Privacy policy
Parutio is a service for keeping track of book releases. We collect the minimum needed to tell you when your authors publish: an e-mail address, the authors you follow and the books you put in your library. We do not sell or rent any data, and we show no advertising. We measure how much the site is visited, but without any cookie and without attaching those statistics to your account; inside the iOS app we count a short list of steps, and there the count is attached to your account (article 5). At any time, from your settings, you can take your data with you or delete your account — without writing to us and without giving a reason (article 9).
1. Who is responsible for your data
The controller is Prismatic, société par actions simplifiée (SAS), a French simplified joint-stock company with a share capital of 100 €, whose registered office is at 49 avenue du Raincy, 93250 Villemomble, France, registered under number R.C.S. Bobigny 888 020 112 (see the legal notice).
For any question about your data, and to exercise any of the rights described in articles 9 to 11: privacy@parutio.com. Anything else — support, a mistake in the catalogue, a content report — goes to contact@parutio.com. No data protection officer has been appointed, none being required for the processing described here, and we have not designated a separate representative in the United States or Canada: both addresses reach the people who actually run the Service.
2. What this policy covers
This policy covers the parutio.com website and the iOS and Android apps. It does not cover the bookshop websites the Service links to: as soon as you leave Parutio, the retailer’s own policy applies.
3. What we collect
- Account: e-mail address, internal identifier, creation date, reading languages, display name if you set one. If you sign in with Apple or Google, all we receive is the associated e-mail address (relayed and masked where that is what you chose). Parutio never knows your password: it is held, encrypted, by our authentication provider.
- Use of the Service: the authors you follow, the books in your library and their status (owned, want to read, read), with the date they were added; notification preferences.
- Subscription: subscription status, purchase channel (web or app store), the subscription reference at the payment provider, renewal date, trial end date. No card details are processed or stored by Parutio: payments are handled by Stripe on the web, and by Apple or Google in the apps.
- Push notifications: the device notification token and its platform (iOS or Android), only if you turn notifications on.
- Share links: if you turn on sharing of your wish list, a random token is created, along with the first name or display name you choose to show on the page. That page shows only the books marked want to read — never what you own or have read, never your e-mail address — is not indexed by search engines, and the link stops working as soon as you turn sharing off or renew it. The calendar feed included with Premium works the same way: a personal address, to be shared only with whoever you want.
- Clicks to bookshops: which link was clicked and when. These events are recorded with no account identifier: they exist to check affiliate earnings, not to profile a reader.
- Error reports: the catalogue entry concerned, your message and, if you are signed in, your account identifier, for as long as a human review takes.
- Audience measurement on the website: page viewed, referring page, arrival channel (the
utm_parameters of the link you clicked), device and browser type, and the fact that certain steps were reached (sign-up, following an author, adding to the library, leaving for a bookshop, seeing the Premium offer, subscribing). These events carry no account identifier, no e-mail address, and not the name of the author or book concerned: they count steps, they do not describe a reader. See article 5. - Measurement inside the iOS app: a short, fixed list of product events — the onboarding steps, an account created, an author or a series followed, a book added to the library, a barcode scanned, the Premium offer seen, a trial or a subscription started, sharing turned on — and the technical report of a crash. Unlike the website, these events are attached to your account identifier, which is what makes a subscription conversion readable. What never leaves the app is the object: no book title, no author or series name, no ISBN, no search text, no e-mail address and no advertising identifier. Crash reports carry neither your IP address nor the content of your account, and the Android app carries no measurement at all today. See article 5.
- Technical data: server connection logs (IP address, date, page or request called, browser type) and error reports, kept for security and diagnosis.
We process no sensitive data in the sense of article 9 of the GDPR, and none of the categories the California statute calls sensitive personal information. The authors you follow may of course reflect your tastes: that information is neither public nor shared with anyone for advertising.
