Open to everyone. One email, one link, no queue.For avid readers, occasional readers, and anyone wondering what to read next.
Privacy

Privacy policy.

Last updated 19 September 2026

The Reading DNA (“we”, “us”, “our”) is a reading platform at thereadingdna.com. This policy explains what personal data we collect, why we collect it, and your rights over it. We have tried to write it plainly. If anything is unclear, email us at hello@getbacklist.com.


1. Data we collect

We collect only what is needed to provide the service:

  • Email address. Collected when you sign up or log in via magic link. Used for authentication and to send you transactional emails (login links, account notices).
  • Reading history, shelves, and ratings. Books you add, shelf status (want to read, reading, read, abandoned), ratings, and notes you record in The Reading DNA.
  • Imported library data. If you import from Goodreads, we store the books and ratings from that export. We do not retain the raw CSV file after import.
  • Reading DNA. A preference profile derived from your reading history, stored as numerical attributes (pacing, tone, themes, etc.). This is computed from your own data and lives in your account.
  • Conversation history. Messages exchanged with the Librarian, our AI reading companion, are stored so the conversation persists across sessions.
  • Usage data. Actions you take in the app (adding a book, rating, abandoning, recommendations viewed) are logged to an append-only events table. This is the signal our recommendation engine learns from. We also use Vercel Web Analytics, a privacy-focused page-view counter provided by our hosting platform. It records which pages are visited and does not use cookies or track you across other sites. No advertising trackers are loaded.
  • Activity telemetry. To understand how the product is used, every page sends us a small first-party heartbeat about every 30 seconds while you are active: an anonymous visitor identifier (a random ID in a cookie that lasts one year), a rolling session identifier (a cookie that expires after 30 minutes without activity), the page path you are on, and how many seconds you were active on it. Active means the tab was visible and you had scrolled, tapped, clicked or typed within the last minute. If you create an account, or did so earlier, that visitor ID is linked to your account (and to any earlier access request made from the same browser or email) so we can see how new readers get on. The tracker does not record keystrokes, what you type into the Librarian or any form, the content of pages, anything in the address bar after the path (such as search terms or query parameters), or anything you do on other websites.
  • Attribution data. If you arrive via a link with UTM parameters (e.g. from a campaign or referral), we store the first-touch source once at sign-up. This helps us understand which channels are working.

We do not collect payment information (no purchases occur on The Reading DNA), and we do not run third-party advertising.

Our reading-data promise. We do not sell individual reading data, and we do not use individual reading history for advertising targeting. This is permanent.


2. How we use your data

  • To authenticate you and keep your account secure.
  • To provide the core service: your shelf, recommendations, Reading DNA, and the Librarian.
  • To send transactional emails (magic-link logins, account-related notices). We will only send marketing or newsletter emails if you explicitly opt in.
  • To improve the service: usage events and activity telemetry help us understand what features are working, where new readers get stuck, and how much of the product is actually used. Where we report on this, we use aggregate or anonymised figures.

We do not train AI models on your data, and we never send an AI provider your name, email address or account identifier. Some features send Anthropic’s Claude API parts of your reading history (set out in the table below) so it can write your Reading DNA summary, the reasons for your picks and the Librarian’s replies. Under Anthropic’s commercial terms, Anthropic does not train its models on API inputs or outputs, and its published policy is to delete them within 30 days, with two exceptions: content its automated safety systems flag as violating its usage policy can be kept for up to two years, and retention can be extended where the law requires it. We have no special retention arrangement with Anthropic beyond those standard terms. Voyage AI receives book catalogue information only, never your reading history.


3. Data storage and processors

Your data is stored in Supabase (PostgreSQL database and authentication). Supabase is our primary data processor. The following third-party services also process data on our behalf as part of delivering the service:

ProcessorPurposeData shared
SupabaseDatabase, authentication, storageAll account and reading data
AnthropicBook DNA extraction, your Reading DNA summary, the reasons for your picks, and the Librarian (Claude API)Book catalogue details (title, author, year, description excerpt) for Book DNA. For your Reading DNA summary, an aggregate taste profile only: your taste dimensions, favourite story elements and themes, and how many books were read, with no titles or ratings. For the reasons behind your picks, up to twelve of your highest-rated titles and authors and your strongest story preferences. For the Librarian, your messages plus a summary of your shelves: titles you have loved, kept, are reading or have abandoned, with ratings and abandon reasons. Never your name, email address or account ID.
Voyage AIBook embeddings (recommendation engine)Book catalogue information only: title, author, a description excerpt and the book’s extracted tropes, themes and moods. No reader data.
VercelHosting and deploymentStandard web request metadata (IP, headers)
ResendTransactional email deliveryYour email address

Supabase, Anthropic, Vercel and Resend handle data only as instructed by us and not for their own purposes. Voyage AI’s published terms let it store API inputs and use them to improve its models unless the customer opts out; because we send Voyage book catalogue information only, none of your personal data or reading history is involved either way.


4. Cookies and local storage

The Reading DNA uses the following cookies and browser storage:

  • Supabase auth session cookie. Set on login to keep you signed in. Strictly necessary; the service cannot function without it.
  • Attribution cookie (fc_attr). Set once when you first visit if a UTM source is present. Stores the referral source so we can record it at sign-up. Expires at the end of the session.
  • Visitor cookie (rdna_vid). A random identifier, set by our own site (first party), that lasts one year. It lets us recognise the same browser across visits for the activity telemetry described above. It contains no personal data on its own.
  • Session cookie (rdna_sid). A random identifier for the current visit, renewed while you are active and expiring after 30 minutes without activity. It is deleted when you sign out.

We do not use advertising cookies, tracking pixels, session-replay tools, or any third-party cookies. All of the above are set by thereadingdna.com itself.


5. Affiliate links

The Reading DNA participates in the Amazon Associates programme. When we link to a book on Amazon (buy or listen links), those links may contain an affiliate tag. If you purchase through such a link, we may earn a small commission at no extra cost to you. Affiliate links do not affect which books we recommend — recommendations are driven entirely by your Reading DNA.


6. Your rights

You have the following rights over your personal data. To exercise any of them, email hello@getbacklist.com from the address associated with your account.

  • Access. Request a copy of the personal data we hold about you.
  • Correction. Ask us to correct inaccurate data (e.g. an email address you want to update).
  • Deletion. Request that we delete your account and all associated personal data. We will action deletion requests within 30 days and confirm by email.
  • Portability. Request an export of your reading data (shelves, ratings, Reading DNA) in a machine-readable format.
  • Objection. Object to any processing of your data that is based on our legitimate interests rather than your consent.

If you are in the European Economic Area or the UK, you have the right to lodge a complaint with your local data protection authority.


7. Data retention

We retain your personal data for as long as your account is active. If you request deletion, we will remove your account and all associated data within 30 days, except where we are required to retain it by law (e.g. financial records, if any). Anonymised, aggregate usage statistics may be retained indefinitely.


8. Children

The Reading DNA is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with their data, please contact us and we will delete it promptly.


9. Changes to this policy

If we make material changes to this policy, we will update the “Last updated” date at the top and, where the changes are significant, notify active users by email. Your continued use of the service after changes take effect constitutes acceptance of the updated policy.


10. Contact

Questions, requests, or concerns about this policy: hello@getbacklist.com