BeBookTerms of Service

Public document — no account needed

Privacy Policy

Version 2026-05 (effective 2026-09-18) · BeBook v1.030

This policy explains what BeBook collects, why, and what control you keep. It applies to the BeBook web application and its book-recognition pipeline.

BeBook is run from the United Kingdom by the individual operator of www.be-book.org. It is not a registered company, so no company number or registered office is claimed anywhere on this site. This policy is written to the UK GDPR and the Data Protection Act 2018.

1. Who is responsible

The data controller is the operator of BeBook (www.be-book.org), based in the United Kingdom. All privacy requests and questions go to the webmaster, through the protected contact on this page. BeBook is a small community project and is not required to appoint a Data Protection Officer; the operator answers requests personally, normally within one calendar month as required by the UK GDPR.

2. Data we collect

  • Account data: first and last name, display name, email address, password (stored hashed by our authentication provider), acceptance of the Terms.
  • Approximate location: a coarse area or postcode district you type yourself (for example "Shoreditch" or "EC1"), plus approximate coordinates used to place listings on the marketplace map. We never ask for or display a street address.
  • Scan data: the one to four photos you take of a book (front cover, back cover, copyright/ISBN page, title page), the technical quality measurements computed on your device (sharpness, glare, brightness, resolution) and the text extracted from those photos.
  • Book metadata: title, subtitle, authors, publisher, edition, publication year, language, ISBN, subjects, cover image, plus the candidate records returned by external bibliographic sources and their match scores.
  • Inventory and marketplace data: the copies you own, their condition, BeBook credits value, availability status and the coarse zone attached to a listing.
  • Exchange and wallet data: exchange requests, their status, BeBook credits movements (earned, spent, locked, bonus).
  • Messages: the content of chat messages you send to other members inside an exchange thread, and who sent them.
  • Operational logs: technical and audit events such as scan processing outcomes, errors and moderation decisions.

Photos should show the book. Please avoid capturing people, handwritten notes, bookplates or anything else you do not want processed.

3. Why we process it, and on what basis

  • Providing the service — creating your account, recognising books, building your library, running the marketplace, chat and exchanges. Basis: performance of the contract you enter into by using BeBook.
  • Security, abuse prevention and moderation — detecting and investigating fraud, abuse, harmful activity, account or service attacks, moderation cases, failed scans and catalogue conflicts, and protecting members and the service. Basis: BeBook's legitimate interests in keeping the service safe and reliable, only where those interests are proportionate and do not override member rights; legal obligations may also apply.
  • Internal BeBook analytics and product improvement — understanding adoption and feature use; analysing scans, searches, wishlists, favourites, recommendation interactions, exchanges and station or QR interactions; measuring matching and recommendation quality; and debugging, improving performance and developing BeBook. We use account-linked or pseudonymous data only for BeBook's own operation and improvement, proportionately, with data minimisation and limited access. Raw private contact details, exact addresses and private message content are excluded unless strictly necessary for a specific operational or security purpose. Basis: BeBook's legitimate interests in operating, measuring and improving the service, only where proportionate and not overridden by member rights; contract where processing is necessary to deliver a feature you request. This internal use does not depend on the separate commercial consent. You may object through the protected webmaster contact; BeBook will assess and act on the objection as required.
  • Commercial data use outside BeBook — optional future use of your personal or behavioural data, or member-linked insights derived from it, to generate revenue outside the BeBook service and ecosystem. Basis: your explicit consent, which is off by default and is never required to use BeBook. Each activation includes a minimum active period of 30 calendar days, after which the consent may be withdrawn. BeBook does not claim that it currently sells member data. Private contact details, exact postal addresses, phone numbers, email addresses and private message contents are excluded. This consent does not cover internal BeBook analytics or processors acting only on BeBook's instructions.
  • Legal obligations — where applicable law requires us to keep or disclose records.

4. What is shared with other members

Other signed-in members can see: your display name, your coarse area, and the books you have explicitly marked as available, with their condition and BeBook credits value. They cannot see your email, your exact location, your unavailable books or your message history with anyone else.

Internal BeBook analytics are not sold, licensed or disclosed to third parties for their own commercial purposes. Service providers acting as processors may receive only the data needed to provide their services to BeBook and must act on BeBook's instructions. A separate “Commercial data use outside BeBook” opt-in would permit only the future external commercial use described in section 3; it does not include your exact address, email, phone number, private contact details or private message content.

5. Processors and third-party providers

  • Hosting, database, authentication and file storage — our managed cloud backend stores your account, your data and your scan photos in a private bucket that is not publicly readable.
  • Automated recognition provider — when advanced recognition is enabled on this deployment, your scan photos are transmitted to an external automated recognition service solely to extract bibliographic text. They are not used by us to train third-party models.
  • Bibliographic sources — Google Books API and Open Library receive search terms (ISBN, title, author, publisher) to return catalogue records. We do not send them your identity or your photos.
  • Map tiles — OpenStreetMap tile servers serve the map background; your browser therefore contacts them when you open the marketplace map.

These providers act only to deliver services to BeBook under BeBook's instructions; that is not external commercial use by BeBook. They receive only what is needed for their task. Depending on the provider, data may be processed outside your country. The operator of this instance is responsible for appropriate transfer safeguards.

