Bookward
Bookward Privacy Policy
Effective date: September 16, 2026
Last updated: September 16, 2026
This Privacy Policy explains how Daniel de Azcárate Muñoz, the person responsible for Bookward, handles information when you use the Bookward application for iOS and Android, its account and cloud backup features, and related support channels. Bookward is designed so that your library, notes, and reading sessions remain primarily on your device. We only send information off the device when you use a feature that requires it, such as searching for books, signing in, uploading a backup, using social features, managing a purchase, enabling analytics, or contacting support.
You can use the core features without creating an account. Some optional features require connectivity, device permissions, or an account. If you do not agree with this Policy, do not use those features or the Service.
1. Controller and contact
The data controller is Daniel de Azcárate Muñoz, with a contact location in Málaga, Andalusia, Spain. For questions, privacy requests, or support, use the Bookward contact form:
- Bookward contact form — https://tally.so/r/kd2ekj
2. Information we process
2.1 Data stored on your device
Bookward stores the information needed to organize and enjoy your reading locally. This may include:
- Your library, reading status, progress, goals, collections, tags, sessions, and statistics.
- Notes, ratings, reminders, preferences, reading-nook scenes, and app settings.
- Book covers, book photos, and profile photo you select or capture.
- Local subscription status, technical installation identifiers, and analytics preferences.
This data remains in the app's private storage until you delete it, erase the app's data, or uninstall Bookward. The widget may display a limited copy of information you selected for that feature in the operating system.
2.2 Camera, photos, and book recognition
With your permission, Bookward uses the camera to scan ISBNs and photograph covers and may access photos you select. Visual recognition and image cropping take place on the device. Selected photos are copied to Bookward's private storage. Bookward does not access your entire photo library where the system lets you select specific items.
To identify a book, recognized text, ISBN, title, or author used in a search may be sent to the Bookward API and catalog providers. We do not send the original photo to perform the search unless a future feature clearly states this and asks for the relevant permission.
2.3 Searches and catalog data
Book and series searches may include a title, author, ISBN, language, and other necessary criteria. The Bookward API may query Google Books, Open Library, ISBNdb, and Wikidata, return metadata and covers, and temporarily cache results to improve performance and limit requests. Providers may receive technical network data, such as the Bookward server's IP address, under their own policies.
2.4 Account and sign-in
An account is optional. If you sign in with Apple or Google, we process the provider's user identifier, the email address the provider shares with us, the linked provider, session tokens, and data needed to maintain and secure the account. We do not receive your Apple or Google password. Sensitive tokens are encrypted or stored in the device's secure storage.
2.5 Private cloud backups
When you choose to create an account backup, Bookward uploads the information included in that backup, which may contain your library, sessions, notes, collections, preferences, scenes, and included personal images. There is no continuous automatic backup. We retain no more than the three most recent backups for each account; older backups are deleted when a new one is uploaded. Backups and their images are stored in private infrastructure and are only delivered to an authenticated session belonging to their owner.
2.6 Social profile, connections, suggestions, and votes
If you use an account, Bookward creates a profile with an initial technical username. You can change your display name and username. The profile is private by default. If you make it public, other readers can find and see your display name, username, and number of books read, and they can follow you. Specific books, notes, photos, and backups are not published through your profile.
Suggestions you submit are stored with your account and may be reviewed before publication. An approved suggestion may display its title, description, status, and vote count. We do not publicly display the author's email address or the identity of voters. Follows, suggestions, and votes are deleted with the account unless retention is strictly necessary to meet legal obligations or resolve abuse.
2.7 Subscriptions and purchases
Apple App Store or Google Play processes payment. Bookward does not receive your full card or bank account details. RevenueCat receives an installation or account identifier and transaction data such as the product, subscription status, trial, expiration date, and renewal status so that premium features can be activated and restored.
2.8 Limited analytics and diagnostics
When analytics is enabled, Bookward uses EU-hosted PostHog to measure a limited set of app opens, onboarding steps, categorized searches and scans, timer usage, permissions, backups, errors, and the purchase journey. We use a random installation identifier. We do not send titles, authors, ISBNs, search terms, notes, photos, emails, usernames, backup content, or local paths to PostHog.
You can disable analytics in Settings. When a trial converts to a paid subscription, Bookward stops sending new analytics events from the app. Data already sent is retained under PostHog's configured retention and privacy policy. Bookward also uses AppsFlyer to attribute installs, app opens, and subscription outcomes to campaigns; RevenueCat may send AppsFlyer purchase, renewal, cancellation, and refund events. TikTok App Events SDK measures Bookward standard events such as starting a trial, subscribing, or making a purchase. AppsFlyer and TikTok may process technical installation and device identifiers, attribution identifiers, IP address, campaign data, and the events needed to measure performance and prevent duplicates. Before enabling advertising identifiers or TikTok on iOS, we request authorization through App Tracking Transparency. If you allow it, iOS may permit use of the advertising identifier and other limited identifiers; if you decline, TikTok is not activated and AppsFlyer runs without advertising identifiers, using aggregated measurement such as SKAdNetwork when available. Your choice does not limit any feature and can be changed in Settings > Privacy & Security > Tracking. Your answer to “Where did you hear about Bookward?” may be recorded in PostHog as a predefined option without free-form text.
