Why ShelfolaCompareImportBrowse books
Sign inCreate account
Home/Privacy policy

Privacy policy

Shelfola is a free, ad-free book tracker at shelfola.com. This page says what we actually store and who can see it.

Updated 6 October 2026

The short version

  • No ads, and we do not sell or rent your personal data.
  • A new profile starts public, including the Want, Reading and Read shelves. Did not finish and Owned stay private. You pick the rest on the welcome step, and you can change it later.
  • We store the account, the books you track, and the things you write. We do not offer a public API or a download of your whole library.

Your account

Signing up asks for an email address and a password (at least 8 characters), plus a display name and a handle. You confirm the email before the account is finished, and you can later sign in with the password or a one-time link. Password resets and email changes use the same login system (Supabase). The handle is public. The email address is not shown on your profile. Moderators can look an account up by email.

Until you finish the welcome step, the profile is public and the Want, Reading and Read shelves are visible. Did not finish and Owned start private. On that step you choose a public or private profile, whether those shelves and your reading stats are visible, and (on a private profile) whether reviews show your name or say “A private reader”. A public profile shows your name on reviews. You can change those later on your settings page, along with a short bio.

We also store the time zone reported by your device, so quiet hours and the weekly email use your calendar, not UTC by accident.

Profile picture

You can upload a picture. We keep a large and a small version, strip the photo’s metadata, and serve them from a public address so other readers can see the picture you chose. You can remove it, and a moderator can remove it. Taking it down deletes the image files we stored for that picture.

Shelves, ratings, reviews, progress and notes

When you track a book we store the shelf (want to read, reading, read, did not finish, owned, or a shelf you named), the edition you picked, quarter-star ratings, reviews (including a spoiler section and the chapter it starts at), reading progress as a percentage, dates, how far you got if you stopped, private notes, tags, lists, moods, content notes, reading goals and challenges, and a year-in-books summary. Notes you attach to a book are for you. Progress stays a percentage, so switching edition does not reset it.

If you play the daily puzzle while signed in, we store that play. Signed-out puzzle progress stays on that device.

Clubs, the feed, and other readers

Clubs and buddy reads store the club, who is in it, checkpoints, and the posts and comments people write. The feed stores posts, comments, likes and @mentions. A public profile can be followed straight away. A private profile approves each follower. You can mute someone (they drop out of your feed) or block them (follows in both directions are removed, and you stop appearing to each other).

Imports

You can bring a library from a Goodreads, StoryGraph or Hardcover export, or from any spreadsheet saved as CSV. Fable has no export, so a spreadsheet is the way across from there. The file is read in your browser. We store the rows you send (titles, authors, ISBNs, shelves, ratings, dates, reviews, notes, tags, lists and moods) and the file’s name. We do not keep the original file. You can undo an import. We do not sign in to those other apps for you.

Email

Product email (a welcome note, replies and mentions, invites, import finished, a weekly email, and the optional follower, like and club notes) is sent with Resend, from notifications@spinefolk.com. That address sends mail. Similar notes are bundled into one message. Quiet hours are on by default (10pm to 8am in your time zone), and non-essential email is capped at 3 a day unless you raise the cap. You can switch each kind to the in-app bell or off, pause product email, or unsubscribe from a link in the message. Login mail (confirming the address, one-time sign-in links, email changes and password resets) is separate and is not part of that cap.

A block in either direction drops that person’s activity from your email. Suspended accounts are not emailed product mail.

Analytics and the error log

The site uses Vercel Web Analytics and Speed Insights. They are cookieless: page views, referrers and loading speed, not an ad profile. We also keep our own error log. When the site breaks, the browser or the server sends the error message, a stack trace, the path (without the query string), and the browser’s user agent. If you are signed in, the log can name your account. Your IP address is not stored; a short-lived hash of it is used only to rate-limit reports. Error groups are kept for 30 days. Moderators can read the log, and they get at most one note a day when something new appears. This log is not used for advertising.

On this device

The sign-in session is a cookie. A time-zone cookie (sf_tz) lasts up to a year. A short-lived cookie remembers that the welcome step is unfinished. The theme, a return path after welcome, and signed-out puzzle progress sit in local storage. Shelf, progress and rating changes made offline sit in a small database in the browser until they can be sent. A service worker may cache pages so the app opens faster. None of that is an advertising cookie.

Reports and moderation

You can report a review, comment, club post, profile, content-warning note, list, feed post or feed comment. The reasons are spam, harassment, hate, spoilers left untagged, inappropriate, or other, plus an optional note. Moderators can hide the content or suspend the account. A suspended reader can still browse and sign out. Likes, ratings, shelves, profile edits, clubs and new reports stay paused until a moderator lifts the suspension.

Deleting your account

There is no delete button in the app. Deleting the login removes the profile, and with it the shelves, ratings, reviews, notes, progress, lists, tags, posts, comments, follows, blocks, mutes and club membership tied to that account. The error log keeps the error text and drops the link to you. Removing a profile picture yourself deletes those image files. Deleting the whole account removes the profile that points at the picture; it does not, by itself, sweep every stored image file. Ask us (see Contact) and we can delete the account for you.

What we don’t do

  • No ads.
  • We do not sell or rent personal data.
  • There is no public API, and there is no export of your library from Shelfola.

The book pages themselves (titles, authors, editions) are the shared catalogue, not your private library.

Changes

If this policy changes, the date at the top changes with it. The Terms are the other half of the agreement.

Contact

Questions about these pages, your data, or deleting your account: hello@shelfola.com.

Track, rate and talk books, honestly.

ProductDiscoverSearchSeriesDaily PuzzleFeatures
Switch to ShelfolaFrom GoodreadsFrom StoryGraphFrom HardcoverFrom FableCompare apps
BlogAll articlesBest book tracking appsExport from GoodreadsSpoiler-free buddy reads
AccountCreate accountSign inBring your books
© 2026 ShelfolaPrivacyTermsGoodreads, StoryGraph, Hardcover and Fable are trademarks of their owners. Shelfola isn’t affiliated with them.