Privacy policy

Version 1.0 · 2026-08-12

Who we are

Nightspine is a small app for people who read: you keep your shelf, review books, build wishlists, and see what your friends are reading. It is built and run by one person, not by a company.

This policy covers the Nightspine app and the public pages Nightspine serves. Questions about it, or about your data, go to hello@nightspine.com and reach that person directly.

What we collect

Your account
Your email address and a hash of your password, held by Supabase Auth. Nightspine never sees your password in plain text.
Your profile
A username, an optional display name, and an optional Instagram handle. You choose all three, and you can change or clear the optional two whenever you like.
Your reading
The books on your shelves and their status, your reading progress, your ratings, the reviews you write, the mood and pace tags you pick, the content-warning votes you cast, and your wishlists with their notes.
Share tokens
When you switch sharing on for a shelf or a wishlist, Nightspine generates a random token and stores it beside that shelf or wishlist. The token is what makes the public link work; switching sharing off invalidates it.
Crash reports
Nightspine uses Sentry to learn when the app crashes. A crash report carries the technical detail of the crash — stack trace, app version, device model, OS version. No personal information is attached: screenshots and breadcrumbs are switched off, and your reading content is never part of a crash report.
Product analytics
Nightspine uses PostHog, on its EU cloud, to count how the app is used — how many people finish onboarding, shelve a first book, or share a card. Events carry a pseudonymous user id, counts, and fixed enum values such as a shelf status. Book titles, review text, wishlist notes and any other reading content are never sent to PostHog. The public share pages (shelf, wishlist, trust and this page) use Vercel Web Analytics — cookieless, aggregate visit counts, no identifiers stored on your device.

We do not collect your contacts, your location, your advertising identifier, or anything from other apps on your device.

Why we collect it

Three reasons, and no others.

We do not profile you for advertising, and we do not build an interest graph to sell.

Where it lives

Each of those four is a processor acting on Nightspine's instructions under its own agreement. Supabase and PostHog hold what we send them in the EU; Sentry and Vercel may process what reaches them outside the EU under their standard contractual clauses.

What we share

Nightspine has no public profiles. Your shelf, your wishlists and your reviews belong to your account, and inside the app they are visible to the friends you follow each other with.

A Nightspine page becomes readable by anyone holding its link only when you create that link yourself: you switch sharing on for a shelf or a wishlist, and Nightspine mints the share token. Anyone with the link can then read that page without signing in, so share it only where you mean to. Switch sharing off and the link stops working.

We do not sell your data. We do not rent it, and we do not pass it to advertisers or data brokers. It goes to the four processors named above, and nowhere else except where the law compels us.

Keeping and deleting your data

We keep your data for as long as your account exists. Deleting the account deletes everything attached to it — profile, shelves, reads, reviews, ratings, tags, warning votes, wishlists and share tokens all cascade away with it. Aggregated content-warning counts survive only as anonymous totals, with no link back to you.

Being straight about where this stands: the in-app delete-my-account button is not built yet, and ships in a later release. Until it does, write to hello@nightspine.com from your account address and your account and its data will be deleted within 30 days, with a confirmation back to you.

Crash reports expire on Sentry's retention schedule. Analytics events are kept as pseudonymous records; ask, and the pseudonymous id tied to your account is deleted with the rest.

Your rights

If you are in the EU or the UK, the GDPR gives you the right to see the data we hold about you, correct it, have it deleted, receive a copy of it, and object to how we use it. Exercise any of them by writing to hello@nightspine.com — no charge, no form to fill in. If you think we have handled your data badly, you may complain to your national data-protection authority.

No unreviewed AI text

Nightspine will never show you AI-generated text dressed up as editorial or as another reader's words. Reviews are written by readers. Book details come from the book data source. Anything Nightspine says in its own voice — copy in the app, this policy, the pages you can share — is read line by line by a person before it ships. If that ever changes, the change is labelled in the app and listed below.

Changes to this policy

When this policy changes in a way that matters, the version goes up, the date changes, and the change is listed here. Material changes are announced in the app before they take effect.

Contact

hello@nightspine.com

Read the trust page