BookFrix

Informativa privacy

Ultimo aggiornamento: 15 settembre 2026 · Versione italiana facente fede

In breve. BookFrix conserva quello che serve a far funzionare la tua libreria: il tuo account, i libri che carichi e i tuoi dati di lettura. Non ci sono pubblicità, strumenti di analisi o di tracciamento, e non vendiamo né cediamo i tuoi dati a nessuno per i suoi scopi.

Puoi eliminare l’account e tutto ciò che contiene in qualsiasi momento, direttamente dall’app: menu dell’account → Elimina account. I dettagli sono nella pagina Eliminazione account.

1. Chi tratta i tuoi dati

Titolare del trattamento: Amirhossein Yaghoubnezhad

Contatto: info@frix.me

BookFrix è un progetto indipendente e gratuito. Non è stato nominato un Responsabile della protezione dei dati (DPO), poiché non ricorrono le condizioni dell’art. 37 GDPR. Per qualsiasi questione relativa ai tuoi dati scrivi all’indirizzo indicato sopra.

2. Quali dati raccogliamo

CategoriaDatiDa dove arrivano
AccountCon Google: indirizzo e-mail, nome e indirizzo dell’immagine del profilo. Con Telegram: identificativo numerico, nome utente, nome e indirizzo dell’immagine del profilo. La data di creazione dell’account. BookFrix non usa password. Se colleghi entrambi i metodi di accesso, sono associati allo stesso account.Google o Telegram, quando scegli di accedere con uno dei due
LibreriaI file dei libri che carichi (dall’app, EPUB e PDF); la copertina, estratta automaticamente dal file o caricata da te; i dati dei libri: titolo, autore, categorie, formato e dimensione, data di aggiunta, stato di lettura, preferiti e gruppi.Tu, usando l’app
Dati di letturaPosizione e percentuale di lettura di ogni libro, segnalibri, evidenziazioni (compreso il testo evidenziato), note, annotazioni e disegni sulle pagine PDF, data dell’ultima apertura e dell’ultima lettura.Generati mentre leggi e sincronizzati tra i tuoi dispositivi
Statistiche di letturaSessioni di lettura: quale libro, ora di inizio e di fine, secondi di lettura attiva e pagine girate. Conta solo il tempo in cui l’app è in primo piano e la stai usando. Servono esclusivamente alla pagina Statistiche, visibile solo a te.Registrate dall’app mentre un libro è aperto
CondivisioneSe crei un link di condivisione: il link, se hai scelto di includere evidenziazioni e note, e quante volte il libro è stato aggiunto tramite il link. Se aggiungi un libro ricevuto: da quale libro e da quale utente proviene.Tu, quando condividi o aggiungi un libro
AssistenzaSe apri una richiesta: la categoria, il messaggio, la conversazione che segue, la valutazione facoltativa e il nome e l’indirizzo e-mail, oppure l’identità Telegram, che scegli di indicare.Tu, quando scrivi all’assistenza
Dati tecniciIndirizzo IP, data e ora, indirizzo richiesto e tipo di browser registrati nei log del server; messaggi di errore dell’applicazione.Automaticamente, quando usi il servizio

Non raccogliamo dati di pagamento, perché BookFrix è gratuito. Non raccogliamo la tua posizione, i tuoi contatti, foto, audio o immagini della fotocamera: l’app Android dichiara un solo permesso, l’accesso a Internet. Non riceviamo il tuo numero di telefono: con Telegram chiediamo soltanto il profilo.

Cosa resta sul tuo dispositivo

Per farti leggere offline, l’app tiene sul dispositivo una copia della libreria (l’elenco dei libri, i file che hai aperto o scaricato, progressi, segnalibri, evidenziazioni, annotazioni e sessioni di lettura non ancora sincronizzate), insieme alla sessione di accesso e alle preferenze. Alcune cose esistono solo lì e non arrivano mai al server: le impostazioni del lettore e i percorsi di lettura che salvi o completi.

