PageLab

Privacy Policy

Last updated 2026-08-20

On this page

  • What we collect, and why
  • Who else receives it
  • Push notifications, and what Google receives
  • Who can see your profile, and what it starts as
  • Your friend code
  • How long we keep it
  • Deleting things, and what deletion actually does
  • Your rights, and how to use them
  • If you are under 18
  • Where your data is
  • Changes to this policy

This describes what PageLab collects about you, why, who else sees it, how long it is kept, and how to get it back or get rid of it. PageLab is operated by Orbyt LLC, a New York limited liability company, at 73 Liberty St., Owego, NY 13827, United States, and Orbyt LLC is the controller of the data described here.

What we collect, and why

Almost all of it is something you typed or tapped.

  • Your account — display name, email address, and either a hashed password or the identifier your sign-in provider gives us. Needed to have an account at all.
  • What you write and upload — posts, comments, reviews, ratings, quotes, reading lists, reading progress, direct messages, written works and their chapters, uploaded images and video, your avatar and profile cover. This is the product.
  • Who you are connected to — follows, follow requests, blocks, group membership, buddy reads.
  • Your friend code — a short code that lets someone who has it find your profile. It is created the first time you look at it, not when you sign up, and it is then stored on your account until you replace it. It has a section of its own below.
  • Your device — a push notification token, and your theme and reader preferences.
  • Your age band. Whether you are an adult, a minor, or not yet established. We keep the band and the fact that it was established; a birth date you enter is used to work out the band and is not kept as a birth date.
  • IP addresses, recorded when an account signs in, posts, sends a message or uploads a file. Collected deliberately, for safety investigations and to answer legal process.
  • Edit history — when you change a post, a quote, your display name or your avatar, the previous version is kept. Drafts of a chapter are kept while you are writing it.
  • Shelving history. Each time you move a book onto or between your shelves, we record that it happened and when. That record is kept even if you later take the book off the shelf — removing a book from your shelves removes the book, not the history of your having shelved it. It powers “trending” and recommendations.
  • A profile of your taste that we generate. Not something you write: PageLab derives it from what you read, shelve and rate, stores it against your account, and uses it to choose what to recommend to you. It is data about you produced by us rather than supplied by you.
  • Moderation records — reports you file, reports filed about you, sanctions, and the actions staff took.
  • Crash diagnostics, if you leave them on — see below.

We do not sell any of it.

Who else receives it

  • Google Firebase Cloud Messaging delivers every push notification and therefore receives the contents of each one. This is not a delivery-only role — see the next section, which describes exactly what that means.
  • Google Firebase Crashlytics receives crash diagnostics from the app: your device model, Android version and the technical details of the failure. It does not receive your books, posts or messages. You can turn this off in Settings, under Diagnostics, and nothing is sent once you do.
  • Google and Apple, if you choose to sign in with them, confirm to us that the account is yours. We receive an identifier and your email address; they learn that you signed in to PageLab.
  • Our hosting provider stores the database and uploaded files, and our email provider sends verification, password-reset and account-deletion codes. Both act on our instructions and for no other purpose.
  • Open Library and ISBNdb supply the book catalogue. They receive lookups for books; they do not receive anything about you.

Beyond that, we disclose personal data only when the law requires it, when it is necessary to report child sexual abuse material to the National Center for Missing & Exploited Children, or to protect someone from serious harm. If PageLab is ever sold or merged, the buyer takes on this policy along with it.

Push notifications, and what Google receives

PageLab does not deliver notifications to your phone itself. It hands each one to Google Firebase Cloud Messaging, which delivers it. The notification’s contents travel through Google’s servers in readable form — they are not encrypted end to end, and nothing is stripped out or shortened on the way.

For a direct message, that means the entire text of the message — the whole thing, however long, not a summary or a preview — together with the sender’s display name and a link to any photo, GIF or video they attached.

Other notifications carry less, but they are not empty. Depending on the type, the payload may include: the display name of the person who followed you, replied to you, reacted to your post, or invited you to a buddy read; the first 140 characters of a reply to your post; the title of a book, a chapter, or a written work; the name of a group; an emoji; a moderator’s stated reason when we act on your account or your content; and your own reading-goal progress when you hit a milestone. Every notification also carries your PageLab account number, so that your device can confirm the notification is for the account currently signed in.

