Citrus Shelf privacy policy

Last updated 18 September 2026. Applies to the Citrus Shelf app for Android and iOS.

The short version. You can use Citrus Shelf without an account. Your reading data stays on your phone unless you choose to sign in, which enables sync to our server. Memory photos and reading sounds stay on your phone. Book lookups send search words or barcode numbers to our server, and technical error reports go to Sentry. There is no advertising or behavioural analytics.

Who this covers

Citrus Shelf is developed and published by an individual developer, referred to here as "we" and "the developer". This policy explains what the app collects, why, where it goes, and how to contact us. It covers the app only, not this website.

What stays on your device

Your books, reading progress and dates, shelf artifacts, room settings, collections, memories and reading sessions are stored on your phone. You can add and manage them without signing in. Signed-out reading data is not uploaded for sync.

When you sign in, the phone also keeps the email address and the sign-in method you used, so the app can show which account it is signed in to. It is kept in the phone's secure storage, is not sent to our API, and is removed when you sign out or delete your account.

Memory photos are stored only on the phone and are not uploaded to our API or synced. Reading sounds are bundled ambient audio played locally, not microphone recordings; they are not uploaded. If you deliberately share or export an image, the app or destination you choose receives that image under its own privacy practices.

What the app sends, and why

Optional accounts. You can sign in with Google, Apple, or a code sent to your email address. An email-code account stores your email address; a Google or Apple account stores the provider's account identifier and a display name when supplied. We assign an internal user ID and keep authentication records to maintain your session. Apple sign-in may also provide a token kept so its access can be revoked when you delete the account. We do not receive or store your Google or Apple password.

Email codes. When you request a sign-in code, your email address and the sign-in message are sent to Resend, our email processor, to deliver the code. We do not use these emails for marketing.

Sync. Only after you sign in, the app syncs books, ornaments (including companion names), room settings, collections and their book membership, text memories, reading sessions, completions and achievements to our API and database hosted by DigitalOcean in Bengaluru, India (region blr). These records are linked to your account's user ID so your devices can read the same shelf. Memory image files are excluded. Requests are encrypted in transit using HTTPS. Signing out stops account sync; it does not delete the server copy.

Book lookups. When you scan a barcode or type a search, the app sends the barcode number (an ISBN) or your search words to our own server so it can fetch the book's title, author, page count, and cover. Our server forwards that ISBN or search to two public book databases, Open Library and Google Books, and keeps a copy of the answer so the next person asking about the same book is served from our cache. The cache holds book information and lookup queries, not a reading history tied to you, your device, or your shelf.

Like any web request, a lookup carries your device's IP address. Our server uses it to limit requests, which protects the service from abuse, and in short-lived server logs used to diagnose problems. We do not build a profile from it.

Cover images. Cover pictures are served from our own storage rather than fetched directly from the book databases. Requesting one carries your IP address in the same way as any image on the web.

Crash reports. If the app crashes or hits an internal error, it sends a report to Sentry so we can fix the bug. Reporting is errors only: no performance tracing or session tracking. A report contains technical details such as a stack trace, app version, device model, operating system version, and navigation breadcrumbs. Sentry is configured not to send default personal information; we do not attach your account identity or shelf contents to reports. Sentry keeps reports for 90 days, then deletes them.

The camera

The barcode scanner uses your camera to read the number printed on the back of a book. The picture is processed on the device, in the moment, to find that number. No scanner photo or video is saved or uploaded. You can decline camera permission and enter books by search or by hand instead. Photos you choose to add to memories remain local as described above.

What we do not do

Who else handles data

DigitalOcean hosts our API, database and cover storage; Resend delivers sign-in codes; Google and Apple handle their respective sign-in methods; Open Library and Google Books answer book lookups; and Sentry processes error reports. They receive the information needed for the purposes described above and have their own privacy policies. Our hosting, email and crash-reporting providers process data on our behalf. No data is used for advertising or tracking.

Children

The app is not directed at children under 13 and we do not knowingly collect personal information from them. Contact us if you believe a child has supplied personal information so we can investigate and remove it.

Your choices and your rights

You can remain signed out. To delete an account, open the You screen, choose Delete account, and confirm. This removes your account and synced reading data from our server, then signs you out and wipes the local app data and memory photos on that phone. Deletion needs a network connection; if it fails, the app tells you and you can retry. Copies you saved to Photos or shared elsewhere are outside the app and must be deleted there separately.

If you cannot use the app, request deletion of your Citrus Shelf account and associated data by emailing [email protected]. Tell us which sign-in method you used; we will verify ownership before removing data. Uninstalling the app or signing out does not delete your server account. Anonymous lookup caches and technical crash reports are not account records; crash reports expire after 90 days. Contact us to request earlier removal or ask about this policy, and we will act within 30 days. Depending on where you live, you may have rights to access, correct or delete personal data and complain to a data protection authority. We honour requests regardless of where you are.

Changes

If we change what the app collects, we will update this page and the date at the top before the change reaches the app.

Contact

Email [email protected].