4. Purposes, legal bases and retention
| Purpose | Legal basis | Retention |
|---|---|---|
| Create and run your account, sign you in, keep the authors you follow and your library | Performance of the contract (art. 6.1.b GDPR) | For as long as the account exists |
| Send you service e-mail: sign-in link, sign-up confirmation, information about your contract | Performance of the contract (art. 6.1.b) | For as long as the account exists |
| Tell you about releases by e-mail | Performance of the contract (art. 6.1.b) — can be switched off at any time in Settings → Emails, or in one click from the unsubscribe link in every such e-mail | For as long as the account exists |
| Send you the weekly digest of releases by the authors you follow | Consent (art. 6.1.a) — the digest is sent only if you turn it on in Settings → Emails, and can be switched off there at any time, or in one click from the unsubscribe link in every such e-mail | Until you turn it off or the account is deleted |
| Tell you about releases by push notification | Consent (art. 6.1.a), given in the app, withdrawable | Until consent is withdrawn, the app is uninstalled, or the account is deleted |
| Publish your wish list on a page reachable by link, if and only if you turn sharing on | Consent (art. 6.1.a), given by turning sharing on, withdrawable at any time — withdrawal kills the link immediately | Until sharing is turned off or the account is deleted |
| Run the Premium subscription, the payment, the invoicing and the accounts | Performance of the contract (art. 6.1.b) and legal accounting obligation (art. 6.1.c) | For the life of the subscription, then 10 years for accounting records (art. L.123-22 of the French commercial code) |
| Count outbound clicks to bookshops in order to check affiliate earnings | Legitimate interest (art. 6.1.f) — aggregate counting, with no account identifier | 25 months |
| Measure website audience: pages viewed, arrival channel, steps reached (sign-up, author followed, subscription) | Legitimate interest (art. 6.1.f) — aggregate statistics, with no account and no cookie; you may object (article 5) | Technical identifier: 24 h (renewed daily). Statistics: 25 months at most |
| Measure how the iOS app is used: the product events listed in article 3, attached to your account, and the technical report of a crash | Legitimate interest (art. 6.1.f) — knowing how our own app is used and fixing what breaks in it; no advertising, no third-party tracking, no advertising identifier | 25 months at most |
| Keep the Service secure, prevent abuse, diagnose technical errors | Legitimate interest (art. 6.1.f) | 12 months at most for technical logs |
| Handle error reports on a catalogue entry and the requests you send us | Legitimate interest (art. 6.1.f): catalogue quality and answering requests | 3 years from the last exchange |
After your account is deleted, personal data are erased within 30 days, backups included as they rotate, except for the accounting records the law requires us to keep.
5. Cookies, trackers and audience measurement
The site uses no advertising cookie and no third-party tracker. No consent banner is shown: the only cookies set are strictly necessary to run the Service.
- Session cookies (prefix
sb-, set by our authentication provider): they keep you signed in from page to page. They disappear when you sign out or when they expire.
Audience measurement
We measure how much the site is visited, to know how many people read it, which pages they read and how they arrived. That measurement is carried out by PostHog, on its European infrastructure (Frankfurt, Germany), acting only for us and on our instructions.
It works without any cookie and writes nothing on your device: no identifier is stored in your browser. PostHog recomputes a pseudonymous identifier on the fly from your IP address and your browser, using a secret key that is renewed every day and destroyed the next; your IP address is not kept. From one day to the next you are therefore a new visitor: this measurement cannot follow you over time, or from one site to another.
The resulting statistics are not matched against your account, are passed to no one, and serve no advertising. The events recorded contain neither your e-mail address, nor your account identifier, nor the names of the authors or books you are interested in. Legal basis: our legitimate interest in knowing the audience of our own site (art. 6.1.f GDPR).
