Rubrica privacy policy
Effective 29 September 2026. Contact: [email protected]
Rubrica is a reading app made by Nicholas Thompson. This page says what it keeps, where, and why. Short version: your books and your reading stay on your phone, there are no ads, and nothing tracks you.
What stays on your phone
Everything, unless you sign in. Your book files, where you are in each book, your reading sessions, highlights, notes, ratings, stats, streaks, seals, your companion, cover photos you take, the name on your weekly reading log and your settings all live on your device. You can back them up to a file from Me › Back up and restore, and erase them from Me › Account.
No tracking
Rubrica has no ads, no analytics and no tracking SDKs. We don't sell or share data with anyone, and we don't build a profile of you.
Crash reports. If the app crashes, it sends a crash report to Sentry so we can fix it: what went wrong in the code, the app version, the phone model and system version. It carries no name, email, account id, IP address, book titles or anything you've written.
If you make an account (optional)
An account lets your library follow you to another device. To make one we keep:
- Your email address and a password, or, if you sign in with Apple or Google, the email and name they share with us. A password is stored hashed; we can't see it.
- The year you were born. We ask before an account is made, because accounts, Friends and the News are for people 13 and up. We keep only the year.
- A synced copy of your reading data: shelves, ratings and review notes, where you are in each book, reading sessions, highlights and notes, books you track from paper or audio, your shelves and tags, reading settings, XP, seals, quests, streak days, and your companion's name and look.
- Your book covers, as small pictures in a private folder only your account can open, so a new phone shows the same covers. Book files never leave your phone.
Your book files are never uploaded. Sign-in codes and password-reset codes are sent to your email address.
If you turn on friends (optional)
Friends only exist if you turn them on. Then we keep:
- Your profile: a display name, an icon, a color and a friend code.
- What every friend sees: your name, icon and color, the day you last read (the day, not the time), and whether you have Pro.
- What you chose to share. Every sharing switch starts off. Beyond the line above, a friend only receives the things you switched on (for example your streak or what you're reading); anything switched off never leaves the server.
- Online now (only if you switch on "Show when I'm online", which starts off): while Rubrica is open we keep one line saying you're online or reading, and the book's name if you also share your current book. Friends who have the same switch on can see it, and you can see theirs. It's overwritten every minute, never kept as a history, and deleted when you switch it off.
- Visits: when your companion visits a friend, we keep its name, look, the gift and the time, so your friend can see it. Visits are deleted when either account is.
- Reading a book together: if you and a friend start one, we keep the book's title and author, how far each of you is, and the notes you leave each other. Only the two of you can see them.
- Gifts of Pro: if you give a friend a week of Pro, we keep who gave it to whom and when.
- Reports: if you report a display name, we keep the report so a person can review it.
Rubrica Pro (optional)
Pro is bought through the App Store or Google Play, which handle the payment; we never see your card. RevenueCat keeps track of whether you have Pro, tied to your account id (or a random id if you're signed out), so Pro works on your other devices and after a reinstall.
The launch list (optional)
If you leave your email on readrubi.com (or readrubrica.com) to hear when Rubrica is out, we keep it only to send that one email, and delete the list once the app has launched. It's stored with our database provider (Supabase) and never shared or sold.
Other services Rubrica talks to
- Supabase runs our database and sign-in, and holds the account data above.
- Resend sends sign-in and password-reset emails.
- Author pages: if you claim an author page, the email, website and note you send are kept so we can check it's you, and the links and line you add are shown to every reader on that page.
- Open Library (run by the Internet Archive): when you search for a book, scan an ISBN, or when Rubrica fetches a missing cover, the book's title, author or ISBN is sent to Open Library. Nothing about you is sent with it.
- Project Gutenberg (and the Gutendex catalog): when you browse or download free classics.
- Wikidata (run by the Wikimedia Foundation): to find a book's series and reading order, and an author's website, Rubrica sends the book's title and author, or the author's name. Nothing about you is sent with it.
- Book news sites: Book news (in the Library, with an account) reads the public RSS feeds of the publications listed in its Sources. Your phone fetches them directly, the same way a browser would; Rubrica sends nothing else.
- Bookshop.org: if you tap "Get a copy" on a book, your browser opens their site with the book's ISBN, or its title and author. The link carries Rubrica's affiliate tag (they pay us a small cut; you pay the same). Nothing about you is sent with it.
- Cloudflare serves readrubi.com and readrubrica.com and the browser version of Rubrica. Like any web host it sees the address a request comes from. The site sets no cookies and has no analytics.
- Apple and Google: only if you choose to sign in with them.
- Sentry: crash reports, as above.
Each of these has its own privacy policy.
Permissions
- Camera: to scan a book's barcode (the image isn't kept) and, if you want, to take a photo of your own copy for its cover (on your phone, and in your private covers folder if you have an account).
- Photos: only when you pick a picture for a cover. Rubrica sees just the one you choose.
- Notifications: for the reading reminder you set, your companion's postcards, the Sunday recap and the reading timer on your lock screen. Each has its own switch. They're scheduled on your phone; there's no push server.
- Microphone: never. Rubrica doesn't ask for it.
Deleting things
- Delete your account from Me › Account › Delete account. The account and everything synced to it are removed from the server right away.
- Deleting the account doesn't touch the library on your phone unless you ask it to. You can also erase the library on its own.
- Or email [email protected] and we'll delete it for you.
Kids
Readers of any age can use Rubrica on their own phone without an account; nothing about them leaves the device. Accounts, Friends and the News are for 13 and up, and the app asks for a birth year before making one. We don't knowingly collect data from children under 13. If you think a child has made an account, email us and we'll delete it.
Changes
If this policy changes, the new version goes here with a new date, and anything that matters will be mentioned in the app.