A link is not the file. Google receives the web address of an attached photo or video, but the file behind that address cannot be opened without a signed-in PageLab account that is allowed to see it, so Google receives the link and not the picture. And if your phone is offline, Google may hold an undelivered notification for up to 24 hours before giving up.

Your control over this is on/off, per category. In Settings you can turn off message notifications, or any other category, or pause all of them; anything you turn off is never handed to Google in the first place. There is no setting that delivers a notification while keeping its contents off Google’s servers. Notices about enforcement action on your account are the one exception that ignores the pause, because you need to be told. Note also that notifications appear on your lock screen with their contents visible, which is a matter for your phone’s own settings rather than ours.

Who can see your profile, and what it starts as

A new account is public. Your profile, your shelves and your activity are visible to anyone using PageLab from the moment you sign up, until you change it.

You can change it at any time in Settings. Alongside the whole-account choices — public, readers you follow who follow you back, or private — there is a per-category option that sets visibility separately for your activity, your wishlist and your reads, so you can leave one open and close another. Accounts belonging to under-18s are restricted by default and are not governed by these controls.

Direct messages are never public. They go to the person you sent them to. If a message is reported, the staff handling that report can read it.

Your friend code

A private profile is left out of the places that surface people, including people search. So that choosing it does not make you unreachable by the people you actually want to reach you, every account can have a friend code: a short code, shown to you in the form PL-XXXX-XXXX, that you can read out, copy or send to someone. Anyone signed in to PageLab can type a code in and be taken to that account’s profile.

Every account can have one, whatever its privacy setting. That is deliberate: if only private accounts had a code, then having one would itself announce the setting. The code is created the first time you look at it, not when you sign up, so an account that never opens that screen never gets one. Once created it stays on your account until you replace it, and it is not shown to anyone else — a code appears only on your own screen, never on your profile as others see it.

It is stored in readable form, because it is a lookup key and not a password. Your password and the codes we email you are stored hashed, precisely because nobody — including you — should be able to read them back. A friend code is the opposite: you have to be able to read yours in order to hand it out, so it is kept as it is shown. What that means is that it is stored the way your display name is, and anyone with access to our database could read it. What it does not mean is that it opens anything. It is not a login and it carries no permissions; it locates an account, it does not unlock one.

Someone holding your code sees your ordinary profile and no more. If your profile is public, they see the public profile. If it is private, they see your display name and nothing else — no avatar, no cover image, no bio, no follower or following numbers, no shelves, no posts — and their only next step is a follow request you can accept or ignore. Being findable is not the same as being visible, and the code does not change what anyone is allowed to see.

Replacing your code cancels the old one. This is the control you have over a code that has travelled further than you meant it to: generating a new one overwrites the old value, so every earlier share — a screenshot, a card, a message in a group chat — stops resolving at once. We keep no history of your previous codes, because keeping them would preserve the very thing replacing a code exists to destroy.

We do not claim the code is a secret. It is eight characters chosen at random by our servers from an alphabet of 32, which is about a trillion possibilities — enough that nobody stumbles onto yours, but short enough to read down a phone, which is the point of it. What makes working through those possibilities impractical is not the code itself but the limit of ten lookups a minute that we apply to each account. Treat a friend code as something you choose to give out, not as something that keeps anyone out.

A failed lookup deliberately tells the person nothing. A code that does not exist, a code typed wrongly, a code belonging to someone who has blocked them, to a suspended or deleting account, or their own code, all get exactly the same answer: not found. We do not say which, because the difference would confirm that a code exists, or that a particular person had blocked them — things a stranger should not be able to establish by guessing. The one thing reported separately is that they have tried too many times in a minute, since in that case nothing was looked up at all.

The code itself stays out of our logs. A lookup sends the code in the body of the request rather than in the web address, so it never reaches the server request logs described below. We record that a lookup happened, who made it and whether it matched something — which is what makes a guessing campaign visible — but never the code that was tried.