You can object, and nothing about the Service changes if you do. Your browser’s Do Not Track signal is honoured; you can also refuse the measurement right here:
Measurement inside the mobile apps
The mobile apps use no cookie and contain no advertising measurement kit; no advertising identifier is read and nothing is shared with an advertising network. The Android app carries no measurement tool at all today. The iOS app carries our own, and it differs from the website’s on one point that has to be said plainly: it is attached to your account. The events are the short list of article 3 and nothing else — automatic screen capture, automatic interaction capture, session recording and in-app surveys are switched off in the code — and they are sent to the same PostHog European infrastructure, together with the technical report of a crash, which carries no IP address.
Legal basis: our legitimate interest in knowing how our own app is used and in fixing what breaks in it (art. 6.1.f GDPR). The app carries no on/off switch for it yet, unlike the website above: to object, write to privacy@parutio.com and we stop it for your account. Deleting your account ends it in any case.
6. Who receives your data
Your data are not sold, rented or handed over. They are accessible to authorised people at Prismatic, to the extent needed, and to the following service providers, who act for us and on our instructions alone, under agreements complying with article 28 of the GDPR:
| Provider | Role | Location |
|---|---|---|
| Supabase, Inc. | Authentication: account, password, sign-in links, Apple and Google sign-in | United States (head office) — project hosted in the AWS eu-west-3 region (Paris, France) |
| Hostinger International Ltd | Hosting of the website, the API and the database (accounts, follows, library, devices) | Cyprus (head office) — server located in Paris, France |
| Plus Five Five, Inc. (Resend) | Sending e-mail: sign-in links, confirmations, release alerts, weekly digest | United States (head office) — sending operated from the AWS eu-west-1 region (Ireland) |
| Apple Distribution International Ltd | iOS push notifications (APNs), in-app purchases and billing on the App Store | Ireland (European Union) |
| Google Ireland Limited | Android push notifications (Firebase Cloud Messaging), in-app purchases and billing on Google Play | Ireland (European Union) |
| Stripe Payments Europe, Limited | Payment and management of subscriptions taken out on the web | Ireland (European Union) |
| RevenueCat, Inc. | Tracking of subscriptions purchased in the mobile apps | United States |
| PostHog, Inc. | Website audience measurement (pages viewed, arrival channel, steps reached — without cookies and without any account identifier) and iOS app usage measurement (product events attached to the account identifier) | United States (head office) — data hosted in the European Union (Frankfurt, Germany) |
| Functional Software, Inc. (Sentry) | Collection of server-side technical errors and of the iOS app's crash reports, for diagnostic purposes | United States (head office) — data hosted in the European region (Germany) |
We may also have to disclose data to an administrative or judicial authority where the law requires it.
7. Where your data are stored
Your data are stored in the European Union, whichever country you read from. The website, the API and the database run on a server in Paris, France; the authentication project is hosted in Paris; e-mail is sent from Ireland; audience statistics are held in Frankfurt, Germany, and error reports in Germany. If you live in the United States or in Canada, this means your personal information is transferred to and processed in France and elsewhere in the European Union, where it is protected by the GDPR, and where a public authority may be able to require access to it under the law of that country.
Some of the providers listed above are established outside the European Union, mainly in the United States, and access the data from there. Those transfers are governed by the standard contractual clauses adopted by the European Commission, completed where appropriate by additional technical measures (encryption in transit, minimisation of what is transmitted), or by the provider’s participation in the EU-US Data Privacy Framework.
- Supabase, Inc.: European Commission standard contractual clauses.
- Plus Five Five, Inc. (Resend): European Commission standard contractual clauses.
- Google Ireland Limited: Standard contractual clauses for the processing carried out by Google LLC.
- Stripe Payments Europe, Limited: Standard contractual clauses for the processing carried out by Stripe, Inc..
- RevenueCat, Inc.: European Commission standard contractual clauses.
- PostHog, Inc.: European Commission standard contractual clauses for access from the United States.
- Functional Software, Inc. (Sentry): European Commission standard contractual clauses for access from the United States.
A copy of the safeguards in place can be requested at privacy@parutio.com.
8. Deleting your account
Deletion is directly available from Settings → Delete my account. It is immediate and permanent: your account, the authors you follow, your library, your registered devices and your local subscription record are erased from our database, and the associated authentication account is deleted at our provider.
