Last updated 21 July 2026

Privacy Policy

Paguely is built to feel good to use, and that includes how we handle your data. This is the plain version, and it is accurate. If something here is unclear, email us and we will fix the wording.

The short version

  • We do not sell your data. Not to anyone, for any price.
  • There are no advertising trackers in Paguely. No Meta SDK, no ad networks, no cross-app tracking, no IDFA.
  • We do not send your name or email to any AI service. Our clue generator sees books and moods, never who you are.
  • You can delete everything, permanently, from inside the app. Settings, then Delete account.
  • Your reading is yours. Your shelf visibility is yours to set, and your reviews are private unless you make them public.

Who we are

Paguely is operated by Mereltech LLC, 30 N Gould St Ste N, Sheridan, WY 82801, United States ("Paguely", "we", "us"). For privacy questions, and for any request described in the Your rights section below, contact hello@paguely.app.

For users in the EEA and the UK, we are the data controller for the data described here.

What we collect, and why

We only collect what the app needs to work. Here is the whole list.

Data Paguely collects, why, and how long it is kept
WhatWhyLegal basis (EEA/UK)
Email address To create and secure your account, and to reset your password. Handled by our auth provider. Contract
Display name and avatar Shown on your profile. If you sign in with Google or Apple, these come from that account. If you sign up by email, your display name is taken from the part of your email before the @. You cannot upload a photo; there is no image upload in Paguely. Contract
Taste profile The genres you pick at onboarding, a few books you have loved, and your reading pace. This is what makes your first match better than random. Contract
Mood quiz answers Every reveal starts with a short mood quiz. We store the answers so the match can be made and so recommendations improve over time. Contract
Reading data Books on your shelf, reading progress, start and finish dates, ratings, reviews, reading-session times, streaks, and which cards you swiped left or right in Browse. Contract
Taste vector and Reading DNA A six-axis summary of your taste (pace, tone, length, intensity, setting, complexity) derived from what you read and rate, plus a few descriptive tags. It powers matching and the Reading DNA screen. Legitimate interests (making the product work as described)
Social activity Who you follow, comments, reactions, poll votes, book recommendations you send, reading groups you join, and group posts. Contract
Time zone Your IANA time zone (for example Europe/Sarajevo), so streak deadlines and reminders land at your local midnight and not ours. This is a region, not a location. Contract
Push notification token A device token from Apple or Google so we can send notifications you have turned on. Consent
Crash and diagnostic data Stack traces, device model, and OS version when the app crashes. Tagged with your account ID, never your email or name. Legitimate interests (keeping the app working)
Usage analytics Anonymous product analytics: which screens are used, whether onboarding was finished, whether a paywall converted. See the section below. Legitimate interests
Purchase status Whether your Paguely+ subscription is active. We never see or store your card details. Contract

We do not collect: your precise location, your contacts, your photos, your microphone or camera, your advertising ID, or your browsing outside the app. Paguely has no ad SDK and no cross-app tracking, so we do not ask for App Tracking Transparency permission, because we do not track you.

How AI is used

First, some perspective: Paguely is a reading app, not an AI chatbot or a wrapper around one. Your library, your streaks, your swipes, and the six-axis taste vector that drives your matches are all handled by our own code. AI is used for one thing: turning a match into the short, playful clues you read before a reveal, and the wording of your Reading DNA. It writes the flavour text on top; it does not run the app or decide what you can do.

That text is generated by OpenAI (model gpt-4o-mini). Because it is the part people ask about most, here is exactly what is sent.

What OpenAI receives

  • Book information: title, author, description, genres, mood tags, page count, publication year.
  • Your mood quiz answers, as text, for example "Feeling: Wistful. Pace: Slow burn."
  • Your six-axis taste vector, as numbers.
  • For the Reading DNA feature only: a list of up to 40 books you have read, with their authors, genres, and the star rating you gave them.

What OpenAI never receives

  • Your name, your email, your username, or your account ID.
  • Your reviews, your notes, or anything you have written.
  • Any way to identify you as a person.

Because your device calls OpenAI directly, OpenAI does see your IP address, as any service you connect to does. We send this data through OpenAI's API, and OpenAI states that data submitted through its API is not used to train its models.

AI-generated clues can be wrong, odd, or occasionally miss the book's tone. They are a game, not a review.

Analytics and session replay

We use PostHog (US region) to understand how the app is used, so we can fix what is broken and improve what is not working. You are never identified to PostHog. We do not send your account ID, your email, or your name, and we never call PostHog's identify function. Events are tied only to an anonymous device identifier.

The events we record are things like: onboarding started, onboarding finished, a paywall was viewed, a purchase completed, a share card was created, an outbound book link was tapped. No event carries a review, a book you are reading, a mood answer, or anything you have typed.

Session replay is enabled. PostHog records the structure of screens you visit, your navigation, and your taps and gestures, so we can see where the app confuses people.

