Legal · Privacy Policy

Privacy Policy

Last updated: September 10, 2026

The short version. Without an account, Lookshelf sends us nothing — no analytics, no tracking, not even a font request. With an account, we store your email, your documents (encrypted), and the handful of records it takes to run a subscription. That is the whole list.

Everything you store is encrypted on our servers with a key unique to you. On Pro+, the Private Vault encrypts on your device with a key we never receive — and then we genuinely cannot read your files. We do not sell data, we do not show ads, and we do not train anything on what you keep. You can export or delete everything whenever you like.

1. What this covers

This policy is written by Gigahertz LLC ("we") and covers the Lookshelf apps — macOS, Windows, Linux, iOS, Android and the web app at try.lookshelf.app — and Lookshelf Cloud, the service behind sign-in, backup, sync and the Private Vault. It also covers the marketing site at lookshelf.app, which has no analytics and sets no cookies.

The app without an account keeps everything on your device. The web app keeps it in your browser's own storage. Nothing leaves. If you never sign in, we collect nothing about you at all, and the rest of this document does not apply to you.

2. What we store when you sign in

WhatWhyNotes
Email addressSign-in, receipts, the emails listed in section 6From you, or from Google or Apple when you sign in with them — that is the only thing we ask those providers for.
PasswordSign-inStored only as a scrypt hash. We never see or store the password itself. Google and Apple accounts have no password with us.
Your documentsBackup and syncEncrypted at rest with a key unique to your account. Filenames are encrypted too. On Pro+ with the vault on, encrypted on your device before we see them.
Document metadataShowing your librarySizes, dates, folders, tags, version numbers, and whether a document is vault-sealed.
Subscription statusKnowing your planWhich plan, whether it is active, and the founder-price flag. Payment details stay with Stripe, Apple or Google.
Access recordsSecurityWho accessed what and when, with identifiers hashed, kept for auditing. Not used for anything else.

3. What we never collect

No analytics or usage tracking in any app. No advertising identifiers. No location. No contacts. No device fingerprints. No behavioural profiles. No crash-reporting service reading your screen. The marketing site sets no cookies. Our emails carry no tracking pixels and no click tracking. We do not buy data about you from anyone, and we do not sell or rent data to anyone.

4. How encryption really works

Every plan, including Free

Traffic is TLS. At rest, each account has its own AES-256-GCM key, itself wrapped by a master key we hold, on top of the storage provider's own encryption. Every stored object is cryptographically bound to its exact identity and hash-checked on read, so a file cannot be moved, swapped or altered without the decryption failing. Filenames are encrypted. Your data export is encrypted under its own key and lives only for as long as its link.

What this does not mean. On Free and Pro, we hold the master key. We chose that so a lost password does not mean a lost library — account recovery works. It also means we could technically decrypt content, and could be compelled to. We do so only with your consent, when the law requires it, or when it is necessary to protect the service, and every such access is recorded.

Pro+: the Private Vault

With the vault on, backups from your device are encrypted on the device with a key derived from your passphrase using scrypt. The key is never transmitted and never stored by us. We keep the ciphertext and nothing else, and we cannot open it, reset it, or recover it — which is why the vault comes with a printable Recovery Kit. Documents backed up before the vault existed remain encrypted with our key until you seal them; the app tells you how many.

5. Who else touches your data

We run a small service on a few well-known providers. Here is each one and exactly what it can see.

ProviderRoleWhat it can see
RenderRuns our serverAPI traffic, in the course of serving it.
NeonDatabaseAccount records: email, password hash, plan, document metadata.
Cloudflare R2Encrypted storage, plus a backup mirror in a separate bucket with separate credentialsEncrypted documents with encrypted filenames. No readable content, no readable names.
VercelHosts the web app and this siteRequests for the pages themselves. The web app's data stays in your browser or goes to our server, not Vercel.
ResendSends our emailYour address and the content of the emails in section 6.
StripePayments on web and desktopYour email and payment details. We never receive card numbers.
Apple App Store, Google Play, RevenueCatPayments on iPhone and AndroidThe store handles payment; RevenueCat tells our server which plan is active under an anonymous app identifier.
Google, AppleSign-in, if you choose itThey tell us your email address. We ask for nothing else.

If we add or replace a provider, this page changes and the date at the top moves.

6. Email we send

That is every email we send. There is no newsletter and no marketing list, so there is nothing to unsubscribe from.

7. How long we keep things

ThingKept for
Your documentsUntil you delete them, or your account.
Deleted documentsRestorable for 30 days, then purged from live storage.
Earlier versionsThe last 10 versions of each document, on Pro and Pro+; removed with the document.
Export archive7 days from the email, then deleted.
Sign-in session30 days from the last sign-in on that device.
Cloud copies after a plan endsRead-only for 30 days above the free 100 MB, so you can download or prune. Then the oldest are moved to the trash until you fit, restorable for a further 30 days.
Access recordsFor security auditing; identifiers hashed.

8. Deleting your account

Account → Delete account asks for your password, emails you a final encrypted archive of everything (valid 7 days), and then removes your account. Concretely: your account record and every document's metadata are erased, and the key that could decrypt your documents is destroyed. The backup mirror is built so that ordinary deletion cannot reach it — that is a durability feature, so a mistake or an attacker cannot wipe your library — which means encrypted blobs can remain there after your keys are gone. Without the keys they are unreadable to anyone, including us. If you want them purged as well, email us from your account address and we will do it.

9. Your rights

Wherever you live, we give you the same rights, in the spirit of the GDPR and the CCPA:

Email support@lookshelf.app from your account address. We answer within 30 days, usually much sooner.

10. Security

Beyond encryption: bearer tokens that expire, per-account download budgets that limit what a stolen token could take, rate limits per address and per account, a deletion-proof backup mirror, hashed access logs, and an automated end-to-end test that exercises the whole data path against real storage every night. No system is perfectly secure. If a breach affects your data, we notify you promptly at your account email and say exactly what happened.

11. Children

Lookshelf is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, contact us and we will delete it.

12. Changes to this policy

We may update this policy. For material changes we notify you by email or in the app before they take effect. The date at the top is always the current version.

13. Contact

Privacy questions, requests or concerns: support@lookshelf.app.