Privacy Policy
Effective date: 1 August 2026 · Version 1.6
Stellary is a reading-tracking app that lets you build a library, log reading sessions, set goals, keep streaks, and read together with friends in clubs. This Privacy Policy explains what personal data we collect when you use the Stellary mobile application and the website stellary.cloud (together, the "Service"), why we collect it, and the rights you have over it.
We designed Stellary to collect as little personal data as possible. We do not sell your data, we do not show ads, we do not use third-party advertising or tracking SDKs, and analytics is off unless you switch it on. The only third-party diagnostic tool we use is a crash-reporting service, described in section 2.2.
1. Who is responsible for your data
The Service is operated by Mattias Olandersson and Olle Larsson, private individuals based in Sweden (together, "we", "us"). We are jointly responsible as data controllers under the EU General Data Protection Regulation ("GDPR"). You can reach us about anything in this policy at hello@stellary.cloud; we have agreed that this shared inbox is the single contact point for privacy matters.
2. Data we collect
2.1 Data you give us
- Account data. When you create an account: your email address, a username/display name, and either a password (stored only in salted, hashed form by our authentication provider) or — if you use Sign in with Apple or Sign in with Google — a sign-in token from Apple or Google confirming your identity (we never see your Apple or Google password). You can use parts of Stellary anonymously before creating an account; an anonymous session has a random identifier and no email.
- Your reading data. The books you add to your library, your reading status and progress, reading sessions (when and how many pages you read), reading goals, and streaks.
- Social content. Book clubs you create or join, posts you write in clubs, club membership, friendships, and friend invites. Your username and reading activity you choose to share are visible to your friends and fellow club members. You can set your profile to private in Settings at any time, which hides your library and reading activity from friends (your username and avatar remain visible, and clubs you take part in are unaffected); this is enforced on our servers, not just in the app.
- Profile customizations. Your chosen avatar style and similar appearance settings. By default, avatars are generated on your device from preset styles. You can optionally upload or take a profile photo instead. The photo is resized and re-encoded on your device before upload, a step that also strips hidden metadata such as the location where it was taken (EXIF); it is then stored in a publicly readable storage bucket at a random, unguessable address so it can be shown wherever your avatar appears in the app. If your profile is set to private, readers who are not your friends are shown your preset-style avatar instead of your photo. Uploading a photo is never required, and you can replace or remove it at any time in the avatar picker; replaced or removed photos are deleted from storage.
- Book cover photos. From a book's detail page, you can optionally photograph or choose a photo from your device to use as that book's cover instead of the catalogue image. Like a profile photo, it is resized and re-encoded on your device before upload — stripping EXIF metadata such as location — and stored in a publicly readable storage bucket at a random, unguessable address. Replacing it with a different photo or a catalogue cover deletes the old upload from storage.
- Friend invitations. If you invite a friend by email, we process the email address you enter in order to send a one-time invitation email. We use it only for that invitation and the invite record; we do not add it to any marketing list.
- In-app feedback. If you use the Help & Feedback form in the app, we store your message and its category, together with your app version and platform, and — only if you choose to provide one — an email address for replies.
- Reports. If you report a club post or another reader, we store a report record — a reference to the reported content or account, a short excerpt of the reported content, the reason you give, and your user ID as the reporter — solely so we can review the report and act on it. Report records are visible only to us; the reported reader is not told who reported them.
- Support messages. If you email us, we receive your email address and whatever you include in the message.
2.2 Data collected automatically
- Usage analytics (opt-in only). If — and only if — you consent in the app, we record product events (for example "opened app", "logged a session") together with your user ID, timestamp, and app context, in our own database. No third-party analytics service is used. If you never consent, or you withdraw consent in Settings → Privacy, these events are not recorded. We also keep a record of your consent choice and when it was made, as required by law.
- Device locale. The app reads your device language/region setting to display content appropriately. It is used on the device and is not used to profile you.
- Crash reports. If the app crashes or hits an unexpected error, technical diagnostic data — device model, operating-system and app version, and the technical trace of the error — is sent to our crash-reporting provider, Sentry, together with your account identifier (the same internal ID used elsewhere in the Service). Crash reports are configured to exclude personal content and message contents, and are used solely to find and fix bugs — never for advertising or profiling.