Uscire dall’account non cancella la copia offline. Viene cancellata quando elimini l’account da quel dispositivo, quando cancelli i dati del sito o dell’app, o quando disinstalli l’app; sul sito web, le ultime risposte del server e le copertine restano nella cache del browser finché non scadono (al massimo 60 giorni). Se usi un dispositivo condiviso, tienine conto. L’elenco completo è nella pagina sui cookie e l’archiviazione locale.

3. Perché trattiamo questi dati e su quale base giuridica

FinalitàBase giuridica
Creare e gestire il tuo account, farti accedere, associare i metodi di accesso che colleghi.Esecuzione del contratto — art. 6, par. 1, lett. b) GDPR
Conservare la tua libreria, estrarre le copertine, ottimizzare i PDF per l’apertura rapida, sincronizzare i dati tra i dispositivi, farti leggere offline, mostrarti le statistiche di lettura.Esecuzione del contratto — art. 6, par. 1, lett. b) GDPR
Condividere un libro con altre persone tramite link, quando lo scegli tu.Esecuzione del contratto — art. 6, par. 1, lett. b) GDPR
Rispondere alle richieste di assistenza.Esecuzione del contratto — art. 6, par. 1, lett. b) GDPR; se non hai un account, legittimo interesse a rispondere a chi ci scrive — lett. f)
Proteggere il servizio, prevenire abusi, diagnosticare malfunzionamenti.Legittimo interesse — art. 6, par. 1, lett. f) GDPR: mantenere il servizio funzionante e sicuro
Gestire segnalazioni di contenuti illeciti o di violazioni del diritto d’autore, adempiere a obblighi di legge, rispondere a richieste dell’autorità.Obbligo legale — art. 6, par. 1, lett. c) GDPR; legittimo interesse a tutelare i diritti propri e altrui — lett. f)

4. Quello che leggi può dire molto di te

I titoli della tua libreria, le evidenziazioni e le note possono lasciar intuire convinzioni religiose o filosofiche, opinioni politiche, condizioni di salute o l’orientamento sessuale: categorie particolari di dati ai sensi dell’art. 9 GDPR.

Il nostro impegno è preciso: non analizziamo la tua libreria, non ne deduciamo caratteristiche personali, non la usiamo per proporti nulla e non la comunichiamo a nessuno. Questi dati sono sul server perché li hai caricati tu e servono solo a farti leggere.

Come gestori del server abbiamo accesso tecnico ai dati conservati. Il pannello di amministrazione mostra i dati degli account e titolo, autore, copertina e dimensione dei libri caricati, non il testo di evidenziazioni e note. Lo usiamo solo per la manutenzione, la sicurezza, l’assistenza che ci chiedi e la gestione di segnalazioni o richieste di legge.

5. A chi comunichiamo i dati

Non vendiamo, non affittiamo e non cediamo i tuoi dati personali. Li riceve soltanto chi serve a far funzionare il servizio, o chi scegli tu:

  • Il fornitore di hosting del server su cui girano BookFrix e il suo database, come responsabile del trattamento (vedi punto 6).
  • Google (Google Ireland Limited, per chi si trova nello Spazio economico europeo) e Telegram (Telegram FZ-LLC) — quando accedi o colleghi l’account con uno dei due, trattano i dati di autenticazione come titolari autonomi, secondo le proprie informative. Le pagine dell’app caricano i loro strumenti di accesso: vedi la pagina sui cookie.
  • Il nostro servizio di assistenza (support.frix.me), che gestiamo noi. Quando apri una richiesta, il messaggio e il nome ed e-mail, o l’identità Telegram, che indichi vengono inoltrati tramite il nostro bot a un canale Telegram privato che usiamo per ricevere le richieste e rispondere; se scegli l’identità Telegram, le risposte ti arrivano anche dal bot. Se preferisci che la tua richiesta non passi da Telegram, scrivici a info@frix.me.
  • Le persone con cui condividi un libro. Chi apre un tuo link di condivisione, anche senza account, vede titolo, autore, formato, dimensione e copertina del libro e il tuo nome visualizzato (o il tuo nome utente Telegram). Chi lo aggiunge alla propria libreria riceve una copia del file e, solo se lo hai scelto, delle tue evidenziazioni, note e annotazioni. Gli altri utenti non vedono la tua libreria.
  • Servizi che ospitano immagini. I percorsi di lettura possono mostrare copertine e fotografie caricate direttamente da Open Library (Internet Archive) e da Unsplash, e la tua immagine del profilo viene caricata dai server di Google o di Telegram: in quel momento il tuo dispositivo comunica loro il proprio indirizzo IP.
  • Autorità competenti — solo se un obbligo di legge lo impone.

