Legal

Privacy policy

Effective 23 July 2026 Replaces the version effective 12 May 2026

Short version

We collect only what is needed to run Cratelog, never sell your data, and let you delete your account and data from Settings at any time.

  • No advertising, no cross-app tracking, and no analytics linked to your account or identity.
  • Book metadata comes from public catalogues; your subscriptions, collection and notes stay private to your account.
A plain-language summary for orientation. The numbered clauses below are the policy that applies.

1. Who this policy applies to

1.1 This Privacy Policy applies to people who create an account, browse, or otherwise use Cratelog.

2. What we do not do

2.1 Cratelog does not:

  • sell personal data;
  • show third-party advertising;
  • use advertising identifiers or cross-app tracking;
  • link analytics data to your account, email address, or identity; or
  • use your reading, collection, or subscription data to build advertising profiles.

3. Data controller

3.1 The controller of personal data processed through Cratelog is Michał Przybyła, an independent developer operating Cratelog. The operator can be reached using the contact details in the in-app legal notice and in the Operator and contact section of this Policy.

3.2 If required by applicable law, Cratelog will designate and publish a Data Protection Officer or other privacy contact.

4. Personal data we collect

4.1 Depending on how the Service is used, Cratelog may collect the following categories of personal data.

Account and identity data

  • Name or display name
  • Email address
  • Authentication identifiers from sign-in providers such as Apple or Google
  • Account preferences

Subscription and collection data

  • Saved subscription services, plans, billing dates, skip settings, waitlist entries, notes, and spending information
  • User-created collection records, book metadata, special-edition attributes, and related notes
  • Reminder and notification preferences

Device and technical data

  • App version
  • Device type
  • Operating system
  • Push notification tokens (where notifications are enabled)
  • Device time zone (used to deliver reminders at the right local time)
  • Crash diagnostics and error logs, linked to your account identifier but not your email address
  • IP address or approximate location derived from network traffic where technically necessary for security and service delivery

Communications data

  • Messages sent to customer support
  • Survey responses
  • Feedback submissions
  • Reports of missing services, issues, or bugs

Data from integrations and third parties

4.2 Where enabled, Cratelog may import limited book-related metadata from third-party sources such as public book databases or authentication providers.

5. How we collect data

5.1 Cratelog collects data:

  • directly from users, for example when they sign up, fill in profile data, add subscriptions, add books, change settings, or contact support;
  • automatically when they use the Service, for example through logs, diagnostics, and essential technical events; and
  • from third parties, for example identity providers, support systems, and external metadata sources used to complete user-requested actions.

6. Camera and barcode scanning

6.1 Cratelog may request camera access so you can scan ISBN barcodes when adding books. Scanning happens entirely on your device. The camera image is used only to detect the barcode; no photos or camera frames are stored, uploaded, or shared.

7. Book search and metadata lookups

7.1 When you search for a book, scan an ISBN, or import books, the search query or ISBN is sent to Cratelog's backend, which may query public book databases such as the Google Books API to fetch titles, authors, covers, and other metadata.

7.2 These requests contain only what you submit as part of the lookup. They do not include your library or other account data.

8. Data imports

8.1 Cratelog can import your library from files such as Goodreads CSV exports. The file is read on your device, and only the records you choose to import are stored in your account, the same way as books you add manually. Metadata lookups for imported books work as described above.

9. Community contributions

9.1 Cratelog lets you submit missing subscription services, books, editions, sales, and releases to the shared catalog. Submissions are reviewed before publication. Approved content becomes part of the catalog visible to all users; it is shown without your name or any public attribution.

9.2 Submission records are linked to your account identifier for moderation and abuse prevention. Approved catalog content may remain in the shared catalog after your account is deleted, as described in the Terms of Service.

10. Purposes of processing

10.1 Cratelog may process personal data to:

  • create and manage user accounts;
  • provide the core Service, including tracking subscriptions, waitlists, books, reminders, and spending;
  • authenticate users and secure accounts;
  • send transactional communications, service notices, and reminders;
  • respond to support requests;
  • improve reliability, performance, and usability of the Service;
  • detect abuse, fraud, security incidents, and violations of the Terms; and
  • comply with legal obligations and enforce legal rights.

11. Legal bases for processing

11.1 Where the GDPR, UK GDPR, or similar laws apply, Cratelog may rely on one or more of the following legal bases:

  • Performance of a contract: to provide the Service requested by the user.
  • Legitimate interests: to secure, improve, and administer the Service, after considering users' rights and reasonable expectations and where those interests are not overridden by those rights.
  • Consent: where required, for example for optional marketing or certain tracking technologies.
  • Legal obligation: where processing is required by law.

11.2 For example, account creation and subscription tracking rely on performance of a contract, while security, fraud prevention, and product improvement rely on legitimate interests.

11.3 Where consent is used, it should be freely given, specific, informed, and unambiguous.

12. How we share data

12.1 Cratelog does not sell personal data. Personal data may be shared only as necessary with:

  • cloud hosting and infrastructure providers;
  • authentication providers;
  • crash reporting and customer support vendors;
  • email or push notification service providers;
  • legal, regulatory, or law-enforcement authorities when required; and
  • a buyer or successor in connection with a merger, acquisition, financing, or asset sale, subject to appropriate safeguards.

