This document describes how BiblioSmart handles personal data. The data controller is the natural person operating the BiblioSmart application. Contact: contact@bibliosmart.app.
1. Data controller
The data controller for BiblioSmart is the operator of the application, a natural person (not a company or other commercial entity). BiblioSmart is a free, non-commercial app; the operator does not monetize the service.
Correspondence address: available on request via contact@bibliosmart.app.
Contact (privacy and GDPR requests): contact@bibliosmart.app.
Website: https://bibliosmart.app
2. Scope
This policy covers use of the BiblioSmart web app (personal book inventory), including account creation, library management, photo/video import, pre-purchase checks, recommendations, and account settings.
It does not cover third-party sites you reach via external links (e.g. online stores, Open Library, Google Books).
3. Data we process
Account data: email, password (hashed only), optional name, role (user/admin), email verification date, temporary tokens for email verification, password reset and account deletion, session version.
Library content: titles, authors, descriptions, covers (URL or uploaded files), categories, reading status, favorites, copy counts, reading years, optional source URLs.
Import jobs: source type, progress, status messages, detected book lists from photos/video until confirmed.
Recommendations: cache derived from your library (kind, UI locale, JSON payload).
AI settings (optional, BYOK): provider, API key, model, base URL — provided by you; used only for AI features in your account.
Minimal technical data: session/auth cookies, theme and language preference, cookie consent record (see Cookie Policy).
We do not currently use analytics services (Google Analytics, Plausible, Vercel Analytics, etc.).
4. Purposes and legal bases
Providing the service — performance of contract (GDPR Art. 6(1)(b)).
Account security, abuse prevention, limited technical logging — legitimate interest (Art. 6(1)(f)), with proportionate measures.
Transactional email (verification, password reset, email change, deletion code) — contract / legitimate interest.
AI features with your API key — contract; sending data to your chosen AI provider is initiated by you.
Legal compliance where required — Art. 6(1)(c).
5. Recipients and processors
Hosting: Vercel Inc. (application, optionally Vercel Blob for optimized covers).
Database: PostgreSQL provider configured by the operator (e.g. Prisma Postgres, Neon, Supabase — per environment).
Transactional email: Resend (or operator-configured SMTP).
Book metadata: server-side requests to Open Library and/or Google Books (optional GOOGLE_BOOKS_API_KEY on the server, not in the browser).
AI providers: when you configure an API key in Settings, requests go from our server to your chosen provider (e.g. xAI, OpenAI-compatible). You are responsible for your relationship with that provider and for your key; we store it in the database only to provide the feature.
We do not sell your data or use it for behavioural advertising.
6. International transfers
Some providers (Vercel, Resend, AI providers, Google) may process data in the US or other countries. Where required, we rely on appropriate safeguards (e.g. EU Standard Contractual Clauses) or adequacy decisions, per vendor contracts.
7. Retention
Account and library data: until you delete your account in Settings (Delete account) or until removed by an administrator on multi-user instances.
Temporary tokens and codes: from a few hours up to 24 hours, then removed or invalidated.
Recommendation cache: refreshed on regeneration; deleted with the account.
Server/hosting logs: per provider policies, typically days to weeks, for security and debugging.
8. Your rights
You have the right of access, rectification, erasure, restriction, portability (where applicable), and to object to processing based on legitimate interest.
Update email and password in Settings. Request account deletion there (confirmation via email code).
Other requests: contact@bibliosmart.app. We respond within legal timeframes (usually 30 days).
You may lodge a complaint with your supervisory authority. In Romania: ANSPDCP (www.dataprotection.ro). In Bulgaria: CPDP (www.cpdp.bg).
9. Security
Passwords are hashed; sessions use JWT. Data access is isolated per user. AI API keys are stored in the database and used server-side only for your account.
10. Children
The service is not intended for children under 16. If you believe a minor provided data without parental consent, contact us for deletion.
11. Changes
We may update this policy. The last updated date appears at the bottom of this page. For material changes, we will notify you by email or in-app where appropriate.