Privacy policy
Last updated 21 August 2026
What we hold, who can see it, how long we keep it, and how to take it out or delete it. Written to describe what this product actually does rather than what a policy of this kind usually says.
The short version
Pages and People is a private place to read with a few people you chose. Almost everything you do here is either yours alone or your circle’s, and the boundary between those two is enforced by the database rather than by the screens - which means a mistake in an interface cannot open it.
- Where you are in a book is private. Nobody sees your position, not organizers by default and not the circle. A circle sees how many of its members have finished a part, never which ones.
- Your shelves, notes, ratings and captured passages are yours. They are readable by you and by nobody else, including us in the ordinary course of running the service.
- What you write in a circle stays in that circle, and only reaches members who have read far enough to see it without being spoiled.
- We sell nothing and track nothing. There is no advertising, no analytics product, no third-party tracker and no profile built for anyone else’s benefit.
Who we are
Pages and People operates this service and decides what happens to the data described here. You can reach us at contacts.pagesandpeople@gmail.com about anything on this page, including a request to see, correct or delete what we hold.
What we hold
Because you told us
- Your email address, which is how you sign in and the only way we can reach you.
- Your profile: display name, and - all optional, all in settings - pronouns and a photograph. Your language, which decides how dates read, and your timezone, which decides which evening a reading reminder reaches you. Setting up asks for your name and your age and nothing else; the timezone is taken from your browser and we ask you to check it the first time you are looking at a meeting.
- What brought you here: whether you said you were reading on your own, joining a circle or starting one. It is optional, it decides what your home screen offers first, and it is a field in settings you can change or clear.
- Your reading preferences: text size, dyslexia-friendly type, reduced motion.
- Your age attestation: that you said you were 13 or older, and the date you said it. We do not ask for a date of birth and do not hold one.
We no longer ask for a password. Signing in is the emailed link and nothing else. If you set a password before 21 August 2026, its hash is still held by our authentication provider and is still never visible to us - but nothing in the product reads it, so it cannot be used to sign in and there is no screen that will change it. Delete your account and it goes with everything else.
Because you used the product
- The circles you belong to, your role in each, and when you joined.
- Books and editions you added, candidates you proposed, and the votes you cast.
- Reading plans, milestones, and your own progress through them.
- Posts and replies you wrote, reactions you left, and threads you muted.
- Meetings, your RSVPs and any private note attached to one, and attendance.
- Your shelves, your private notes and ratings, and passages you captured while reading.
- Reports you filed, and notifications sent to you with your notification settings.
Because a shared space needs a record
We keep an audit trail of actions that change a circle for everybody in it: role changes, invitations, removals, ownership transfers, moderation, configuration changes, starting and rescheduling a cycle, and any time an organizer looks at per-member progress. Each entry records who did it, what they did and when. The circle’s organizers can read it; nobody else can.
Who can see what
These are not settings. They are authorization rules in the database, applied to every read and write, so they hold whether a request comes from our own screens or from somebody with a session and a curl command.
- Your profile is readable by you and by people who share a circle with you. It is not public and not reachable by anyone else.
- Your progress is readable by you. A circle can only ever see aggregate completion - a count of how many members have finished a part - through a function that is structurally incapable of naming anybody.
The one exception is deliberate and narrow: a circle’s organizers can see per-member pace so they can help. It is stated on the screen to everybody in the circle, and every such look is written to the audit trail.
In a circle of exactly two, the arithmetic of an aggregate identifies the other person, and the interface stops claiming otherwise rather than pretending. - Posts are readable by members of that circle who have reached the point in the book the post is attached to. This is the spoiler gate, and it covers the post, its title, an image’s description, a search result, a quoted reply, and any notification preview - because a post you have not reached is never handed to the screen at all.
- Your shelves, passages, private notes, ratings, ballots, notifications and preferences are readable by you and nobody else.
- A report you file is readable by you and by that circle’s moderators. Nobody is told who reported them.
- Someone you block stops seeing your writing and you stop seeing theirs. They are not told, and the record of the block is readable by you alone.
Who we share it with
Nobody, in the sense that word usually carries. We do not sell data, do not trade it, and do not disclose it for anybody else’s marketing. We use three service providers to run the product, and each one only ever sees what it needs to do its job:
- Supabase hosts the database and the sign-in system, in the United States (us-east-1). This is where everything above lives.
