Skip to content
collected
ReadersAPIDocs
API liveSign inCreate account

Privacy

Your reading belongs to you.

Collected is built around a simple boundary: the personal record of what you read and think about stays on your device by default. Some features send limited information off-device when you choose to use them. This page spells out those boundaries.

Effective August 31, 2026

The short version

  • We do not sell personal information.
  • We do not run advertising or track you across other apps or sites.
  • Your shelves, ratings, notes, and reading history are stored on your device by default.
  • Book lookups go to the Collected API so the app can return current metadata.
  • Security and abuse controls use a pseudonymous app-installation credential.

Information the iPhone app handles

Your library and notes

Books you save, reading status, ratings, favorites, notes, and other personal reading activity are kept in the app's local storage by default. No reader account is required, and Collected does not currently provide cloud synchronization for this information.

Book requests

When the app searches, resolves, or refreshes a book, it sends the minimum useful lookup information to our API, such as an ISBN, title, author, or Collected work identifier. Those values are used to answer the request. The API usage meter is designed not to retain search terms, book identifiers, request bodies, IP addresses, or user-agent strings.

Recommendations

When you ask for a recommendation, the app may send your prompt, selected filters, aggregate reading signals, titles and authors that should be excluded, and up to six short excerpts from notes, reviews, takeaways, or rejection reasons. Collected does not store that request body in its API usage ledger. A bounded version is forwarded to OpenAI with response storage disabled; unless a stricter retention arrangement applies, OpenAI may retain request and response content for up to 30 days for abuse monitoring.

Imports, covers, and exports

Catalog lookups, public Goodreads imports, and cover retrieval may send identifiers or search terms to services such as Open Library, Apple Books, Goodreads, LibraryThing, and Audible or Amazon media. If you deliberately export or share a backup, the export can contain your full library, notes, and local cover images. The destination you choose controls that copy.

Metadata feedback

If you flag incorrect book information, we retain the work and field identifiers, issue type, your note or suggested correction, a catalog snapshot, and timestamps. Feedback is kept as an audit record rather than silently rewriting published data.

App integrity and usage

Apple App Attest provides a pseudonymous credential that helps us distinguish a legitimate installation from automated abuse. We retain the credential state, request counts, timestamps, result status, and coarse performance measurements needed to operate and protect the service. This information is not used for advertising or cross-app tracking.

Website, developer, and support information

If you request API access, sign in to a developer account, create a key, or contact support, we receive the information you submit. That may include your email address, organization, product URL, use case, expected usage, support topic, message, and app version. Developer accounts also retain credential metadata, sessions, plan state, usage totals, security events, and the sign-in methods you connect. If you use Google or Apple sign-in, we receive the provider's stable account identifier and verified email, plus a name when the provider supplies one. Passwords are stored only as salted, one-way hashes. API secrets and one-time sign-in tokens are stored as protected digests rather than recoverable plaintext after they are issued.

How we use information

We use it only to:

  • return book information and operate Collected;
  • authenticate app installations and developer accounts;
  • enforce quotas, prevent abuse, and investigate failures;
  • answer support and access requests; and
  • understand service reliability without building advertising profiles.

Service providers and disclosure

We use Apple and Cloudflare to distribute the app, authenticate accounts, protect network traffic, and host parts of the service; Cloudflare processes IP addresses and ordinary request metadata for delivery and security. Google may process a login when you choose Google sign-in. Resend delivers account verification, sign-in, and password-reset email. Optional features may also use OpenAI, Open Library, Apple Books, Goodreads, LibraryThing, and Audible or Amazon media as described above. Those providers process information under their own terms. We may also disclose information when required by law, to protect the service or its users, or as part of a business transfer. We do not sell it.

Retention and control

Local app information remains until you remove it or delete the app. Service credentials and operational records remain as long as reasonably needed to run, secure, and account for the service. Metadata feedback is retained as an audit record. Access and support submissions remain while we evaluate or answer them and for a reasonable follow-up period. Recommendation content handled by OpenAI may remain in abuse-monitoring logs for up to 30 days.

You can delete local reading information in the app, avoid the optional recommendation and import features, revoke developer keys from the account dashboard, or ask us to review or delete information tied to your email through the support page.

Children

Collected is not directed to children under 13, and we do not knowingly collect personal information from them.

Changes and questions

If this policy changes materially, we will update the effective date here. For a privacy question or request, use the Collected support form and choose Privacy.

collected
APIDocsCreate accountTermsSign inSupportPrivacy
© 2026 Collected