Draft pending legal review. The processing described below reflects how the software actually behaves, but the highlighted values must be completed and the whole document reviewed by a qualified adviser before it is relied upon.
Who we are
Book Buddy is a digital library and reading platform operated by [registered entity name], [registered address]. For any privacy question, contact [privacy contact email].
What we collect
We hold the following, and nothing beyond it:
- Account details — your name, email address, and (where you supply them) a phone number, avatar and student identifier. Passwords are stored only as a bcrypt hash.
- Institution membership — which institution you belong to, your role there, and any join requests you submit.
- Reading activity — the books you borrow, your position in them, time spent per page, daily reading totals and streaks.
- Study content you create — highlights, notes, bookmarks, flashcards, saved vocabulary and uploaded personal files.
- AI interactions — questions you ask Varta, the answers returned, quiz attempts, and per-concept mastery estimates derived from them.
- Technical data — session tokens, login attempts (including failures, for account-lockout protection), device push tokens if you use the mobile app, and error reports.
Why we process it
To provide the service you signed up for: authenticating you, showing the right catalogue for your institution, restoring your reading position, answering your questions about a book, and adapting study material to what you have and haven't mastered. Login-attempt records exist to protect your account against brute-force access. Aggregate reading statistics may be shown to your institution's administrators in a form that does not identify individual passages you read.
Who it is shared with
We do not sell personal data. It is shared only with the processors that make the product work:
- Resend — transactional email delivery.
- OpenAI — generating embeddings and answers for AI study features. Your questions are sent as part of that request.
- Object storage and CDN ([Cloudflare R2 / AWS]) — storing book files and your uploads.
- Expo — mobile push notification delivery.
- Self-hosted error monitoring — crash and error reports, on infrastructure we operate.
- Linked applications — where you use a linked account, identity and shared course content are exchanged with the connected partner applications you choose to link.
Retention
Account and study data is retained while your account is open. You can ask to delete your account at any time from Settings or at /delete-account; we email a link to confirm, and confirming removes your personal data, the study content attached to it and the files you uploaded. AI conversation history can be cleared separately without deleting the account. Retention periods for backups and audit logs are [retention period].
Your rights
You can access, correct, export or delete your personal data. Downloading a copy of your data (Settings → Data & privacy), account deletion and AI-history deletion are self-service; for anything else, write to [privacy contact email] and we will respond within [response window].
Children
The platform is used in schools. Where a student is below the age of consent in their jurisdiction, the institution acts as the controller for that account and is responsible for obtaining any consent required. [Confirm this framing with your adviser.]
Changes
Material changes to this policy will be notified in-app before they take effect.