Privacy policy
My Pocket Library is a reading tracker made by DNA TECHBASE S.R.L. ("we", "us"), a company registered in Romania. This policy explains what the app stores about you, why, where, and how to remove it. It applies to the website at my-pocket-library-app.web.app and to the iOS and Android apps.
Who is responsible
DNA TECHBASE S.R.L., Aleea Romanilor Nr. 23, Bl. 12, Sc. 2, Ap. 107, Deva, Hunedoara, Romania (trade register J2025048383009, CUI 52084942) is the data controller. Write to contact@dnatechbase.com for anything in this policy.
What we store, and why
| Data | Why | Where it comes from |
|---|---|---|
| Account: email address, display name, a user ID; for Google or Apple sign-in, the identifier those services give us | To sign you in and keep your library yours | You, or Google / Apple when you sign in with them |
| Your library: books, shelves, reading status, pages read, ratings, notes, and the arrangement of objects on your shelves | This is the app: it is what you asked us to keep | You, plus book details (title, author, publisher, page count, description, cover image address) fetched from the catalogues below |
| Photos you take or choose: book covers, spines, backs, and pictures placed in frames | Shown on your shelves | Your camera or photo library, only when you choose a photo |
| Profile: display name, style-quiz answers, the Atlas starting place | To make the library look the way you chose | You |
| Location (one point): the latitude and longitude of your Atlas starting place, with the nearest city's name | Only if you press "Use where I am" on the Atlas; you can pick a city instead and the app never asks otherwise | Your device, with your permission |
We do not run advertising, analytics or tracking in the app, and we do not sell or share your data for advertising. The app does not collect your contacts, precise movements, or anything from other apps.
Services that process data for us
- Firebase (Google LLC) — sign-in (Firebase Authentication), the database that holds your library and profile (Cloud Firestore), and the storage for your photos (Cloud Storage), in Google Cloud's us-central1 region. Google processes this data under our instructions and its own data-processing terms.
- Google Books and Open Library — when you add a book, the app looks up its ISBN or title in these public catalogues. The request carries the ISBN or title you typed or scanned, not your identity.
- Google Gemini — only when you press "Ask AI to read the cover". The compacted cover photo is sent, through our own server function, to Google's Gemini API to read the title and author printed on it. Nothing is sent until you press that button, and the caption under it says so. We do not store the photo on that path beyond answering the request. We use the paid Gemini API, under which Google does not use prompts or responses to train or improve its models, and processes them under the Google Cloud Data Processing Addendum.
Where your data is processed
Your account, library and photos live in Google Cloud's us-central1 region, in the United States, and the AI cover reading is answered there too, so your data leaves the European Economic Area. Google acts as our processor under the Google Cloud Data Processing Addendum, which incorporates the European Commission's standard contractual clauses as the safeguard for those transfers.
What the app keeps on your device
The app stores things locally so it opens quickly and works offline: a copy of your library and profile in the app's own database, your sign-in session so you are not asked for a password every time, and two small markers — whether you have seen the welcome tour, and which Atlas badges have already been celebrated on this device. We do not send any of that anywhere, and it goes when you sign out, delete the account, or clear the app's data.
Server logs
When the app calls one of our server functions — reading a cover with AI, or deleting an account — Google Cloud records a technical log for us with the time, the outcome, your account identifier and the usual request metadata such as an IP address. We use these only to keep the service working and secure, and they are discarded on Google Cloud's standard schedule, within 30 days.
Automated decisions
Nothing about you is decided automatically. The AI cover reading only suggests a title and author for you to accept or reject; it has no effect on your account.
Text recognition of a cover photo on the device ("reading" the cover before you ask AI) happens in the app itself; that photo does not leave your device for it.
Legal bases (for readers in the EU/EEA)
- Keeping your account and library: performance of our contract with you (the terms of use).
- Location and the AI cover reading: your consent, given by pressing the button each time; you can decline or withdraw by not using them, and change or clear your Atlas place at any time.
- Keeping the service secure and preventing abuse: our legitimate interest.
How long we keep it
For as long as your account exists. When you delete your account, your library, photos, profile and sign-in are erased at once; residual copies in backups are removed within 30 days. Photos that leave the device for the AI cover reading are not stored by us on that path.
Deleting your account
In the app: Profile → Delete account, or, if you have not yet confirmed your email address, from that verification screen. You are asked to confirm it is you — your password, or a fresh sign-in with Google or Apple — and then everything listed above is erased and your sign-in is removed. You can also ask by email from the address on your account: contact@dnatechbase.com. See Delete your account for details.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to its processing, and to receive it in a portable form. Write to contact@dnatechbase.com. You may also complain to your data-protection authority; ours is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP, dataprotection.ro).
Children
The app is not directed at children under 16, and we do not knowingly keep accounts for them. If you believe a child has an account, write to us and we will remove it.
Security
Data travels over HTTPS only. Your library and photos are readable only by your own signed-in account, enforced by server-side rules; shared catalogue data is read-only for readers.
Changes
If this policy changes, the new version is posted here with a new effective date. Material changes are also announced in the app.