6. How long we keep it

  • Account, library, wallet and exchange records: for as long as your account exists.
  • Scan photos and raw recognition text: kept with the scan so it can be reviewed, corrected and audited; deleted when you delete the scan or your account.
  • Chat messages: kept for the life of the exchange thread.
  • Canonical book records (title, ISBN, publisher and similar edition-level facts) are shared catalogue data and remain in the catalogue after your copy is removed. They do not identify you.
  • Operational and audit logs: retained for a limited period for security and troubleshooting.

7. Your rights

Subject to applicable law you can request access to your data, correction, deletion, restriction of processing, objection to processing based on legitimate interest, and portability of the data you provided. You can also lodge a complaint with your local data protection authority.

Send requests through the protected webmaster contact on this page. In the UK you may complain to the Information Commissioner's Office (ico.org.uk). Much of this is also self-service: you can edit book metadata, hide a copy from the marketplace, and delete copies from your library at any time.

8. Deleting your account (right to erasure)

You can delete your account yourself at any time from Settings → Account details. Deletion is immediate and permanent. We erase your sign-in record, name, email, phone, postcode and coordinates, avatar, bio, reading preferences, scan photos and extracted text, exchange photos, voice notes, reviews, forum posts, feedback threads and meeting-point preferences.

Three things survive, and none of them identifies you. Your profile row is kept as an anonymous "Deleted member" tombstone; the messages you sent are redacted to a placeholder so the other member keeps a coherent conversation; and completed or cancelled exchanges together with their BeBook credits ledger entries are retained as accounting records. UK GDPR Article 17(3) permits this: we cannot erase another member's transaction history, and the ledger must stay internally consistent. Facts about book editions in the shared catalogue are not personal data.

Deletion is refused only while you have an exchange in progress or a book lent out — finishing or cancelling it first protects the person on the other side. If you leave us a reason for going, it is stored with no link to you or your account.

The operator may also suspend an account for breaches of the Terms. A suspended account cannot sign in; its data is unchanged and it can be reactivated.

Safety checks on messages and public contributions

Automated safety checks run on new and edited messages in private conversations, on book discussions and on public reviews. They look only for abuse, threats, exposure of personal details, scams and spam. Content that clearly threatens someone is refused; anything else is delivered normally and may be flagged for limited human review by the webmaster.

Access to flagged content is restricted to the webmaster, requires a stated reason, and every access is recorded in an audit trail. It is never used for advertising, profiling or any purpose other than safety and platform integrity. Evidence kept for a case is deleted automatically after the retention period, leaving only anonymous statistics.

If your message is refused, you can ask a human to look at it. Repeated confirmed violations may lead to the usual account measures, decided by a person and never by the automatic check alone.

Reviews and ratings if you leave BeBook

Star ratings, written reviews and book discussion messages belong to the book, not to a copy or a listing, so they survive when a copy is given away, sold or removed. If you delete your account, these public literary contributions are kept but irreversibly detached from you: your identifier and profile link are removed, any contact details are stripped, and the contribution is shown as written by a former BeBook member. Private conversations, personal notes and private data are deleted as described above and are never published.

9. Invitations and recommendations (PECR)

BeBook does not send marketing email and keeps no marketing list. When you recommend BeBook or a book to a friend, the message is composed in your own email application and sent by you, from your address — we never store or transmit your friend's address, so no unsolicited electronic mail is sent under the Privacy and Electronic Communications Regulations 2003. Emails we do send are service messages tied to your account: sign-in codes, exchange notifications and calendar invitations.

11. Security

Access to data is enforced at the database level with row-level security: you can only read and write your own records, marketplace listings are limited to copies members explicitly made available, and scan photos live in a private bucket reachable only through short-lived signed links. Administrators can access scans placed in the moderation queue in order to review recognition quality; those accesses are limited to operational needs. No system is perfectly secure, and we cannot guarantee absolute security.

12. Children and age assurance

BeBook is for people aged 16 and over. Registration asks you to confirm your age, and we do not knowingly collect data from children. Exchanges happen in public places between adults or older teenagers who arrange them themselves.

BeBook carries user-to-user messaging, so the operator keeps an illegal-content risk assessment and a children's access assessment under the Online Safety Act 2023, reviews reports of harmful content, and can suspend or erase accounts that break the rules. Report anything concerning to .

14. Dispute prevention and account verification

To prevent and resolve disputes between members, BeBook may place an account at an internal verification level and ask for a phone number and, where a stronger check is needed, a postal address to which a one-time 6-digit code is posted. This is necessary for the legitimate interest of keeping exchanges safe and for handling claims. BeBook has no text-message service, so a phone number you provide is recorded as provided, not verified. Codes are stored hashed, expire (15 days for a letter code), and are never shown again once issued. The verification level, phone number, postal address and verification status are visible only to you and to the BeBook operator — never to other members. They are kept while your account exists and for as long as needed for dispute and accounting records, then deleted. To exercise your rights or contest a decision, use the protected webmaster contact on this page.

13. Changes to this policy

We may update this policy as the product evolves. Material changes to how we use your data will be announced in the app before they take effect.

Questions: · Back to BeBook