Privacy Policy

Last updated: August 28, 2026

Backlist ("we," "our," or "us") operates the Backlist mobile applications for iOS and Android and the backlist.app website. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.

1. Information We Collect

Account information. When you create an account, we collect your email address and a hashed password. You may also sign in with Apple, in which case we receive a unique Apple user identifier and, at your discretion, your name and email address from Apple.

Phone number. If you enable SMS release alerts, we collect your US phone number. We store it in E.164 format (e.g., +15555551234). Your phone number is used exclusively to send you SMS notifications you have requested and is never sold or shared with advertisers.

Reading data. We store the authors and books you add to your shelf, your reading log entries (start dates, finish dates, ratings, notes), and your tier preferences. This data is stored in your account and used to power the app's features. An account may contain multiple household reading profiles, and your shelf and reading activity may be associated with a specific profile.

Crash and performance monitoring. We use Sentry (sentry.io), a third-party error and performance monitoring service, to collect crash reports, diagnostic information, and performance data so we can identify and fix problems with the app. Sentry's privacy policy is available at sentry.io/privacy. We do not use third-party advertising or marketing analytics.

Release-page link clicks. When a book release page on our website (for example, a backlist.app/r/… link) shows retailer links such as Amazon or Apple Books, we may record a first-party, non-personal event noting that a retailer link on that release page was selected and when. This event records only the release page, which retailer destination was chosen, and the time of the click. It is not attached to your account, household profile, phone number, email address, subscriber identity, or any device or advertising identifier, and we do not use cookies, local storage, or fingerprinting for it. As with any website request, our hosting and infrastructure providers may process ordinary network and request metadata — such as IP address, browser/user-agent information, request timestamps, and similar operational logs — for delivery and security purposes; that processing is separate from this non-personal click measurement.

2. How We Use Your Information

  • To create and maintain your account
  • To sync your shelf and reading records across devices
  • To send SMS notifications for new book releases when you have opted in
  • To process subscription payments for alert features
  • To respond to support requests sent to hello@backlist.app

3. SMS Notifications (Twilio)

SMS delivery is powered by Twilio (twilio.com). When you enable release alerts, your phone number is transmitted to Twilio to send messages on our behalf. Twilio's privacy policy is available at twilio.com/en-us/legal/privacy.

You can opt out of SMS notifications at any time by replying STOP to any message, or by disabling alerts in the app. Standard message and data rates from your carrier may apply.

4. Apple Sign In

We support Sign in with Apple. Apple may share your name and email (or a relay address) with us depending on your privacy settings. We use this information only to create and identify your account. Apple's privacy policy is available at apple.com/legal/privacy.

5. Data Storage and Security

Your data is stored in Supabase (supabase.com), a managed Postgres database hosted on AWS infrastructure. Data is encrypted in transit (TLS) and at rest. Supabase's privacy policy is available at supabase.com/privacy.

We take reasonable technical and organizational measures to protect your data, but no method of electronic transmission or storage is 100% secure.

6. Data Sharing

We do not sell your personal information. We share data only with the service providers listed in this policy (Supabase, Twilio, Sentry, Apple, and RevenueCat) and only to the extent necessary to operate the service. We may disclose information if required by law or to protect our legal rights.

On iOS, subscription purchases are processed through Apple's in-app purchase system and managed using RevenueCat (revenuecat.com). Android subscriptions are not currently enabled in the beta. RevenueCat's privacy policy is available at revenuecat.com/privacy.

7. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal information within 30 days, except where retention is required by law.

Your phone number and alert preferences are deleted immediately upon request or when you disable all alerts.

8. Children's Privacy

Backlist accounts are intended for adults age 18 and older. An adult account holder may create household reading profiles for younger readers. These profiles do not create separate login credentials or independently authenticated child accounts. Backlist does not offer independent child accounts in this beta.

If you believe a child has created an independent account or provided us personal information directly, please contact us at hello@backlist.app and we will address it promptly.

9. Your Rights

You may request access to, correction of, or deletion of your personal data at any time by contacting us at hello@backlist.app. We will respond within 30 days.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page with an updated date. Continued use of the app after changes constitutes acceptance of the revised policy.

11. Contact

Questions about this policy? Email us at hello@backlist.app.