Privacy Policy

Effective: September 2026Last Updated: September 2026Version: 2026-09

1. Scope and Service Operation

This Privacy Policy describes how Tytld collects, uses, stores, and protects your data when you use the Tytld web application or the Tytld mobile application. It applies to both unauthenticated visitors and authenticated members.

Tytld is provided by Michael Jones, operating under the registered Australian business name Tytld, based in Australia. Privacy and data inquiries may be sent to contact@tytld.com. Signed-in users may also use the in-app Support channel. This policy does not publish a postal or business address.

Tytld is designed to provide a warm, personal book-tracking library, and we treat your reading history with the absolute privacy it deserves.

2. Information We Collect Directly

We collect information that you actively provide to us when setting up an account, updating your profile, or interacting with support. This includes:

  • Account Credentials: Standard email address and encrypted password on account sign-up.
  • Authentication Services: Identity tokens when signing in via Google web OAuth or native Apple ID-token sign-in on mobile.
  • Reader Profile: Your display name, username, biography, and profile visibility selection (public or private).
  • Taste and Onboarding Answers: Your selections regarding reading preferences, onboarding questions, and your annual reading goal.

3. Library Data Synced to the Managed Backend

To sync your reading journey across devices, the following information is securely transmitted to and stored on our managed cloud backend:

  • Library Catalog: Books, reading status (To Read, Currently Reading, Read, Did Not Finish), ownership status, reading progress (page count or position), personal ratings, public reviews, custom library shelves, custom lists, and recorded book loans or metadata corrections.
  • Reading Cycles and Logs: Your reading history structured as reading cycles (original reads and rereads), and reading sessions (both manual session logs and timed reading sessions, containing precise start/end timestamps and derived duration fields).
  • Private Journal and Notes: Your private thoughts, reflections, book notes, quotes, and custom tags. These private notes are strictly private under row-level database security (RLS) and are never exposed through public reader profiles or public catalog surfaces.
  • Challenges and Anniversaries: Active reading challenges, annual goals, goals progress, and deterministic private memories or finished-anniversary milestones.
  • Preferences: In-app notification preferences, reminder times, and registered operating system notification permission states.
  • Import Processing: When you import reading history from Goodreads, StoryGraph, LibraryThing, Libib, or a standard CSV, the source files are parsed locally on your device. Only the finalized parsed rows are sent to our managed backend in bounded chunks for analysis and library insertion after your explicit confirmation. Original import files are not retained on our servers.

4. Support and Subscription Records

To provide customer support and manage subscriptions, Tytld retains the following records on its managed backend:

  • Remote Support and Feedback: When you submit a support request or feedback message through the app, we store a record of this communication. This record includes the message content, contact email address, feedback category, diagnostics (such as your current route path and platform type), status, and any administrator response fields where applicable.
  • Remote Subscriptions and Entitlements: If you activate or reconcile a premium subscription, we store entitlement records. These records include the billing provider (such as Apple, Google, or Web), product identifier, subscription status (active, cancelled, or in grace period), purchase reference, and billing period information where applicable.

5. Data Processed Locally and Temporarily

Certain data is kept strictly local to your browser or mobile device, or is only processed in-memory. This includes:

  • Local Drafts: Unsaved text in the support message form or note-composer.
  • Session Storage: Authentication session tokens and temporary states stored locally in your browser storage or secure device keychain.
  • Export Packages: Reading history export files generated from remote data are assembled locally before being saved or downloaded.
  • Share-Card Generation: Images generated to share your reading progress are built locally on-device. While your private notes are kept off public reader profiles, you may explicitly choose to include selected note content in a locally generated outward share card. Your private journal notes are strictly excluded from share cards unless you explicitly toggle their inclusion.
  • Camera Barcode Processing: When using the mobile camera to scan a book's barcode, ISBN processing is performed locally on your device's camera frame. We do not capture, record, or upload video frames or camera feeds to our servers.

