Privacy Policy

NoBookEnds — Last updated: 14 September 2026

NoBookEnds ("we", "our", or "us") is a peer-to-peer book sharing app. This policy explains what personal data we collect, why we collect it, who we share it with, and what happens to it when you delete your account. We've tried to write it plainly, including the parts that are less comfortable to say.

1. Who we are

NoBookEnds is operated by Icarus Apps Limited, a company registered in England and Wales (company number: 16149839). If you have any questions about this policy, or want to exercise any of the rights described below, contact us at agent.gray1911@gmail.com. We're a very small team, so that inbox reaches the founder directly rather than a support desk — you'll get a personal reply, not an automated one.

2. Why we collect it

Most of this rests on it being necessary to provide the service you've signed up for — matching you with nearby books and readers, and letting exchanges happen. Keeping the app working (fixing bugs, understanding usage) rests on our legitimate interest in running a working product. Notifications rely on the permission you give your device. We don't currently offer a separate way to opt out of analytics or crash reporting while continuing to use the app — section 7 says more about what that means.

The newsletter is the one thing here that rests on nothing but your consent: the box you tick when you join, or the form on our website. Nothing else on this list depends on it, and you can take that consent back at any time, from any email we send or by writing to us, without it changing anything about your account.

3. What we collect when you join

We don't collect your phone number.

If someone invited you. If you join NoBookEnds through another reader's invite link, or tell us during onboarding who invited you, we record that connection — which reader invited you, and when. This is a record we keep ourselves, in our own database. No third-party service is involved in making that match — we don't use any outside link-tracking or device-fingerprinting company to connect you to whoever invited you. The reader who invited you can see, in their own account, the readers who've joined through their invite — the same public information described in section 4 (username, display name, and general area). If you weren't invited, or you skip the question, no such record is created. What happens to this record if either of you deletes your account is described in section 10.

Whether you'd like our newsletter. When you set up your account there's an unticked box asking if we may email you now and then about books, readers and what we're building. It's optional, and your account works exactly the same if you leave it alone. We record your answer either way, with the time, the wording you saw and the email address it was given for, so we can always show what you agreed to and to which address. Nothing is sent unless you ticked it, and section 14 says how to stop it.

4. Your profile

You give us a username, and you may add a display name, a short bio, a profile photo, the book you're currently reading, and genres you like.

You also tell us a general area — a town or postcode — which we turn into a set of coordinates using Google Places. Those coordinates are the centre point of that area, not your address, and we don't apply any further adjustment to them because they're already just an area centre.

These profile coordinates, your notification token, and any payment-related identifier aren't part of what other readers can see about you — our database restricts them to your own account. What other readers do see, when they look at your profile, is your username, display name, bio, profile photo, currently-reading book, genres, and the general area label you gave us as text — the town or postcode name itself, not the coordinates behind it. We call this your public profile.

Blocking someone is immediate and needs no review from us. The moment you block another reader they are gone from your app: search, the book feed, comments, followers and your inbox. From that moment our database refuses anything they try to send you, a follow, a request or a message, so nothing of theirs reaches you, even in the short gap before their own app catches up. On their side, you disappear the next time they open a profile or come back to the app. We don't announce it: there is no notification, and nothing on any screen tells a reader they have been blocked. If the two of you had a book in hand, arranging a hand-over or waiting for one, that exchange alone stays in both inboxes with the other person's details removed and marked "On hold", because cancelling it from that thread is the only way to release the book. Blocking doesn't delete anything and doesn't cancel an exchange by itself. It takes effect whether or not you also send a report.

5. Your books, and where they are

When you add a book, we store its title, author, description, genres, any note you write about it, and a location for that book.

Please read this part carefully — it's the part we hold with the most care.

That location usually starts from the area you typed when adding the book. If you've allowed the app to use your device's location, and what you typed matches where your phone thinks you are, we use your phone's GPS position instead as the starting point — accurate to roughly 100 metres. If neither of those is available, we fall back to the general area on your profile (section 4), or to a geocoded version of whatever location label we do have.

Location permission is requested through your phone's normal permission prompt. You can decline it, or turn it off later in your device settings — the app still works, it just relies on typed locations and your profile's general area instead of GPS.

