BOOKGLANCE · YOUR PRIVACY
Bookglance web privacy notice
Updated 23 September 2026
This notice explains how we use personal data in the Bookglance web onboarding, checkout and account connection flow. It supplements the Aurello Privacy Policy, which also covers our mobile apps. Where a general description differs from this web flow, the specific information below applies. A privacy notice explains processing; using the service or accepting its terms does not itself give consent to optional advertising measurement.
Who is responsible
AURELLO CODE SOFTWARE GROUP LTD is the data controller for the Bookglance processing described here. Contact us at contact@aurello.app for privacy questions or requests.
AURELLO CODE SOFTWARE GROUP LTDGriva Digeni, 782nd floor, Flat/Office V1Neapoli, 3101, Limassol, Cypruscontact@aurello.appaurello.appYour guest account and saved choices
When the website opens, we use Google Firebase Authentication to create or restore a guest session with a unique account identifier. You can begin without providing your name or email. A guest identifier still lets us recognise the same session; it does not make the associated data anonymous.
We save your onboarding step, topic and idea choices, learning goal, reading preferences, recommended books and completion status against that identifier in Firebase Firestore. A copy of your onboarding draft is also stored in your browser so you can resume after an interruption. Account data can include saved books, reading progress and review history where those records already exist or are created through a supported feature. These records let us personalise your starting plan and connect your progress with the app.
Firebase also processes technical information needed for authentication and security, such as IP address and browser information. See Firebase privacy and security information.
Connecting Google or Apple
If you choose Google or Apple sign-in, Firebase receives the provider identity and available profile details, such as your name and email address, including an Apple private relay address if you choose one. We do not receive your Google or Apple password.
We use the connection to let you sign in again and recover your access in the app. Normally the sign-in is linked to your guest account. If it already belongs to an existing Bookglance account, the flow verifies both accounts and the purchase before connecting access and merging saved content where that recovery feature is available. Source records can remain for recovery; connecting accounts does not itself delete the guest records.
The sign-in providers also process information under the Google Privacy Policy and Apple Privacy Policy.
Checkout and subscription access
Paddle is the merchant of record for web purchases made through Paddle Checkout. It collects the contact, billing, payment and technical information needed to process the transaction, prevent fraud, provide receipts and manage the subscription. Payment details are entered into Paddle's checkout, including when you use an available wallet. Bookglance does not receive your full payment card number or security code. Paddle is responsible for its own processing as described in the Paddle Privacy Notice.
We use RevenueCat to connect purchases and subscription access to your Bookglance account. Your Firebase account identifier is also your RevenueCat customer identifier. RevenueCat and our server process purchase and subscription identifiers, the selected product, payment status and access status so we can verify, restore and manage what you purchased. If you are already signed in, your account email may be passed to checkout to prefill it. See RevenueCat's privacy information, including its explanation of processing end-user information on behalf of developers.
Hosting, support and security
Vercel hosts this website and its server endpoints. Requests pass through its infrastructure and can include your IP address, browser information, requested URL and request time. Our endpoints also process authentication tokens and the information needed for the action you request. We use these services to deliver the website, verify access and investigate errors or abuse. See the Vercel Privacy Notice.
If you contact us, we use your contact details, message and relevant account or purchase information to respond. Please do not send passwords, full card details or payment security codes.
Optional Meta advertising measurement
Where enabled, we ask before using Meta Pixel and server-side Conversions API measurement. You can use onboarding and checkout without agreeing. Test checkouts do not enable this advertising measurement.
With permission, we measure visits, onboarding steps, viewing the offer, starting checkout, registration and verified purchases. Meta may receive browser and advertising click identifiers, page and device information, a hashed account identifier, event identifiers, purchase value and currency. The browser Pixel also connects directly to Meta, which receives connection information such as your IP address and may use advertising cookies. Hashing an identifier does not make it anonymous.
Our advertising event fields do not include your quiz answers, book selections, name or email address. Our server uses consent and attribution records to associate a verified purchase with an ad visit, and matching event identifiers to avoid counting the browser and server reports as two purchases. These measurement records are held in a server-side data store. Meta's own processing is described in the Meta Privacy Policy.
When ad measurement is enabled, open Ad privacy on this website and choose No thanks to withdraw permission. This stops the browser measurement and sends your choice to our server. If the site reports a sync error, retry the control or contact us so the server choice can be updated. Withdrawal does not undo events already sent or affect the lawfulness of earlier processing. Your choice is stored in this browser; clearing its storage or using another browser may require a new choice.
Cookies and browser storage
We use browser storage for your sign-in session, onboarding draft, privacy choice and unfinished checkout or account-connection recovery. Where purchase recovery is available, a secure cookie helps verify the account connection. These functions help preserve your progress and avoid an accidental repeat purchase. Paddle and the sign-in providers may use storage needed for their own services.
Optional advertising storage includes Meta browser and click identifiers and a local record that a purchase event has been reported. You can manage cookies and site data in your browser. Clearing them does not cancel a subscription or erase cloud account records, and can make an unlinked guest session harder to recover.
Why we process this information
- To provide the onboarding, account, purchase and restoration services you request: performance of a contract or steps you request before a contract, under Article 6(1)(b) GDPR.
- To operate and secure the website, prevent abuse, resolve support issues and avoid duplicate processing: our legitimate interests under Article 6(1)(f), subject to your rights and interests.
- For optional advertising measurement and associated non-essential storage: your consent under Article 6(1)(a), which you can withdraw.
- Where records must be kept or disclosed to meet legal obligations: Article 6(1)(c).
The information needed to authenticate you, save your requested plan or verify a purchase is necessary for those features. Advertising permission is optional. Book recommendations use your choices to personalise the service; they do not make decisions with legal or similarly significant effects about you.
Storage locations and retention
Our providers may process data outside Cyprus and the European Economic Area, including in the United States. Firebase states that its Authentication service runs in US data centres. Our general Aurello Privacy Policy describes international transfer safeguards and how to request further information; the provider links above explain their practices.
We retain account, onboarding and purchase-related records for the purposes described above, taking account of restoring your service, support, security and applicable legal obligations. Closing a browser, uninstalling the app or connecting a guest account does not automatically erase cloud records. You can contact us to request deletion.
Browser drafts and recovery hints can remain until replaced, cleared by the flow or removed through your browser. Server-side advertising attribution and detailed purchase-measurement records expire, while minimal hashed event markers are retained to prevent duplicate reporting. Withdrawing advertising permission removes the associated attribution and detailed measurement records from our measurement store once the server update succeeds; it does not delete information Meta has already received. Providers may retain records under their own applicable obligations and policies.
Your rights and how to reach us
Depending on applicable law, you can request access, correction, deletion, restriction or portability of your personal data, object to processing based on legitimate interests, and withdraw consent. Contact contact@aurello.app. We may need information to verify that the account belongs to you before acting on a request.
You can complain to a data protection authority, including the Office of the Commissioner for Personal Data Protection in Cyprus or the authority where you live or work. The Aurello Privacy Policy provides additional information about rights, security, children and policy updates.