villarino.app

Privacy Policy for ReadTally

Last updated: 24 August 2026

ReadTally is an iPhone app for tracking the books you read. It is made by Joe Villarino, an independent developer.

The short version: ReadTally keeps your reading data on your iPhone. There is no account to create, no server to sign in to, and no copy of your library sitting on a computer I control. I cannot see what you read.

This policy explains that in full — what stays on your device, the two things the app sends over the internet, and how Apple fits in when you subscribe.

The short version

What ReadTally stores on your device

Everything you enter in ReadTally is written to a private database (Apple's SwiftData) inside the app's own storage on your iPhone. That includes:

Importing a library. ReadTally can import a CSV export from another reading service, such as Goodreads or The StoryGraph. You choose the file yourself, it is read on your device, and the books in it are written straight into the same local database as everything else. The file is never uploaded anywhere.

Reading the file makes no network requests, and no export file from any service contains cover images. Afterwards the app may offer two optional steps, each of which you have to tap: looking up missing covers and page counts from Open Library, and finding genres with Claude. Both are described below. Decline them and the import stays entirely on your device — with plain placeholder covers, because there was never a cover in the file to show.

This data belongs to you. It stays in the app's private storage, which other apps cannot read. It is not uploaded anywhere.

About device backups. ReadTally does not sync or upload your data. However, if you back up your iPhone — to iCloud or to a computer — that backup is made by iOS itself and may include ReadTally's data along with the rest of your apps. Those backups are controlled by you and by Apple, under Apple's terms and privacy policy, not by ReadTally.

What ReadTally sends over the internet

There are three network destinations. Two belong to Open Library and are used to find books and covers. The third is the optional AI help described in sections 3 and 4, which only ever runs after you agree to it. There are no others.

1. Book search — openlibrary.org

When you search for a book by typing, or when you scan a barcode, ReadTally sends the text you typed, or the scanned ISBN number, to Open Library's public search service (openlibrary.org/search.json) to get back matching titles, authors, page counts, and cover references.

The same service is used by the optional lookup pass that fills in missing covers and page counts after an import, which you can start from the import screen or from Settings → Book Covers. For each book it asks about, it sends that book's ISBN, or — when the book has no ISBN — that book's title and author. Nothing else about the book goes with it: not your rating, review, notes, reading dates, or progress. Books it cannot identify simply keep the plain placeholder cover.

2. Cover images — covers.openlibrary.org

Book cover artwork is downloaded from Open Library's cover image service (covers.openlibrary.org) so your library shows real covers. ReadTally stores only the web address of a cover, not the picture itself; the image is fetched and cached by iOS when a cover appears on screen.

About Open Library

Open Library is a free public service operated by the Internet Archive, and it is not run by me. Like any website you connect to, their servers necessarily see the incoming connection itself — including your device's IP address — as a technical requirement of answering the request. How the Internet Archive handles that is governed by their own privacy policy, not this one.

3. Genre categorization — Anthropic's Claude (optional, consent required)

Reading services do not export a usable genre. A real Goodreads export of 213 books contained no genre at all once shelf names were filtered out; a StoryGraph export of 675 contained 81, most of which were plot tropes rather than genres. So ReadTally can offer to identify genres for you using Claude, an AI service operated by Anthropic, PBC.

This never happens automatically. After an import, ReadTally shows a button. Tapping it opens a confirmation that names Anthropic and states exactly what will be sent. Nothing leaves your device unless you then confirm.

What is sent: the title and author of each book that has no genre. That is the whole payload.

What is never sent: your reviews, your private notes, your star ratings, your reading dates, your progress, your session history, your shelves, your search history, your camera images, or any name, email or account — the app has no account to send.

How it is sent. The request goes to a small server I operate (a Cloudflare Worker), which forwards it to Anthropic. This exists so the API key is not inside the app, and so the number of requests can be limited. The only identifier attached is a random ID generated on your device the first time the feature is used. It contains nothing about you or your phone, is used solely to count requests against a daily limit, and is destroyed when you delete the app. Neither server keeps your titles after the answer is returned.

What comes back. One genre per book, chosen from a fixed list of about thirty-five categories built into the app. Anything outside that list is discarded rather than saved, so the feature cannot introduce arbitrary text into your library. Books Claude does not recognize are simply left uncategorized — ReadTally does not guess.

AI-generated content. Genres identified this way are produced by AI and can be wrong. You can change any book's genre yourself at any time, which overrides the suggestion permanently.

Anthropic's handling of the request is governed by their own privacy policy and commercial terms, not this one. Under those terms, data sent through their commercial API is not used to train their models.

Declining costs you nothing else. Every other feature works normally; the affected books stay uncategorized, exactly as they arrived.

4. Reading an unfamiliar export file — Claude (optional, consent required)

ReadTally recognizes the export formats of the major reading services. If you import from somewhere it doesn't know — or from a spreadsheet you made yourself — it can offer to work out what your columns mean.

This never happens automatically, and it never happens for a file ReadTally already understands. A Goodreads or StoryGraph export makes no request at all.

What is sent: your file's column names, and up to three short sample values per unrecognized column. Also the date formats and shelf names it could not read.

What is never sent: any column holding your writing. A column whose values look like prose — a review, a note, a comment — has its values withheld, and only its name is sent. This is decided by looking at the content, not by guessing from the column's title, so it works even if your file calls that column something unexpected.

Nothing about your reading is sent: not your dates, ratings, progress, or session history. The request describes the shape of your file, not what is in it.

What comes back. Which column holds which field, what format your dates are in, and what your shelf names mean. Every answer is checked against your actual file before it is used, and anything ReadTally cannot verify is discarded.

You see what it decided. The import preview lists each thing it worked out in plain language — "Read your 'Pgs' column as Page count" — before you import anything. If it looks wrong, don't import.

If you use none of the above

If you never search for a book, never load a cover, and never tap "Find Genres" or "Figure Out This File", ReadTally makes no network requests at all.

Camera and barcode scanning

ReadTally can scan a book's barcode so you don't have to type in its details.

Subscriptions and Apple

ReadTally Pro is an optional auto-renewing subscription that unlocks the Insights dashboard. It is sold entirely through Apple's In-App Purchase system.

Third-party code in the app

ReadTally includes two open-source libraries — Pow and Lottie — used only to draw animations on screen. They collect no data, and neither makes any network requests.

There are no analytics SDKs, no advertising SDKs, no crash-reporting services, and no other third-party services in the app.

Children's privacy

ReadTally is a general-audience reading tracker and is not directed at children under 13.

Because the app collects no personal information from anyone — of any age — and stores everything locally on the device, there is no personal information about a child for me to hold, disclose, or delete. If you are a parent or guardian and have a question, please get in touch at the address below.

Your data, and how to delete it

Because your data lives on your device, you are always in control of it:

There is nothing to request from me, because I hold nothing. There is no account to close and no server-side copy to erase.

One important note: deleting the app does not cancel a subscription. Subscriptions are managed by Apple — cancel in Settings → your name → Media & Purchases → Subscriptions on your iPhone.

Contact

Questions about this policy or about privacy in ReadTally:

[email protected]

Changes to this policy

If ReadTally changes in a way that affects this policy — for example if a future version added a new network service — I will update this page and change the "Last updated" date at the top. Significant changes will be noted in the app's release notes. Because the app has no accounts, there is no mailing list to notify; please check back here.

Last updated: 24 August 2026