Before that point is ever stored, we move it. A fixed, private offset of roughly 250 metres — generated once for your account and reused for every book you list — is applied to it, in a direction that isn't recoverable from the stored data alone by another reader, or by anyone without direct access to our database. So the location we store for any book isn't your real position; it's a point about 250 metres away from it. This is deliberate protection, not cosmetic rounding, and it applies whether the starting point came from your typed address or your device's GPS.

One trade-off is worth naming plainly rather than glossing over. Because this offset is generated once per account and reused for every book, rather than freshly generated for each one, it isn't independent from book to book. If your real location were ever learned some other way — at an in-person handover, say, or from a photo with identifiable surroundings — that same offset could in principle be worked out for every other book you have listed or will list, not just the one involved. We chose a per-account offset because it's what makes distance-based search work consistently; a fresh offset for every book would break that. We think this is still meaningfully better than showing your real position, but it isn't a guarantee that a location learned once stays hidden for your other books too.

Even so, a 250-metre offset is still a fairly precise point — closer to street-level than to a town or postcode area. We're precise about that distinction because proximity, showing you books that are genuinely close by, is central to how the app works, and it's more precise than the postcode-area point your profile uses (section 4).

Books on your library or looking-for shelf, including this displaced location, are visible to any signed-in reader on NoBookEnds. An account is required — this is not visible to anyone who hasn't signed in.

Your phone also keeps a copy of its last known location in the app's own local storage on the device, until you uninstall the app.

6. Messages, exchanges, and the Book Journey

Can we read your messages? Technically, yes — message content sits in our database in the same way as the rest of your account data, and anyone with direct database access (in practice, the founder) could look at it. We don't have a formal process for doing that today: there's no moderation team reviewing messages, and no routine monitoring. In practice we'd only look if we needed to investigate a safety report, and we don't currently have a formal reporting or escalation process built for that either — section 12 says more about this honestly.

Is message content encrypted? Supabase, our database provider, encrypts all data at rest by default — including your messages — using AES-256, as a standard part of their infrastructure. That's Supabase's own published security practice, not a setting we chose or configured, and it applies to everything in our database, not just messages. It protects against someone getting hold of the physical storage or a backup. It doesn't change the answer above: because our own access goes through Supabase the same way any normal database query does, that encryption doesn't stop us, or anyone with direct database access, from reading message content in the ordinary course of using the database. We haven't added any encryption of our own on top of that — there's no additional scrambling of message text that only the two people in a conversation could undo.

Exchange records and exchange messages are kept indefinitely, on purpose. The Book Journey — the record of every reader a book has reached — is the point of NoBookEnds, and it wouldn't survive if we erased the exchanges behind it. The Book Journey is shown on a book's own page, and is visible to the same people who can see that book at all — any signed-in reader, the same as the rest of the book's listing (section 5). Once someone deletes their account, they appear in it as "A reader" rather than by name. What happens to this when you delete your account is described in section 10.

7. How we learn what's working

Product analytics, through PostHog (servers in the EU). We record a small number of named actions: joining, adding a book, sending a request, accepting one, completing a handoff, and passing a book on again. PostHog is also configured to record which screens you visit (the screen's name only — never which book or message) and when the app is installed, updated, opened, or put in the background, along with technical details about your device — its type and model, operating system, app version, language, and time zone.

PostHog also automatically works out an approximate location from your device's IP address at the time you use the app — city and postal-code level, plus a latitude and longitude for that area. PostHog itself doesn't store your IP address — that's specific to PostHog, and separate from the sign-in IP addresses we store ourselves, described in section 3 — but this IP-derived location estimate is linked to your account. It is separate from, and in addition to, the location you enter yourself described in sections 4 and 5.

Crash and error reporting, through Sentry (servers in Germany). When something goes wrong we receive the error, your device and app details, and a trail of the recent network requests the app made — these can include your account's internal id, but not the content of your messages or what was on your screen. We also sample a portion of app performance data (around one event in five) to spot slow screens. Our app is configured not to attach your IP address to any of this; Sentry's own servers may still see the connecting IP as a normal part of receiving the request, the way any server does.