How long we keep it

  • Your account and everything in it — for as long as the account exists. Deleting the account removes it, subject to the exceptions below.
  • IP addresses — 180 days, then deleted automatically.
  • Server request logs — at most 14 days, on an automatic rotation. They record which address was requested, the response status, and the account number that made the request. They deliberately do not record IP addresses, search terms or anything else from the query string. Because they are files rather than database rows, they are not searched or erased account by account; they age out.
  • Content retained as evidence in an open moderation matter — until that matter is resolved.
  • Content under a legal retention hold — for the length of the hold. Where the hold exists because a report was filed with the National Center for Missing & Exploited Children, the law sets a minimum of 12 months and we cannot shorten it.
  • Backups — taken weekly and overwritten on their ordinary cycle. They are not searched to remove individual records; deleted data disappears from backups as those backups are replaced.

Deleting things, and what deletion actually does

Deleting a post removes it from PageLab. It stops appearing in feeds, searches, your profile and anyone else’s view, and it cannot be recovered by you or by another user. What it does not do is erase the underlying record immediately: the post and anything attached to it remain in our systems until the account is deleted, at which point they are erased along with everything else. If you want a post gone from our storage and not merely from the product, deleting your account is what does that.

Deleting your account erases it. Not deactivation: your profile, posts, comments, reviews, quotes, shelves, reading progress, messages, uploaded images, derived taste profile and shelving history are removed. Anything you wrote and published is removed too, and that includes its edit history — we keep a copy of each earlier draft while you are writing, and those go with the rest rather than outliving the work they belong to. Three things deliberately survive, and each exists so that deletion cannot be used to clean up after harming someone: content retained as evidence in an open moderation matter, anything under a legal retention hold, and an anonymised [deleted] marker where you replied in someone else’s thread, so the conversation around it does not collapse.

There is a 30-day wait. When you ask us to delete your account it is closed immediately — you are signed out and it stops being usable — and the data is erased 30 days later. The delay exists so that an account taken over by someone else can be recovered by its owner. Signing back in during those 30 days cancels the deletion, and so does completing a password reset.

A legal hold can push that date back. If any of your content is under a retention hold when the 30 days elapse, the erasure waits for the hold to expire rather than proceeding without it. In that case deletion happens after the hold ends, not on the thirtieth day. This is why the deletion screens say “on or after 30 days” rather than promising the thirtieth day itself.

Your rights, and how to use them

  • Get a copy. Settings → Export library gives you a CSV of your shelves, your ratings and reviews, your reading progress and your quotes, with the book each one refers to. It does not cover your posts, messages or written works — ask us for those and we will put them together.
  • Correct something. The profile editor changes your name, avatar, bio and cover. Your email address is changed from the account page, and the new one has to be confirmed.
  • Delete it. In the app, or from /delete-account on the web if you cannot sign in.
  • Object, restrict, or withdraw consent. Turn off crash reporting in Settings; turn off any category of notification; make your profile private; replace your friend code, which cancels the one you gave out. For anything broader, email us.
  • Complain. If you are in the UK or the EU you may complain to your data protection authority.

Ask at support@orbytgames.com. We will respond within 30 days. We may need to confirm you control the account before acting on a request, because acting on an unverified one is itself a way to leak someone’s data.

If you are under 18

PageLab is for readers aged 13 and over. Accounts we know belong to under-18s are restricted by default: reading records are private, direct messages are limited to connections that both people accepted, recommendations do not use their data, and they are not shown to strangers in the places that surface people. Notifications for these accounts are transactional only, and are held between midnight and 6am local time. The child-safety page at /legal/children sets out the rest, including how to report concerns about a child.

If we learn we hold data from a child under 13, we delete the account and its contents.

Where your data is

PageLab is operated from the United States and your data is stored there. If you use PageLab from outside the US, using it means your data is transferred to the US, where privacy law differs from your own country’s.

Changes to this policy

When this changes we update the date shown on this page. If a change materially affects what we collect or who receives it, we will tell you in the app rather than relying on you to check. Continuing to use PageLab after that means the updated policy applies.

Other policies

Terms of Service Cookies Content Policy Acceptable Use Copyright and DMCA Child Safety and Children's Privacy Intimate Image Removal Legal Contact

Back to PageLab