Privacy Policy
HashShelf was built so that it doesn't need to know who you are. There are no accounts and no tracking, and your reading list lives in the link rather than in a profile on our server. This policy explains, honestly, the little that is stored anyway.
1 Who this covers
This policy applies to the HashShelf website at hashshelf.com and everything
served from it (the "Service"), operated by [OPERATOR — "ZackBot98," or your legal
name/entity once formed] ("we," "us"). It doesn't cover third-party sites you reach
through the Service, such as Amazon or Open Library, which have their own policies.
2 What we do not collect
- No accounts, names, emails, or passwords — there's nothing to sign up for.
- No cookies, no advertising pixels, no third-party analytics or tracking scripts.
- No cross-site tracking, and no selling, renting, or trading of personal information.
- No profile of you, your reading, or your behavior.
3 What is stored, and where
Here is everything, laid out by where it lives:
- On your device
- Your shelves, a cache of book details, and the set of links you created are kept in your browser's local storage, and the app's files are kept in a service-worker cache so it works offline. This data stays on your device and is not sent to us — it only ever leaves your device as part of a link you choose to share. You can clear it any time by clearing your browser's site data.
- Inside your links
- A HashShelf shelf is encoded into the link itself (the part after the
#). Browsers do not transmit that fragment to servers, so the contents of a HashShelf link never reach us. Anyone you send a link to can read the shelf it contains — so share links the way you'd share a note. - On our server — book cache (the only thing we store)
- To avoid hammering Open Library, we cache public book facts (titles, authors, cover references, subjects/genres, and search results). This is information about books, not about you. We store no shelves and no other user content — an earlier optional "short link" feature that saved shelves on our server has been removed, and any copies it stored have been deleted.
- With our host & CDN
- Like every website, the Service runs behind infrastructure providers (Render for hosting, Cloudflare for DNS/CDN and security) that keep standard server access logs. Those logs can include your IP address, the time of a request, the page requested, and general browser/device information, and are used to operate, secure, and troubleshoot the Service. They're handled under those providers' privacy policies.
4 Cookies
We don't set cookies. The app uses your browser's local storage to remember your shelves on your own device; unlike cookies, local storage isn't attached to network requests and isn't sent to us.
5 Third parties
- Open Library / Internet Archive. Book searches and lookups are proxied through our server to Open Library; book cover images load directly from Open Library and the Internet Archive to your browser, which means those services receive your IP address and which cover you're viewing, under their policies.
- Amazon Associates. "Buy" links point to Amazon and carry our affiliate tag. If you click one, Amazon receives that request and handles it under Amazon's privacy policy; the tag identifies the referral to us, not you. We don't receive your Amazon activity or purchases — only aggregate commission reporting.
- Hosting & network. Render and Cloudflare process requests as described in Section 3.
6 How long things are kept
Cached book facts are refreshed or expired over time as part of normal operation. We keep no shelves at all, so there is nothing of yours to retain or delete on our side. Data on your device stays until you clear it. Provider access logs follow our host's and CDN's own retention schedules.
7 Your choices & rights
- Nothing of yours sits on our server. Your shelf lives only in its link, never on our server, so there is no stored copy for us to hold or remove. If you don't want to share a shelf, simply don't share its link.
- Clear your device data. Clearing your browser's site data for
hashshelf.comremoves your shelves and caches from that device. - Regional rights. Depending on where you live (for example, the EEA/UK under the GDPR, or California under the CCPA/CPRA), you may have rights to access, correct, or delete personal information, and not to be discriminated against for exercising them. Because we hold so little and none of it is tied to an identity, in practice this comes down to clearing your device data — but you're welcome to contact us about any of them.
8 Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided personal information, contact us and we'll address it.
9 International users
The Service is operated from, and hosted in, the United States. If you use it from elsewhere, you understand that your requests are processed in the United States, which may have different data-protection laws than your country.
10 Security
The Service is served over HTTPS with a strict content-security policy and other protective headers, and shared shelves are integrity-checked. No method of transmission or storage is perfectly secure, so we can't guarantee absolute security — but by design there is very little about you to protect.
11 Changes to this policy
If we change what the Service collects or how we handle it, we'll update this page and revise the "Last updated" date. Continued use after a change means you accept the updated policy.
12 Contact
Privacy questions and requests: report@hashshelf.com.
← Back to your shelf