Tezorah Trove
Tezorah Trove policies

Privacy Policy

Effective October 11, 2026 ยท Version 2026-10-11

This Privacy Policy explains how Tezorah Trove handles personal information in its website, app and invite-only 10ALPHA service. Personal information includes information that identifies a person or can reasonably be linked to a person, account or household. A username, device identifier, review, rating or collection history can be personal information even when it is visible to others or does not contain a real name. Tezorah Trove is operated by Aaron Sanquez as an individual. Our privacy contact is ThezoraTrove@gmail.com.

Information you provide

Account and profile information can include your email and sign-in identifiers, first and last name, display name, username, full date of birth, optional ZIP code, avatar, biography, genre preferences, privacy choices and onboarding information. Invitation or application forms can collect your name, email and birthday separately from the app account. We treat your birthday as private account information, not information you publish to other users. Authorized operators, support personnel and service providers may still process it for permitted service purposes.

Collection information can include books and individual copies, condition, ratings, reading progress and dates, reviews, catalog corrections and uploaded covers or other material. If a social feature is enabled for your account, its records can include relationships and profile modules. Feedback and support submissions can contain messages, screenshots and other attachments. The information involved depends on the features you use. Do not include passwords, access codes, unnecessary financial information or other people's private information in contributions or support messages.

Service operation can involve IP address processing, authentication and session information, browser or device information, and access or error records. Account-linked diagnostics can record the screen or action involved, a scan or operation identifier, processing stage, app and build version, platform and operating system, and provider error information. Security controls can use identifiers derived from an IP address for rate limiting. These records are not necessarily anonymous.

Scans and image recognition

Using image recognition sends the submitted image off your device through our service infrastructure to the configured recognition provider. Scan-related data can include image files or references, extracted text and suggested book matches. Images and extracted text can remain in local scan records; recognition processing and synchronized match summaries involve separate copies and purposes. Avoid capturing people, documents or surroundings that are not needed to identify an item. This policy does not promise immediate scan deletion, zero provider retention or a particular provider training restriction.

Why we use information and when it is shared

We use information to provide the functions you request, manage invitations and accounts, maintain collections and catalog records, respond to support and correction requests, investigate abuse and security issues, troubleshoot problems and improve the service. We also process information where needed to meet legal obligations, resolve disputes, and establish or defend legal claims. Optional uses requiring consent are subject to the consent and choices presented for that use. An account agreement or privacy acknowledgment does not authorize unrelated uses of personal information.

Depending on the enabled feature, service integrations can include Supabase for authentication, database, storage and service functions; Vercel for hosting; Resend for service email; and Google Forms and Google Sheets for invitation intake. Catalog lookup and external images can involve Google Books and Open Library. Image recognition can involve OpenAI or another configured recognition provider identified for that feature. These recipients process information involved in the relevant request; their contractual roles, independent uses and retention depend on the applicable service and arrangement.

If you choose a third-party sign-in option, the information received depends on the enabled provider, requested permissions and your choices. Catalog searches and image requests can go directly to external providers, which receive the query or item identifier and technical information associated with the request.

Sharing a profile, collection, review or other contribution can make it visible to the audience allowed by that feature and its visibility setting. A private setting limits display to other users; it does not prevent authorized operator, administrator or support access for service purposes, or necessary provider processing. External covers and avatars can also create requests to the image host. Someone who can view shared material may be able to copy or redistribute it.

We may disclose information when legally required or when reasonably necessary to protect people, investigate abuse, or establish, exercise or defend legal rights, subject to applicable law. We may disclose information to another recipient at your direction or with a valid authorization for that disclosure. Processing locations depend on the service providers and systems used for the functions you access. Cross-border processing must follow applicable legal requirements; use of the service alone does not waive privacy protections or supply a required transfer safeguard.

We do not sell personal information

Tezorah Trove does not sell users' personal information. We do not treat identifiable reviews, ratings, usernames, personal collection records or pseudonymous account activity as nonpersonal catalog data. A service-provider disclosure is not permission for that provider to sell or independently exploit personal information. Any proposed business transfer or other disclosure must remain consistent with this commitment and applicable law. A transfer that would constitute a prohibited sale cannot be authorized simply by calling it a business transfer.

Rights-cleared catalog facts or other genuinely nonpersonal materials may be used, analyzed, aggregated or separately licensed. Personal information is excluded from that commercial scope. Removing a name or replacing it with an identifier does not necessarily make information anonymous. Information is treated as deidentified only when the applicable legal and practical requirements for preventing identification are met. A right to use content under the Terms of Service does not remove privacy obligations.

Device storage and retention

Tezorah Trove uses persistent device or browser storage for functions such as authentication and session continuity, reading state, onboarding drafts, scan queues and preferences. Scan records can include image references and extracted text; mobile captures can also be held in local files. Some information can remain after a screen is closed or a session ends. Local storage is not the same as a cookie, but both can store or access information on a device.

We retain personal information for as long as reasonably needed for the purposes described here, considering account activity, the type of information, operational needs, legal obligations and relevant limitation periods. Account records, invitation forms, email, uploaded files, diagnostics, local scan records and backups can involve separate copies and retention processes. Browser and mobile storage may behave differently. Deleting one record or signing out does not necessarily remove every related copy.

Deletion is subject to limited exceptions, including security investigations, fraud prevention, legal holds, recordkeeping obligations, and establishing or defending legal claims. Backup or archived copies can follow a different deletion cycle and must not be used to avoid a valid deletion request. No fixed retention period or complete immediate erasure is promised by this policy. Uninstalling the app, logging out or removing a shortcut does not by itself delete an account.

Your choices, rights and deletion requests

Email ThezoraTrove@gmail.com to request access, correction, deletion or information about our processing. For account deletion, identify the account and the scope of your request. Do not send your password, invitation code, session token or unnecessary identity documents. If you cannot sign in, explain that in the request so an appropriate alternative can be considered.

Depending on where you live and whether a particular law applies, you may also have rights to receive a portable copy, limit certain uses or disclosures, withdraw consent, object to processing, opt out of specified processing, use an authorized agent or appeal a denied request. We will explain any applicable verification steps and any lawful limitation on a request. We do not require more information than reasonably needed to verify and handle it. We will not unlawfully discriminate against you for exercising a protected privacy right. Applicable legal response periods control.

A request can involve separate account and database records, uploaded covers or screenshots, invitation-form responses, service email, diagnostic records, local caches and provider-held copies. Rights-cleared, genuinely nonpersonal catalog facts or lawfully deidentified statistics may remain where permitted. Identifiable reviews, usernames, personal collection histories and pseudonymous records do not become exempt merely because a name is removed. Copies that other people independently made after an authorized disclosure may be outside our control, without reducing duties the law places on us.

Eligibility

For eligible readers aged 13 and older. Younger readers may not create an account. Additional consent requirements may apply in your location. Participation also depends on the invitation and access requirements of the test you are admitted to. A book's content rating does not establish account eligibility.

Email ThezoraTrove@gmail.com if you believe a younger reader has provided information or obtained access. We will address the account and associated information under applicable law.

Security, changes and contact

No online service, storage system or method of transmission can be guaranteed completely secure. Protect your account and invitation credentials, use appropriate device security, and report suspected unauthorized access to ThezoraTrove@gmail.com. This notice does not waive our legal duties to safeguard information or respond to a qualifying security incident.

This page identifies the effective version. We will make updated policies available here and provide additional notice or obtain consent when required by law. Materially different uses of previously collected personal information are subject to applicable notice, consent and other legal requirements; a quiet policy edit does not by itself authorize them.