2.9 Reminders and distraction blocking
Notifications are optional and are used for reminders and session completion. On supported devices, distraction blocking uses Apple's Screen Time or Family Controls APIs. Selected blocked apps are represented by opaque system tokens stored locally; Bookward does not receive a readable list of every app installed. You can revoke these permissions in device settings.
2.10 Support
When you use the Tally form, we process the information you choose to provide, such as contact details, a description of the issue, and attachments. Tally may also process technical data needed to provide the form. Do not include passwords, payment data, or information that is not necessary for your request.
3. Why we use information
- Provide, maintain, and personalize Bookward's features.
- Search for and identify books and display catalog metadata.
- Create accounts, authenticate sessions, and maintain profiles, connections, suggestions, and votes.
- Create, restore, and delete private backups requested by the user.
- Manage purchases, trials, subscriptions, and restorations.
- Send reminders and apply distraction blocking when requested.
- Measure limited product operation, prevent failures, improve the app, and attribute installs and campaign results when the corresponding analytics or tracking is enabled.
- Answer requests, protect the Service, prevent abuse, and comply with legal obligations.
We do not sell personal data or display personalized advertising inside Bookward. Data sent to AppsFlyer or TikTok is used to attribute and optimize Bookward campaigns according to your iOS tracking choice.
4. Legal bases
Where the General Data Protection Regulation applies, we rely on these legal bases:
- Performance of a contract: to provide the app, account, backups, social features, and purchases you request.
- Consent: for optional permissions, configurable analytics, campaign attribution when tracking authorization is required, and information you send through support. You may withdraw consent without affecting earlier processing.
- Legitimate interests: for security, fraud prevention, limited diagnostics, and Service improvement, balanced against your rights.
- Legal obligation: when we must retain or disclose information under applicable law or a valid authority request.
5. Providers and recipients
We share only the information needed with providers that help us deliver the Service:
- Apple — https://www.apple.com/legal/privacy/
- Google — https://policies.google.com/privacy
- RevenueCat — https://www.revenuecat.com/privacy/
- PostHog — https://posthog.com/privacy; AppsFlyer — https://www.appsflyer.com/legal/privacy-policy/; TikTok for Business — https://www.tiktok.com/legal/page/global/tiktok-for-business-privacy-policy/en
- Tally — https://tally.so/help/privacy-policy
- Google Books — https://policies.google.com/privacy
- Open Library and Internet Archive — https://archive.org/about/terms.php
- ISBNdb — https://isbndb.com/privacy
- Wikimedia Foundation and Wikidata — https://foundation.wikimedia.org/wiki/Policy:Privacy_policy
We may also disclose information when required by law, to respond to a valid authority request, or to protect the rights, safety, and integrity of the Service. If a business reorganization occurs, we will provide notice of any material change in the controller or use of data.
6. International transfers
Some providers may process information outside the European Economic Area. Where required, we rely on recognized safeguards such as adequacy decisions, standard contractual clauses, or other valid mechanisms. PostHog is configured for EU hosting, although some subprocessors may operate in other jurisdictions.
7. Retention
- Local data: until you delete it, erase Bookward's data, or uninstall the app.
- Account and profile: while you keep the account; deleted when you request account deletion, subject to temporary technical copies and legal duties.
- Cloud backups: up to three recent backups; you can delete a backup or your account in the app.
- Suggestions and votes: while the account exists or as needed to operate the feature, subject to legal duties.
- Analytics, attribution, and purchases: under PostHog, AppsFlyer, TikTok, RevenueCat, and store retention, or as needed to operate the service and meet tax or legal duties.
- Support: as long as needed to resolve and document the request and meet legal duties.
8. Security
We use reasonable safeguards such as HTTPS, private system storage, Secure Store for local secrets, authenticated access controls, request limits, encryption for sensitive credentials, and private account-scoped backups. No system is completely secure. Protect your device and notify us through the form if you suspect unauthorized access.
9. Your choices and rights
You can use Bookward without an account, keep your profile private, disable analytics, revoke device permissions, change tracking authorization in iOS Settings, export local data, erase books and local content, delete backups, and delete your account in the app. Deleting Bookward does not cancel a subscription; manage it through the relevant store.
Depending on where you live, you may request access, correction, deletion, restriction, objection, and portability, withdraw consent, and complain to a data protection authority. In Spain, you may contact the Spanish Data Protection Agency. To exercise rights, use the contact form and state that your message is a privacy request. We may request reasonable information to verify your identity.
10. Children
Bookward is not directed at knowingly collecting personal data from children who cannot consent under applicable law. If you are below the digital consent age in your country, use account, public profile, and support features with permission from a parent or legal guardian. If you believe we processed a child's data without valid authorization, contact us so we can review and delete it.
11. Changes to this Policy
We may update this Policy to reflect changes to Bookward, providers, or law. We will publish the new version and update the date at the top. For material changes, we will provide reasonable notice in the app or through another available channel.
12. Contact
For questions, support, or privacy requests:
- Contact Bookward — https://tally.so/r/kd2ekj
Controller: Daniel de Azcárate Muñoz
Location: Málaga, Andalusia, Spain