6. Dove sono conservati i dati e trasferimenti extra-UE

I dati sono conservati su un server virtuale che affittiamo da un fornitore di hosting, il quale lo gestisce per nostro conto come responsabile del trattamento ai sensi dell’art. 28 GDPR. I file dei libri e le copertine sono salvati sul disco del server; gli altri dati nel suo database. Il traffico tra l’app e il server è cifrato (HTTPS).

Se identici byte vengono caricati più di una volta — la stessa edizione caricata da due persone, o un libro aggiunto da un link di condivisione — il server ne conserva una sola copia e la collega a ciascuna libreria. Titoli, note e progressi restano separati per ogni utente, e nessun altro utente vede la tua libreria. Quando elimini un libro viene rimosso il tuo collegamento; il file viene cancellato quando nessuna libreria lo usa più.

Google e Telegram trattano i dati di accesso secondo le proprie informative, e questo può comportare trasferimenti fuori dall’Unione Europea che non dipendono da noi. BookFrix non offre un accesso alternativo a questi due. Lo stesso vale per le richieste di assistenza inoltrate su Telegram, che puoi evitare scrivendoci per e-mail.

7. Per quanto tempo conserviamo i dati

DatoConservazione
Account, libreria, dati e statistiche di lettura, link di condivisioneFinché mantieni l’account. Quando lo elimini vengono cancellati subito dal database. Se elimini un singolo libro, il tempo che gli hai dedicato resta nelle tue statistiche come «libro rimosso».
File dei libri e copertineRimossi dal disco dalla pulizia periodica dell’archivio, non appena nessuna libreria li usa più.
Libri che altri hanno aggiunto dai tuoi linkRestano nelle loro librerie anche se revochi il link, elimini il libro o elimini l’account: sono ormai la loro copia.
Richieste di assistenzaNon hanno una scadenza automatica: puoi chiederne la cancellazione in qualsiasi momento.
Log tecniciPer il periodo limitato necessario alla sicurezza e alla diagnosi dei malfunzionamenti.
Copie di sicurezzaSe per manutenzione viene fatta una copia di sicurezza del server, i dati cancellati possono restarvi finché quella copia non viene eliminata. Non la usiamo per altro.
Dati sul tuo dispositivoFinché non li cancelli tu (vedi «Cosa resta sul tuo dispositivo», punto 2).

8. I tuoi diritti

Ai sensi degli artt. 15-22 GDPR hai diritto di:

  • accedere ai tuoi dati e ottenerne copia;
  • rettificare dati inesatti o incompleti;
  • cancellare i tuoi dati («diritto all’oblio»);
  • limitare il trattamento in determinati casi;
  • ricevere i tuoi dati in un formato strutturato, di uso comune e leggibile da dispositivo automatico, e trasmetterli a un altro titolare (portabilità);
  • opporti al trattamento fondato sul legittimo interesse.

Come esercitarli

  • Cancellazione: nell’app apri il menu dell’account (la tua immagine, nella barra laterale) e scegli Elimina account. L’operazione è immediata e irreversibile. Se non riesci ad accedere, scrivici. Tutti i dettagli sono nella pagina Eliminazione account.
  • Rettifica: titolo, autore, categorie e copertina dei libri li modifichi direttamente nell’app; per il resto scrivici.
  • Accesso, portabilità e ogni altro diritto: scrivi a info@frix.me dall’indirizzo associato all’account, o indicando il tuo nome utente Telegram. Rispondiamo entro un mese dalla richiesta, come previsto dall’art. 12 GDPR.

