← Back to home

Privacy Policy

Last updated: 2 June 2026

✓ Local-first — your collection data never leaves your device

1. Overview

Marrow Library is designed with privacy by default. Your collection data — every item you catalog, every note you write, every valuation you track — is stored locally on your device. We cannot access it. We do not want it.

This policy describes the limited data we do collect and how we use it.

2. Data We Collect

2a. Purchase data (via Stripe)

When you purchase a paid plan, Stripe processes your payment. To ensure reliable license delivery across all checkout types (guest, saved account, subscription, and one-time payment), we retrieve your full Stripe session profile upon purchase completion. This includes:

  • Your email address (from customer_details, saved Customer record, payment receipt, or session field — whichever is available)
  • Order / session ID and plan type
  • Saved Customer profile (name and email) if you have a Stripe account
  • Payment intent receipt email, if set by your card issuer

We retrieve this comprehensive profile solely to extract your email address for license key delivery. No other fields from the profile are stored, logged, or processed beyond what is needed to dispatch your confirmation email.

We do not receive or store your credit card number, billing address, or any other financial information. All payment data is handled by Stripe under their Privacy Policy.

2b. License key data

Your license key contains your email address, plan type, and purchase date — encoded and signed cryptographically. This is stored only on your device after activation.

2c. Metadata lookups

When you scan a barcode, the App queries third-party APIs (Open Library, TMDB, Discogs, eBay) to fetch metadata. These requests include the barcode or ISBN — no personal information is sent.

2d. Email delivery transparency

To guarantee license key delivery regardless of how you checked out, our system retrieves the most complete version of your Stripe session record available. This is a read-only API call made immediately after purchase. The data accessed is:

  • Purpose: Resolve your email address for license delivery
  • Retention: Not stored — used transiently in memory during request processing only
  • Scope: Limited to the session you initiated; we do not access any other Stripe records
  • Security: All Stripe API calls are authenticated with a server-side secret key never exposed to the client

Data fields accessed but not required for email delivery (such as expanded customer name fields) are never written to any database, log, or third-party service.

2e. What we do NOT collect

  • Your collection data (books, records, games, etc.)
  • Analytics or usage tracking
  • Crash reports (no telemetry)
  • Location data
  • Device identifiers

3. How We Use Your Data

We use your email address solely to:

  • Send your license key after purchase
  • Respond to support requests you initiate

We do not send marketing emails. We do not sell your data. We do not share your data with any third party except as required by law.

4. Data Retention

We retain your email address and order record for accounting purposes for up to 7 years as required by law. You may request deletion of your data by emailing us — we will delete what we can outside of legal obligations.

5. Third-Party Services

  • Stripe — payment processing. Privacy Policy
  • Gmail (Google) — transactional email delivery via Gmail SMTP. Your email address is transmitted to Google's mail servers solely to deliver your license key. Google Privacy Policy
  • eBay — market valuation data. Privacy Policy
  • Vercel — website hosting. Standard access logs (IP, browser) are retained per Vercel's policy.

6. Your Rights

Depending on your location, you may have rights under GDPR, CCPA, or similar laws to access, correct, or delete your personal data. To exercise any of these rights, contact us at fullstackdeveloper829@gmail.com.

7. Children's Privacy

Marrow Library is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page with a new "Last updated" date. Continued use of the App after changes constitutes acceptance.

9. Contact

Privacy questions? Email us at fullstackdeveloper829@gmail.com