Legal
Privacy policy
We process as little data as possible. This policy says what that is, why, on what legal basis and for how long.
Last updated: 8 August 2026
Controller
The controller within the meaning of Art. 4(7) GDPR is Andrei Svirida, c/o Adressgeber #2006, An der Alten Ziegelei 38, 48157 Münster, Germany. For anything under this policy, a message is enough: hallo@bookheap.app
This website
This website is static and sets no cookies. That is why there is no consent banner.
It is served through Amazon Web Services; the files sit in the EU region Frankfurt. On each request AWS processes technically necessary connection data (IP address, timestamp, requested file) in order to deliver the page. We keep no access logs. Legal basis: Art. 6(1)(f) GDPR, the legitimate interest in secure, functioning delivery. A data processing agreement with AWS is in place.
Delivery runs through Amazon CloudFront, whose locations are also outside the EU. Your request may therefore be answered from a location in the United States, where the connection data named above is processed. That transfer is covered by the European Commission's standard contractual clauses (implementing decision 2021/914), which form part of the data processing agreement with AWS, and additionally by the Commission's adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework. A copy of the standard contractual clauses is available on request.
The app, without an account
Without an account, your books, reading progress and settings stay only on your device. There is no server that receives them. Delete the app and everything is gone.
The only request that leaves the device is the book search you trigger yourself. Your search term is sent to Open Library (Internet Archive, USA) to fetch titles and covers; Open Library receives the search term and your IP address. Legal basis for the processing: Art. 6(1)(b) GDPR.
For this transfer to the United States there is neither an adequacy decision nor a contract with Open Library; as a US non-profit, the Internet Archive cannot certify under the EU-US Data Privacy Framework. The transfer is therefore made under Art. 49(1)(b) GDPR: it is necessary to perform the search you asked for. The United States does not offer a level of protection equivalent to the GDPR; in particular, US authorities may be able to access transferred data without you having comparable legal remedies against that. If you never search, no request is ever made, and every book can be entered by hand.
Account and sync (optional)
If you create an account, we store your email address (sign-in via AWS Cognito) and your library (books, shelves, moods, notes, progress) on servers in the AWS Frankfurt region. The purpose is to sync between your devices. Legal basis: Art. 6(1)(b) GDPR.
Providing your email address is neither a statutory nor a contractual requirement. Without it you cannot create an account and use the app without sync; every other function is unchanged.
We store both for as long as your account exists. You can delete it at any time in the app's settings; your email address and library are then removed from the live system immediately and remain in backups only until those are overwritten in the normal rotation.
AI agents
You can give an AI agent (Claude, for instance) access to your library. The agent signs in through the same OAuth dialogue you use and receives a time-limited access token with exactly the permissions you approve: read (books/read) and/or write (books/write). If you revoke access, no further tokens are issued; an access token already issued lapses at the latest on its regular expiry.
If your agent uses the book search, our server forwards your search term to Open Library. Unlike the search in the app, that transfer is made by us and not by your device; otherwise what is said in section 3 applies. What you entrust to your agent, and where it processes it, lies with your agent's provider; its privacy policy applies in addition.
Oura ring (optional)
You set this connection up yourself; without it, none of the processing described here takes place. If you connect your Oura ring, we process health data: the daily summaries of recovery, sleep and activity, together with your name and email address at Oura in order to label the connected account. These are special categories of personal data within the meaning of Art. 9 GDPR. We retrieve no other values, even where you have granted Oura wider permissions. This data does not come from you directly: we obtain it from your account at Oura Health Oy, Finland (Art. 14(2)(f) GDPR). Oura is the controller for the processing inside that account; its privacy policy applies in addition.
The only purpose is to offer you a starting point for the mood of your next book. The sole legal basis is your explicit consent under Art. 9(2)(a) together with Art. 6(1)(a) GDPR. You give it in the app, before the connection to Oura is established; releasing the individual permissions in Oura's own dialogue comes on top of that and does not replace it. Without your consent we request nothing from Oura, and the app works exactly as before with the mood picked by hand.
The mapping from values to moods is a fixed rule in the application code. Your Oura data is not fed to any AI model, neither for training nor as input, it does not appear in Bookheap's agent interface, and it is not passed to third parties. There is no automated decision-making including profiling within the meaning of Art. 22 GDPR: the suggestion has no legal effect on you and one tap overrides it.
We retrieve only the current day's figures, process them in memory and discard them immediately afterwards; they are not written to our database. What is stored is the access token that keeps the connection alive, and nothing else. You may withdraw your consent at any time with effect for the future, in the app's settings and separately in your Oura account. Disconnecting is itself a deletion request: we delete the access token immediately and any remaining data obtained from Oura within 72 hours at the latest, with no further step from you.
Your rights
Under the GDPR you have, in particular, the following rights:
- Access to the data stored about you (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure (Art. 17), in the app: Settings, Delete account
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Withdrawal of a consent you have given, with effect for the future, without affecting the lawfulness of the processing carried out before it (Art. 7(3))
- Objection to processing based on legitimate interests (Art. 21)
A message to the address above is enough to exercise any of them. You also have the right to lodge a complaint with a data protection supervisory authority, in particular the authority where you habitually reside (Art. 77).
About this translation
This English text is a courtesy translation. The German version at bookheap.app/datenschutz is the authoritative one.