- Technical logs. Our backend keeps short-lived technical logs — rate-limit counters and server error logs — needed to run the Service securely and reliably; these are anonymous and are kept regardless of your analytics choice. Separately, when you opt in to usage analytics, we also time how individual backend actions performed (for example, how long a search or sign-in took, and whether it succeeded) and tie those measurements to your user ID; that data is part of the opt-in analytics above, not this always-on log.
2.3 Notifications, and data we do not collect
We do not collect your precise location, contacts, photo library (the only photos we ever receive are a profile photo or a book-cover photo you choose to upload — see section 2.1), health data, browsing history, or advertising identifiers. We do not track you across other companies' apps or websites.
Personal reading reminders — the daily reminder, streak-at-risk, goal-pace, and monthly-report notifications — are scheduled locally on your device and never touch our servers. Social notifications (a friend request, a friend accepting your request, a new note in one of your clubs, a reaction to your reading, or a buddy-read progress update) work differently: to deliver them, we store a push token for your device — a random identifier issued by the Expo push service — on our servers, together with your notification preferences (which categories you want, and any clubs you have muted). Both are protected by row-level security so only you can access them. Push messages are delivered through the Expo push service (see section 4), which relays them to Apple or Google for delivery to your device. Your push token is deleted when you sign out on that device, when you delete your account, and automatically when the push service reports that the device is no longer registered (for example, after you uninstall the app).
3. Why we use your data and our legal bases
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing your account, syncing your library, sessions, goals, streaks, clubs, and friends across devices | Account data, reading data, social content, customizations | Performance of a contract (Art. 6(1)(b)) |
| Sending a friend-invitation email you request | Invitee's email address, your username | Legitimate interest in delivering an invitation you initiated (Art. 6(1)(f)); the invitee can decline and the address is not reused |
| Delivering the social notifications you have switched on | Push token, notification content | Performance of a contract (Art. 6(1)(b)); each category can be turned off in Settings or at OS level |
| Remembering your notification preferences across devices | Notification category settings, per-club mutes | Performance of a contract (Art. 6(1)(b)) |
| Understanding how Stellary is used so we can improve it | Opt-in product events | Your consent (Art. 6(1)(a)) — withdrawable at any time in Settings → Privacy |
| Keeping the Service secure: authentication, abuse prevention, rate limiting | Account data, technical logs | Legitimate interest (Art. 6(1)(f)) |
| Diagnosing crashes and technical errors | Crash reports | Legitimate interest (Art. 6(1)(f)) |
| Complying with legal obligations | Consent records, export/deletion audit records | Legal obligation (Art. 6(1)(c)) |
| Responding to support requests and in-app feedback | Support messages, in-app feedback | Legitimate interest (Art. 6(1)(f)) |
| Suggesting books you might enjoy (premium recommendations) | Your library/ratings matched against aggregated, non-identifying reading patterns | Performance of a contract (Art. 6(1)(b)) |
| Reviewing reports of objectionable content or behavior | Report records | Legitimate interest (Art. 6(1)(f)) |
We do not use your data for advertising, we do not sell or rent it, we do not use it to train AI models, and we do not make automated decisions with legal or similarly significant effects about you. Data collected for one purpose is not reused for an incompatible purpose without asking you first.
4. Third parties and processors
We share personal data only with the service providers below, who process it on our instructions under data-processing agreements. Each of them is contractually required to protect your data to at least the same standard as this policy and applicable law. We never share your data with advertisers or data brokers, and no third-party AI service receives your personal data.
| Provider | Role | Data involved |
|---|---|---|
| Supabase, Inc. | Database, authentication, backend and file-storage hosting | All account, reading, social, consent, and analytics data described above, and any profile or book-cover photo you upload |
| Resend, Inc. | Email delivery | Recipient email address and email content |
| 650 Industries, Inc. (Expo) | Push-notification delivery | Device push token and notification content, relayed to Apple/Google. Never your email, username, or library |
| ISBNdb and Internet Archive (Open Library) | Book search and metadata | Search text sent by our backend; cover images loaded directly by the app (so that provider sees your device's IP). Your identity and account data are never shared |
| Google LLC | Optional Sign in with Google | Google account email address and sign-in token |
| Apple Inc. | App distribution, optional Sign in with Apple, payment processing, support inbox hosting | Purchases handled entirely by Apple; sign-in email and token if used; support inbox receives your email and message content |
| RevenueCat, Inc. | Subscription management | Your account identifier (the same internal ID used elsewhere in the Service) and purchase/entitlement status. Never your name, email, or payment details |
| Functional Software, Inc. (Sentry) | Crash reporting | Crash data with your account identifier (the same internal ID used elsewhere in the Service) — never your email, username, or reading data |
| Railway | Hosting for our internal operations and moderation dashboard | Account, reading, social, and report data described above, queried directly from Supabase; the dashboard is accessible only to us as the app's operators |
We may also disclose data if required to do so by law or a valid legal order, or to protect the rights, safety, or property of our users, ourselves, or others — and, if the Service is ever transferred to a company or new owner, to that successor under this same policy (we would notify you first).
