Privacy policy
Effective September 15, 2026
Shelf is a private record of your taste. You log the films, shows, books and meals you want to remember, rank them, and look back at them. This page says what we keep, why we keep it, and how to have it deleted.
Shelf is run by Alex Neyman. Write to a.neyman17@gmail.com with any question about this page.
What we collect
- Your phone number. It is how you sign in. We text you a code, so there is no password.
- What you log. The items you add, the notes and ratings you attach, and the comparisons you make when you rank them.
- Photos you attach. Pictures you add to an item or a memory, including the date and place stored inside the file when you leave that information in it.
- A connected account, if you choose to connect one. See the next section.
- Service records. Request logs and error reports, kept so the service keeps working.
Two things the app asks your phone for, and only when you use the feature that needs them. You can say no to either and keep using Shelf.
- Your contacts, if you choose to find friends from them. Your phone turns each number into a scrambled code before anything is sent, and only those codes reach us, so we can tell you which of your contacts are already on Shelf. The names and numbers themselves stay on your phone. We check the codes against our members and do not keep them.
- Your location, if you allow it, when you search for a restaurant or another place. We send it with your search so the right spot comes up first. It is used for that search and is not saved to your record. The place photos Shelf shows come straight from Google and are never stored by us.
Signing in works by text message: we send a code to your phone and you type it in. Shelf does not read your text messages. It reads your mail only if you connect a Gmail account, and only with your approval, as the next section explains.
Google account data
Connecting a Google account is optional and Shelf works without it. If you connect one, Shelf asks for two read-only scopes:
- Gmail, read-only. Shelf reads ticket confirmations and restaurant reservation mail so it can offer to add the films you saw and the places you booked to your own record.
- Google Calendar, read-only. Shelf reads past events so it can offer to add things you already attended.
Shelf uses this to build your own record and for nothing else. It never writes to your mail or your calendar, never sends mail as you, and never shows your Google data to another person. We do not use it for advertising and we do not use it to train models. From a matched message or event we keep the title, the date and the place, and we do not keep the message itself. A person reads your Google data only when you ask for support and give permission, or where the law requires it.
Shelf’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. That policy is published at developers.google.com/terms/api-services-user-data-policy.
You can remove Shelf’s access at any time from https://myaccount.google.com/permissions. That stops any further reading at once. To have what was already imported deleted, email us.
What we do with it
We use your data to run Shelf: to sign you in, to store and show your record, to rank what you log, to find cover art and place details, and to write the short summaries the app shows. We do not sell your data or share it with advertisers, and Shelf carries no ads.
Who processes it for us
Shelf runs on other companies’ infrastructure. Each one receives only what it needs:
- Vercel hosts the site and the API, and its AI Gateway generates the short summaries the app shows.
- Neon runs the Postgres database that holds your record.
- Twilio Verify sends your sign-in code and receives your phone number.
- Google Cloud answers restaurant searches through the Places API and serves the place photos Shelf shows.
- TMDb returns film and show details and artwork.
- Open Library returns book details and covers.
A provider that answers a search receives the words you searched for. None of them receives your record.
Who else sees it
Your record is private. Another person sees an item only when you share a shelf or a memory with them. Outside the processors named above, we disclose your data only if the law compels us, and we will tell you unless we are forbidden to.
Keeping it and deleting it
We keep your record until you ask us to delete it. Email a.neyman17@gmail.com and we will delete your account, your logged items, your notes, your comparisons, your photos and anything imported from a connected Google account within 30 days. Backup copies roll off within 90 days. The support page has the steps.
Security
Traffic runs over HTTPS. The database is access-controlled and encrypted at rest by the provider. You sign in with a one-time code sent to your phone, so there is no password to steal. No service is perfectly safe, and we will tell you if a breach reaches your data.
Children
Shelf is not meant for anyone under 13 and we do not knowingly keep their data. Write to us if a child has signed up and we will remove the account.
Changes
If this policy changes, the date at the top changes with it. When a change affects what we collect or how we use it, we will tell you in the app before it takes effect.