6. Third-Party Services and Analytics

We engage third-party providers to resolve book catalogs, manage sign-ins, and deliver essential platform capabilities:

  • Book Metadata Resolution: Book search, details, and cover images are requested directly from public providers, including Open Library, Google Books, and the Internet Archive.
  • Google Fonts: System-wide typography assets are loaded via Google Fonts requests on the web.
  • Platform Authentications: Google and Apple sign-in services validate user identity via secure ID-token exchanges.
  • Subscription Verification: Subscription state is reconciled on the server side using RevenueCat's secure API integrations and webhooks. There is no client-side Purchases SDK compiled into the application.
  • Diagnostics and Logs: An optional CatDoes Watch integration (for mobile diagnostics) and Lovable integration (for runtime web error reporting) operate only when explicitly configured or injected in the relevant build or environment. When active, diagnostics are limited to error messages and technical context those integrations receive, and are not used as a general analytics channel for reading content.

First-Party Authenticated Analytics: Where enabled, Tytld logs first-party analytics on the web. These events are tied to your authenticated account or user identifier and are stored in our managed database in the 'analytics_events' table. This tracking includes allow-listed event names (such as 'support_message_sent' or page-navigation views) and short scalar or categorical properties (such as your platform and application version). To protect your reading privacy, free-text notes, public reviews, private journal entries, support message text, and authentication tokens are strictly excluded and are never transmitted through this analytics tracking path.

No Third-Party Ads: Tytld does not display third-party advertisements and contains no ad-serving trackers or SDKs.

No Sale of Data: We never sell your personal information, reading history, or library contents to third parties.

7. Data Storage, Security, and Retention

Tytld utilizes a managed cloud infrastructure to sync and store your records. Data transmission uses industry-standard HTTPS encryption, and stored data is protected using secure row-level security (RLS) database policies.

Because our backend services are fully managed, the exact geographic server regions, active subprocessors, specific application log configurations, and database backup schedules are subject to hosting provider policies and vary based on deployment.

Active data is retained in our live databases for as long as your account remains active. Tytld will retain information only as long as reasonably necessary for business, legal, accounting, and security purposes.

8. Your Rights, Choices, and Deletion

You retain complete control over your reading data:

  • Data Export: You can download a complete export package containing your library, cycles, sessions, journal entries, goals, and shelves in structured JSON and CSV formats directly from the 'Privacy and data' settings.
  • Profile Visibility: You can toggle your reader profile to private at any time, which immediately hides your profile, reviews, and shelves from other readers.
  • Account Deletion: Initiating account deletion from our application settings invokes the current account deletion workflow. Please note that the deletion paths differ by platform: the web application currently blocks deletion if an active, non-cancelled premium subscription or entitlement is detected, while the mobile application currently invokes the account deletion operation through the app.
  • External Subscriptions: If you have purchased a premium subscription through Apple or Google, deleting your Tytld account does not automatically cancel your subscription. You must cancel billing directly in your Apple App Store or Google Play settings to prevent future charges.

Deletion Limitations: Tytld does not promise unconditional immediate deletion or deletion of every associated database record. Account deletion may leave or de-identify support messages, first-party analytics event summaries, security logs, accounting transaction records, store provider receipts, legal compliance files, and backup archives where required by law, regulatory compliance, or technical necessity.

Public Deletion Request: A public unauthenticated deletion request form is currently not functional. All secure deletions must be initiated by signing into your Tytld account.

Local App Removal: Uninstalling Tytld from your device generally removes app-local files and caches. However, secure operating system storage (such as device keychains or secure keystores), device backups, and any data synced to our managed cloud backend or shared elsewhere follow platform-specific behavior and are not guaranteed to be erased by app uninstall.

9. Children's Privacy

Tytld is not designed for or targeted to children. The age threshold of eligibility is qualified subject to applicable local regulations and parental consent requirements. We do not knowingly collect personal information from individuals below the legal age without parental consent.

10. Policy Changes and Contact

We may update this Privacy Policy to reflect modifications to our application or regulatory requirements. Any updates will be published to this page with an updated effective date and version identifier.

For privacy and legal enquiries, email contact@tytld.com. Signed-in users may also use the Help and support screen in account settings. This policy does not publish a postal or business address.