logomyShelf

Cookies

Cookies and trackers

Last updated: 23 September 2026

This English version is provided for convenience. In case of any discrepancy, the French version prevails.

A tracker is any information read from or stored on your device: a cookie on a website, but also data stored by an app or the identifier used by a software development kit (SDK) built into an app. Article 82 of the French Data Protection Act requires your consent before a tracker is used, unless it is strictly necessary for the service you request. Here is the complete list of the ones we use.

In short

  • No advertising or social media trackers, neither on the website nor in the app.
  • The website only uses strictly necessary trackers, so it does not show a consent banner.
  • In the app, analytics only start once you agree.

1. On the myshelfapp.app website

The website presents myShelf, displays public profiles and lets you complete some account actions (email verification, new password). It uses no analytics tool and no advertising.

NEXT_LOCALE

Type
Cookie set by myshelfapp.app.
Purpose
Remembering the website language (French or English).
Duration
Your browsing session.
Consent
Not required: personalisation you asked for.

theme

Type
Browser local storage.
Purpose
Remembering the light or dark theme you chose.
Duration
Until you clear it.
Consent
Not required: personalisation you asked for.

Cloudflare security cookies (e.g. __cf_bm)

Type
Cookie that our hosting provider may set.
Purpose
Telling visitors apart from malicious bots and protecting the website against attacks.
Duration
30 minutes.
Consent
Not required: security of the service.

Third-party content. Public profile pages display book covers directly from the bibliographic providers’ servers (Google Books, Open Library…). We attach no tracker to them, but your browser sends them your IP address to load the image, and those services apply their own rules.

2. In the app: necessary trackers

These items are essential for the app to work or to stay secure. They do not require your consent and are never used for advertising or analytics.

Sign-in session

Where
Your device’s secure storage (Keychain on iOS, Keystore on Android).
Purpose
Keeping you signed in.
Duration
Until you sign out.

Preferences

Where
Your device’s secure storage.
Purpose
Remembering your theme, language, the “what’s new” notes already seen and your analytics choice.
Duration
Until the app is uninstalled; 13 months for your analytics choice.

RevenueCat

Purpose
Managing your purchases, checking your Premium status and restoring purchases.
Identifier
Your myShelf account identifier.
Duration
As long as the app is installed.

Notifications (Expo, Apple Push Notification service, Firebase Cloud Messaging)

Purpose
Delivering the notifications you allowed.
Identifier
The device’s notification token.
Duration
Until you sign out or turn notifications off.

Sentry

Purpose
Detecting crashes and errors in order to fix them.
Data
Error report: device, operating system, app version, technical trace, account identifier.
Duration
90 days.

Updates (Expo Updates)

Purpose
Downloading app updates.
Identifier
Random technical identifier of the installation.
Duration
As long as the app is installed.

3. In the app: analytics

PostHog — only with your consent

Purpose
Measuring how the app is used in order to improve it: screens viewed, features used, sign-up flow.
Data
Random device identifier, then your account identifier once signed in; usage events; device model, operating system, language; approximate location inferred from the IP address.
Hosting
PostHog, European Union (Germany).
Duration
Data kept for 25 months at most; identifier erased from the device if you withdraw your consent.

We ask for your consent on first launch, with two buttons of equal weight: “Decline” and “Accept”. Until you accept, PostHog is not started: nothing is read from or written to your device, nothing is sent. Declining has no effect on how you can use the app. Your choice is kept for 13 months, after which we ask again.

We do not track you across other companies’ apps or websites for advertising, which is why the app does not ask for Apple’s App Tracking Transparency permission.

4. Managing your choices

  • In the app: open your profile, then the settings menu, under Account → Privacy, and turn “Analytics” on or off. Withdrawing your consent stops collection immediately and erases the PostHog identifier from your device.
  • On the website: there is nothing to choose, since no tracker requiring consent is used. You can delete cookies and local storage at any time from your browser settings.

To learn more about all the data we process, see our privacy policy.

5. Contact

Any question about trackers: contact@myshelfapp.app.