Privacy policy

Your reading data belongs to you.

Effective 1 March 2026 · Last updated 4 September 2026 · Version 1.2

The short version. If you use Foxed for free, your entire library stays on your device and never leaves it. We don't sell your data or share it with advertisers — that's true across every plan, including Premium with cloud sync on. Cloud sync happens only if you choose Premium and explicitly agree to it.


01 · Who we are

Foxed is a reading tracker application for iOS and Android, developed and operated as a sole trader based in the United Kingdom. Where this policy says "Foxed", "we", "us" or "our", it means the individual data controller responsible for your personal data.

For the purposes of the UK GDPR and the Data Protection Act 2018, we are the data controller — we decide how and why your personal data is processed.


02 · What data we collect, and why

DataWhoWhere storedPurpose
Book library, ratings, shelves, notes, reading sessionsAll usersYour device only (SQLite)Core app functionality
App settings and preferencesAll usersYour device onlyRemembering your theme, defaults and consent choices
Waitlist email addressPeople who select “Notify me” on getfoxed.appMailjetSending Foxed launch news, product updates and occasional reader offers
One-way hash of IP addressPeople submitting the waitlist formCloudflare Durable ObjectsRate-limiting the form and preventing abuse
Email addressPremium onlyFirebase AuthenticationAccount login for cloud sync
Book library (cloud copy)Premium with sync onCloud FirestoreCross-device sync and backup
Anonymous crash reportsAll usersFirebase CrashlyticsIdentifying and fixing bugs
Anonymous usage analyticsOpted-in onlyFirebase AnalyticsApp improvement — off by default
Advertising identifier (IDFA / GAID)Free, with consentGoogle AdMobServing ads. Non-personalised ads shown if you decline.

What we do not collect: location, contacts, microphone data, financial information, or the specific book titles and reviews you log — those never appear in an analytics event.


03 · Legal bases for processing

GDPR requires a lawful reason — a "legal basis" — before we process any personal data. Think of it as a permission slip.

Processing activityLegal basisWhat this means
Storing your book library locallyLegitimate interestsThis is the core purpose of the app
Anonymous crash reportingLegitimate interestsFixing crashes benefits all users; the data is anonymised
Account creation and cloud syncConsent + contractYou explicitly agree when upgrading to Premium
Waitlist emailConsentYou ask us to send you Foxed news by selecting “Notify me”; you can unsubscribe at any time
Waitlist abuse preventionLegitimate interestsProtecting the form and mailing list from automated or excessive sign-up attempts
Usage analyticsConsentAsked before enabling; off by default
Personalised advertisingConsentVia Google's consent framework; you can decline

04 · Third-party services

Google / Firebase — Firebase Authentication, Cloud Firestore, Crashlytics and Analytics. Transfers to the US are made under Standard Contractual Clauses. Firebase privacy policy

Google AdMob — free-tier users see a single bottom-banner advert. Personalised ads require your explicit consent; non-personalised ads are always available. Google privacy policy

Cloudflare — hosts getfoxed.app, provides the Turnstile human-verification service, and stores the temporary, one-way-hashed IP rate-limit record used to protect the waitlist form. Cloudflare privacy policy

Mailjet — processes the email address you give us through the getfoxed.app waitlist form, so we can send the messages you asked for. Mailjet privacy policy

Google Books API and Open Library API — when you search for a book, the search term goes to these APIs. No personal data is sent, just the query.

RevenueCat — manages Premium subscriptions. Receives only your Foxed account ID (used to link your subscription to your account) to verify subscription status. It never receives your book data. RevenueCat privacy policy

Apple App Store and Google Play — all payments are processed by Apple or Google. We never see your card details.

We do not sell your data to anyone. No data brokers, no marketing companies. The services above receive only what they technically need to function.


05 · Where your data is stored

Free users. Your entire library, reading sessions and app data live exclusively on your device in a local SQLite database. They never leave it. Delete the app and the data goes with it.

Premium users. When you enable cloud sync, a copy of your library is stored in Google Cloud Firestore (EU/US data centres, under SCCs). Firebase security rules mean only your authenticated account can read it — no other user, and not us.


06 · How long we keep it

DataRetention period
Local device dataUntil you delete the app or clear it in Settings
Account and cloud dataUntil you delete your account — completed within 7 days
Crash reports90 days (Crashlytics default)
Analytics data14 months (Firebase default) — consent required
Waitlist email addressUntil you unsubscribe or we stop operating the waitlist and marketing list; we review the list periodically and remove addresses that are no longer needed
Waitlist rate-limit recordOne hour

07 · Your rights

Under GDPR you have the following rights.

Access — ask for a copy of all personal data we hold about you.

Rectification — ask us to correct inaccurate data.

Erasure — delete your data yourself in the app: Profile → Settings → Delete Account. Deletion completes within 7 days, as Apple and Google require.

Portability — export all your book data as a CSV file (Premium: Settings → Export Data).

Objection — object to processing based on legitimate interests, such as crash reporting. Contact us and we will assess the request.

Restriction — ask us to limit how we use your data while a dispute is resolved.

Withdraw consent — unsubscribe from waitlist emails using the link in every email, or withdraw consent for analytics, personalised ads and cloud sync in Settings. This doesn't affect the lawfulness of processing before withdrawal.

We respond to all rights requests within one calendar month, as GDPR requires.


08 · Age requirement

Foxed is intended for users aged 18 and over. Book search results (powered by the Google Books and Open Library APIs) are not filtered for mature content, so we cannot guarantee the catalogue is appropriate for younger readers. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has used Foxed and provided personal information, contact us and we will delete it promptly.


09 · Cookies and tracking

The app. No cookies. Data is stored with SQLite and MMKV, both entirely on your device.

getfoxed.app. No tracking cookies and no third-party analytics scripts. The waitlist form sends your email address to Mailjet. To protect that form, we use Cloudflare Turnstile and temporarily store a one-way hash of your IP address for one hour; we do not store the IP address itself. The relevant providers are listed in section 4 above.


10 · Changes to this policy

We may update this policy as the app gains features or the law changes. Material changes are announced by in-app notification and the "last updated" date above changes with them. We will not reduce your rights without your explicit consent.


11 · Contact and complaints

Foxed — data controller

United Kingdom
privacy@getfoxed.app
getfoxed.app

Complaints to the ICO

Information Commissioner's Office
ico.org.uk · 0303 123 1113
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

If you are based in the EU, you may instead contact the data protection authority in your country of residence.