Privacy Policy
Last updated: December 27, 2025
Our Commitment to Your Privacy
This Privacy Policy explains how Jade Systems LLC ("we," "us," "our") collects, uses, and protects your information when you use Agathos Books.
1. Information We Collect
Account Information
- Display name (required)
- Email address (optional, for authentication and notifications)
- Phone number (optional, for authentication and SMS notifications)
- Profile avatar image
- Age bracket (13-17 or 18+, not specific birthdate)
- Timezone
Privacy and Preferences
- Activity visibility settings
- Profile visibility preferences
- Notification preferences
- SMS consent status
Activity Data
- Reading activity (books started, progress, completed)
- Library membership and roles
- Book lending and borrowing history
- Book collection and tags
- Reliability scores based on lending history
Technical Data
- Device information and browser type (for service delivery)
- IP address (for security, geolocation, and fraud prevention)
- Push notification subscriptions
- Authentication tokens
- Error logs (without personal data)
2. How We Use Your Information
- Provide and maintain the library management service
- Enable library discovery and facilitate book lending
- Send notifications about loans, due dates, and library updates
- Authenticate users and protect account security
- Prevent fraud, abuse, and unauthorized access
- Improve the platform based on usage patterns
- Comply with legal obligations
- Enforce our Terms of Service
3. Information Sharing
Within Libraries
- Library Members: Your display name and avatar are visible. Reading activity is visible only if you enable it in your privacy settings (disabled by default for ages 13-17)
- Profile Visibility: You control profile visibility per library. When visible, members may see your reading statistics based on your settings
- Activity Feed: Your reading activities may appear in library feeds. You can hide individual activities or enable retroactive hiding of all past activities
- Library Administrators: Admins can see your email address (not phone), membership status, lending history, and reliability scores
- Book Owners: When you request a book, the owner sees your name and reliability scores
- Supervisors: If you add a supervisor, they can view basic account information and library participation
- Contact Information: Your email and phone are never visible to regular library members
Service Providers
We share information with third-party services that help operate the platform:
- Email and SMS delivery services (for notifications and authentication)
- Email and phone validation services
- Payment processing (via our merchant of record)
- Cloud database hosting (with encryption at rest)
- Image hosting and content delivery
- Security and bot protection services
- Book metadata providers (for cover images and book information)
- Error monitoring services (no personal data included)
- Geolocation services (for timezone detection)
Legal Requirements
We may disclose information when required by law, court order, or legal process, or to protect rights, property, or safety.
What We Do Not Do
- We do not sell your personal information
- We do not share your data for advertising purposes
- We do not provide your information to data brokers
- We do not use your data for AI training purposes
4. Data Security
We implement security measures to protect your information:
- Encryption in transit (HTTPS) and at rest
- Passwordless authentication with one-time codes
- Token versioning for session security
- Rate limiting to prevent brute force attacks
- Bot protection at signup
- Row-level database security policies
- Regular security monitoring
5. Your Rights and Choices
Access and Control
- Access: View and update your profile through settings
- Delete: Delete your account from profile settings (after resolving loans and library ownership)
- Export: Request a copy of your data by contacting us
Privacy Controls
- Activity Privacy: Control whether reading activity is visible to library members
- Profile Visibility: Set profile visibility level (limited or full)
- Activity Hiding: Hide individual activities from feeds
- Retroactive Hiding: Option to hide all past activities when enabling privacy
- Supervision: Add or remove parental supervision at any time (ages 13-17)
Communication Preferences
- Customize notification channels (push, email, SMS) per notification type
- Opt out of SMS by replying STOP to any message
- Essential service communications cannot be disabled
Account Deletion
You can delete your account from profile settings. Requirements:
- Return all borrowed books and resolve active loans
- Transfer or delete any libraries you own
- Deletion is permanent and cannot be undone
- Supervised accounts will lose their supervisor connection
6. Data Retention
- Account data is retained while your account is active
- Inactive accounts may be deleted after 2 years of inactivity
- Deleted libraries have a 90-day recovery window before permanent deletion
- We may retain certain information as required by law
- Payment records are retained by Paddle according to their policies
7. Children's Privacy (COPPA Compliance)
Age Requirements
Our service is not intended for children under 13. We do not knowingly collect personal information from children under 13 in compliance with COPPA. Users must confirm they are at least 13 years old during account creation. If we learn that we have collected information from a user under 13, we will delete that account.
Privacy for Users Ages 13-17
- Private by Default: Reading activity is hidden from library members
- Limited Profile: Profile visibility defaults to limited
- Minimal Data: We do not collect birthdates or unnecessary information
- Contact Protection: Email and phone are protected for all users
- Optional Supervision: Minors can add a parent or guardian to supervise
- User Control: Minors can modify settings and supervision at any time
Parental Rights
Parents or guardians of users ages 13-17 may:
- Be added as supervisor (minor must add you)
- View basic account information of supervised accounts
- Request information about their minor's account by contacting us
- Request deletion of their minor's account
Limitations
We provide privacy controls and supervision options but do not actively monitor user interactions. Parents are responsible for supervising their children's online activities. Libraries using our platform for youth programs are responsible for their own safety protocols.
8. Geographic Discovery
For public library discovery, we collect location data:
- Browser geolocation (with your permission)
- IP-based location estimation (as fallback)
- Saved location preference (stored locally for 7 days)
- Library addresses (for administrators setting up public libraries)
You can deny location permission and manually enter a ZIP code for discovery. Location data is used only for finding nearby libraries and is not shared externally.
9. Cookies and Local Storage
We use browser storage for:
- Authentication tokens (localStorage)
- Theme preference (dark/light mode)
- Last used login method
- Location cache for library discovery
We do not use tracking cookies or third-party advertising cookies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date and, for significant changes, by email or in-app notification. Continued use of the service after changes constitutes acceptance of the updated policy.
11. Contact Us
For questions about this Privacy Policy or our privacy practices:
For data export or deletion requests, please include your account email address. We will respond within 30 days.