All text and all images are masked before they leave your device. That means your shelf, your reviews, your clues, your book covers, and anything you type are blocked out in the recording. A replay shows the shape of the interface and where you tapped, not what you read or wrote.

Who we share data with

We use a small number of processors to run the app. We do not sell data to anyone, and we do not share your reading history with advertisers.

ServiceWhat it doesWhat it sees
Supabase Our database and authentication. This is where your account and reading data live. Everything in the table above.
OpenAI Writes the reveal clues and Reading DNA descriptions from a match our own code has already made. Books and moods only. No personal identifiers. See above.
PostHog Anonymous product analytics and masked session replay. Anonymous usage events, device type, IP.
Google Firebase Crash reporting (Crashlytics) and push notification delivery (FCM). Crash traces tagged with your account ID, your push token, and the text of notifications we send you (which can include a book title).
RevenueCat Manages Paguely+ subscriptions. Your store receipt and subscription status. You are not identified to RevenueCat; it uses its own anonymous ID. We never see your payment details, which stay with Apple or Google.
Open Library (Internet Archive) Our book catalogue, cover images, and free-to-borrow availability. Your search queries, which books and covers you view, and your IP. No account identifier is sent.
Google Fonts Serves the two typefaces the app and this site use. Your IP address when fonts are fetched.

Some of these providers are in the United States. Where we transfer personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses.

We will also disclose data if we are legally required to, or to protect the rights and safety of our users.

Buy and borrow links

When you tap Buy or Borrow, we open your browser to Amazon, Bookshop.org, Audible, or Open Library. Some of those links are affiliate links, which means we may earn a commission if you buy. It costs you nothing extra, and it does not change which book you get matched with.

The link carries the book's identifier and a single affiliate tag that is the same for every Paguely user. No identifier of you is ever attached. Once you land on that site, it is their site: they will see your IP and may set their own cookies, under their own privacy policy, not ours.

What stays on your device

Some things never leave your phone at all:

  • The email address you last signed in with, saved so we can pre-fill the sign-in form.
  • Your reading rhythm: roughly which hours of the day you tend to read, used to time the optional smart reminder. This is computed and stored locally, and is never uploaded.
  • The book and page shown on your home-screen widget.
  • Onboarding progress flags and the counters that decide when to show the "rate us" prompt.

Share cards are rendered on your device and handed to your system share sheet. We never upload them. Where a card goes is entirely your choice.

What other people can see

Paguely has a social layer, so some things are visible to others by design. You control this.

  • Your shelf defaults to public. You can change it to Friends (mutual followers) or Private at any time, in Settings, and you can override the setting for individual books.
  • Your reviews are private by default. A review only becomes visible to others if you explicitly mark it public.
  • Your profile, follows, comments, reactions, and poll votes are visible to other signed-in users.
  • Your mood quiz answers, your reveals, your reading sessions, your swipes, and your streak history are private to you.

Your rights

Delete everything

Open Settings, then Delete account. This permanently deletes your account and every row attached to it: your shelf, reveals, ratings, reviews, reading sessions, swipes, follows, comments, group posts, and push tokens. It is immediate and it cannot be undone. We do not keep a shadow copy.

Get a copy of your data

Email hello@paguely.app and we will send you a machine-readable export of your data within 30 days.

Correct, restrict, or object

You can edit much of your data in the app directly. For anything else, including correction, restriction of processing, objection to processing, or withdrawal of consent, email hello@paguely.app.

If you are in the EEA or UK you also have the right to complain to your local data protection authority. If you are in California, you have the right to know, delete, and opt out of "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of, but you can still contact us.

How long we keep things

  • Account and reading data: as long as your account exists. Delete the account and it is gone.
  • Crash reports: up to 90 days, per Firebase Crashlytics defaults.
  • Analytics events: retained by PostHog in anonymous form, and not linked to your account.
  • Backups: deleted data may persist in encrypted database backups for up to 30 days before those backups roll off.

Security

Data is encrypted in transit (HTTPS) and at rest. Access to your rows is enforced at the database level with row-level security, so one user cannot read another user's private data. We never see your password: authentication is handled by our auth provider, and passwords are stored only as salted hashes.

No system is perfectly secure. If we ever discover a breach affecting your personal data, we will notify you and the relevant regulator without undue delay, and within 72 hours where the law requires it.

Children

Paguely is not for children. You must be at least 13 years old to use it, and at least 16 if you are in the European Economic Area, unless your country sets a lower age and your parent or guardian consents.

We do not knowingly collect data from children under those ages. If you believe a child has created an account, email hello@paguely.app and we will delete it.

Changes to this policy

If we change how we handle your data in any way that matters, we will update the date at the top of this page and tell you in the app before the change takes effect. We will not quietly start doing something with your data that this page says we do not do.

Privacy questions

hello@paguely.app