Privacy Policy
BookRecs · Effective date: September 28, 2026
BookRecs (“the App”) is an iOS application developed and operated by HBKL Labs LLC. This policy explains what data the App collects, why, and what you can do about it.
The short version
- We collect only what the app needs to generate and save your book recommendations.
- No third-party analytics, no ads, no tracking across other apps or websites.
- AI services help write your recommendations and reading plans. The app asks for your permission before any of your data is sent to them.
- You can delete your account and all associated data from inside the app at any time.
What we collect
BookRecs requires an account so your library and recommendations sync across devices. Everything we store is tied to your account and used solely to run the app.
From sign-in
The iOS app supports Sign in with Apple and Google Sign-In. The bookrecs.ai website also offers an emailed sign-in code. Authentication is handled by Firebase Authentication. We never see or store your password.
- Your email address. Used as your account identifier. If you choose Apple’s “Hide My Email,” we only ever see the relay address.
- A user ID. A Firebase Authentication identifier that links your library and recommendations to your account.
- A display name, if your sign-in provider supplies one or you set one.
From using the app
Once signed in, the following lives in Google’s Firestore, tied to your user ID:
- Books you add to your library
- Recommendations you save, dismiss, or ask for more like
- Reading plans you create or activate, and your progress
- Prompts and reading goals you type to get books or plans
- The date you agreed to AI processing in the app
- Your taste preferences (recommendation styles, reading vibe, time to read, and fiction preference) gathered during onboarding
- Recommendation usage counters (daily and lifetime counts) used to apply free-tier limits
- Your subscription tier and subscription state
What we do NOT collect
- Location data
- Contacts
- Photos, microphone, or camera access
- Browsing history outside the app
- Analytics, crash reports, or telemetry from third-party SDKs
BookRecs does not send push notifications and does not register your device for remote notifications.
How we use it
- App functionality only. Your library, recommendations, reading plans, and preferences exist so the app works across your devices.
- Recommendation generation. When you request a recommendation or a reading plan, your taste preferences, library context and any prompt you type are sent to our server-side function. It uses the AI services listed below to choose and explain books, then writes the result back to your account. We ask for your permission in the app before this happens.
- Subscription entitlements. We use your subscription state to decide which features to unlock and how many recommendations you can request.
- No advertising. We do not share or sell data to advertisers, data brokers, or anyone else.
Who else sees your data (processors)
BookRecs relies on a few third-party services to operate. They process data on our behalf and are bound by their own privacy terms:
- Firebase (Google). Privacy . Provides authentication, the Firestore database that stores your library and recommendations, and the Cloud Functions that generate your recommendations.
- Google Sign-In. Privacy . Only if you chose Google to sign in. Google sees the sign-in event, not your in-app activity.
- Anthropic (Claude). Privacy . Writes your recommendations, the reasons behind them, and your reading plans. It receives the titles, authors, ratings and genres of books in your library, your taste preferences, and any prompt or reading goal you type. It does not receive your email or account ID.
- OpenAI. Privacy . Turns the text of a prompt or reading goal into a numeric representation (an embedding) so we can search for matching books. It receives that text only, never your email or account ID.
- Pinecone. Privacy . Hosts our book catalog search index. It receives the numeric representations described above to find matching books, never your email, account ID or library list.
- Apple StoreKit. Privacy . Manages in-app subscription purchases and verification. Apple processes your payment; we never see your card details.
We do not share your data with anyone else, and we never sell it. AI providers process it only to produce your results.
Your rights
- Delete your account. Open the app, go to Settings, and choose Delete Account. Your account, library, saved recommendations, reading plans, preferences, and subscription state are removed immediately on the server side and within 30 days everywhere else.
- Sign out. Settings, then Sign Out. Your data stays in your account; sign back in any time to restore it.
- Export your data. Email us and we’ll send you a JSON export within 30 days.
Data retention
- Account data is kept while your account is active.
- When you delete your account, the server wipes your data immediately. Any tombstoned records left over are removed within 30 days.
Data security
All network traffic uses encrypted HTTPS. Data lives in Google Cloud infrastructure with row-level access scoped to your user ID. Server-side functions that handle your data require authenticated requests. No method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
Children’s privacy
BookRecs is rated 4+ on the App Store. We do not knowingly collect personal information from children under the age of 13. If you believe a child under 13 has provided us with personal information, please contact us so we can take appropriate action.
Changes to this policy
We may update this privacy policy from time to time. Material changes will be noted in the app or by email before they take effect. Minor edits (typos, clarifications) may happen silently.
Contact us
If you have questions or concerns about this privacy policy or your data, please contact us at: