Privacy policy
Effective August 16, 2026. Last updated August 16, 2026.
Casebound is operated by Pixel Master Technologies LLC ("Pixel Master," "we," "us"), a Colorado limited liability company. For the purposes of the GDPR and similar laws, Pixel Master is the data controller. This policy explains what Casebound collects, why, who we share it with, and what control you have. If you have a question about anything here, email support@pixel-master.com.
This policy replaces the version dated May 28, 2026, which described Casebound before it had profiles, following, reviews, book clubs, lending, or photo uploads.
The short version
- Your library, reading sessions and stats are private by default, and you control per book whether anything about that book is visible to other people.
- Casebound has an optional social layer. Nothing in it is required to use the app, but anything you post in it is visible to other people, and some of it is visible to anyone on the internet.
- We do not sell your personal information, and we do not share it with advertisers.
- You can export your data and delete your account, permanently, from inside the app.
The rest of this document is the long version. The sections on what we collect and what other people can see are the ones that matter most.
Who this applies to
This policy covers the Casebound mobile app on iOS and Android, the casebound.co website, and the backend services that support them. Casebound is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has created an account, email us and we will delete it.
What we collect
Information you give us
- Email address. Required to create an account. If you sign in with Apple using Hide My Email, we receive and store only the private relay address Apple gives us.
- Password. Only if you create an account with email and password. Stored as a salted hash by our authentication provider. We never see or store your plaintext password.
- Display name and username. Required. Your username is how other Casebound users find you. If you sign in with Apple and allow it, your name is used to prefill your display name on first sign-in only.
- Profile photo and bio. Optional.
- Your library. Books you add, formats you own, ownership status, reading status, page and time progress, ratings, personal notes, custom lists, wishlist.
- Reading sessions. Start and end times, pages or minutes read, the book, and whether the session was logged live or entered manually.
- Reviews and social content. Book reviews, book club posts and comments, activity feed posts and comments, friend recommendations and their notes, club names and descriptions.
- Photos. Book cover photos and book spine photos you capture, profile avatars, photos attached to posts, and book club cover images.
- Lending records. If you use lending, the book, the counterparty, dates, and return status.
- Support messages. Anything you send through in-app feedback, including your email address as reply-to.
Information collected automatically
- User ID. A random identifier assigned to your account.
- Crash reports and diagnostics. Stack traces, device model, OS version, app version, and the sequence of screens and actions immediately before an error.
- Product analytics. Which screens you open and which features you use, associated with your user ID. This is off unless you turn it on — the switch is in Settings → Privacy & data → "Share anonymous analytics."
- Subscription status. Whether you have an active Casebound Pro subscription, when it renews or expires, and the store transaction identifiers behind it.
- Push token. If you enable notifications, the device token needed to deliver them.
We do not collect your precise or coarse location, your contacts, your calendar, your messages, your browsing history outside the app, or any advertising identifier. We do not use any tracking technology for advertising purposes, and we do not participate in cross-app or cross-site tracking.
We never receive your card number. Subscriptions are purchased through the Apple App Store or Google Play, which process payment and share with us only the fact of a valid purchase and its status.
What other people can see
This is the section most privacy policies bury. Please read it.
Private by default
Your library, your reading sessions, your stats, your streaks, your notes, your wishlist and your custom lists are private unless you take an action that makes something visible. Casebound's privacy control is per book, not per profile. Each book in your library has its own privacy toggle, and a book marked private is excluded from everything below.
Visible to other Casebound users
- Your username, display name, avatar and bio
- Your earned badges
- Your non-private library entries, including reading status and rating
- Reviews you write, attached to your profile
- Book club posts, comments and membership, to other members of that club
- Activity feed posts and comments, to people who follow you
- Friend recommendations you send, to the person you send them to
- Your followers and following lists
- Community spine photos you upload, to other users who own the same edition
- If you lend a book through Casebound, the borrower's progress on that specific book only is visible to you, and nothing else about their library
Following is open — anyone can follow you, and follower counts are visible.
Visible without signing in
Some data is readable by anyone with access to our public API, including people who are not signed in to Casebound: public profile fields (username, display name, avatar and bio), non-private library entries, and earned badges.
Uploaded images are stored in public storage buckets. Avatars, post photos, spine photos and club cover images are served from URLs that are not access-controlled. Anyone who has the URL can view the file, whether or not they have a Casebound account. Do not upload an image you would not be willing to have publicly accessible. If this is not what you want, mark books private and do not upload photos.
The shared book database
Casebound maintains one shared catalogue of book metadata — titles, authors, page counts, publishers, covers, genres — used by every user. It is not personal to you. If you correct or add book metadata, that correction becomes part of the shared catalogue and benefits other users. Your identity is not displayed alongside it, but the record of who created a book entry is retained internally.
