Rubrica privacy policy
Effective 23 September 2026. Contact: hello@readrubrica.com
Rubrica is a reading app made by Nicholas Thompson. This page says what it keeps, where, and why. Short version: your books and your reading stay on your phone, there are no ads, and nothing tracks you.
What stays on your phone
Everything, unless you sign in. Your book files, where you are in each book, your reading sessions, highlights, notes, ratings, stats, streaks, seals, your companion and your settings all live on your device. You can back them up to a file from Me › Back up and restore, and erase them from Me › Account.
No tracking
Rubrica has no ads, no analytics, no crash reporting and no tracking SDKs. We don't sell or share data with anyone, and we don't build a profile of you.
If you make an account (optional)
An account lets your library follow you to another device. To make one we keep:
- Your email address and a password. The password is stored hashed; we can't see it.
- A synced copy of your reading data: shelves, ratings and review notes, where you are in each book, reading sessions, highlights and notes, books you track from paper or audio, reading settings, XP, seals, quests, streak days, and your companion's name and look.
Your book files are never uploaded. Sign-in codes and password-reset codes are sent to your email address.
If you turn on friends (optional)
Friends only exist if you turn them on. Then we keep:
- Your profile: a display name, an icon, a colour and a friend code.
- What you chose to share. Every sharing switch starts off. A friend only ever receives the things you switched on (for example your streak or what you're reading); anything switched off never leaves the server.
- Visits: when your companion visits a friend, we keep its name, look, the gift and the time, so your friend can see it. Visits are deleted when either account is.
- Reports: if you report a display name, we keep the report so a person can review it.
Other services Rubrica talks to
- Supabase runs our database and sign-in, and holds the account data above.
- Resend sends sign-in and password-reset emails.
- Author pages: if you claim an author page, the email, website and note you send are kept so we can check it's you, and the links and line you add are shown to every reader on that page.
- Open Library (run by the Internet Archive): when you search for a book, scan an ISBN, or when Rubrica fetches a missing cover, the book's title, author or ISBN is sent to Open Library. Nothing about you is sent with it.
- Project Gutenberg (and the Gutendex catalog): when you browse or download free classics.
- Wikidata (run by the Wikimedia Foundation): to find a book's series and reading order, and an author's website, Rubrica sends the book's title and author, or the author's name. Nothing about you is sent with it.
- Book news sites: the News tab reads the public RSS feeds of the publications listed in its Sources. Your phone fetches them directly, the same way a browser would; Rubrica sends nothing else, and turning the News tab off (Me › App) stops it.
Each of these has its own privacy policy.
Permissions
- Camera: only to scan a book's barcode. Images aren't saved or sent.
- Notifications: for the reading reminder you set. They're scheduled on your phone; there's no push server.
- Microphone: never. Rubrica doesn't ask for it.
Deleting things
- Delete your account from Me › Account › Delete account. The account and everything synced to it are removed from the server right away.
- Deleting the account doesn't touch the library on your phone unless you ask it to. You can also erase the library on its own.
- Or email hello@readrubrica.com and we'll delete it for you.
Kids
Rubrica isn't made for children under 13, and we don't knowingly collect data from them. If you think a child has made an account, email us and we'll delete it.
Changes
If this policy changes, the new version goes here with a new date, and anything that matters will be mentioned in the app.