Both are linked to your account. When you're signed in, your account id is attached to your analytics and crash reports, so this isn't anonymous data — it's tied to you specifically, which is why we're telling you plainly. We stop sending new events the moment you sign out. We don't currently offer a separate way to opt out of analytics or crash reporting while continuing to use the app — using NoBookEnds means this data is collected in the ways described above.

Where we know the retention period, we'll say so rather than pointing you elsewhere. PostHog's plan currently sets analytics retention at around 12 months, though that's their setting rather than something we control, and it isn't strictly enforced as an automatic deletion — data older than that may move into a form of cold storage rather than being deleted outright. Sentry's retention period for crash and error reports is something we haven't verified yet; check Sentry's own policy, or contact us and we'll find out.

We don't track you across other companies' apps or websites, we don't run advertising, and we don't sell your data to anyone.

8. What leaves your phone, and who receives it

Our database, authentication, and file storage are run by Supabase, hosted in Stockholm, Sweden.

Emails the app sends go out through Resend. That covers the note we get when you report something or send us feedback, which carries what you wrote, and any email the app sends to you, which goes to the address on your account. Our sending domain is set up in Resend's European region.

Some of the companies we use are based outside the UK and European Economic Area, including in the United States. Netlify, which runs our website and takes its newsletter signups (section 14). Resend, which sends our email, including that newsletter. Expo and Apple's push-notification infrastructure, and some of Google's services. These are all large, established providers with their own safeguards for data leaving the UK/EEA, but we haven't separately verified which specific legal transfer mechanism each one relies on. If that detail matters to you, contact us and we'll find out.

9. How we share your data — a summary

Putting the sections above together, in one place:

We don't sell your personal data, and we don't run advertising.

10. How long we keep things, and what happens when you delete your account

We don't run any automatic deletion. The data described above is kept for as long as your account is active.

You can delete your account from within the app. If you no longer have the app, nobookends.app/delete-account says how to ask by email. If you have an exchange in progress, you'll need to finish or cancel it first — deletion doesn't currently work around an open exchange. Once you confirm, deletion happens immediately — it isn't queued or delayed.

We know that requirement is a real problem if you need to leave quickly because you feel unsafe about an exchange — you shouldn't have to finish arranging a meetup with someone before you're able to delete your account. If that's your situation: you can block the other reader straight away, regardless of the exchange's status, and you can contact us directly at agent.gray1911@gmail.com for anything urgent — don't wait on the in-app flow. We think this gap in the deletion flow needs fixing, and we're not pretending otherwise by staying quiet about it here.

What's removed entirely: your login and password, your linked Apple sign-in, the IP addresses and device details recorded with your sign-in sessions, your profile (including its coordinates and notification token), any book you listed that nobody has since received from you, your comments, hearts, follows, blocks, saved and wishlisted books, direct messages, notifications, and your profile photo — including the copy held in our file storage. If you joined through another reader's invite, the record connecting you to them (section 3) is removed at the same time.

What's kept but stripped of anything that identifies you: exchange records, notes you left on other readers' books, feedback you sent us, and gift records. In each of these, the text of the record stays, but your username and account id are replaced with a marker, and other readers see you referred to as "A reader" rather than by name. The wording of your exchange request and any reason you gave for a reported issue are part of the exchange record and are kept in this anonymised form. If you invited other readers to join, the record that they joined through your invite survives the same way — it still counts, but it's no longer linked to you.

Chat messages inside an exchange are different: the message text itself is removed, not just your name. When you delete your account, the content of any message you sent is replaced entirely — only the fact that a message existed remains, not what it said. (System messages generated by the app itself, like "handover confirmed," keep their content but lose your name.)

Books connected to a completed exchange: if a book you gave away, or a book you received and haven't since passed on, has a completed handover on record, the book's row stays rather than being deleted outright — it's part of that book's shared history with whoever else touched it, and of any comments or hearts other people added to it — but it's disconnected from your account entirely: no owner, no location, and it can't be exchanged again from your side. A book you listed that was never received by anyone else is deleted outright, along with your comments, hearts, and other data on it.

