Privacy Policy
Last updated: September 5, 2026
Libraco ("we", "us", or "our") operates the Libraco website and mobile applications. The controller's legal identity and contact details are in our Legal Notice. This policy explains what personal data we collect, for what purposes, and on what legal basis under the EU General Data Protection Regulation (GDPR) and applicable German law.
1. Data We Collect
a. Account Information
When you sign in with Google or Apple, we receive the account identifier and information you choose to share, which may include your name, email address, and profile photo. Apple may provide a private relay email address. You may alternatively register with an email address and password, in which case Firebase Authentication stores the password securely. We use this data to create and manage your Libraco account. Your email address is never shown publicly on the platform.
b. Content You Provide
We store the books you add to your shelf, borrow requests you send or receive, reviews you write, direct messages you exchange with other users, and any reports or support requests you submit through the app. Support requests include your account name, email address, the message you provide, and the page from which you sent it. This information is visible only to authorised Libraco support and administrative staff so they can investigate and respond to your request.
Public and shared data:Your book shelf — including titles, authors, availability status, and city and country — may be accessible to the public without login as part of discovery. We store a Google Place ID and city-centre coordinates when you select a city; these describe an approximate pickup city, not your device or home location. You can clear your saved location. Profile information is shown to other signed-in users where the service needs it. Direct messages are available to the relevant participants and are processed by Libraco's service providers and authorised staff when needed for support, safety, security, or legal obligations. They are not end-to-end encrypted.
c. Uploaded Bookshelf Photos (AI Shelf Scan)
If you use the "Shelf Scan" feature, you upload a photo of your physical bookshelf. This image is transmitted to OpenAI's API, where a vision model reads the book spines and returns a list of detected titles. The image is not stored by Libraco after the scan completes; only the resulting book metadata (title, author) is retained. Please do not upload images that contain identifiable personal information beyond your book spines.
d. IP-Based Location Prefill
When you set up your profile, we use your IP address to suggest a city and country as a convenience prefill. Your IP address is forwarded server-side to ipapi.co (a third-party geolocation service) to perform this lookup. The result is only a suggestion — you can change or clear it at any time. We do not use it for precise location tracking. Hosting, security, and provider systems may independently retain technical request data, including IP addresses, under their applicable retention settings.
e. Push Notification Tokens
If you grant permission for push notifications, Libraco stores a Firebase Cloud Messaging (FCM) registration token on your account. This token is used solely to deliver push notifications to your device (for example, new messages, borrow requests, or activity updates). You can withdraw this permission at any time by disabling push notifications in your profile settings or in your device/browser notification settings. Withdrawn tokens are removed from your account.
f. Notification Preferences
You can control whether Libraco sends you push notifications and email notifications from your profile settings at any time. These preferences are stored on your account. Disabling a channel prevents optional notifications through that channel. We may still send necessary account, security, deletion, or service messages.
g. Venue Partner Application Data
If you submit an application for Libraco's venue partner programme (open to bookstores, cafés, libraries, etc.), we collect your contact name, email address, venue name, address, city, country, website, and a short description. This data is stored in our database and used solely to evaluate and respond to your application. We also query the Google Places API using a Place ID you provide to retrieve publicly available venue metadata (rating, location) to assist with verification.
h. Usage and Analytics Data
Google Analytics 4 (GA4) is disabled. We do not load its tracking script or send new usage events to GA4. Hosting and security logs are separate from analytics and may still contain technical request information needed to operate the service.
i. Technical Hosting and Security Data
When you use Libraco, our hosting, delivery, and security providers may process technical data such as IP address, request URL, browser or device information, timestamps, and server logs to deliver, secure, troubleshoot, and prevent abuse of the service. We do not use this data for advertising profiles.
2. Legal Basis for Processing
We process your personal data on the following legal bases (GDPR Art. 6):
- Contract performance (Art. 6(1)(b)) — account creation and management, book requests and loans, direct messaging, in-app notifications, push and email notifications (where enabled by you), and the AI Shelf Scan feature.
- Legitimate interests (Art. 6(1)(f)) — service security, abuse prevention, technical operation, IP-based city prefill during onboarding, and venue verification via Google Places. We consider these interests proportionate and not overriding your rights and freedoms.
- Legal obligation (Art. 6(1)(c)) — where required by applicable German or EU law.
3. How We Use Your Information
- To provide and operate the Libraco service.
- To match you with other users for borrowing and lending books.
- To deliver in-app, push, and email notifications about requests, messages, and activity on your account — subject to your notification preferences.
- To provide direct messaging between users for borrowing coordination.
- To investigate, respond to, and keep records of support requests and safety concerns.
- To process AI shelf scans and enrich book metadata.
- To prefill your location during profile setup.
- To surface eligible shelf listings publicly so prospective users can discover available books before signing up.
- To evaluate and manage venue partner applications.
- To improve, debug, and develop the platform.