9. Reclamo all’autorità di controllo

Se ritieni che il trattamento dei tuoi dati violi il GDPR, puoi proporre reclamo al Garante per la protezione dei dati personali:

Piazza Venezia 11 — 00187 Roma

Centralino: +39 06 696771

E-mail: protocollo@gpdp.it — PEC: protocollo@pec.gpdp.it

www.garanteprivacy.it

Se risiedi in un altro Paese dell’Unione Europea puoi rivolgerti anche all’autorità di controllo del tuo Paese. Puoi inoltre rivolgerti all’autorità giudiziaria.

10. Minori

In Italia l’età minima per il consenso digitale è fissata a 14 anni (art. 2-quinquies del D.Lgs. 196/2003). BookFrix non è destinato a chi ha meno di 14 anni. Non chiediamo la data di nascita: se veniamo a sapere che un account appartiene a un minore di 14 anni senza il consenso di chi esercita la responsabilità genitoriale, lo eliminiamo. Se ne sei a conoscenza, scrivici.

11. Decisioni automatizzate

Non effettuiamo processi decisionali automatizzati né profilazione che producano effetti giuridici o incidano in modo analogamente significativo sulla tua persona, ai sensi dell’art. 22 GDPR. Le statistiche di lettura sono semplici somme del tempo e delle pagine, mostrate solo a te.

12. Sicurezza

Adottiamo misure tecniche e organizzative adeguate ai sensi dell’art. 32 GDPR: connessioni cifrate; nessuna password da custodire, perché l’accesso avviene tramite Google o Telegram; ogni richiesta alla tua libreria è legata alla tua sessione e riguarda soltanto i tuoi dati; accesso al pannello di amministrazione limitato a un elenco di account autorizzati. Una sessione dura fino a 180 giorni. Uscire dall’account la cancella dal dispositivo ma non la revoca sul server: se perdi un dispositivo su cui eri collegato, scrivici.

Nessun sistema è invulnerabile: in caso di violazione dei dati personali che comporti un rischio elevato per i tuoi diritti, ti informeremo come previsto dall’art. 34 GDPR.

13. Modifiche a questa informativa

Se modifichiamo questa informativa in modo sostanziale, aggiorniamo la data in cima alla pagina e ne diamo notizia con un preavviso ragionevole prima che le modifiche abbiano effetto. Le versioni precedenti sono disponibili su richiesta.

Privacy notice

Last updated: 15 September 2026 · Courtesy translation — the Italian version prevails

In short. BookFrix keeps what it needs to run your library: your account, the books you upload and your reading data. There are no ads, no analytics and no tracking tools, and we do not sell your data or hand it to anyone for their own purposes.

You can delete your account and everything in it at any time, from inside the app: account menu → Delete account. The details are on the account deletion page.

1. Who processes your data

Data controller: Amirhossein Yaghoubnezhad

Contact: info@frix.me

BookFrix is an independent, free project. No Data Protection Officer has been appointed, as the conditions in GDPR art. 37 do not apply. For anything concerning your data, write to the address above.

2. What we collect

CategoryDataSource
AccountWith Google: email address, name and profile picture URL. With Telegram: numeric user ID, username, name and profile picture URL. When the account was created. BookFrix has no passwords. If you connect both sign-in methods, they are linked to the same account.Google or Telegram, when you choose to sign in with one of them
LibraryThe book files you upload (from the app, EPUB and PDF); the cover, extracted from the file automatically or uploaded by you; book details: title, author, categories, format and size, date added, reading status, favourites and groups.You, using the app
Reading dataReading position and percentage for each book, bookmarks, highlights (including the highlighted text), notes, annotations and drawings on PDF pages, when each book was last opened and last read.Created as you read and synced between your devices
Reading statisticsReading sessions: which book, start and end time, seconds of active reading and pages turned. Only time with the app in the foreground and in use counts. Used solely for the Statistics page, which only you can see.Recorded by the app while a book is open
SharingIf you create a share link: the link, whether you chose to include highlights and notes, and how many times the book was added through it. If you add a book you received: which book and which user it came from.You, when you share or add a book
SupportIf you open a request: the category, your message, the conversation that follows, an optional rating, and the name and email address, or Telegram identity, you choose to give.You, when you contact support
Technical dataIP address, date and time, requested address and browser type recorded in the server logs; application error messages.Automatically, as you use the service