What isn't removed yet: your history in PostHog (analytics) and Sentry (crash and error reports). We don't currently have an automated way to ask either company to delete the events tied to your account when you delete it, so those events remain, linked to your account id, subject to each provider's own retention policy. We're working on closing this gap, and we'd rather tell you now than wait until it's fixed.

One thing this section doesn't reach. If you also signed up for our newsletter on the website, that address isn't part of your account and deleting the account doesn't unsubscribe you, because nothing links the two. Section 14 says how to stop the newsletter: every newsletter email carries an unsubscribe link, and using it, including any confirmation it asks you for, stops the emails for good. You can also write to the address in section 14 and we'll take you off the list by hand. Neither route needs an account, which matters here, because by then you won't have one, and section 14 says what we keep afterwards.

11. Your rights

If you're in the UK or the EU, you have rights over your personal information, including the right to access it, correct it, ask us to erase it, and object to how we use it. Deleting your account (section 10) is the most direct way to exercise the right to erase what we hold — though, as section 10 explains, it doesn't reach everything immediately. Most notably, your analytics and crash-report history in PostHog and Sentry currently survives account deletion. If erasing that specifically matters to you, contact us directly and we'll look at what we can do by hand while the automated fix is still being built. There's a second thing account deletion doesn't reach, and it's there by design rather than by omission: if you signed up for our newsletter on the website, that email address isn't part of your account, so deleting the account leaves it where it is. Section 14 says how to stop the newsletter, and if you'd rather we erased the address altogether than keep it on our do-not-contact list, ask us and we will.

If you're outside the UK or EU, these specific rights may not apply to you in the same legal form, but we'll still do what we can with any request about your data, regardless of where you're writing from.

You also have the right to complain to a data protection regulator. In the UK, that's the Information Commissioner's Office (ico.org.uk).

To exercise any of these rights, or if you have a question about this policy, contact us at agent.gray1911@gmail.com.

12. Age

NoBookEnds is for readers aged 13 and over. We don't currently verify age — this is a stated minimum, not something we check. If you're under 13, please don't create an account.

If you're 13 to 17, please read this part — it's about you specifically. NoBookEnds puts you in direct contact with people you don't know: they can message you freely, and exchanging a book usually means agreeing to meet in person. That's true for every reader on NoBookEnds, but it matters more if you're a teenager arranging to meet an adult you've only spoken to in an app.

We're going to be honest rather than reassuring: we don't currently have a formal moderation process in place. There's no dedicated safety team reviewing reports, and no established escalation process behind the report and block features in the app. Those features exist and you can use them, but right now there's no guarantee of a timely human response behind them. We think a vague promise here would be worse than telling you plainly that this is still being built.

If you're a parent or guardian with a concern about a young person's use of the app, contact us directly at agent.gray1911@gmail.com rather than relying on in-app tools we haven't finished building — a direct message to us will get a faster, more accountable response right now.

If we learn that an account belongs to someone under 13, we'll remove it. That follows the same account-deletion process described in section 10 — including its current limits. Concretely: the account, profile, books and messages are removed or anonymised as section 10 describes, but analytics and crash-report history tied to that account in PostHog and Sentry is not guaranteed to be removed at the same time, for the same reason it isn't for any other account (section 10, "What isn't removed yet"). We're naming that gap here rather than letting the cross-reference imply a completeness section 10 doesn't actually promise.

13. Security

We use encrypted connections (HTTPS) throughout, and Supabase's authentication to protect your login. Our database applies access rules that restrict what each account can see from other accounts — for example, your profile's coordinates, notification token, and saved books aren't visible to other users under those rules. Content you choose to share, like the books on your public shelf, is visible to other signed-in readers, because that visibility is how the app works; sections 4 and 5 describe exactly what that includes. As with anything stored in our database, direct database access (in practice, the founder) sits outside those per-account rules — section 6 says more about what that means for messages specifically.

If we ever have a personal data breach that's likely to put your rights or freedoms at risk, we'll tell you and the Information Commissioner's Office without undue delay, as UK data protection law requires.

14. Our website, nobookends.app

Everything above is about the app. What a visit to the website involves is described here, and only here. Who we are (section 1), your rights (section 11) and how to reach us (section 16) apply to the website too.

