Rubrica privacy policy
Effective 24 September 2026. Contact: [email protected]
Rubrica is a reading app made by Nicholas Thompson. This page says what it keeps, where, and why. Short version: your books and your reading stay on your phone, there are no ads, and nothing tracks you.
What stays on your phone
Everything, unless you sign in. Your book files, where you are in each book, your reading sessions, highlights, notes, ratings, stats, streaks, seals, your companion, cover photos you take, the name on your weekly reading log and your settings all live on your device. You can back them up to a file from Me › Back up and restore, and erase them from Me › Account.
No tracking
Rubrica has no ads, no analytics and no tracking SDKs. We don't sell or share data with anyone, and we don't build a profile of you.
Crash reports. If the app crashes, it sends a crash report to Sentry so we can fix it: what went wrong in the code, the app version, the phone model and system version. It carries no name, email, account id, IP address, book titles or anything you've written.
If you make an account (optional)
An account lets your library follow you to another device. To make one we keep:
- Your email address and a password, or, if you sign in with Apple or Google, the email and name they share with us. A password is stored hashed; we can't see it.
- The year you were born. We ask before an account is made, because accounts, Friends and the News are for people 13 and up. We keep only the year.
- A synced copy of your reading data: shelves, ratings and review notes, where you are in each book, reading sessions, highlights and notes, books you track from paper or audio, reading settings, XP, seals, quests, streak days, and your companion's name and look.
Your book files are never uploaded. Sign-in codes and password-reset codes are sent to your email address.
If you turn on friends (optional)
Friends only exist if you turn them on. Then we keep:
- Your profile: a display name, an icon, a colour and a friend code.
- What you chose to share. Every sharing switch starts off. A friend only ever receives the things you switched on (for example your streak or what you're reading); anything switched off never leaves the server.
- Visits: when your companion visits a friend, we keep its name, look, the gift and the time, so your friend can see it. Visits are deleted when either account is.
- Reports: if you report a display name, we keep the report so a person can review it.
Rubrica Pro (optional)
Pro is bought through the App Store or Google Play, which handle the payment; we never see your card. RevenueCat keeps track of whether you have Pro, tied to your account id (or a random id if you're signed out), so Pro works on your other devices and after a reinstall.
Other services Rubrica talks to
- Supabase runs our database and sign-in, and holds the account data above.
- Resend sends sign-in and password-reset emails.
- Author pages: if you claim an author page, the email, website and note you send are kept so we can check it's you, and the links and line you add are shown to every reader on that page.
- Open Library (run by the Internet Archive): when you search for a book, scan an ISBN, or when Rubrica fetches a missing cover, the book's title, author or ISBN is sent to Open Library. Nothing about you is sent with it.
- Project Gutenberg (and the Gutendex catalog): when you browse or download free classics.
- Wikidata (run by the Wikimedia Foundation): to find a book's series and reading order, and an author's website, Rubrica sends the book's title and author, or the author's name. Nothing about you is sent with it.
- Book news sites: Book news (in the Library, with an account) reads the public RSS feeds of the publications listed in its Sources. Your phone fetches them directly, the same way a browser would; Rubrica sends nothing else.
- Apple and Google: only if you choose to sign in with them.
- Sentry: crash reports, as above.
Each of these has its own privacy policy.
Permissions
- Camera: to scan a book's barcode (the image isn't kept) and, if you want, to take a photo of your own copy for its cover (kept on your phone only).
- Photos: only when you pick a picture for a cover. Rubrica sees just the one you choose.
- Notifications: for the reading reminder you set. They're scheduled on your phone; there's no push server.
- Microphone: never. Rubrica doesn't ask for it.
Deleting things
- Delete your account from Me › Account › Delete account. The account and everything synced to it are removed from the server right away.
- Deleting the account doesn't touch the library on your phone unless you ask it to. You can also erase the library on its own.
- Or email [email protected] and we'll delete it for you.
Kids
Readers of any age can use Rubrica on their own phone without an account; nothing about them leaves the device. Accounts, Friends and the News are for 13 and up, and the app asks for a birth year before making one. We don't knowingly collect data from children under 13. If you think a child has made an account, email us and we'll delete it.
Changes
If this policy changes, the new version goes here with a new date, and anything that matters will be mentioned in the app.