Privacy Policy
Last updated 10 October 2026
Draft. This page isn’t final and isn’t in effect yet. Some details are still to be filled in.
Who we are
Haste is a reading tracker with social features, run by [legal entity name, e.g. Haste Books Pty Ltd] (ABN [number]), [address] (“Haste”, “we”, “us”). This policy explains what we collect when you use the Haste app and website, why, and the choices you have.
Questions or requests: [privacy@makehaste.app]. You can also reach us from Settings → Contact support in the app.
Information we collect
We collect what you give us, what the app records as you read, and a small amount of technical data. We do not use advertising trackers.
| What | Examples | Where it comes from |
|---|---|---|
| Account | Email address, or your Apple ID’s email or private relay address if you use Sign in with Apple; display name; username | You |
| Date of birth | Your birthday, asked once when you create an account to check you are old enough for Haste. Only you can see it | You |
| Profile | Photo, avatar colour, bio, location you type in, profile settings | You (all optional except name and username) |
| Reading activity | Books in your library and shelves, reading sessions (start and end time, duration, pages, progress, and a place if you type one in), reading goals, ratings and reviews, reflections | You and the app |
| Social content | Posts, comments, reactions, mentions, follows and follow requests, book club posts, replies and events, people you read with | You |
| Photos and videos | Media you attach to sessions or posts; the camera is used only when you take a photo, record a video, or scan a barcode or a friend’s code, and the microphone only while you record a video | You |
| Imports | Shelves, books, ratings and reviews from Goodreads or Hardcover, if you connect them or upload a Goodreads export; and your Goodreads user ID, or Hardcover username and API token, kept so we can keep them in sync | Those services, at your request |
| Device and notifications | Push notification token and notification preferences. Our servers’ logs also record your IP address and basic details of your app or browser | Your device |
| Safety | Reports you send (what you reported, your reason, and a copy of the reported content) and the readers you have blocked | You |
| Support | Messages you send us and any details you include | You |
We do not collect your precise GPS location, contacts, health data or payment card details. On the web, Haste keeps you signed in and remembers your display choices in your browser’s storage; we set no advertising or analytics cookies.
How we use it
We use your information to run Haste and to keep it safe. We do not sell it or use it for targeted advertising.
- To provide the app: track your reading, show your stats and goals, build your feed, run clubs and send the notifications you choose.
- To connect you with readers: show your profile and activity to the people your settings allow, and suggest readers to follow.
- To keep Haste safe: review reports, remove content that breaks our Terms, stop spam and abuse, and check that people are old enough to use Haste.
- To support you: answer your messages and fix problems with your account.
- To improve Haste: fix bugs and keep the service reliable, using server logs and any crash reports Apple passes on if you have chosen to share them with developers. There is no analytics or advertising software in the app.
- To meet legal duties: keep records the law requires and respond to valid legal requests.
If you are in the EU or UK, our legal bases are: performing our contract with you (running the app), our legitimate interests (safety, improvement, support), your consent (optional permissions such as notifications and camera, which you can withdraw in iOS Settings), and legal obligations.
What other people can see
You control who sees most of what you share.
- Always visible to other Haste users: your display name, username, profile photo or avatar, and any badges (Founder, Verified).
- Your choice per session and post: each reading session and post is Public (anyone on Haste), Friends (people who follow you) or Private (only you). The default is Friends. Anyone can follow you unless you turn on Approve new followers in Settings. You can also hide parts of a session, such as its time, place, note or photos.
- Your choice per shelf: shelves are Public or Private. New shelves start Public and appear on your profile. The rest of your library is private: people see a book of yours only through a public shelf, a session, a review or a club.
- Ratings and reviews you give a book are visible to other Haste users.
- Profile details: your bio and location are shown on your profile if you add them. Your reading stats, milestones and who you follow are shown unless you turn them off in Settings. Your goals and Goodreads shelves are shown only if you turn them on.
- Clubs: clubs are invite-only. Posts, replies, events and votes in a club are visible to its members, along with how far you are through the club’s current book. People who are invited can see the club’s name, description and cover.