13. International transfers

13.1 If personal data is transferred outside the European Economic Area, the United Kingdom, or other jurisdictions with transfer restrictions, Cratelog will use an appropriate transfer mechanism, such as adequacy decisions, standard contractual clauses, or another lawful safeguard where required.

14. Data retention

14.1 Cratelog retains personal data only for as long as necessary for the purposes described in this Privacy Policy, including to provide the Service, comply with law, resolve disputes, maintain security records, and enforce agreements.

14.2 Typical retention logic may include:

  • account data for as long as the account remains active;
  • support records for a limited period after the request is closed;
  • security logs and diagnostics for a shorter operational period unless an incident requires longer retention.

14.3 When a user deletes their account, personal data is deleted or anonymized within a reasonable period, unless retention is required by law.

15. Security

15.1 Cratelog uses reasonable technical and organizational measures (including encryption in transit, access controls, and data minimization practices) designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.

15.2 No method of storage or transmission is completely secure. Users are responsible for maintaining the confidentiality of their credentials and notifying Cratelog if they suspect unauthorized access.

16. User rights

16.1 Depending on applicable law, users may have the right to:

  • access their personal data;
  • correct inaccurate data;
  • delete personal data;
  • restrict or object to certain processing;
  • receive a portable copy of certain data;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with a supervisory authority.

16.2 Users may exercise these rights by contacting the privacy contact listed in the app's legal notice. Cratelog may need to verify identity before completing a request.

17. Children

17.1 Cratelog is not intended for children under the age required by applicable law to use the Service independently, typically under 16 in the European Economic Area, or the equivalent age set by local law. If Cratelog becomes aware that personal data was collected from a child in violation of applicable law, that data will be deleted or otherwise handled as required.

18. Cookies and similar technologies

18.1 By default, the Cratelog website (cratelog.club) uses only technologies that are strictly necessary to provide it. For example, local storage used to complete authentication flows such as password resets, and local storage used to remember your cookie choice described below. It does not use advertising cookies.

18.2 The website also uses Google Analytics (GA4) to understand which pages are visited and how people find the app, using Google's Consent Mode. The underlying script loads on every visit, starting in a denied state in which Google does not set analytics cookies or store data that identifies you; it only switches to using cookies and fuller measurement after you accept the cookie banner shown on your first visit. Declining, or leaving the banner unanswered, keeps analytics storage denied. Cratelog does not use Google Analytics for advertising, and the ad-related consent signals (ad_storage, ad_user_data, ad_personalization) are always kept denied.

18.3 You can change your choice at any time from the "Cookie settings" link in the website footer, which clears the stored choice and shows the banner again.

18.4 This section covers the marketing website only. The Cratelog app itself does not use Google Analytics or any cookie-based tracking; see the section below for the anonymous, on-device analytics the app uses instead.

19. Anonymous product analytics

19.1 Cratelog uses TelemetryDeck, a privacy-focused analytics provider, to understand which screens and features are used and where users drop off during onboarding.

19.2 This analytics data is collected under a randomly generated installation identifier stored only on your device. It is never linked to your account, email address, or any other identifier that could reveal who you are, and it does not include IP address, precise location, or the content of your subscriptions, collection, or notes.

19.3 Because this analytics does not process personal data about an identified or identifiable person, no separate consent banner is shown for it.

20. Third-party services we use

20.1 Cratelog uses the following services to run the app:

  • Supabase for backend hosting, authentication, database, and file storage. Cratelog's data is hosted in the European Union (eu-west-1, Ireland).
  • Sentry for crash and error diagnostics. Reports include technical data such as app version, device model, operating system, and stack traces, linked to your account identifier but not your email address.
  • TelemetryDeck for anonymous product analytics, described above. TelemetryDeck does not receive your account identifier, email address, or any data that could identify you.
  • Expo's push notification service, which delivers notifications through Apple Push Notification service on iOS and Firebase Cloud Messaging on Android.
  • Apple and Google as optional sign-in providers.
  • Google Books API for book metadata lookups.
  • Frankfurter (ECB-sourced exchange rates) for currency conversion. These requests contain no personal data.
  • Apple App Store and Google Play for app distribution and, if paid features are offered, payment processing.

20.2 These services process data under their own privacy policies and terms.

20.3 Separately, the marketing website (cratelog.club, as opposed to the app itself) uses Google Analytics on a consent basis, described in section 18.

21. App stores and third parties

21.1 When the mobile app is downloaded through the Apple App Store or Google Play, those platforms may independently process user data under their own privacy notices. Cratelog is not responsible for the privacy practices of third-party services it does not control.

22. Changes to this policy

22.1 Cratelog may update this Privacy Policy from time to time. If changes are material, Cratelog will provide notice through the app, website, or email before or when the change becomes effective. Continued use of the Service after the effective date means the updated Privacy Policy applies, to the extent permitted by law.

23. Operator and contact

23.1 Cratelog is operated by Michał Przybyła, an independent developer. Privacy questions and requests under clause 16 should be sent to support@cratelog.club.

This policy is provided for information and does not constitute legal advice. Where a translated version differs, the English version applies.