Last updated 2026-04-25
Privacy.
The short version, and then the long version.
Short version
- We collect your email, handle, the books and reading sessions you log, and any quotes, notes, or imports you add. That's it.
- Your shelf is public by default — flip it to friends-only or private in /account.
- We never sell, license, or trade your reading data. We don't use it to train third-party AI models.
- You can export everything (CSV, JSON) or delete your account anytime.
What we collect
Account: email address, chosen handle, display name, optional bio and avatar, timezone, and — if you use a third-party sign-in option — the identifier that provider gives us.
Reading data: the books on your shelf, status (want / reading / finished), reading sessions and pages-read entries, quotes and notes you save, finish cards, your streak history, freezes used, and your follows.
Imports: if you upload a shelf export or highlights file from another reading service, we store the rows and highlights as part of your shelf and quote archive.
Payment data: Pro subscriptions are processed by a third-party payments provider. We never see or store full card numbers.
Technical: server request logs (IP address, user agent, timestamps) kept up to 30 days for security and abuse prevention.
Who sees what
Your profile privacy setting controls who sees your shelf, streak, and finishes. Private profiles are invisible to everyone but you. Friends-onlyshelves are visible to people you've accepted as followers (currently open-follow; approval comes later). Public profiles appear in /discover and the ambient feed of anyone who follows you. Quotes can be marked private even on a public shelf.
Service providers
We use a small set of third-party providers to run Margin — hosting, database and storage, transactional email, payments, sign-in, AI chat for Virgil, embeddings for related-passage search, and book-metadata lookups. Each only sees the data it needs to do its job. None receives your reading data for any purpose other than running the feature you're using, and none uses your prompts or text to train models.
Cookies & analytics
Essential cookies are always on — they keep you signed in and protect core features like form submissions.
Analytics cookies run only after you accept in the consent banner. We use third-party analytics providers to understand how the site is used. No advertising pixels, no cross-site tracking, no data sold.
Data retention
Account data and reading history are kept as long as your account is open. Server logs roll off within 30 days. After you delete your account, your shelf, sessions, streaks, quotes, finish cards, and follow relationships are wiped within 30 days. Anonymized, non-identifying aggregates (e.g. “total books finished on Margin”) may be retained. Backups are purged on a 60-day cycle.
Your rights
Wherever you live, you can: export your data (CSV / JSON), correct anything that's wrong, and delete your account. If you're in the EU, UK, EEA, or Switzerland, you also have GDPR rights to access, rectify, restrict, port, and object to processing, and to lodge a complaint with your local data-protection authority. If you're in California, you have CCPA/CPRA rights to know, delete, and correct — and to opt out of “sale” or “sharing” (we don't do either).
Email privacy@readmargin.club to exercise any of these. We respond within 30 days.
International transfers
Margin's servers and several vendors are based in the United States. By using Margin you understand your data may be processed in the US and other countries with different privacy laws. We rely on standard contractual clauses with vendors where required.
Children
Margin is not for children under 13 (or the higher minimum age in your country). We don't knowingly collect data from kids. If you believe a child has signed up, email privacy@readmargin.cluband we'll delete the account.
Security
We use TLS for everything in transit, row-level security in the database to enforce who can read what, and password-less auth so there's no password to leak. No system is perfect — if you spot a vulnerability, email security@readmargin.club.
Changes
When we change this policy we'll update the date at the top and email active users if the change is material.