Privacy Policy
Last updated 20 August 2026
Cove is a reading tracker. Your library is yours: we don't sell it, we don't advertise against it, and we don't train anything on it. This page explains exactly what we hold and how to take it back.
Who we are
Cove is operated by [OPERATOR NAME] ("we", "us"), based in the United Kingdom. We are the data controller for the information described here. You can reach us at hello@covebooks.app.
What we collect
Your account
- Email address — to sign you in and to send account emails (confirmation, password reset). We do not send marketing.
- Display name and avatar choice, if you set them.
- When you last opened the app — so we can tell whether Cove is actually being used, and spot accounts that break.
Your library
- The books you add, and which shelf each one is on.
- Your ratings, notes, tags, reading progress and dates.
- Where you place books on the taste graphs.
- Your reading goal and app settings.
If you use friends
- Who you are friends with, and pending requests.
- A feed entry when you start or finish a book, visible only to accepted friends. A "finished" entry includes the rating you gave that book.
- What you're currently reading, shown to accepted friends.
- Your profile — display name, avatar, shelf counts, reading goal and favourites — shown to accepted friends unless you set your profile to private, which limits it to your name and avatar.
- Reactions you leave, and book recommendations you send or receive.
- Anyone you mute or block. A mute is private to you and is never shown to the other person; a block is enforced by the database, not just hidden in the app, and they aren't told either.
Friends never see your notes, your reading dates, your full ratings history, or anything about books you haven't started or finished. Nothing at all is shared with anyone who isn't an accepted friend.
If you report a problem
What you typed, plus technical context: app version, browser, screen size, which screen you were on, how many books you have, and any recent errors. If your report is about a specific book, that book's title travels with it so we can fix it. Your library itself is never attached.
What we do not collect
- No analytics or tracking pixels. No Google Analytics, no Facebook pixel, no session recording, no advertising identifiers.
- No payment details. Cove is currently free. If paid features arrive, payment will be handled by a specialist provider and card details will never reach us.
- No location, contacts, photos or microphone. The barcode scanner uses your camera in the browser only — the image is never uploaded or stored; only the barcode number is read from it.
Why we're allowed to hold it
Under UK GDPR our lawful bases are:
- Contract — we can't run a reading tracker without storing your books and signing you in.
- Legitimate interests — keeping the service secure, fixing bugs you report, and understanding whether the app is being used at all.
- Consent — for anything optional, such as adding friends. You can withdraw it by removing the friend or turning the feature off.
Where it lives, and who can see it
Your data is stored with Supabase (our database and authentication provider) and the site is served by Netlify. Account emails are sent via Resend, and email you send us at the addresses on this page is handled by Zoho Mail. These providers process data on our behalf under contract; they don't get to use it for their own purposes.
Access is enforced at the database, not just in the app: security rules mean one account cannot read another account's library, even if someone tampered with the app in their own browser.
Cove's fonts are served by Google Fonts, so when the app loads, your browser requests the font files from Google's servers — like any web request, that reveals your IP address to Google. No account information or library data is included in those requests.
Some providers operate outside the UK. Where data is transferred abroad it is protected by the safeguards those providers offer, such as standard contractual clauses.
Book information
To fill in covers, descriptions and page counts we query Open Library, Google Books, Wikidata, Wikipedia and Apple's iTunes catalogue. These requests contain the book being looked up — never your identity or your library.
Fetched book information (title, author, cover, description) is kept in a shared cache so the next person to add the same book gets it instantly. This cache holds book facts only. Nothing personal — no ratings, no notes, no shelves — ever goes into it, and it is readable only by signed-in users.
How long we keep it
- While your account exists, we keep your library — that's the point of a reading tracker.
- When you delete your account, your books, profile, friendships and feed entries are deleted immediately. This is real deletion, not a flag.
- Bug reports are kept while we work through them, and are deleted with your account.
- Shared book information stays — it's about the book, not you, and nothing in it identifies you.
Your rights
Under UK GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable format. Two of these you can do yourself, right now, without asking:
- Get it all back — Settings → Export library (CSV). Free, always, no conditions. It opens in any spreadsheet and imports into other apps.
- Delete everything — Settings → Delete account.
For anything else, email hello@covebooks.app. We'll respond within one month. If you think we've handled your data badly you can complain to the Information Commissioner's Office at ico.org.uk — though we'd rather you told us first so we can fix it.
Storage on your device
Cove stores your library in your browser so it loads instantly and keeps working on a bad connection. This is essential to how the app works, not tracking, and it is cleared when you sign out. We use no advertising or analytics cookies.
Children
Cove is not intended for children under 13. If you believe a child has created an account, email us and we'll remove it.
Security
Traffic is encrypted in transit. Passwords are hashed by our authentication provider and never visible to us. Database access rules are enforced server-side. No system is perfect — if you find a security problem, please email us before disclosing it publicly and we'll work with you.
Changes
If we change this policy we'll update the date above, and for anything significant we'll tell you in the app before it takes effect.
← Back to Cove · Terms of Use · Thanks & attributions · Help & FAQ