5. International transfers
We are based in Sweden and aim to keep data storage within the European Economic Area (EEA) where feasible. Some of our providers (including Resend, RevenueCat, Sentry, Expo and, depending on configuration, Supabase and Google) may process data in the United States. Where personal data leaves the EEA, we rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework for certified providers and/or the EU Standard Contractual Clauses, together with additional safeguards where appropriate. You may contact us for details of the safeguards applied to a specific transfer.
6. How long we keep data
- Account and reading data: kept while your account exists; deleted when you delete your account.
- Profile photo: kept until you replace or remove it (the old photo is deleted from storage) or delete your account.
- Raw analytics events: automatically deleted after 90 days. Only aggregated, non-identifying statistics are kept longer. Withdrawing consent erases raw events immediately.
- Backend technical logs and performance events: automatically deleted after 30 days.
- Crash reports: retained by our crash-reporting provider for around 90 days, then deleted automatically.
- Push tokens and notification preferences: deleted on sign-out, account deletion, or automatically when the device is no longer registered.
- Consent records: kept as long as needed to demonstrate consent was validly given or withdrawn.
- Friend-invite records: kept until accepted, declined, or expired.
- Export/deletion audit records: a minimal record (user ID and timestamp, never the exported content) is kept to document that we handled your request.
- In-app feedback, reports, and support emails: kept as long as reasonably needed; report records are deleted with your account.
7. Your rights
Under the GDPR you have the right to: access the personal data we hold about you; rectify inaccurate data; erase your data; restrict or object to certain processing (including any processing based on legitimate interest); data portability (receive your data in a machine-readable format); and withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
You can exercise the most important rights directly in the app: Settings → Privacy lets you withdraw analytics consent instantly, the export function delivers a machine-readable copy of your data, and the delete account function erases your account (see section 8). For anything else, email hello@stellary.cloud and we will respond within one month.
You also have the right to lodge a complaint with a supervisory authority. In Sweden, that is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), www.imy.se. If you live elsewhere in the EU/EEA, you may complain to your local authority instead.
8. Deleting your account and data
You can delete your account at any time from within the app (Settings → Account → Delete account). Deletion is performed by our backend and permanently removes your account together with your profile, profile photo, library, reading sessions, goals, streaks, club memberships and posts, friendships, customizations, push tokens, notification preferences, and analytics events tied to your account. Content you posted in shared spaces is removed or disassociated from you. Deletion is not a deactivation — the data is actually erased, apart from the minimal audit record described in section 6 and anything we are legally required to retain. You can also request deletion by email if you no longer have access to the app.
9. Security
All traffic between the app and our servers is encrypted in transit (TLS). Passwords are stored only as salted hashes. Our database enforces row-level security so that each user's data is accessible only to that user (and, for shared content, to the friends or club members it is shared with). Backend functions verify your identity from your authenticated session and never trust client-supplied identifiers for sensitive operations. No system is perfectly secure, but if we become aware of a personal-data breach that risks your rights, we will notify the supervisory authority and, where required, you, in line with the GDPR.
10. Children
Stellary is not directed at children under 13, and you must be at least 13 years old to create an account. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us personal data, contact us at hello@stellary.cloud and we will delete it.
11. Changes to this policy
If we change this policy in any material way — for example because we add a new feature that processes new categories of data — we will update the version and effective date above and notify you in the app, where you will be asked to review your consent choices again. Earlier versions are available on request. Continued use of the Service after a non-material update constitutes acceptance of the updated policy; material changes that require consent will always ask for it explicitly.
12. Contact
Questions, requests, or concerns about your privacy: hello@stellary.cloud.