If you had turned on sharing of your wish list, the token is destroyed with the account and the public page ceases to exist at once.
What remains has no connection to you. Outbound clicks to bookshops are kept in anonymous form, with no account identifier, solely to check affiliate commissions. Error reports you sent us stay in the review queue because they fix a catalogue entry, but your account identifier is stripped from them. Accounting records relating to a paid subscription are kept for as long as the law requires.
A subscription bought from Apple or Google has to be cancelled separately with that store: deleting your Parutio account does not stop it.
Before you go, you can take your data with you: see the right to portability in article 9.
9. Your rights
You have the right to access, rectify, erase, restrict, object to and port your data, the right to withdraw your consent at any time for the processing that depends on it, and the right to give directions about what happens to your data after your death.
Several of these are exercised on your own, without writing to us and without waiting:
- Portability and access (art. 15 and 20 GDPR): Settings → My data → Export my data immediately downloads a JSON file containing your profile, your preferences, the state of your subscription, the authors you follow and your library, in a structured, machine-readable format.
- Erasure (art. 17): Settings → Delete my account, on the terms described in article 8.
- Rectification (art. 16): e-mail address, password, display name and reading languages can all be changed from the settings.
- Objecting to audience measurement (art. 21): directly in article 5 above.
- E-mail: release alerts are switched off in Settings → Emails, or in one click from the unsubscribe link at the bottom of each of those e-mails. The weekly digest is sent only if you have turned it on there, and is switched off the same way. E-mail that is strictly necessary to run the account (sign-in link, contractual information) keeps being sent.
- Push notifications: from your device settings or from the app.
- Wish-list sharing: consent is withdrawn from your library, and the link stops working at once.
For anything else — restriction, objecting to another processing, or simply a question — write to privacy@parutio.com. We answer within one month of receiving the request, extended to three months if the request is complex. Proof of identity may be asked for where there is serious doubt about who is making the request.
If, after contacting us, you believe your rights are not being respected, you may complain to the French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL): 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, cnil.fr. Readers in the United States and in Canada have the additional routes described in articles 10 and 11.
10. Your U.S. privacy rights
This article is for readers in the United States, and in particular for residents of California, whose Consumer Privacy Act (CCPA, as amended by the CPRA) gives the rights described below. Residents of the other states that have passed a comprehensive privacy law have rights that are substantially the same, and we handle every request the same way wherever it comes from.
What we collect, and why
In the vocabulary of the California statute, the categories of personal information we have collected over the past twelve months are:
- Identifiers — e-mail address, internal account identifier, device notification token, IP address in the server logs.
- Commercial information — the subscription you bought, its status and its dates, the books in your library, the authors you follow.
- Internet or other electronic network activity — pages viewed, referring page, arrival channel, device and browser type, the steps of the funnel described in article 3, and outbound clicks to bookshops.
We collect them from you (what you type and what you do in the Service), from your device and browser automatically, and — for subscriptions — from Stripe, Apple or Google, who tell us that a payment happened. They are used for the purposes listed in the table of article 4, and for nothing else. We collect no sensitive personal information in the sense of the statute, no biometric or precise geolocation data, and we draw no inferences about you for advertising.
We do not sell and we do not share
We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the past twelve months, and we do not do so today. Those two words carry their statutory meaning: no personal information is disclosed to anyone for money or for any other valuable consideration, and none is disclosed to an advertising network for targeting you elsewhere. There is no advertising SDK in the apps, no advertising identifier is read, and no advertising tag is loaded on the site. That is also why no “Do Not Sell or Share My Personal Information” link is published here: it would switch off something that does not exist. We do not knowingly sell or share the personal information of anyone under 16 — the Service is not intended for anyone under 15 at all (article 14).
What we do disclose, and only for a business purpose, is what the table in article 6 lists: the service providers who host, authenticate, e-mail, bill and monitor on our behalf, each bound by contract to use the data only for us.
