Legal
Privacy Policy
Version 2 · effective 11 October 2026 · replaces the BookNest policy of 10 October 2026
Who we are
Shelf of Mind (formerly BookNest) is an iOS app and website for cataloguing your personal library. It is made by Zenithalig BV. For the personal data that the app and shelfofmind.com process, Zenithalig BV is the data controller under the EU General Data Protection Regulation (GDPR).
Zenithalig BV
Industriepark-West 75, 9100 Sint-Niklaas, Belgium
Company number (KBO) 1016.996.795
customer@zenithalig.com
What data we process and why
- Account: your email address and a password, or your Apple ID if you use Sign in with Apple. Firebase Authentication stores passwords in hashed form; we never see them. With Sign in with Apple, Apple may give us a private relay address instead of your real email. Purpose: to create your account and let you sign in. Legal basis: performance of a contract (GDPR art. 6.1.b).
- Profile: first name, last name, username, and if you choose them, a profile photo and a short bio. Purpose: to show who owns a library. Legal basis: contract (6.1.b).
- Your library:the books you add (title, authors, ISBN, language, publisher, year, cover link, reading and ownership status), your categories and places (rooms, bookcases, shelves), and details such as “lent to”, return dates, “gift from”, signed or first edition, inscriptions and notes. If you type another person's name in these fields, only you can see it. Inscriptions and lending names are never shown on a public page. Purpose: the core function of the app. Legal basis: contract (6.1.b).
- Following and blocking: the libraries you follow and the users you block. Only you can see these lists. A person you follow can see that you follow them.
- Purchases: if you buy Shelf of Mind Pro, Apple handles the payment. We do not receive your payment details. The app only checks with Apple whether your Pro access is active.
- Technical data: our providers (Google Firebase for the app, Vercel for this website) process your IP address and device or browser information to deliver the service and protect it against abuse. The app uses Firebase App Check with Apple App Attest to confirm that requests come from the real app. Legal basis: our legitimate interest in a secure service (6.1.f).
Camera and photos.The app uses the camera to read barcodes and the text on book covers and spines. This recognition runs on your device. We do not save or upload camera images or shelf photos; only the recognised text is used to search for the book (see “Book search”). The app reads only the one photo you pick as your profile photo, and makes it smaller (at most 720 pixels) before the upload.
Notifications and widgets. Return-day reminders are local notifications, scheduled on your device. Widgets show a small summary of your library that is stored on your device. Neither is sent to us.
Public libraries and social features
Your library is private by default. If you switch on Public libraryin the settings, anyone, also people without an account, can see your display name, username, profile photo, bio, the books you own, your categories, your showcase and the lines you write under “Why it stays”, and can find you by name or username. Your places (rooms and shelves) are shown only if you also switch on “Show places”. Your public page is at shelfofmind.com/u/<username>. Legal basis: your consent (6.1.a). You can switch it off at any time; your library then becomes private again immediately.
When your library is public, these extra features are available:
- Feed posts: when you choose to share new books, a post with your name, username, photo and those books is visible to signed-in users of the app. You can delete a post at any time.
- Reactions: when you react to a post, the author and other signed-in users can see your reaction.
- Borrow requests: only possible when the owner allows them and you follow each other. A request contains your name, username and the book. Only the two of you can see it. There is no free text.
Book search
When you search for a book, scan a barcode or a cover, the app sends the search text or ISBN to Google Books (Google) and Open Library (Internet Archive) to find the book details and cover. We do not send your name, email or account ID with these requests. These services do see your IP address, under their own privacy policies. Book covers are loaded directly from these services.
This website
shelfofmind.com shows public libraries, the Journal and these pages. It sets no advertising or analytics cookies. Fonts are served from our own domain. If you sign in on the web, Firebase stores a sign-in session in your browser, which is strictly necessary for that function.
What we do not do
- No advertising, no tracking across apps or websites, no analytics SDKs.
- We never sell your data.
- No automated decision-making with legal effects (GDPR art. 22).
Who processes the data
We use Google Firebase (Google Ireland Ltd and Google LLC) as processor for authentication, the database and file storage, under Google's data processing terms. The database is located in the European Union (region eur3). This website is hosted by Vercel Inc. Some services of Google and Vercel can process data in the United States. Such transfers are based on the EU-US Data Privacy Framework (GDPR art. 45) and the European Commission's standard contractual clauses (art. 46). Apple processes purchases and Sign in with Apple as an independent controller under its own privacy policy.
We share data with authorities only when the law requires it.
How long we keep data
We keep your data as long as you have an account. You can export your library at any time, and you can delete your account in the app: Settings → Account → Delete account. This deletes your profile, library, settings, public profile, username, profile photos, feed posts, reactions and borrow requests. Copies in our provider's backups are removed on the provider's normal backup cycle.
Age
Shelf of Mind is meant for people of 13 years and older. If you are younger, ask a parent or guardian first.
Security
All connections are encrypted (HTTPS/TLS). Access rules on the database make sure that only you can read and change your private data.
Your rights
You can ask us to access, correct or delete your data, to restrict or object to processing, and to receive your data in a portable format. You can withdraw consent at any time. Email customer@zenithalig.com. We answer within one month.
You can also file a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), Drukpersstraat 35, 1000 Brussels, dataprotectionauthority.be, or with the authority in your own country.
Outside the EU. If you live outside the European Union, the data protection law of your country may give you additional rights. Contact us at the address above and we will help you use them.
Changes
If we change this policy, the new version appears on this page with a new date. We tell you in the app about important changes.