Shelf is a place to keep and show the books, records and CDs you love. This page explains, plainly, what we collect to do that, who else is involved, and how you stay in control. Shelf is operated by [operator name], the controller of your personal data. Questions: [contact email].
What we collect
- Your account. Your email address, name and profile picture, and how you sign in (password or a connected account such as Google). This is held by our sign-in provider, Clerk. We keep a copy of your username, display name and picture to show your shelf.
- Your shelf. Everything you add: titles, authors and artists, dates, favourites, notes, the way your shelf looks, words you write on your wall, the labels you give pictures, and pictures and textures you upload.
- What you do with other shelves. Which shelves you follow and upvote, which friends-only shelves you’ve asked to see or been let into, and the notifications we create for you about them.
- Feedback you send. Your note, the page you sent it from and, if you’re signed in, which account sent it. If you’re signed out you can leave an email address so we can reply; it’s optional and used for nothing else.
- Reports you make. If you report a shelf: which shelf, the reason and note you give and, if you’re signed in, which account made it; if you’re signed out, the email you choose to leave. The shelf’s owner is never told who reported it.
- Technical data. Our hosting and database providers process IP addresses and request logs to run and protect the service. To stop abuse we count how often some things are done (searches, uploads, feedback, reports) per account, or per IP address when you’re signed out; these counters are deleted within a day. We do not use advertising trackers or sell data, and we do not run analytics that profile you.
Why we use it
- To provide Shelf: store your shelf, show it to the people you choose, and send in-app notifications (the contract between us).
- To keep the service secure and working, prevent abuse and fix problems (our legitimate interest).
- To meet legal obligations, for example responding to valid legal requests.
Who can see your shelf
New shelves are private: only you can see them. You can make a shelf available to friends (only people you let in; your link lets someone ask, and nobody sees the shelf until you say yes), anyone with the link (it stays out of search and the public listing, and you can renew the link at any time to cut off old ones) or public (listed on Shelf, searchable by username, and visible to search engines). Notes, favourites and pictures on your wall are part of your shelf and are visible to whoever can see it. Following and upvoting only works on shelves that aren’t private, and upvoting only on public ones.
When you ask to see a friends shelf, its owner sees your name, username and picture, and is told you asked. If they let you in, you’re told too. They can remove you at any time, which also ends your follow.
Services that process data for us
- Clerk: sign-in and account management.
- Supabase: our database and image storage.
- [hosting provider]: runs the website.
- Open Library and MusicBrainz: when you search to add something, our server sends the search text to these public catalogues. Nothing identifying you is sent with it.
- Open Library Covers and the Cover Art Archive: cover images for catalogue items are loaded by your browser directly from them, so they receive your IP address, as with any image on the web.
- Ko-fi: the “Support Shelf” link opens our Ko-fi page. Nothing is sent to Ko-fi unless you follow it, and anything you do there is covered by Ko-fi’s own privacy policy.
Some of these providers may process data outside your country. Where that happens we rely on appropriate safeguards such as the European Commission’s standard contractual clauses.
Cookies and storage
We use only what’s needed to keep you signed in (Clerk’s session cookies) and a little browser storage for things like interface preferences. No advertising or cross-site tracking cookies.
How long we keep it
For as long as you have an account. Feedback and reports are kept until we’ve dealt with them, and are deleted with your account (a report is also deleted with the shelf it’s about). Items, pictures and notifications you delete are removed from our database straight away; uploaded images are removed from storage at the same time. Backups held by our providers roll off within their standard retention windows.
Your rights and choices
- Change or delete anything on your shelf at any time from the editor.
- Delete your account from your account settings. This erases your shelf, everything on it, your uploads, follows, upvotes and friends-shelf requests.
- Ask us for a copy of your data, to correct it, or to restrict or object to how we use it, by emailing [contact email]. You can also complain to your local data protection authority.
Children
Shelf isn’t intended for children under 13 (or the minimum age of digital consent where you live).
Changes
If we change how we handle data, we’ll update this page and its date, and tell you in the app if the change is significant.