← Back to Stellary

Privacy Policy

Effective date: 1 August 2026 · Version 1.6

Stellary is a reading-tracking app that lets you build a library, log reading sessions, set goals, keep streaks, and read together with friends in clubs. This Privacy Policy explains what personal data we collect when you use the Stellary mobile application and the website stellary.cloud (together, the "Service"), why we collect it, and the rights you have over it.

We designed Stellary to collect as little personal data as possible. We do not sell your data, we do not show ads, we do not use third-party advertising or tracking SDKs, and analytics is off unless you switch it on. The only third-party diagnostic tool we use is a crash-reporting service, described in section 2.2.

1. Who is responsible for your data

The Service is operated by Mattias Olandersson and Olle Larsson, private individuals based in Sweden (together, "we", "us"). We are jointly responsible as data controllers under the EU General Data Protection Regulation ("GDPR"). You can reach us about anything in this policy at hello@stellary.cloud; we have agreed that this shared inbox is the single contact point for privacy matters.

2. Data we collect

2.1 Data you give us

2.2 Data collected automatically

2.3 Notifications, and data we do not collect

We do not collect your precise location, contacts, photo library (the only photos we ever receive are a profile photo or a book-cover photo you choose to upload — see section 2.1), health data, browsing history, or advertising identifiers. We do not track you across other companies' apps or websites.

Personal reading reminders — the daily reminder, streak-at-risk, goal-pace, and monthly-report notifications — are scheduled locally on your device and never touch our servers. Social notifications (a friend request, a friend accepting your request, a new note in one of your clubs, a reaction to your reading, or a buddy-read progress update) work differently: to deliver them, we store a push token for your device — a random identifier issued by the Expo push service — on our servers, together with your notification preferences (which categories you want, and any clubs you have muted). Both are protected by row-level security so only you can access them. Push messages are delivered through the Expo push service (see section 4), which relays them to Apple or Google for delivery to your device. Your push token is deleted when you sign out on that device, when you delete your account, and automatically when the push service reports that the device is no longer registered (for example, after you uninstall the app).

3. Why we use your data and our legal bases

PurposeData usedLegal basis (GDPR Art. 6)
Providing your account, syncing your library, sessions, goals, streaks, clubs, and friends across devicesAccount data, reading data, social content, customizationsPerformance of a contract (Art. 6(1)(b))
Sending a friend-invitation email you requestInvitee's email address, your usernameLegitimate interest in delivering an invitation you initiated (Art. 6(1)(f)); the invitee can decline and the address is not reused
Delivering the social notifications you have switched onPush token, notification contentPerformance of a contract (Art. 6(1)(b)); each category can be turned off in Settings or at OS level
Remembering your notification preferences across devicesNotification category settings, per-club mutesPerformance of a contract (Art. 6(1)(b))
Understanding how Stellary is used so we can improve itOpt-in product eventsYour consent (Art. 6(1)(a)) — withdrawable at any time in Settings → Privacy
Keeping the Service secure: authentication, abuse prevention, rate limitingAccount data, technical logsLegitimate interest (Art. 6(1)(f))
Diagnosing crashes and technical errorsCrash reportsLegitimate interest (Art. 6(1)(f))
Complying with legal obligationsConsent records, export/deletion audit recordsLegal obligation (Art. 6(1)(c))
Responding to support requests and in-app feedbackSupport messages, in-app feedbackLegitimate interest (Art. 6(1)(f))
Suggesting books you might enjoy (premium recommendations)Your library/ratings matched against aggregated, non-identifying reading patternsPerformance of a contract (Art. 6(1)(b))
Reviewing reports of objectionable content or behaviorReport recordsLegitimate interest (Art. 6(1)(f))

We do not use your data for advertising, we do not sell or rent it, we do not use it to train AI models, and we do not make automated decisions with legal or similarly significant effects about you. Data collected for one purpose is not reused for an incompatible purpose without asking you first.

4. Third parties and processors

We share personal data only with the service providers below, who process it on our instructions under data-processing agreements. Each of them is contractually required to protect your data to at least the same standard as this policy and applicable law. We never share your data with advertisers or data brokers, and no third-party AI service receives your personal data.

