Privacy Policy
Last updated: July 19, 2026
ChapterPals is a small, independent app for running cozy book clubs. We try to collect as little as possible and to be plain about what we do with it. If anything here is unclear, you can reach us from Settings → Help in the app.
Information we collect
We only collect what we need to run the service:
- Account information: your email address (used for passwordless sign-in) and the name, photo, and profile details you choose to add.
- Club activity: the clubs you create or join, your reading progress and shelves, ratings and reviews, book votes and meeting RSVPs, and the messages you post in club discussions.
- Imported & synced library data: if you upload a library export (e.g. Goodreads, StoryGraph, Libby), the book and shelf data in that file, plus the uploaded file itself for 7 days (see Data retention below). If you instead connect your Goodreads account, we store a read-only key to your Goodreads shelves and re-check them about once a day to keep your shelves in sync, until you disconnect (from Settings → Your library).
- Photos you capture: only if you use the camera to add books (scan a cover or a shelf of books) or set a profile picture. On our iOS and Android apps, the text reading happens on your device and the photo is not sent anywhere. On the mobile web, a cover/shelf photo is sent to Google Cloud Vision (see Third-party services) to read the book titles in it; either way the photo is not stored after that scan. A profile picture you choose is stored with your account. We access the camera only when you tap one of these features.
- Contacts you choose to import: only if you tap Find contacts to invite in the Pals tab, agree to the notice shown before anything is sent, and grant your device's contacts permission. When you do, the names, email addresses, and phone numbers from your address book are sent to and stored on our servers. They are used for exactly two things: showing you which of your contacts already have a ChapterPals account, and sending an invite when you tap to invite someone. We never message anyone on your behalf unless you tap invite, we do not sell or share this data, and no other user can see your contacts. You can delete all of it at any time with Remove imported contacts in the Pals tab, and deleting your account removes it too.
- Usage & device data: analytics about which features are used (the pages you visit and actions like adding a book), session recordings of interactions with the app, plus standard technical logs such as IP address (and the approximate city/country derived from it) and device/browser type, used to operate, secure, and improve the service. We don't use third-party advertising or cross-site tracking.
- Bug reports: when you choose to report a problem (shake-to-report or Settings → Report a bug), we capture a screenshot of the current screen plus diagnostic details (device and browser, connection, language and time zone, and a short trail of your recent in-app actions) so we can reproduce and fix it. This is gathered only when you submit a report. The report is filed to our private issue tracker (GitHub); the screenshot is stored at an unlisted link referenced from that report.
We do not ask for, or store, passwords.
How we use your information
Your data is used to operate and improve ChapterPals: showing your clubs, coordinating meetings, tracking group reading progress, generating recommendations, sending the reminders and digests you've opted into, keeping the service secure, and understanding which features help clubs most. We do not sell your data or share it with advertisers.
Email & notifications
We email you sign-in links and any club notifications you've enabled: meeting reminders, new-book votes, club messages, and reading milestones. Each category is a toggle in Settings → Notifications, and you can turn them off at any time. Sign-in emails are essential to the service and can't be disabled while your account is active.
Analytics & session replay
We use PostHog to understand how ChapterPals is used and to find confusing flows and bugs. It receives product events (for example, opening a club or adding a book) and session replays showing navigation, taps, scrolling, and the app layout. Signed-in sessions are associated with the account's user ID so we can understand and help a specific reader.
Text entered into form fields, rendered discussion messages, and account email addresses are masked before replay data leaves the device. We also disable console-log recording and network request/response bodies and headers, and remove query strings from recorded URLs. PostHog acts only as our analytics processor; this data is not used for advertising or cross-app/cross-site tracking.
Third-party services
We rely on a small number of vendors to run ChapterPals. Each processes data only to provide its function to us and is not permitted to use it for its own purposes. We don't use third-party advertising or cross-site tracking. Our current providers:
- Vercel: application hosting, serverless compute, and image storage (your profile picture, and any bug-report screenshot you submit).
- Neon: the managed database where your account and club data live.
- Resend: transactional email delivery (sign-in codes and notifications).
- GitHub: our issue tracker, where bug reports you submit (including their screenshot and diagnostics) are filed.
- PostHog: product analytics and session replay, as described above.
- Apple & Google: optional “Sign in with Apple / Google,” if you choose it.
- Apple (APNs) & Google (FCM): delivery of the push notifications you enable.
- Open Library & Google Books: book metadata and cover images (we send book titles/identifiers, not your personal data).
- Google Cloud Vision: when you photograph a book cover or a shelf of books to add them, we send that one image to Google Cloud Vision to read the printed text (titles/authors). It processes the image only to return that text to us, is not permitted to use it for its own purposes, and we don't store the photo after the scan.
Cookies
ChapterPals uses a small number of cookies, all first-party. We don't use advertising, cross-site, or third-party tracking cookies of any kind, and we never sell or share this data:
- Session cookie: keeps you signed in. Set when you sign in; cleared when you sign out or it expires. Strictly necessary.
- Sign-in state cookie: a short-lived cookie used only during the few seconds of a "Sign in with Apple/Google" flow, to confirm the request came from you. Strictly necessary.
- Visitor cookie: a long-lived, anonymous identifier so we can tell how many people visit ChapterPals and whether they're new or returning, for our own internal analytics. It isn't tied to ads, isn't shared with anyone, and stops mattering entirely once you're signed in and using the app normally.
All three are HttpOnly (invisible to page scripts) and Secure (sent only over an encrypted connection). The first two are strictly necessary for the app to function; the visitor cookie exists only to help us understand traffic and isn't required for the app to work.
Data retention
We keep your information for as long as your account is active so the app keeps working as expected. When you delete your account, we remove your personal data and content, except where we're required to retain limited records to comply with the law or resolve disputes. Backups are rotated on a regular schedule.
If you import a library file, we keep the uploaded file itself for 7 days so that an import which fails or comes in incomplete can be diagnosed and retried, then we delete it automatically. Deleting your account removes it straight away.
Security
We use industry-standard measures (encrypted connections, scoped access, and reputable infrastructure) to protect your data. No online service can be perfectly secure, but we work to limit what we collect and to guard what we hold.
Your choices and rights
You control your data, and most of these are self-serve in the app:
- Access & edit: view and edit your profile, and manage what you share with your clubs, any time.
- Export: download a copy of your data (profile, shelves, reviews, clubs, and more) from Settings → Your library → Export.
- Delete: permanently delete your account and associated data yourself from Settings → Delete account; it takes effect immediately.
- Notifications: turn any notification category on or off in Settings → Notifications.
- Disconnect Goodreads: stop the ongoing shelf sync any time from Settings → Your library.
- Analytics deletion: ask us at support@chapterpals.com to delete analytics and replay data associated with your user ID.
Depending on where you live (for example under the GDPR in the EU/UK or the CCPA in California), you may have additional rights: to access, correct, port, or delete your personal data, to object to or restrict certain processing, and to not be discriminated against for exercising them. We do not sell your personal data or share it for cross-context behavioral advertising. To make a request or ask a question, email support@chapterpals.com and we'll honor valid requests.
Children
ChapterPals isn't directed to children under 13, and we don't knowingly collect personal information from them. If you believe a child has provided us data, contact us through the app and we'll remove it.
Changes to this policy
As the product matures, we may update this policy. When we make material changes, we'll update the date above and, where appropriate, let you know in the app.
Contact
Questions about privacy? Reach us from Settings → Help in the ChapterPals app and we'll be glad to help.
← Back to ChapterPals