How we use your information
- To operate the app: your library, sessions, stats, lists and social features
- To authenticate you and keep your account secure
- To deliver notifications you have enabled, including reading reminders, follows, club activity and recommendations
- To identify books from photos you capture
- To diagnose crashes and fix defects
- To understand which features are used, in aggregate, so we can decide what to build
- To manage subscriptions and entitlements
- To respond to your support requests
- To enforce our Terms of Service and Community Guidelines, and to comply with law
We do not use your information to build advertising profiles, and we do not sell or rent personal information to anyone. We have not sold or shared personal information for cross-context behavioural advertising in the preceding twelve months, and we do not intend to.
Who we share it with
We use the following service providers. Each processes data on our instructions, for the purpose listed, and not for their own purposes. All are US-based.
- Supabase — authentication, database, file storage. This is where your account and library live.
- Railway — hosts our book metadata service.
- Sentry — crash reporting and error diagnostics, associated with your user ID.
- PostHog — product analytics, associated with your user ID, only if you have enabled analytics.
- RevenueCat — subscription state and entitlements.
- Expo — push notification delivery.
- Apple and Google — payment processing, sign-in, and app distribution.
Photo processing. When you use the cover scanner or spine photography features, the image is transmitted to Google's Gemini API and, in some fallback cases, Google Cloud Vision, for the sole purpose of identifying the book. We do not control Google's handling of that request beyond the terms of their API.
Book metadata sources. We query Open Library, Google Books and Hardcover for book information. These requests contain the ISBN or search text — they do not contain your identity.
We may also disclose information if we are legally required to, or where we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others. If Pixel Master is acquired or merges with another company, your information may transfer as part of that transaction. We will give notice in the app before that happens.
International transfers
Pixel Master operates in the United States, and our service providers store and process data in the United States. If you use Casebound from outside the United States, your information is transferred to and processed in the United States, which may have different data protection rules than your own country. Where required, we rely on the European Commission's Standard Contractual Clauses, or an equivalent mechanism, for transfers out of the European Economic Area and the United Kingdom.
Your rights and controls
Regardless of where you live, you can:
- Access and correct your account information and library from within the app.
- Export your library and reading data from Settings.
- Control visibility per book with the privacy toggle.
- Block and report other users.
- Turn off notifications in Settings or at the OS level.
- Opt out of product analytics in Settings → Privacy & data. It is off by default; turning it on is a choice you make.
- Make new books private by default in Settings → Privacy & data.
- Delete your account from Settings. This is a permanent deletion of your account, library, sessions, reviews, posts, uploaded photos and profile — not a deactivation. Full detail is on our account deletion page.
If you signed in with Apple, deleting your account also revokes Casebound's Sign in with Apple token, so the app no longer appears in your Apple ID's list of connected apps.
If you are in the EEA, UK or Switzerland
You have the right to access, rectify, erase, restrict and object to processing of your personal data, and the right to data portability. You may lodge a complaint with your local supervisory authority.
Our legal bases: contract for operating the app and your account; legitimate interests for crash reporting, security and abuse prevention; consent for product analytics, push notifications and camera access; and legal obligation where applicable.
If you are in California
You have the right to know what personal information we collect, to delete it, to correct it, and to not be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.
If you are in Colorado or another US state with a comprehensive privacy law
Colorado, where we are based, along with a growing number of other states, gives residents rights to access, correct, delete and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. We do not sell personal data, do not use it for targeted advertising, and do not profile you in a way that produces legal or similarly significant effects. We honour these rights for residents of any US state regardless of whether the relevant law's thresholds apply to us, and you can exercise them in the app or by emailing us.
To exercise any right not available in the app, email support@pixel-master.com with "Privacy request" in the subject line. We will verify your request against the email address on your account and respond within the time required by applicable law.
Content moderation
Casebound has user-generated content. Every surface that displays content from another user provides a way to report it and to block that user. Reported content is reviewed against our Community Guidelines, which are available in the app under Settings and are presented when you first post. Content that violates them may be removed and accounts may be suspended or terminated. Reviews that receive reports from multiple distinct users are automatically hidden pending review. To report content or an account outside the app, email support@pixel-master.com.
Retention
- Account, library and social content — kept until you delete the item or your account.
- Crash reports and diagnostics — retained for up to 90 days.
- Product analytics — retained for up to 12 months.
- Subscription records — retained as long as required for tax, accounting and dispute resolution.
- Moderation reports — retained while the report is open and for a reasonable period after resolution, so repeat behaviour can be identified.
Security
Data is encrypted in transit using TLS on every connection between the app and our services. Passwords are stored as salted hashes. Access to production data is restricted to the operator of the service. Database access is governed by row-level security rules that scope each query to the requesting user. No system is perfectly secure. Note in particular the limitation described above: uploaded images are stored in public buckets and are not access-controlled.
Changes to this policy
If we make a material change, we will update the effective date at the top and notify you in the app before the change takes effect. Continuing to use Casebound after that means you accept the updated policy.
Contact
Pixel Master Technologies LLC
support@pixel-master.com