Privacy Policy
Last updated: March 17, 2026
1. Introduction
This privacy policy describes how Bukku collects, uses, stores and protects the personal data of its users.
Bukku is a mobile reading tracker available on Android. We are committed to respecting your privacy in compliance with the GDPR (EU Regulation 2016/679) and the French Data Protection Act.
2. Data controller
Publisher: Bukku
Contact email: contact@bukku.app
Country: France
3. Data collected
We collect the following categories of data:
3.1 Data provided directly by the User
- Account data: email address, username (pseudonym), password (stored encrypted)
- Profile picture (avatar): optional image
- Biography: optional free text visible on the profile
- Reading preferences: favorite literary genres
- Library data: books added, reading status, notes and ratings
- Visibility setting: public or private profile choice
3.2 Social data
- Relationships: list of followers and followed users
- Profile views: recording of visits to your profile by other users (anonymized visitor)
- Activity feed: library-related actions (adding, completing a book) shared with your followers
3.3 Data collected automatically
- Technical data: device type, operating system, app version, language
- Usage data: usage frequency, features viewed, sessions
- Advertising data: advertising identifier (Google Advertising ID), via Google AdMob
3.4 Data NOT collected
- We do not collect geolocation data
- We do not collect biometric data
- We do not collect banking or payment data
- We do not collect contacts or address books
4. Purposes and legal bases of processing
Our processing is based on the following legal bases:
- Performance of the contract (Art. 6.1.b): account creation and management, Application features, personalization, social features (follow, public profile, activity feed)
- Consent (Art. 6.1.a): sending marketing communications by email (via Brevo)
- Legitimate interest (Art. 6.1.f): displaying advertisements (Google AdMob), improving the Application, usage statistics
- Legal obligation (Art. 6.1.c): compliance with legal obligations
5. Storage and hosting
- Supabase: database and file storage (avatars), on AWS. GDPR compliant with SCCs.
- AsyncStorage (local): user preferences stored locally.
- Brevo: email and language for marketing. French company, GDPR compliant.
- ISBNdb: book search. Only search terms are transmitted.
- Google Analytics: web analytics for bukku.app. Anonymized browsing cookies. Google LLC (DPF compliant).
6. Data sharing
We never sell your personal data. Service providers:
- Supabase (AWS): hosting and database
- Google AdMob: advertising
- ISBNdb API: book search
- Brevo: email marketing
- Google Analytics: website analytics
7. Advertising and cookies
Bukku uses Google AdMob for ads. You can disable ad personalization in your Android settings. As a native mobile app, Bukku does not use cookies in the traditional sense.
7.3 Google Analytics (website)
The website bukku.app uses Google Analytics for audience measurement. You can disable these cookies via the Google Analytics opt-out add-on or your browser settings.
8. Data retention
- Account and library data: kept while account is active. Deleted within 30 days after account deletion.
- Avatar: deleted immediately upon account deletion.
- Public web profile: the public profile page (
bukku.app/u/username) is automatically removed when the account is deleted or the profile is set to private. - Social data: follow relationships and profile views are deleted with the account.
- Local data: deleted when uninstalling the app.
- Brevo data: deleted within 30 days after unsubscription.
9. Your rights (GDPR)
Under GDPR, you have the right to: access, rectification, erasure, restriction, portability, opposition, and withdrawal of consent.
Contact: contact@bukku.app. Response within 30 days.
Complaint: CNIL.
10. Data security
- Secure authentication via Supabase (bcrypt)
- Encrypted communications via HTTPS/TLS
- Row Level Security (Supabase)
- Restricted access to production data
11. International transfers
Some data may be transferred outside the EU (USA), governed by Standard Contractual Clauses (SCCs) and the Data Privacy Framework (DPF).
12. Minors
Bukku is not intended for children under 16. Contact us at contact@bukku.app if you believe a child has provided personal data.
13. Changes
We reserve the right to modify this policy at any time. Significant changes will be communicated via the Application or email.
14. Contact
Email: contact@bukku.app
Subject: [Personal data] Your request