Privacy Policy
Digital Library is operated by Mohammad Toosi. The service lives at https://digital-lib.com. The iOS and Android apps talk to that same origin.
This policy describes what the service actually does. It is not a catalogue of every data type an app could collect.
What an account is
There are no email addresses, phone numbers, or personal profiles. You sign in as a library: a name you choose and a password. When the library is created you are shown a recovery code once. Only a hash of the password and of the recovery code is stored.
The library name is the identifier. Do not put your legal name or an email address in it unless you are willing for that string to be stored.
What we store
For each library:
- The library name, password hash, recovery-code hash, and timestamps (created, last sign-in, recovery issued or used).
- An optional unguessable share token, only if you turn sharing on.
- The books you add: title, authors, publisher, year, language, page count, ISBN, format, series, categories, the country whose literature the book belongs to, rating, reading status, page position, the month you finished it, and the history of progress events.
- Where each metadata field came from (a bibliographic source, a manual edit, or an AI estimate).
- Cached cover artwork fetched from public sources, never from your camera.
- Feedback notes you send from Settings. Each note is stored against the library and emailed to the operator.
- Session records. The website uses an HttpOnly, Secure, SameSite=Strict cookie named
dl_session. The native apps store a bearer token in the device keychain / Android Keystore. The server stores only an HMAC of the token, not the token itself.
A Goodreads CSV you import is parsed in memory. The file is not kept. Books created from it are stored like any other book.
Deleting the library (Settings → Delete this library) deletes the library row and everything that cascades from it: books, sessions, custom categories, progress, share token, and stored feedback. A feedback email that has already been delivered may remain in the operator's mailbox until it is deleted there.
What we do not store
Photographs. A photo of a cover, a barcode, or a shelf exists for one identification request. It is sent to our servers, used, and discarded. It is not written to disk, not written to object storage, and not hashed. Cover art on the shelf is fetched from public bibliographic sources after you confirm the book.
Comparison demographics. Country, age band, and optional sex used on the statistics comparison are sent in the body of one request, used to select published Eurostat figures, and discarded with the request. They are not a column and not a setting. The native app may remember the last selection on the device only. You can forget it on that screen. The website may remember it in the browser. The server never does.
Analytics SDKs, advertising IDs, crash-reporter vendors, and marketing pixels. None of those are in the app. Server errors go to Google Cloud Logging and Error Reporting, which is the hosting platform, not a third-party product in the client.
Photographs and AI
If you photograph a book or a shelf, that image is sent to Google's Gemini API so the service can read titles, authors, and barcodes. Google is a processor for that request. We do not keep the image after the response is produced. Google's own terms for the Generative Language API apply to what they receive.
ISBN lookups and title searches are sent to Open Library and Google Books. Those requests carry bibliographic queries, not your library name.
When you add a book, the service works out which country's literature it belongs to. It first checks the book's ISBN against Wikidata. If that does not settle it, the book's title, subtitle, authors, language, year, ISBN, subject headings, and categories are sent to the Gemini API. When you ask for another cover, the title, authors, and ISBN go to Gemini to search for one. These requests carry the book's details, not your library name or anything else about you.
Sharing
Sharing is off by default. If you turn it on, anyone with the link can see the library name, the books with their details and covers, and the curated categories. Reading status and ratings are included unless you turn them off. Your own category names are included only if you turn them on. Statistics and settings never are. Rotating or turning sharing off invalidates the old link. Treat the URL like a password.
Logs, rate limits, and security
The service rate-limits sign-in, recovery, registration, and feedback by IP address. Google Cloud Run access logs may include IP address, user agent, and request path. Those logs are used to run and secure the service, not to profile readers. Comparison demographics are sent in a POST body so they do not appear in Cloud Run's URL logs.
Processors
| Who | Why |
|---|---|
| Google Cloud (Cloud Run, Cloud SQL, Cloud Storage, Secret Manager, Logging) | Host the app, database, cached covers, and operational logs. Region: europe-west4. |
| Google Gemini API | Identify books in photographs you upload for that purpose, work out a book's country of literature, and search for a cover when you ask. |
| Wikidata (Wikimedia Foundation) | Look up a book's country of literature by ISBN. |
| Google Books | Bibliographic lookup and some cover art. |
| Open Library / Internet Archive | Bibliographic lookup and some cover art. |
| Resend | Deliver the Settings feedback email. |
Cover files are public bibliographic images, cached at small sizes (200×300 and 400×600).
Legal bases (EEA / UK)
- Contract. Running the library you created: storing the shelf, signing you in, identifying books you asked us to identify.
- Legitimate interests. Security, rate limiting, diagnosing outages.
- Consent / your request. Optional comparison demographics, optional share link, optional feedback, optional camera and photo access.
Retention
Library data is kept until you delete the library. Sessions expire. Cached covers are reused across libraries and are not your personal data. Cloud logs follow Google Cloud's retention for the project. Photographs are not retained by us.
Your rights
You can access and correct the shelf from inside the app. You can delete the library, which deletes the stored account. To ask a question that the app cannot answer, use Support.
If you are in the EEA or UK you may also complain to a supervisory authority. The service is hosted in the Netherlands (europe-west4).
Children
The app is not directed at children under 13. Do not create a library for a child under 13.
Changes
If the practices above change, this policy will change and the effective date will move. This page is the current version.
Contact
Mohammad Toosi
digital-lib.com/support
graysquare99@gmail.com