Cookies
Cookies and trackers
Last updated: 23 September 2026
This English version is provided for convenience. In case of any discrepancy, the French version prevails.
A tracker is any information read from or stored on your device: a cookie on a website, but also data stored by an app or the identifier used by a software development kit (SDK) built into an app. Article 82 of the French Data Protection Act requires your consent before a tracker is used, unless it is strictly necessary for the service you request. Here is the complete list of the ones we use.
In short
- No advertising or social media trackers, neither on the website nor in the app.
- The website only uses strictly necessary trackers, so it does not show a consent banner.
- In the app, analytics only start once you agree.
1. On the myshelfapp.app website
The website presents myShelf, displays public profiles and lets you complete some account actions (email verification, new password). It uses no analytics tool and no advertising.
NEXT_LOCALE
- Type
- Cookie set by myshelfapp.app.
- Purpose
- Remembering the website language (French or English).
- Duration
- Your browsing session.
- Consent
- Not required: personalisation you asked for.
theme
- Type
- Browser local storage.
- Purpose
- Remembering the light or dark theme you chose.
- Duration
- Until you clear it.
- Consent
- Not required: personalisation you asked for.
Cloudflare security cookies (e.g. __cf_bm)
- Type
- Cookie that our hosting provider may set.
- Purpose
- Telling visitors apart from malicious bots and protecting the website against attacks.
- Duration
- 30 minutes.
- Consent
- Not required: security of the service.
Third-party content. Public profile pages display book covers directly from the bibliographic providers’ servers (Google Books, Open Library…). We attach no tracker to them, but your browser sends them your IP address to load the image, and those services apply their own rules.
2. In the app: necessary trackers
These items are essential for the app to work or to stay secure. They do not require your consent and are never used for advertising or analytics.
Sign-in session
- Where
- Your device’s secure storage (Keychain on iOS, Keystore on Android).
- Purpose
- Keeping you signed in.
- Duration
- Until you sign out.
Preferences
- Where
- Your device’s secure storage.
- Purpose
- Remembering your theme, language, the “what’s new” notes already seen and your analytics choice.
- Duration
- Until the app is uninstalled; 13 months for your analytics choice.
RevenueCat
- Purpose
- Managing your purchases, checking your Premium status and restoring purchases.
- Identifier
- Your myShelf account identifier.
- Duration
- As long as the app is installed.
Notifications (Expo, Apple Push Notification service, Firebase Cloud Messaging)
- Purpose
- Delivering the notifications you allowed.
- Identifier
- The device’s notification token.
- Duration
- Until you sign out or turn notifications off.
Sentry
- Purpose
- Detecting crashes and errors in order to fix them.
- Data
- Error report: device, operating system, app version, technical trace, account identifier.
- Duration
- 90 days.
Updates (Expo Updates)
- Purpose
- Downloading app updates.
- Identifier
- Random technical identifier of the installation.
- Duration
- As long as the app is installed.
3. In the app: analytics
PostHog — only with your consent
- Purpose
- Measuring how the app is used in order to improve it: screens viewed, features used, sign-up flow.
- Data
- Random device identifier, then your account identifier once signed in; usage events; device model, operating system, language; approximate location inferred from the IP address.
- Hosting
- PostHog, European Union (Germany).
- Duration
- Data kept for 25 months at most; identifier erased from the device if you withdraw your consent.
We ask for your consent on first launch, with two buttons of equal weight: “Decline” and “Accept”. Until you accept, PostHog is not started: nothing is read from or written to your device, nothing is sent. Declining has no effect on how you can use the app. Your choice is kept for 13 months, after which we ask again.
We do not track you across other companies’ apps or websites for advertising, which is why the app does not ask for Apple’s App Tracking Transparency permission.
4. Managing your choices
- In the app: open your profile, then the settings menu, under Account → Privacy, and turn “Analytics” on or off. Withdrawing your consent stops collection immediately and erases the PostHog identifier from your device.
- On the website: there is nothing to choose, since no tracker requiring consent is used. You can delete cookies and local storage at any time from your browser settings.
To learn more about all the data we process, see our privacy policy.
5. Contact
Any question about trackers: contact@myshelfapp.app.