ProviderRoleData involved
Supabase, Inc.Database, authentication, backend and file-storage hostingAll account, reading, social, consent, and analytics data described above, and any profile or book-cover photo you upload
Resend, Inc.Email deliveryRecipient email address and email content
650 Industries, Inc. (Expo)Push-notification deliveryDevice push token and notification content, relayed to Apple/Google. Never your email, username, or library
ISBNdb and Internet Archive (Open Library)Book search and metadataSearch text sent by our backend; cover images loaded directly by the app (so that provider sees your device's IP). Your identity and account data are never shared
Google LLCOptional Sign in with GoogleGoogle account email address and sign-in token
Apple Inc.App distribution, optional Sign in with Apple, payment processing, support inbox hostingPurchases handled entirely by Apple; sign-in email and token if used; support inbox receives your email and message content
RevenueCat, Inc.Subscription managementYour account identifier (the same internal ID used elsewhere in the Service) and purchase/entitlement status. Never your name, email, or payment details
Functional Software, Inc. (Sentry)Crash reportingCrash data with your account identifier (the same internal ID used elsewhere in the Service) — never your email, username, or reading data
RailwayHosting for our internal operations and moderation dashboardAccount, reading, social, and report data described above, queried directly from Supabase; the dashboard is accessible only to us as the app's operators

We may also disclose data if required to do so by law or a valid legal order, or to protect the rights, safety, or property of our users, ourselves, or others — and, if the Service is ever transferred to a company or new owner, to that successor under this same policy (we would notify you first).

5. International transfers

We are based in Sweden and aim to keep data storage within the European Economic Area (EEA) where feasible. Some of our providers (including Resend, RevenueCat, Sentry, Expo and, depending on configuration, Supabase and Google) may process data in the United States. Where personal data leaves the EEA, we rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework for certified providers and/or the EU Standard Contractual Clauses, together with additional safeguards where appropriate. You may contact us for details of the safeguards applied to a specific transfer.

6. How long we keep data

7. Your rights

Under the GDPR you have the right to: access the personal data we hold about you; rectify inaccurate data; erase your data; restrict or object to certain processing (including any processing based on legitimate interest); data portability (receive your data in a machine-readable format); and withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.

You can exercise the most important rights directly in the app: Settings → Privacy lets you withdraw analytics consent instantly, the export function delivers a machine-readable copy of your data, and the delete account function erases your account (see section 8). For anything else, email hello@stellary.cloud and we will respond within one month.

You also have the right to lodge a complaint with a supervisory authority. In Sweden, that is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), www.imy.se. If you live elsewhere in the EU/EEA, you may complain to your local authority instead.

8. Deleting your account and data

You can delete your account at any time from within the app (Settings → Account → Delete account). Deletion is performed by our backend and permanently removes your account together with your profile, profile photo, library, reading sessions, goals, streaks, club memberships and posts, friendships, customizations, push tokens, notification preferences, and analytics events tied to your account. Content you posted in shared spaces is removed or disassociated from you. Deletion is not a deactivation — the data is actually erased, apart from the minimal audit record described in section 6 and anything we are legally required to retain. You can also request deletion by email if you no longer have access to the app.

9. Security

All traffic between the app and our servers is encrypted in transit (TLS). Passwords are stored only as salted hashes. Our database enforces row-level security so that each user's data is accessible only to that user (and, for shared content, to the friends or club members it is shared with). Backend functions verify your identity from your authenticated session and never trust client-supplied identifiers for sensitive operations. No system is perfectly secure, but if we become aware of a personal-data breach that risks your rights, we will notify the supervisory authority and, where required, you, in line with the GDPR.

10. Children

Stellary is not directed at children under 13, and you must be at least 13 years old to create an account. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us personal data, contact us at hello@stellary.cloud and we will delete it.

11. Changes to this policy

If we change this policy in any material way — for example because we add a new feature that processes new categories of data — we will update the version and effective date above and notify you in the app, where you will be asked to review your consent choices again. Earlier versions are available on request. Continued use of the Service after a non-material update constitutes acceptance of the updated policy; material changes that require consent will always ask for it explicitly.

12. Contact

Questions, requests, or concerns about your privacy: hello@stellary.cloud.