Privacy policy
Privacy
What we know about you, why, who we rely on and how to take your data back. Written to be read.
Updated on October 5, 2026
In short
- We only ask for what we need to let you in and keep your library.
- Your profile and the books you are reading, have read and love are public. Your email and your want to read list are not.
- No ads, no profiling, no tracking cookies.
- Fix your data and delete your account from the settings, whenever you like.
Who handles your data
Readingram is a project by Ciro Lo Sapio, the data controller for the personal data collected through readingram.app.
For any privacy question, or to exercise your rights, write to [email protected].
What we collect
Here is everything we store, and where it comes from.
- Account
- Email, name, username and, if you write one, a bio. If you sign in with Google we also get your Google identifier and profile photo. If you choose a password we only store an encrypted fingerprint of it (a hash), never the password itself.
- Your library
- The books you mark (want to read, reading, read), your favorites, when you marked them and the people you follow. For each marked book we keep the title, authors and cover from Google Books.
- Sign-in links
- When you ask for a link by email we store the address, an encrypted code and the expiry. The link lasts fifteen minutes and works once.
- Technical data
- As with any website, the servers hosting us receive your IP address and the request details (browser, page, time), which stay in their technical logs.
- Errors
- When something breaks, your browser or our server sends us a technical report: the page, the browser and the spot in the code where it happened. No name, email or library contents.
What others see
Readingram profiles are public, including to people without an account and to search engines. Anyone can see your name, username, photo, bio, the books you are reading, the ones you have read and your favorites, who you follow and who follows you. On a book page you appear among its readers, and your followers see your updates in their feed.
Your email and the books you want to read stay private.
Why, and on what basis
- The service
- Account, sign-in, library, profile and follows are how we give you Readingram, the service you ask for when you sign up (Art. 6(1)(b) GDPR).
- Security
- Technical data and the bot check protect the service from abuse, in our legitimate interest (Art. 6(1)(f) GDPR).
- Quality
- Error reports help us find and fix faults, in our legitimate interest (Art. 6(1)(f) GDPR).
We do not sell your data, use it for advertising or build commercial profiles.
Who we rely on
Readingram runs on these services, which only receive the data their job needs.
- Deno Deploy
- Hosts the application.
- Neon
- Hosts the database with accounts and libraries.
- Cloudflare
- Runs the domain, shields the site from malicious traffic and performs the bot check (Turnstile) when you ask for a link by email. It also measures visits in aggregate (Web Analytics): pages viewed, load times, country, browser and device, with no cookies and no way to recognize you from one visit to the next.
- Resend
- Sends the emails with sign-in links.
- Confirms who you are, only if you choose to sign in with Google.
- Sentry
- Collects error reports, to help us fix them.
Covers come from Google Books and author photos from Wikimedia Commons: your browser downloads them straight from there, so they receive your IP address, as with any image on the web.
Some of these services are based in the United States. Transfers rely on the safeguards the GDPR provides: the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.
Cookies and browser storage
We only use technical tools the site needs to work: that is why we do not ask for consent and you see no banner.
- nuxt-session
- Cookie that keeps you signed in. It is encrypted and the page code cannot read it.
- locale
- Cookie that remembers the language you chose.
- google_auth_redirect
- Cookie that lasts ten minutes, during Google sign-in, to bring you back to the page you started from.
- Theme
- Your light or dark choice lives in the browser's local storage and never leaves your device.
- Installed app
- The service worker only keeps the site's files (styles, scripts, icons), so it opens faster.
No profiling, advertising or analytics cookies: we count visits without cookies, through Cloudflare.
How long we keep it
Your account and library stay as long as your account exists. When you delete it, your statuses, favorites and follows go with it right away.
When you remove both status and favorite from a book, the row linking it to you is deleted, not archived. Sign-in links are deleted when you ask for a new one.
Error reports and the technical logs of the services hosting us are short lived, then deleted according to their own policies.
Your rights
You can ask us at any time to access your data, correct it, delete it, receive it in a machine readable format, restrict its processing or object to it. You can change your name, username and bio yourself in Settings.
You can delete your account yourself, at the bottom of Settings. For any other request write to [email protected] from the address you signed up with: we reply within a month.
If you think the processing breaks the law you can lodge a complaint with your data protection authority, or with the Italian one, the Garante per la protezione dei dati personali (garanteprivacy.it).
Minimum age
Readingram is meant for people aged 14 and over, the age at which Italian law lets you consent to online services on your own.
Changes
If we change this policy we update the date at the top of the page. We also tell you by email about important changes.