Shelf

Privacy

Effective August 2026 · Shelf 1.0

The short version

Shelf is a private place to leave links for people you already know. Your shelves are visible only to their members. There are no ads, no tracking or analytics SDKs, no crash-reporting SDKs, no contact upload, and nothing is sold or shared with data brokers.

What Shelf stores

  • An anonymous account. Shelf creates a random account identifier on your device or in your browser. No email, phone number, password, or real name is required.
  • The name you choose — shown only to people who share a shelf with you.
  • An email address, only if you protect your shelves. Protecting is optional. If you do it, we store the address so you can sign in again on another device, and we send it a sign-in code when you ask for one. It is never shown to other members and is never used for anything else.
  • What you leave — the links you leave, the optional notes on them, and the names of shelves, visible only to members of that shelf.
  • Invitations— stored as a cryptographic hash; the invitation link itself can't be recovered from our records.
  • A posting credential for the iPhone share sheet — a random device token, stored server-side only as a hash, so the share sheet can leave links without holding your account session.
  • Reports and blocks — if you report something or block someone, we keep that record so we can act on it.
  • Cached link previews.When someone leaves a link, Shelf's server — not your device — fetches the page and, when one exists, a small preview image, which is resized, stripped of hidden metadata, and stored on Shelf's own storage. Browsing a shelf therefore contacts only Shelf's services; the original site learns nothing about who is browsing until you deliberately open the link.
  • A notification token, only if you opt in.Quiet notifications are off by default and per shelf. If you turn them on, Shelf stores your device's Apple push token and that per-shelf preference. The notification itself carries only the shelf's name and the words "Something new was left." — never the link, note, or sender.

Data is stored with Supabase (Postgres, hosted in the United States) and protected in transit with TLS and at rest by row-level access rules: the database itself enforces that only shelf members can read a shelf's content.

When you write to us

Sending feedback from inside the app stores what you typed, the category you chose, and your Shelf account id so we can make sense of the report. An email address is optional — we ask for one only so we can reply, we use it for nothing else, and without one we have no way to write back.

If you leave “include technical details” on, the app also attaches its version and build, your iOS version, your device family (“iPhone”, never the name you gave it), which screen you were on, and an error code if you came from a failure. The app shows you that list before you send it.

It never attaches, and the server would discard if it were sent: your links, your notes, shelf names, invitation links, the credential your device posts with, push tokens, or anything from your sign-in.

What Shelf doesn't do

  • No ads and no sale or sharing of personal data.
  • No analytics, advertising, or crash-reporting SDKs.
  • No access to your contacts, photos, or location.
  • No public profiles, no search, no way for strangers to find you.
  • No reading of what you share beyond what's needed to store and show it — except when something is reported, in which case a human reviews the reported content.

Deleting your account

You can delete your account any time, in the app under Settings or on this site under Settings. Deletion is immediate and permanent: everything you left comes off every shelf, your name and account are erased, any push notification tokens and preferences are deleted, and any shelf you owned passes to its longest-standing member (or is closed if you were the only one on it). Reports you filed are kept, with your identity removed. Your private "last visited" markers are deleted with the account — they were never visible to anyone else to begin with.

Losing a device

By default your identity lives only on your device or in your browser. If you lose it or clear the browser, we have no way to prove the account was yours, and no way to give it back. You can prevent that by protecting your shelves with an email address, which lets you sign in again somewhere else. It's optional, and nothing else changes if you skip it.

Questions

Contact us any time via the support page.