Skip to content
Tropely
Theme
Tropely

Privacy Policy

Effective from

The short version

Tropely helps you discover, save, and track books. We use information you give us and information from your use of the app to provide those features, keep your account in sync, understand what works, and protect the service. Friends is optional. Creating a Friends profile turns on reading sharing, which you can pause at any time. Friends can see eligible activity only after you connect and both have sharing on. We do not sell your personal information or share it for cross-context behavioural advertising.

Tropely is operated by Caeron Seabourne ("Tropely", "we", "us"), who is the data controller for the personal information described in this policy. Contact us at admin@tropely.io or 18 Dinas Path, NP44 4QQ, United Kingdom.

Information we collect

Depending on how you use Tropely, we collect:

  • Account information, such as your email address and information Apple or Google provides if you choose their sign-in services.
  • Reading preferences, saved and passed books, books currently being read, completed books, ratings, reading check-ins, and reading goals.
  • Usage information such as app opens, book views, actions, and feature outcomes. Mobile analytics may be associated with your Tropely account; website analytics has a separate consent choice described below.
  • Device and diagnostic information such as app version, device platform, crash reports, and error details.
  • Push tokens and notification settings if you enable reminders, including device platform, locale, timezone, and delivery metadata.
  • Your marketing-email choice and its wording version, if you are offered that choice.
  • Information you send when you contact us or submit feedback.
  • On your device, your session, tutorial state, pending book actions, and other data needed for app continuity.

If you opt into Friends, we also process your social handle and display name; record of accepted Terms and Community Guidelines; sharing and hidden-book choices; requests, friendships, invitations, blocks, and reports; limited abuse-prevention counters; and the reading state needed to show eligible friend activity. We use random social profile IDs so other users do not receive your authentication account ID.

How Friends works

An exact-handle search may show your handle and display name to another eligible user. A person with an invitation link may see an invitation preview. Friendship requires an accepted request or an explicit acceptance of an invitation. Your social profile is not a public web page.

Creating a Friends profile turns on reading sharing. Once you connect, eligible friends who also share may see:

  • Books you currently read, even if you started them more than 90 days ago.
  • Eligible finishes from a moving 90-day window, with your current rating where present.

We derive this view from your current reading records. Moving a finished book back to Saved removes its finish from the social view. Saves, passes, and individual discovery swipes are not shared through Friends. You can hide a book from friends, pause sharing, remove a friend, block a user, or delete your social profile. Re-enabling sharing may show eligible reading activity recorded while sharing was paused.

Pausing sharing also stops your access to friends' activity. Your handle, display name, friendships, and exact-handle discoverability remain until you delete your social profile or account. A block prevents social connection and activity access between the blocked accounts. Private block records remain after social-only deletion so the protection continues if either person opts into Friends again. They are removed when either whole Tropely account is deleted.

Invitations and device storage

An invitation contains a short-lived, single-use token. The token is stored as a digest on our server. If you open a link in the app, the pending token may be held in secure device storage while you sign in or decide whether to connect. It is cleared after use, cancellation, expiry, or ordinary sign-out. If you explicitly choose to use a different account for an invitation, it may be held across that one account switch. On-device cached copies of your social profile, relationships, friend activity, and book context are kept only in app memory and cleared when your account changes or social access is removed. The underlying account and social records are stored on our server as described above.

Safety reports and moderation

You can report a person from their social profile, friend request, or friendship in the app. We record the reason and information needed to investigate, including a snapshot of the reported handle/display name and, where relevant, the request or friendship context at the time. This evidence can remain if a profile changes or an account is deleted. Access is restricted to people operating moderation. We may use it to review abuse, enforce our rules, respond to appeals, and protect users.

An open report is kept until it is resolved. After resolution, the report evidence is retained for 12 months, then removed; anonymous aggregate outcomes may remain. Full account deletion removes live account identifiers from retained reports, but the historical name and relationship snapshot may remain for the stated period if needed to finish the case or review abuse.

Why we use your information

We use the information above to provide your account and reading features, honour your sharing choices, connect you with friends if you opt in, protect against misuse, respond to reports and support requests, improve Tropely, deliver optional reminders and marketing you chose, and meet legal duties.

Our lawful bases are: contract for the account, reading features, and Friends features you request; consent for optional website analytics and marketing email; legitimate interests in protecting users and the service, investigating abuse, providing support, and diagnosing faults, where those interests do not override your rights; and legal obligation where processing is required by law. You can withdraw a consent-based choice without affecting earlier lawful processing. The basis for account-linked mobile analytics is our legitimate interests in understanding how people use Tropely, diagnosing problems, measuring feature performance and improving the service. We balance these interests against users’ privacy rights and provide controls where appropriate.