- Resend delivers our email. It sees the address a sign-in link is going to and the content of that message.
- Vercel serves the application and handles the requests your browser makes.
Some requests are made on your behalf to somewhere outside all three, and they are worth naming one at a time rather than counted, because what each one carries and who receives it are different. None of them happens unless you act.
- When you search for a book by title, that search text is sent to Open Library to find its details. Nothing identifying you goes with it, and you can add a book by hand instead.
- When you add a book, we ask that same place once more about that edition’s ISBN, to fill in its page count and contents page so a reading plan has something to divide up. An ISBN identifies the book and not you.
- A book’s cover comes from that same catalogue, from covers.openlibrary.org, and this one is different in a way worth stating plainly: our servers fetch it, not your browser. Your address and the page you were on never reach them, and we will fetch a cover from nowhere else. A great many books have no cover art at all, and those fetch nothing.
We would disclose data if the law required it of us. If that ever happens, we will tell the people affected unless we are forbidden to.
Cookies
Two, both necessary, both set only after you sign in: the pair that holds your session so you stay signed in between pages. There are no analytics cookies, no advertising cookies, and nothing that follows you to another site. Signing out removes them.
How long we keep it
For as long as you have an account, because the product is a record of what you have read and who you read it with, and quietly deleting last year’s circle would be the opposite of what it is for. When you delete your account, what happens next is described below and happens immediately rather than on a schedule.
Not yet settled: a retention period for audit events. They are kept indefinitely today, attributed to an anonymous record after an account is deleted. We will state a period here before we claim one anywhere else.
Taking a copy
Sign in, open Settings, then Your data and your account, and press Download my data. You get a readable JSON file straight to your device: your profile, your shelves and where you are in each book, your captured passages, your reading statistics, your notification settings and your notifications. It is built by reading the database as you, so it can only ever contain what you can already see - and it is never emailed anywhere.
What the export does not include yet: the posts you wrote in a circle. Those sit behind the spoiler gate, and exporting them needs a path that respects it, which is not built. We would rather say that here than hand you a file that quietly omits half your writing. Ask us and we will get you a copy in the meantime.
Deleting your account
Same place: Settings, then Your data and your account. It is immediate and it cannot be undone. Three things happen, and they are different on purpose:
- Removed - everything that is only ever yours: shelves, passages, private notes and ratings, reading progress, RSVPs, reactions, muted threads, notifications and preferences, ballots, memberships, pending invitations and requests, and any blocks either way.
- Anonymised - what other people’s experience is built from. Your posts stay where they are and your name comes off them; you become “A former member”. A discussion with holes punched in it is a worse outcome for the people still in it than one where a voice becomes anonymous, and replies to a deleted post would otherwise disappear with it.
- Kept - audit events, attributed to that same anonymous record. They exist to say who did what to a shared space, and a record that its own subject can erase is not a record. The fact and date of your age attestation stay with it, and name nobody.
One thing will stop a deletion: being the only owner of a circle. Hand it to somebody else or close it first, so that deleting your account cannot silently delete other people’s.
Your rights
We launch in the United States and work to the shape of the GDPR anyway - export, deletion, consent and data minimisation - so that reaching Europe is a review rather than a rebuild. You can see what we hold, take a copy, correct it, or delete it, and the first three are self-serve rather than a request you have to wait on. If any of that does not work, write to us at the address above and we will do it by hand.
Age
You must be 13 or older to hold an account. We ask when you set one up and we record the answer. We do not knowingly hold accounts for children under 13; if you believe we do, tell us and we will remove it.
Security
Every read and write is authorised in the database rather than in the application, which is the difference between a rule and a habit. Traffic is encrypted, and data is encrypted at rest by our provider. Sign-in is by a one-time link, emailed to you, that works once and expires. There is no password to guess, reuse or leak.
Being straight about the size of this: Pages and People is small and new. We do not have a formal certification, a published incident-response commitment or a bug bounty. If you find a problem, write to us at the address above and we will treat it seriously and quickly.
Changes
When this page changes in a way that matters, the date at the top changes and we say so in the product. We will not quietly widen what we do with what you have written.
The terms cover the other half: what the service is, and what is expected of everybody using it.