We collect no payment data, because BookFrix is free. We do not collect your location, contacts, photos, audio or camera images: the Android app declares a single permission, internet access. We never receive your phone number: with Telegram we ask only for your profile.

What stays on your device

So you can read offline, the app keeps a copy of your library on the device (the book list, the files you opened or downloaded, progress, bookmarks, highlights, annotations and reading sessions not yet synced), together with your sign-in session and preferences. Some things exist only there and never reach the server: your reader settings and the reading paths you save or complete.

Signing out does not erase the offline copy. It is erased when you delete your account from that device, clear the site or app data, or uninstall the app; on the website, the server’s latest responses and book covers stay in the browser cache until they expire (60 days at most). Bear this in mind on a shared device. The full list is on the cookies and local storage page.

3. Why we process it, and on what legal basis

PurposeLegal basis
Creating and running your account, signing you in, linking the sign-in methods you connect.Performance of a contract — art. 6(1)(b) GDPR
Storing your library, extracting covers, optimising PDFs to open quickly, syncing between devices, offline reading, showing your reading statistics.Performance of a contract — art. 6(1)(b) GDPR
Sharing a book with other people through a link, when you choose to.Performance of a contract — art. 6(1)(b) GDPR
Answering support requests.Performance of a contract — art. 6(1)(b) GDPR; if you have no account, legitimate interest in answering people who write to us — art. 6(1)(f)
Protecting the service, preventing abuse, diagnosing faults.Legitimate interests — art. 6(1)(f) GDPR: keeping the service working and secure
Handling reports of unlawful content or copyright infringement, meeting legal obligations, responding to lawful requests.Legal obligation — art. 6(1)(c) GDPR; legitimate interest in protecting our rights and those of others — art. 6(1)(f)

4. What you read can say a lot about you

The titles in your library, your highlights and your notes can suggest religious or philosophical beliefs, political opinions, health conditions or sexual orientation: special categories of data under GDPR art. 9.

Our commitment is specific: we do not analyse your library, we do not infer personal characteristics from it, we do not use it to recommend anything to you and we do not disclose it to anyone. This data is on the server because you uploaded it, and it is there only so you can read.

As the operators of the server we have technical access to the data stored on it. The administration panel shows account details and the title, author, cover and size of uploaded books, not the text of highlights or notes. We use it only for maintenance, security, support you ask for, and handling reports or legal requests.

5. Who we share data with

We do not sell, rent or trade your personal data. It reaches only those needed to run the service, or those you choose:

  • The hosting provider of the server that runs BookFrix and its database, as a processor (see section 6).
  • Google (Google Ireland Limited, for people in the European Economic Area) and Telegram (Telegram FZ-LLC) — when you sign in or connect your account with one of them, they handle the authentication data as independent controllers under their own policies. The app’s pages load their sign-in tools: see the cookies page.
  • Our support desk (support.frix.me), which we run ourselves. When you open a request, your message and the name and email, or Telegram identity, you give are forwarded by our bot to a private Telegram channel we use to receive and answer requests; if you choose the Telegram identity, replies also reach you from the bot. If you would rather your request did not pass through Telegram, write to info@frix.me.
  • People you share a book with. Anyone who opens one of your share links, even without an account, sees the book’s title, author, format, size and cover and your display name (or Telegram username). Anyone who adds it to their library receives a copy of the file and, only if you chose so, of your highlights, notes and annotations. Other users cannot see your library.
  • Image hosts. Reading paths may show covers and photographs loaded directly from Open Library (Internet Archive) and Unsplash, and your profile picture is loaded from Google’s or Telegram’s servers: at that moment your device tells them its IP address.
  • Competent authorities — only where the law requires it.