- Comments and reactions are visible to anyone who can see the session or post they are on.
- People you read with: if you tag someone on a session, they are told, and people who can see the session can see their name.
- Blocking: if you block someone, neither of you can see the other’s profile or anything the other shares.
- Image links: profile photos, club and event covers, photos in club posts, shelf photo frames and covers you upload for books are stored at web addresses that anyone with the link can open. Photos and videos on your sessions and posts are private files that only people allowed to see that session or post can load.
Anything you make public can be seen by anyone with the app, and people can screenshot it. Think before sharing something you would not want copied.
Who we share it with
We share information only to run Haste, when you ask us to, or when the law requires it. We never sell personal information.
| Who | Why | What they get |
|---|---|---|
| Supabase (database, login and file storage) | Stores your account, reading data and photos | Everything in Haste, stored on our behalf in Sydney, Australia |
| Latitude.sh (server host) | Runs our API: imports, push notifications and account deletion | The data in those requests as it passes through, in [server location] |
| Cloudflare | Hosts the web app, delivers images and runs our domain | Web requests, including your IP address, and images as they are delivered |
| Apple | Sign in with Apple, push notifications, TestFlight | Your Apple sign-in token, push token and notification text |
| Goodreads or Hardcover | Imports you start | Only what is needed to fetch your shelves: your Goodreads user ID, or the Hardcover API token you gave us |
| Hardcover and other book databases | Book details and covers | Book searches and ISBNs, never your identity |
| [Email provider, e.g. Google Workspace] | Support email | Messages you send us |
These providers may use your data only to provide their service to us. We may also share information to comply with the law or a valid legal request, to protect someone’s safety, or as part of a sale or merger of Haste, in which case this policy continues to apply.
How long we keep it
We keep your information while your account is open. You can delete your account at any time in Settings → Account → Delete account.
- When you delete your account, we delete your profile, reading data, posts, comments and photos straight away, along with the files behind them. Backup copies are overwritten within [7] days.
- Your username becomes free to reuse. Comments other people left on your sessions and posts are deleted with them. Clubs you run pass to another member, or close if you were the only one in them. Details of a book you added yourself stay if another reader has it too, with no link to you.
- We keep a small amount of data longer only where the law requires it or to deal with a dispute or safety report, for example a record that an account was banned, or a report about something you posted, which keeps a copy of it.
- You can delete individual sessions, posts, comments and photos at any time, and they disappear from Haste straight away. The stored photo and video files are deleted with your account.
Your rights
Wherever you live, you can ask us to access, correct, export or delete your information. Email [privacy@makehaste.app] and we will reply within 30 days. We may need to confirm it’s you first.
- Australia: we handle personal information under the Privacy Act 1988 and the Australian Privacy Principles. If you’re unhappy with how we handle a complaint, you can contact the Office of the Australian Information Commissioner (oaic.gov.au).
- EU and UK: you also have the right to object to or restrict our use of your data, to withdraw consent, and to complain to your local data protection authority.
- California and other US states: you have the right to know, delete and correct your information, and to opt out of its sale or sharing for advertising. We do not sell or share it for advertising. We will not treat you differently for using these rights.
Most of this you can do yourself in the app: edit your profile, change session and shelf privacy, turn off notifications, or delete your account.
Children
You must be at least 13 to use Haste, or older if your country requires it. We ask for your date of birth when you create an account. If it shows you are under 13, the account is deleted straight away and the date is not kept. We do not knowingly collect information from children under 13. If you think a child under 13 has an account, email [privacy@makehaste.app] and we will delete it.
Security, transfers and changes
Security. Data is encrypted in transit and at rest, and access rules in our database stop users seeing data they aren’t allowed to. Only [the Haste team] can access production data, and only to run and support the service. No system is perfectly secure, and we will tell you and the regulator if a breach puts you at risk.
International transfers. Our main database is in Sydney, Australia. Some providers, such as Apple and Cloudflare, may process data in other countries, including the United States. Where the law requires, we use safeguards such as standard contractual clauses.
Changes. We will update the date at the top when this policy changes. For significant changes we will tell you in the app before they take effect.