Privacy Policy

Last updated: 9 July 2026

This Privacy Policy explains what personal data BookNest collects, why we collect it, how we use it, and the rights you have over it. We keep it short and plain on purpose.

1. Who we are

BookNest is a personal reading library service available at book-nest.net. For the purposes of the EU General Data Protection Regulation (GDPR) and the Law of Ukraine "On Personal Data Protection", the data controller is the operator of BookNest.

You can reach us about anything in this policy, including to exercise your rights, at privacy@book-nest.net.

2. What data we collect

We only collect what the service needs to work.

Account data you give us

  • Name and, optionally, last name and nickname
  • Email address
  • Password (we never store it in plain text; we store only a one-way bcrypt hash)
  • Optionally, your date of birth and a profile picture, if you choose to add them
  • Optional profile details such as social links

Content you add to your library

  • Books, series, authors, publishers, custom lists, favorites and your reading queue
  • Reading progress, ratings and personal reading impressions or notes
  • Loan and delivery records. These can include names of other people you enter yourself, for example the name of a person you lent a book to or who is delivering an order. Please only add information about other people that you are entitled to add.

Technical data collected automatically

  • Your IP address and basic request information in our server logs, kept for security and troubleshooting
  • A single strictly necessary session cookie (see Cookies below)

We do not use advertising trackers, and we do not run third-party analytics that profile you.

3. Why we use your data and our legal basis

  • To create and run your account and provide the service: performance of our contract with you (GDPR Art. 6(1)(b))
  • To send you essential emails such as email verification, password reset and important security notices: performance of our contract and our legitimate interest in securing accounts (Art. 6(1)(b) and (f))
  • To keep the service secure, prevent abuse and fix problems: our legitimate interest (Art. 6(1)(f))
  • To meet legal obligations where they apply (Art. 6(1)(c))

We do not sell your personal data, and we do not use it for automated decision-making or profiling.

4. Cookies

We use one cookie, called refresh_token. It is strictly necessary: it keeps you signed in securely. It is set as HttpOnly (not readable by JavaScript) and SameSite=Lax, and it is only sent to our authentication endpoints.

Because this cookie is strictly necessary to provide a service you actively asked for, it does not require consent under the GDPR and the ePrivacy rules. We do not use any advertising, marketing or analytics cookies. If that ever changes, we will ask for your consent first.

5. Who we share data with

We do not sell or rent your data. We share it only with the service providers (processors) that we need to run BookNest:

  • Hetzner Online GmbH (Germany, EU): hosting of our servers and database.
  • Cloudflare, Inc. (USA): DNS, content delivery and protection against attacks. Cloudflare processes technical data such as your IP address when you connect to the site.
  • Email delivery: transactional emails (verification, password reset and security notices) are sent from our domain through our email service provider.

Each provider only processes data on our instructions and under a data processing agreement.

6. International transfers

Our servers and database are located in the EU (Germany). Some providers, such as Cloudflare, may process technical data outside the EU, including in the United States. Where that happens, the transfer is covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses.

7. How long we keep your data

  • Account and library data: for as long as your account exists. When you delete your account, we delete or anonymize your personal data, except where we must keep something to meet a legal obligation.
  • Email verification and password reset tokens: these are short-lived and expire automatically.
  • Server logs: kept for a limited period for security and troubleshooting, then deleted.

8. Your rights

Under the GDPR and Ukrainian law you have the right to:

  • access the personal data we hold about you
  • correct data that is wrong or incomplete
  • delete your data ("right to be forgotten")
  • restrict or object to certain processing
  • receive your data in a portable, machine-readable format
  • withdraw consent at any time, where we rely on consent

To use any of these rights, email us at privacy@book-nest.net. You also have the right to complain to a data protection authority, in Ukraine the Ukrainian Parliament Commissioner for Human Rights, or the supervisory authority in your EU country of residence.

9. How we protect your data

We store passwords only as a one-way bcrypt hash, serve the whole site over HTTPS, keep the session cookie HttpOnly, and apply rate limiting and other safeguards. No system is perfectly secure, but we take reasonable steps to protect your data.

10. Children

BookNest is not intended for children under 16. If you are under 16, please do not create an account. If you believe a child has given us personal data, contact us and we will delete it.

11. Changes to this policy

If we make significant changes, we will update the "Last updated" date and, where appropriate, notify you. Continuing to use BookNest after a change means you accept the updated policy.

12. Contact

Questions, requests or complaints: privacy@book-nest.net.