- To detect and respond to abuse or policy violations.
We do not sell your personal data to any third party.
4. Data Sharing and Third-Party Processors
We share data with providers necessary to operate the platform and with other users where you use a sharing feature. Providers may act as processors or, where their own service terms determine purposes and means, under their own privacy terms.
- Google / Firebase — authentication (Firebase Auth), database (Firestore), file storage (Firebase Storage), and push notification delivery (Firebase Cloud Messaging), hosted on Google Cloud Platform.
- Resend — used to deliver transactional email notifications (e.g. new borrow requests, messages, activity updates). Only your email address and the notification content are transmitted. You can disable email notifications in your profile settings at any time.
- OpenAI — processes Shelf Scan images and related book-detection data. It also processes inputs, attachments, task information, and outputs used by the administrator-only Command Center. OpenAI says API data is not used to train models by default, but API retention still applies under the configured service terms.
- ipapi.co — receives your IP address server-side during profile setup to determine your approximate city and country for prefill purposes.
- Google services — Google Places powers city autocomplete and venue metadata; Google Maps may load when you open an embedded map; Google Books and Custom Search may receive book searches, titles, or ISBNs to retrieve book information.
- Hosting and delivery providers — Vercel hosts the web application; Cloudflare delivers and protects proxied traffic; Google Cloud Run and Cloud Logging run and log the API. These providers process technical request and log data to deliver and secure the service.
- Other data sources and delivery services — Open Library, Wikimedia, Wikipedia, Wikidata, CountriesNow, and external image hosts may receive book, author, country, or image requests. Expo provides mobile update delivery. Apple and Google provide their sign-in and app-distribution services under their own terms.
Your display name and profile photo can be visible to other users when they view your shelf or interact with you through requests, groups, reviews, follows, or messages. Your city and country may be shown for discovery. We do not show your email address, stored Place ID, or city-centre coordinates to other users as profile fields. A meetup address or note that you voluntarily send to another user is shared with that user.
5. International Data Transfers
Our providers may process data outside the European Economic Area (EEA), including in the United States. We use the transfer mechanism applicable to the relevant provider and service, such as an adequacy decision or standard contractual clauses where appropriate. You can ask us for further information about the safeguards applicable to your data.
6. Data Retention
We retain your account data for as long as your account is active. If you request deletion, we remove your profile, shelf, uploads, reviews, direct chats and associated records through a cleanup process that retries temporary failures. Group messages you sent and messages that explicitly mention your account are removed. Borrowing history needed by other participants remains with your identity replaced and personal notes removed. We retain a minimal account identifier to prevent deleted identities from signing back in. Provider backups, security records, and already-delivered emails may follow separate retention periods. Disabling GA4 does not automatically delete data collected previously. You can contact us about previously collected analytics data using the contact details below.
We keep venue applications, support records, moderation reports, and operational logs for the period needed for their purpose, security, legal claims, and applicable retention duties. We are still finalising the detailed retention schedule and will publish it before launch. Provider backups and logs follow their documented retention settings.
7. Security
We use industry-standard measures — including TLS encryption in transit and access controls — to protect your data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Cookies and Local Storage
Libraco uses the following cookies and browser storage:
- Authentication cookies / session tokens — set by our authentication layer (NextAuth.js) to keep you signed in. These are strictly necessary and cannot be disabled without logging out.
- Previous analytics cookies (
_ga,_ga_*)— cookies from an earlier version may remain on your device. Libraco no longer loads GA4 to read or renew them. You can remove them through your browser's site-data settings. - Necessary preferences and Terms acknowledgement — theme and layout preferences are stored in browser storage; the
libraco_terms_acknowledgementcookie is an httpOnly, first-party cookie retained for up to 180 days to remember the version of the Terms of Use accepted by the signed-in account. The account retains the Terms-acceptance timestamp and version as the audit record. Neither is consent for all processing of personal data.
9. Children's Privacy
Libraco is intended for users aged 16 and over. We do not knowingly allow people under 16 to use the service. If you believe we have inadvertently collected data from a person under 16, please contact us and we will delete it promptly.
10. Your Rights
Under the GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure— request deletion of your personal data ("right to be forgotten").
- Restriction — ask us to limit processing in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdrawal — withdraw a consent you have given at any time, without affecting processing that took place before the withdrawal.
To exercise any of these rights, contact us at hello@libraco.app. We will respond within one month as required by the GDPR. You also have the right to lodge a complaint with your national supervisory authority — in Germany, this is the data protection authority of your federal state (Landesdatenschutzbehörde).
11. Changes to This Policy
We may update this policy from time to time. We will post the revised policy on this page with an updated "Last updated" date, and notify you of material changes through the app. Where a change affects processing that requires your consent, we will request that consent before the change takes effect.
12. Contact
Questions about this policy? Reach us at hello@libraco.app. Instructions for deleting an account are available on our account deletion page.