6. Where data is stored, and transfers outside the EU

Data is stored on a virtual server we rent from a hosting provider, which runs it on our behalf as a processor under GDPR art. 28. Book files and covers are kept on the server’s disk; everything else in its database. Traffic between the app and the server is encrypted (HTTPS).

When identical bytes are uploaded more than once — the same edition uploaded by two people, or a book added from a share link — the server keeps a single copy and links it to each library. Titles, notes and progress stay separate for every user, and no other user can see your library. Deleting a book removes your link to it; the file itself is erased once no library uses it.

Google and Telegram process sign-in data under their own policies, which may involve transfers outside the European Union that are not in our control. BookFrix offers no sign-in method other than these two. The same applies to support requests forwarded to Telegram, which you can avoid by emailing us.

7. How long we keep it

DataRetention
Account, library, reading data and statistics, share linksFor as long as you keep the account. Deleted from the database immediately when you delete it. If you delete a single book, the time you spent on it stays in your statistics as a “removed book”.
Book files and coversRemoved from disk by the periodic storage clean-up once no library uses them.
Books others added from your linksStay in their libraries even if you revoke the link, delete the book or delete your account: they are their copy by then.
Support requestsThey have no automatic expiry: you can ask us to delete them at any time.
Technical logsFor the limited period needed for security and diagnosing faults.
BackupsIf a backup of the server is taken for maintenance, deleted data may remain in it until that backup is deleted. We use it for nothing else.
Data on your deviceUntil you remove it (see “What stays on your device”, section 2).

8. Your rights

Under GDPR arts. 15–22 you have the right to:

  • access your data and obtain a copy;
  • rectify inaccurate or incomplete data;
  • erase your data (the “right to be forgotten”);
  • restrict processing in certain cases;
  • receive your data in a structured, commonly used, machine-readable format and pass it to another controller (portability);
  • object to processing based on legitimate interests.

How to exercise them

  • Erasure: in the app, open your account menu (your picture, in the sidebar) and choose Delete account. It is immediate and irreversible. If you cannot sign in, write to us. Full details are on the account deletion page.
  • Rectification: you can edit a book’s title, author, categories and cover directly in the app; for anything else, write to us.
  • Access, portability and every other right: write to info@frix.me from the address linked to your account, or giving your Telegram username. We respond within one month of the request, as required by GDPR art. 12.

9. Complaining to the supervisory authority

If you believe the processing of your data breaches the GDPR, you may lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali:

Piazza Venezia 11 — 00187 Rome, Italy

Switchboard: +39 06 696771

Email: protocollo@gpdp.it — PEC: protocollo@pec.gpdp.it

www.garanteprivacy.it

If you live in another EU country you may also complain to your local authority. You may also bring the matter before the courts.

10. Children

In Italy the minimum age for digital consent is 14 (art. 2-quinquies, Legislative Decree 196/2003). BookFrix is not intended for anyone under 14. We do not ask for your date of birth: if we learn that an account belongs to a child under 14 without the consent of a parent or guardian, we delete it. If you know of one, tell us.

11. Automated decision-making

We carry out no automated decision-making or profiling producing legal effects, or similarly significantly affecting you, within the meaning of GDPR art. 22. Reading statistics are plain sums of time and pages, shown only to you.

12. Security

We apply appropriate technical and organisational measures under GDPR art. 32: encrypted connections; no password to protect, because you sign in through Google or Telegram; every request to your library is tied to your session and reaches only your data; administration panel access limited to an allowlist of accounts. A session lasts up to 180 days. Signing out removes it from the device but does not revoke it on the server: if you lose a device you were signed in on, write to us.

No system is invulnerable: in the event of a personal data breach posing a high risk to your rights, we will inform you as required by GDPR art. 34.

13. Changes to this notice

If we change this notice materially, we update the date at the top of the page and give reasonable notice before the changes take effect. Earlier versions are available on request.

PrivacyTermini di servizioCookieEliminazione accountBookFrix