Libinvenio
Privacy Policy
Effective date: 8 June 2026 · Last updated: 26 July 2026
Libinvenio ("the app") is developed by Pedro Araújo, an independent developer based in Porto, Portugal ("we", "us"). This policy explains what data the app handles and how. It is written to be honest and specific rather than exhaustive boilerplate.
Contact: pedro.araujo@libinvenio.com
The short version
- Your library is yours. Everything you catalogue — books, shelves, wishlist, tags, notes, condition and price details — is stored only on your device. We do not have user accounts and we do not keep a copy of your library on any server.
- We don't track you. No advertising, no advertising identifiers, no cross-app or cross-site tracking, no profiling, no selling of data. The only thing we receive automatically is a crash report when the app breaks — it can't identify you (section 6).
- Some actions need the internet. Scanning a cover, looking up a book, or comparing prices sends a request to our server, which forwards it to the third-party services listed below. These requests are processed and then discarded — they are not stored against you or your library.
1. Data stored on your device
Libinvenio stores your data locally using your device's storage (SQLite + app preferences). This includes:
- Your library, shelves and wishlist, and any tags, notes, ratings, condition grades, prices paid, and acquisition details you add.
- Book cover thumbnails you capture, saved in the app's private storage.
- A temporary 24-hour cache of price results.
- Your app settings (language, theme) and your purchase/usage status.
This data never leaves your device except when you choose to export a backup file or share a book (which uses your device's standard share sheet — you control where it goes). Deleting the app removes all of this data.
2. What is sent to our server, and when
Libinvenio's backend is a stateless proxy: it forwards requests to external book and price services and returns the results. It has no user database and stores no personal profile. Data is sent only when you take a specific action:
| When you… | What is sent | Notes |
|---|---|---|
| Scan an ISBN barcode | The decoded ISBN number | The barcode is read on your device; the photo itself is not transmitted. |
| Scan a cover or shelf photo | The photo | Used once to read the text and identify the book, then discarded. Not stored. |
| Look up a book | Title, author and/or ISBN | To fetch metadata from book catalogues. |
| Compare prices | Title, author and/or ISBN | To search for current prices across bookstores. |
We do not attach your identity, account, or library to these requests — there is no account to attach. Photos and the text extracted from them are processed transiently and are not persisted on our server.
3. Third-party services we use
To provide its features the app relies on the following services, which receive only the data described above (a book photo, a book title/author, or an ISBN — never your personal library):
To identify books from photos
- Google Cloud Vision — reads text from cover/shelf photos (OCR).
- Anthropic (Claude) — turns that raw text into a title and author.
To fetch book metadata
- Google Books, PORBASE / National Library of Portugal (BNP), Open Library.
To find prices
- The participating bookstores' own websites.
To keep the app working
- Sentry — receives a crash report when the app fails, plus a 10% sample of performance timings (how long a screen or request took). Our Sentry project uses Sentry's European data region. See section 6 for exactly what a report contains.
To handle purchases
- RevenueCat — validates the App Store / Google Play receipt so a Supporter unlock can be restored on your device. See section 5.
Infrastructure
- Fly.io — hosts our backend server.
- Expo / EAS (Expo Application Services) — delivers the app and any over-the-air updates.
Some of these providers operate outside the European Union, so the data sent to them (a photo, a book title, or an ISBN) may be processed internationally. Each provider handles that data under its own privacy policy.
4. Camera
The app requests camera access only to scan ISBN barcodes and book covers/spines. It is not used for anything else. You can decline or revoke this permission in your device settings; the rest of the app continues to work.
5. Purchases
Any in-app purchase (the one-time Supporter unlock, or a tip) is handled by the Apple App Store or Google Play. The app never sees or stores your payment card details, and we never learn your name, email or Apple/Google account.
We use RevenueCat to check the store receipt and remember that the unlock was bought, so you can restore it after reinstalling or on a new device. RevenueCat holds that purchase record against a random anonymous identifier generated on your device — not an account, and nothing you can be identified by. Your purchase status is also kept on your device, which is what the app reads day to day.
6. Advertising, tracking and crash reports
No advertising or tracking. Libinvenio contains no advertising SDKs, no advertising identifier (IDFA), no cross-app or cross-site tracking, and no product analytics measuring what you do in the app. We do not build a profile of you and we do not sell or share data with data brokers or advertisers.
Crash reports. The app does include Sentry, so that when something breaks we find out and can fix it. A report is sent only when the app hits an error (and, for 10% of sessions, timings for how long a screen or request took). A report contains:
- the error type and the stack trace (which line of our code failed);
- the app version, operating-system version and device model;
- a random installation identifier, so repeated crashes from one install can be counted as one problem. It is not linked to you, and we cannot use it to contact or identify you.
A report never contains your library, your books, your notes, the photos you scan or the terms you search for.
7. Children
Libinvenio is a general-audience cataloguing tool and is not directed at children under 13. We do not knowingly collect data from children.
8. Your rights (GDPR / EU)
Because your library lives on your device and we hold no personal profile on our servers:
- Access & portability — your data is on your device; you can view it in the app and export a backup file at any time (Settings → Data).
- Rectification — edit or delete any entry directly in the app.
- Erasure — delete individual items in the app, or uninstall the app to remove all local data. Backups you exported are held by you, not us.
- The transient requests in section 2 are not retained, so there is no server-side copy to access or erase.
- Crash reports and the purchase record (sections 5–6) carry no name, email or account, and no identifier we can tie back to a person — so there is nothing we can look up, correct or delete on request, because we cannot tell which report is yours. We rely on legitimate interest (keeping the app working and honouring purchases); this data is never used to profile you or for marketing.
The data controller is Pedro Araújo (contact above). You also have the right to lodge a complaint with the Portuguese data protection authority (CNPD, cnpd.pt).
9. Data retention & security
We do not retain your personal data on our servers. The scan, lookup and price requests in section 2 are processed in memory and discarded. Network requests use HTTPS. On-device data is protected by your device's own security (lock screen, OS sandboxing).
Two things are held by our providers rather than by us: crash reports, kept by Sentry for a limited retention window (90 days by default) and then deleted, and the purchase record, kept by RevenueCat for as long as the purchase remains restorable.
10. Changes to this policy
If we change how the app handles data, we will update this page and the "Last updated" date above. Material changes will be reflected before the new behaviour ships.
11. Contact
Questions about this policy or your data: pedro.araujo@libinvenio.com