Release gate: Before publishing, the operator and legal reviewer must confirm the data controller, legal entity or individual, jurisdiction, age/target audience, monitored contact route, retention commitments, and this policy. This draft does not make those decisions for them.
ReadRats Privacy Policy
- Effective date: 2026-07-16
- Last updated: 2026-07-19
ReadRats is a social reading app for logging reading sessions and joining
reading challenges. This policy applies to the iOS and Android apps, the web
app at web.readrats.app, the public site at readrats.app, and the API at
api.readrats.app.
Information we process
We process account email, display name, Firebase user ID, reading sessions, book references, pages, minutes, notes, challenge memberships, challenge chat messages, reports and blocks, and optional images. Images can be selected for a session photo, profile avatar, challenge banner, or manual book cover.
Sign-in supports email and password and Google Sign-In. Apple Sign-In is not shipped. Firebase Authentication manages credentials and SDK tokens; the app does not use a repository-managed JWT or password hash for current sign-in.
On Android, gallery selection uses the system Photo Picker or its document fallback. It receives access only to the item selected by the user and does not require broad photo-library access. Camera capture is a separate, user-initiated action. Saving a generated share QR image is local to the device and is separate from selecting an image.
If you turn on push notifications, we process a device notification token, your device platform, your app language, and your timezone so we can send reminders and challenge updates to that device. We collect these only after you grant notification permission on the device. You can turn notifications off at any time from Profile → Notifications. We delete the device token when you sign out and when you delete your account. Delivery uses Google Firebase Cloud Messaging as a processor; the token routes notifications to your device and is never used for tracking or advertising.
We do not use advertising, analytics, or crash-reporting SDKs. We do not sell personal information or use it for advertising.
Why and where
We use this information to provide accounts, reading features, challenge ranking, chat and moderation, support, and account deletion. Application data and uploaded content are hosted on AWS in the production service. Firebase Authentication is used for identity. Book searches may send the search text to the Google Books API. The public website is served by GitHub Pages and does not add analytics trackers.
Deletion and your choices
The app includes Profile → Delete account. Deletion and retention behavior must be verified against the deployed backend before release. You may also use the public support page for an account or privacy request. The operator must publish a monitored contact route and approved response and retention commitments before this policy goes live.
Children, legal rights, and changes
The operator and legal reviewer must set the applicable age and audience, controller identity, jurisdiction, and rights-request process before release. Do not infer an App Store rating, Play target audience, or response time from this draft.
If this policy changes, its last-updated date will change with the approved policy. The Portuguese version is a courtesy translation; the approved English version controls if there is a conflict.