Our newsletter. If you type your email address into the form in our footer and press "Sign up", we add you to the NoBookEnds newsletter. It is an occasional email about books, readers, and what we're building. There is no set schedule and we aren't promising you one: we send it when there's something worth sending. Pressing that button is how you say yes to it, and sending you that newsletter is the only thing the form is for. Every email has an unsubscribe link at the bottom, and using it stops the newsletter for good. There's no account to log into, no password, nothing to pay and no reason to give: if the link asks you to confirm, that confirmation is the whole of it. You can also write to agent.gray1911@gmail.com at any time and we'll take you off the list by hand. Signing up doesn't create an account, doesn't give you anything in the app, and doesn't cost you anything.

Who's writing to you. The newsletter comes from NoBookEnds, which is a trading name of Icarus Apps Limited, the company in section 1. Every email says so at the bottom, with the company number and the address you can write to if you want it to stop.

Where your address is kept. The form is run by Netlify, the company that hosts our website. Your address is stored with Netlify along with the time you sent it and, if you arrived from one of our own social links, the short tag that says which one. That record is how we know when you said yes, which is why we keep it. Before we see a submission, Netlify runs it through Akismet, a spam-filtering service. A copy of each signup is also emailed to us, so your address sits in our inbox too. Netlify also keeps, with each submission, your IP address, your browser's description of itself (its user-agent string) and the address of the page the form was on, and those go when the submission does: if you ask us to erase your address, they are erased with it. The newsletter itself is sent by Resend, which holds your address so that it can send to it and so that it can act on your unsubscribe: the link at the bottom of every email is Resend's, and it is Resend that stops the sending. Netlify and Resend are both United States companies, so what section 8 says about companies outside the UK and EEA applies to both.

How long we keep it. While you're subscribed we keep your address for as long as you want the newsletter. There's no automatic clock on it. When you unsubscribe we stop sending, and your address stays on a do-not-contact list, because keeping it there is the only reliable way to be sure we never write to you again. That list holds your address and nothing else, it's used for one thing only, which is not writing to you, and it lasts as long as we send a newsletter at all. If you'd rather we erased your address completely instead, say so and we'll do that, including the copies held by Netlify and the one in our inbox. The honest trade there is that we'd then have no record telling us not to write to you, if your address ever reached us again some other way. And if we ever stop sending the newsletter, we delete the list, and the do-not-contact list with it, within 30 days.

What we don't do with it. We don't send you anything else. We don't put tracking pixels in the newsletter, so we don't record whether you opened it, when, or what you clicked. We don't sell the list, we don't share it, and your email address never goes to PostHog.

Counting visits. We use PostHog, the same EU-hosted analytics service described in section 7, to count visits to the website. For each page you view it records the page address, including a short tag on links from our own social posts that tells us which post you came from; the page your browser says referred you; and your browser, operating system, device type, screen size, language and time zone. If you send the email form, PostHog also records that a sign-up happened and which tag it carried. Your email address never goes to PostHog. Unlike in the app, PostHog is told not to work out a location from your connection when you visit the website. PostHog keeps this on the same terms as section 7, currently around 12 months, and we use it for one thing: to see which pages and channels are working.

We don't identify you. The website has no login, nothing ties a visit to an app account even if you have one, and we store nothing in your browser to recognise you next time, so each visit counts as a new one. That also means we can't single your visit out to delete it; nothing records which visit was yours.

If you'd rather not be counted. Use the "Don't count my visits" switch on this page. It turns counting off for this browser and stores one thing on your device: the fact that you switched it off, so the site remembers your choice. Nothing else is stored, and you can turn it back on from the same place.

Don't count my visits

15. Changes to this policy

If we make significant changes to this policy, we'll notify you in the app. The "last updated" date at the top of this page always reflects the current version. We'll keep a dated record of earlier versions — contact us if you'd like to see one.

If NoBookEnds is ever acquired, merged with another company, or shut down, your data would either transfer to whoever continues running the service, under a policy at least as protective as this one, or be deleted. We'd tell you which, and before it happened, not after.

16. Contact

Questions or requests: agent.gray1911@gmail.com