Who receives information

We use service providers to operate Tropely. Supabase supports sign-in and data storage. Apple and Google may support sign-in and push delivery. Expo supports optional push delivery. PostHog supports analytics when enabled. Sentry supports diagnostics and feedback when enabled. We restrict provider access to the work they perform for us. Book retailers and other external sites receive information directly from you if you choose to open their links.

Your eligible friends receive only the social information described above. Exact-handle lookup and invitation preview can show limited identity information before friendship. We may disclose information if lawfully required or necessary to address a serious safety or security issue.

We do not ask for precise location, contacts, camera, microphone, photos, payment card details, or government ID to use Tropely.

Analytics and diagnostics

On the website, optional analytics starts only if you accept. When enabled, we send web_page_viewed with canonical path and page type, and web_store_cta_clicked with canonical path, page type, platform, and CTA surface. These events omit query strings, URL fragments, referrers, search terms, and DOM content. PostHog uses an anonymous identifier after website consent and has IP capture disabled. Declining or withdrawing consent stops capture and removes PostHog persistence while retaining your choice. Global Privacy Control is treated as a decline. Use Privacy choices in the footer to change your choice.

Mobile analytics is separate from the website choice. It can identify the acting Tropely account to PostHog. Social event properties do not include friend or target identities, handles, display names, invitation tokens, or raw URLs. Diagnostic reports may contain technical context needed to fix problems; we work to remove sensitive invitation data from logs and error reports.

Notifications and email

If you enable reminders, we store the token and device settings needed to send them. We also keep delivery metadata to avoid duplicates and troubleshoot failures. You can turn reminders off in the app or device settings. Friends social actions do not currently send push notifications. We send marketing email only if you affirmatively choose it, and you can change that choice or use the unsubscribe link.

Your choices and deletion

You can change reading preferences, social sharing, hidden-book choices, and marketing or reminder preferences in the app. You can sign out at any time.

Deleting your social profile removes its handle, display name, friendship links, requests, invitations, and sharing settings from active social use. Private blocks remain for abuse prevention, and report evidence follows the retention rule above. We reserve a deleted handle for 30 days; the same account may reclaim it during that period. After that, it can be used by another person.

Deleting your whole account through the Account screen removes your account, profile, reading preferences, book activity, social profile, and active connections from our main systems. If you used Apple sign-in, we may ask you to complete a fresh Apple authorization step to revoke the connected token. After full account deletion, any remaining handle reservation has no owner and expires no later than 30 days from the original reservation or deletion. Private block records involving the deleted account are removed. A limited report snapshot may remain for the period described above, without live account identifiers. The app also tries to clear its local session and unsynced book actions.

Some information may remain for a limited time in backups, logs, analytics, diagnostics, or records that we need for legal, security, or operational reasons.

How long we keep other information

We keep account, reading, and active social information while your account or social profile exists. We delete or de-identify it when it is no longer needed, unless a law or a justified safety or operational need requires longer. Invitation tokens expire after seven days and are single use. Deleted handles are reserved for 30 days. Report evidence is retained as described above. Notification delivery metadata and technical logs are retained only as long as needed for duplicate prevention, security, troubleshooting, and operational purposes.

Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to uses of your information, and to withdraw consent. To make a request, email admin@tropely.io. We may need to confirm your identity. You may also have a right to complain to your local data protection authority; if you are in the UK, that includes the Information Commissioner's Office.

Children, international processing, and security

Tropely is intended for adults aged 18 or over and is not directed to children. If you believe someone under 18 has provided information, contact us so we can investigate and take appropriate action.

We store core account and reading information with Supabase in its West EU (Ireland) region. We configure PostHog analytics to use its EU endpoint and Sentry diagnostics to use its Germany endpoint. These locations do not mean that all processing stays in Europe. If you enable push notifications, Expo processes the device token and notification message through its US-hosted push service, then passes the notification to Apple or Google for delivery. Our providers and their subprocessors may also access information from other countries, including the United States.

For transfers from the UK to the European Economic Area, we rely on UK adequacy regulations. For transfers to US providers covered by the UK Extension to the EU-US Data Privacy Framework, we rely on that adequacy framework. Other restricted transfers are covered by appropriate contractual safeguards where required, such as the UK Addendum to the EU Standard Contractual Clauses. Email admin@tropely.io for more information about a transfer or to request a copy of the relevant safeguards.

We use secure connections, access controls, and protected local storage for sensitive session and invitation information. No online service can be completely secure.

Changes and contact

We may update this policy. For material changes, we will take reasonable steps to tell you and request any renewed acceptance required for Friends. For privacy questions or requests, email admin@tropely.io.