting a website, Cloudflare handles connection data including your IP address, and keeps request logs. Their own account of that is in the Cloudflare privacy policy. Data is held in Cloudflare's D1 database.
- Open Library, run by the Internet Archive, supplies book metadata
and cover images. When you search for a book to add, the search text is sent from our
server to theirs — your IP address is not, because the request is made by the server
and not by your browser. Cover images are different: those are fetched by your browser
directly from
covers.openlibrary.org, which means Open Library can see the IP address of anyone looking at a shelf with covers on it. Their terms are in the Internet Archive privacy policy.
Nobody else. No advertising networks, no analytics providers, no CRM, no mailing list — there is no mailing list, because there are no email addresses.
One small thing Cloudflare's connection data is used for, on the pricing page only:
the country it resolves at the edge picks which currency to quote you in, and which rate
of VAT to name inside that price. No lookup is performed, no third party is asked, the
country is not written down anywhere, and the selector beside the prices overrides the
currency. That choice is remembered in your browser
under betweenbooks-currency and, like the theme, never sent to us.
Both companies are American, so serving this site involves an international transfer of the limited connection data described above. Cloudflare relies on the standard contractual clauses for that transfer.
What other readers can see
Nothing, unless you turn Friends on. It is off by default, and while it is off no other reader can look you up, connect to you, or see that your account exists.
When it is on, you choose it shelf by shelf, and what a friend sees is a deliberately short list: the book, its author, its cover, its status, and the standard genre tags. In particular:
- Your review, thoughts and notes are never shared, with anyone, under any setting. There is no toggle that turns them on, because they are the private half of the app.
- Your own tags stay yours. Only tags from the standard genre vocabulary cross over — the private ones you invented for your own organisation do not.
- Ratings, reading dates and page progress are each their own switch, off unless you turn it on.
- A shelf you have not ticked is not shared, and your wishlist is separate again.
- You can block another reader, which removes the connection and hides you from them.
How long it is kept
- Your session: fourteen days, extended while you keep using it, and deleted when you sign out. Expired sessions are swept away automatically.
- Everything else: until you delete it. A book you remove is removed; a tag nobody uses is dropped the moment its last book lets it go.
- Your account: until you delete it, and there is no automatic clear-out of quiet accounts — a shelf you have not opened in two years is still your shelf.
- After deletion: the account and everything hanging off it — books, shelves, tags, ratings, notes, settings, sessions, friendships — are deleted from the database at once. Not hidden, not deactivated, not held for thirty days in case you change your mind. Backups taken before the deletion age out on their own within a month.
Your rights, and the quickest way to use them
You have the right to see your data, correct it, delete it, take it elsewhere, restrict what is done with it, and object to processing based on legitimate interests. Two of those are buttons rather than requests, because a right you have to ask for politely is not much of a right:
- See it and take it: Settings → Your data → Download. JSON gives you the complete record; CSV gives you the books as a spreadsheet. Both are available on the free plan, immediately, as many times as you like.
- Delete it: Settings → Your data → Delete account. It asks for your password and then does exactly what it says.
- Correct it: everything you typed is editable in the app, whenever you like.
- Anything else — restriction, objection, or a question about any of the above — goes to privacy@betweenbooks.net, and will be answered within 30 days.
If you think this site is handling your data badly, please tell us first — but you are also entitled to complain to a regulator without asking us at all. In the UK that is the Information Commissioner's Office; in the EU it is the supervisory authority of the country you live or work in, listed by the European Data Protection Board.
Cookies
One cookie. It is called bt_session, it holds a random sign-in token, and
it is set only when you sign in. It is HttpOnly (JavaScript cannot read it),
SameSite=Lax (it is not sent from other people's sites), marked
Secure over HTTPS, and it lasts fourteen days. Signing out deletes it.
That cookie is strictly necessary to deliver a service you explicitly asked for, which is exactly the case the ePrivacy rules exempt from consent — which is why this site has no cookie banner. There is nothing to consent to. If there were ever a non-essential cookie here, there would be a banner, and this paragraph would say so.
Your browser also remembers two preferences in local storage: your light or dark
choice under booktracker-theme, and a currency you picked on the pricing
page under betweenbooks-currency. Neither leaves your device, and neither
is ever sent to the server.
Children
BetweenBooks is not intended for children under 16, and accounts should not be created by them. If you believe a child has an account here, write to privacy@betweenbooks.net and it will be removed.
Security, briefly
Passwords are hashed with scrypt and are not recoverable by anyone, including us. Every query is scoped to the signed-in account, and asking for someone else's book returns "not found" rather than "not allowed", so account numbers cannot be probed. Sign-in and sign-up are rate limited. Custom CSS is validated against a strict allow-list before it is ever served, and uploaded images must be real PNG, JPEG or WebP data — SVG is refused outright, because it can carry scripts.
No system is perfect, and this one is small. If you find a hole in it, please write to privacy@betweenbooks.net before writing about it anywhere else.
Changes to this policy
If this changes, the date at the top changes with it, and anything material will be said plainly rather than folded into a longer sentence. There is no mailing list to announce it on, so the date is the honest signal — this page is the whole record.
Written to be read, not to be waved at a regulator. If any part of it is unclear, that is a fault worth reporting to privacy@betweenbooks.net.