last updated 4 September 2026
Privacy
This policy covers both the PassageShelf website (passageshelf.com) and PassageShelf product accounts (the browser beta at app.passageshelf.com). It is written to be read, not skimmed past. If anything is unclear, write to us and we will answer plainly.
Who is responsible
The controller is Adrien Paul, sole trader, Damstraat 14, 9320 Aalst, Belgium. Enterprise and VAT number BE 1018.423.190. For any privacy request — access, correction, deletion, export, objection — contact passageshelf@pm.me.
Data on this website
The website itself sets no cookies and runs no visitor tracking. If you sign up for mobile-launch news, we store your email address, signup and update timestamps, and the choices you made (mobile-launch news, occasional product updates). Legacy beta and lifetime-offer flags may remain on older records. Each signup is kept for at most 12 months, then deleted automatically; a new explicit signup starts a new 12-month period. You can ask us to delete your record sooner at any time.
Data in your product account
When you create a PassageShelf account, we store your email address, a hashed password (bcrypt — we never see or store the password itself), an optional display name, your plan and account status, and your settings such as digest preferences and color meanings.
Your library is the heart of the product, and all of it is personal data in your account: books and their details, passages and highlights, notes, tags, bookmarks, chapters, reading progress and reading events, spaced-review history, loans you record, practice actions and check-ins, and import sessions. The page photos you scan are stored as image files (the original scan and a cleaned version) on our servers, linked to your passages.
Short-lived records also exist: email-verification and password-reset tokens (stored only as hashes) and invite codes used to join the beta.
Text recognition (OCR)
When you scan a page, the photo must be turned into text. Depending on how the server is configured, one of two things happens. When cloud recognition is enabled, the photo is sent to Google’s Cloud Vision API, which extracts the text and returns it; Google acts as our processor for that step and the image is not used for anything else. When cloud recognition is not enabled, recognition runs on our own infrastructure with a local engine and the photo never leaves our servers. The result is the same either way: the recognized text is stored in your library and the photo stays attached to your passage.
Service providers
We use a small number of providers, each for one job. By category:
- Hosting — the product runs on operator-managed servers in the European Union. The website and its signup list are served and stored by Cloudflare.
- Cloud text recognition — Google Cloud Vision API, only when cloud OCR is enabled, receiving the scanned page image for text extraction.
- Email delivery — Resend sends account email: verification messages, password resets, and the optional daily digest if you turn it on. Our own correspondence runs through Proton Mail.
- Backup storage — backups of the database and uploaded images are taken to storage under the same operator control and pruned on a rolling basis. They are never used for anything but restoring the service.
- Book metadata — when you look up a book, its ISBN or title is sent to Google Books or Open Library to fetch details and covers. Only the book reference is sent, never your identity or library.
There are no advertising networks, no data brokers, no cross-site trackers, and no sale or sharing of personal data for anyone else’s purposes. No analytics run in the product today; if we ever add privacy-respecting, cookie-less analytics, this page will say so before it happens.
Why we process data, and on what legal basis
We process account and library data to provide the service you signed up for (performance of a contract). We process security-related data — password hashes, session tokens, verification tokens — to keep accounts safe (legitimate interest). We send signup news and the optional digest because you asked for them (consent, withdrawable at any time). Where the law obliges us to keep something, we keep it for exactly that reason and no longer (legal obligation).
How long we keep data
Account and library data live as long as your account does. Delete your account and everything in it is removed immediately, including your scan images; backups taken before the deletion may still hold a copy for a short time and are pruned on a rolling basis. Website signups are deleted after 12 months. Verification and reset tokens expire quickly and are stored only as hashes. Records the law requires us to keep are kept only as long as it requires.
Where data goes
Your account and library are stored in the European Union. Two providers can involve processing outside the EU: Google (cloud OCR, when enabled) and Resend (account email). Where a provider processes data outside the EU or EEA, the transfer is covered by the European Commission’s standard contractual clauses or an adequacy decision, under that provider’s data-processing terms.
Security
Connections are encrypted with TLS. Passwords are hashed with bcrypt. Sessions use an httpOnly cookie valid for at most 7 days — the product’s only cookie, and an essential one. Access to production systems is limited to the operator.
Your rights
Under the GDPR you can ask for access to your data, correction, deletion, restriction of processing, portability, and you can object to processing based on legitimate interest or withdraw any consent. Most of these you can exercise yourself: export your whole library at Settings → Data, and delete your account at Settings → Account or via the account-deletion page — no sign-in needed for the email route. For anything else, email passageshelf@pm.me; we answer within 30 days. You also have the right to complain to a supervisory authority — in Belgium, the Data Protection Authority (dataprotectionauthority.be), or the authority of your own country.
Children
PassageShelf is not directed at children under 16, and we do not knowingly hold accounts for them. If you believe a child has created an account, contact us and we will delete it.
Changes to this policy
When this policy changes, the date at the top changes with it. If a change materially affects how account data is handled, account holders are notified by email before it takes effect.