Your rights and how to use them
- Right to know what we have collected about you, the categories, the sources, the purposes and who received it — this article and article 3 answer it in general, and Settings → My data → Export my data answers it for your own account, immediately.
- Right to delete — Settings → Delete my account, permanent, on the terms of article 8.
- Right to correct inaccurate personal information — from the settings, or by writing to us.
- Right to opt out of sale, sharing and profiling — there is nothing to opt out of, as explained above; the audience measurement, which is neither, can nonetheless be refused in article 5.
- Right to limit the use of sensitive personal information — none is collected.
- Right not to be discriminated against for exercising any of these: the Service works exactly the same for a reader who does, and no price, feature or quality of service depends on it.
The two self-service routes above need no contact with us at all. For anything else, write to privacy@parutio.com from the address of the account concerned; we answer within 45 days, extended once by a further 45 days where the request is complex, and we will tell you if we need it. Where there is serious doubt about who is asking, we may ask for something that establishes it. An authorised agent may make a request on your behalf if he provides your written permission, and we may still ask you to confirm it.
Your browser’s Do Not Track signal is honoured by our audience measurement. A Global Privacy Control signal is not currently read: it is designed to opt a reader out of sale and sharing, and we do neither.
11. Your Canadian privacy rights
If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) applies to what we do with your personal information, alongside the GDPR. We collect it for the purposes identified in the table of article 4 and for no other; we ask for your consent where consent is the basis (push notifications, wish-list sharing) and you can withdraw it at any time as described in article 9; and we keep it only for the periods stated there.
You may ask us for access to the personal information we hold about you, and for its correction. The export in Settings → My data → Export my data answers the first immediately; anything beyond it can be asked at privacy@parutio.com, and we answer within 30 days.
If you are in Quebec, the Act respecting the protection of personal information in the private sector, as amended by Law 25, applies as well. Nobody has been designated as a separate person in charge of the protection of personal information: under that Act the function belongs, by default, to the person exercising the highest authority within the company — the president of Prismatic, named in the legal notice — and privacy@parutio.com is the address that reaches him. We would rather write that than name a role nobody holds. The same article 9 rights apply, including the right to be informed of, and to withdraw from, a use we base on your consent, and no decision concerning you is taken by automated processing alone (article 13).
Commercial e-mail. We send you release alerts because you created an account to receive them, and the weekly digest — where the market has it — only if you expressly turned it on in your settings. You can stop either at any time from Settings → Emails or from the unsubscribe link every one of them carries, and the request takes effect at once. Nothing is sent to an address that did not ask for it, and we do not pass your address to anyone for their own mailings.
As stated in article 7, your personal information is stored and processed in the European Union by the providers listed in article 6, and is subject to the law of the countries concerned.
If our answer does not satisfy you, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca). Residents of Quebec may also contact the Commission d’accès à l’information du Québec (cai.gouv.qc.ca) under the province’s Act respecting the protection of personal information in the private sector.
12. Security
Traffic to and from the Service is encrypted in transit (HTTPS). Access to production data is restricted to authorised people. Passwords are never kept in clear: they are handled by our authentication provider, which stores them as hashes. The servers are rate-limited to prevent abuse. If a data breach were likely to result in a high risk to your rights, you would be told, as article 34 of the GDPR requires and as the notification laws of your state or province may also require.
13. Automated decisions
No decision producing legal effects concerning you is taken solely on the basis of automated processing. We carry out no advertising profiling.
14. Minors
The Service is not intended for anyone under 15 — a stricter floor than the 13 years of the U.S. Children’s Online Privacy Protection Act — and we do not knowingly collect their data. If an account were created by someone under 15 without the permission of a parent or legal guardian, write to us and it will be deleted.
15. Changes to this policy
This policy may change, in particular if a new processing or a new provider is put in place. Any substantial change is notified to you by e-mail or in the app before it takes effect. The date it was last updated is at the top of this page.