Privacy & Data Architecture
Bookarium is engineered with an uncompromising commitment to digital sovereignty: zero tracking, zero marketing networks, and zero monetization of your reading habits.
1. Zero Tracking & No Ad Networks
GDPR Recital 30 & Privacy by Design
Bookarium does not load Google Analytics, Meta Pixels, Hotjar, tracking beacons, or third-party marketing scripts. We do not profile your reading tastes, build behavioral advertising dossiers, or sell information to data brokers. Your reading journey is strictly private.
Privacy-First Aggregate Telemetry: To monitor system reliability and understand general catalog reach, Bookarium utilizes first-party, cookie-less Vercel Web Analytics and Real User Speed Insights. Telemetry is strictly anonymous and aggregate—no IP addresses are stored, no persistent device fingerprints are collected, and no cross-site tracking occurs.
2. Why There Is No Cookie Consent Banner
EU ePrivacy Directive (Article 5(3)) Exemption
Under the European Union ePrivacy Directive and European Data Protection Board (EDPB) guidelines, websites are only legally required to display intrusive consent banners when using non-essential or advertising cookies.
Strictly Necessary Authentication Cookies: When you explicitly log into your account, our authentication provider (Supabase) sets a single secure session cookie (sb-*-auth-token) solely to maintain your authenticated session. This cookie is 100% exempt from consent banner requirements.
Functional Jurisdiction Verification: To ensure regulatory compliance with international public domain copyright statutes (e.g. Life+70 vs. Life+100 rules), Bookarium sets a non-tracking, functional cookie (bookarium-geo-country, SameSite=Lax, Max-Age=1 year) storing solely your two-letter ISO country code. This functional cookie retains zero personal data, zero IP addresses, and zero browsing history, serving exclusively to withhold copyrighted works in restricted countries. Under EU ePrivacy Directive Art. 5(3), functional cookies strictly necessary for delivering a legally compliant requested service are exempt from consent banners. For details on term calculations, consult our Copyright & Public Domain Governance.
As a guest reader, zero marketing or tracking cookies are written to your browser. First-party aggregate analytics and Core Web Vitals operate completely cookie-free.
3. Local-First Browser Storage
Client-Side Persistence
Bookarium prioritizes local-first architecture. Your reading preferences and offline library are preserved directly on your device:
- localStorage: Stores your active theme (Dark, Light, Sepia), reader typography choices (font size, line height, font family), audio speech rate, and local guest bookmarks.
- IndexedDB: Caches unabridged public domain text and EPUB packages when you click “Download for Offline”, allowing seamless in-browser reading even without an internet connection.
This data resides exclusively on your hardware and is never transmitted to analytics providers.
4. Cloud Sync & Account Data
GDPR Article 6(1)(b) (Performance of Service)
If you choose to create an optional account, we store minimal data strictly necessary to fulfill your request to access your curated library across devices:
- Your email address and cryptographically salted password hash (handled by Supabase Auth).
- Optional public display name and preferred reading atmosphere.
- The IDs of books you have saved to your personal custom shelves or favorites list.
5. Your Rights & Self-Service Data Erasure
GDPR Articles 15–20 (Right to Erasure)
You maintain total dominion over your personal data. Under GDPR and global privacy standards, you have the right to access, rectify, export, and completely delete your account at any moment.
6. United States & Global Privacy Frameworks
California CCPA/CPRA, COPPA, UK GDPR & Canada PIPEDA
California Consumer Privacy Act (CCPA / CPRA)
Do Not Sell or Share My Personal Information: Bookarium does not sell, rent, release, disclose, or transfer personal data to third parties for monetary or other valuable consideration, nor do we share information for cross-context behavioral advertising (Cal. Civ. Code § 1798.120).
Non-Discrimination: We will never discriminate, charge different rates, or deny library services to any reader who exercises their statutory privacy rights.
Children's Online Privacy Protection (COPPA & GDPR Art. 8)
Bookarium is a dedicated open-access cultural archive. Guest reading operates anonymously with zero account requirement or personal data collection. For optional cloud bookshelf synchronization, account registration is strictly limited to individuals aged 13 or older (or the digital age of consent in their jurisdiction). We do not knowingly collect, solicit, or maintain personal information from children under the age of 13.
United Kingdom (UK GDPR) & International Parity
Readers in the United Kingdom, Canada (PIPEDA), Brazil (LGPD), Australia, and worldwide receive the same uncompromising standard of privacy protection: zero behavioral profiling, strictly necessary session cookies, and self-service account deletion.
7. Infrastructure Partners
Data Processors & Content Delivery
Edge hosting, global CDN, and cookie-less aggregate performance telemetry (Vercel Web Analytics & Speed Insights).
Encrypted PostgreSQL database and authentication with Row Level Security (RLS).
Open-source archive providing unabridged public domain texts and metadata.
Last Updated: March 2026 • 100% CC0 Public Domain Preservation