Who operates Sibyl
Sibyl is an independently operated book discovery service. In this policy, “Sibyl,” “we,” and “us” refer to the individual operating the service under the Sibyl name.
Privacy questions and requests can be sent to support@sibylbooks.com.
Information Sibyl collects
Sibyl collects the information needed to run accounts, discovery, public Stacks, support, safety, and the optional Sibyl Supporter membership.
- Account and profile information. Email address, username, display name, bio, avatar choices, privacy settings, book source preferences, and notification settings.
- Reading and discovery activity. Stacks, ratings, saved Stacks, follows, dismissed books, recommendation interactions, taste profile data, and the choices you make on book cards.
- Reader content. Profile text, public or private Stacks, Stack notes, comments, correction reports, and visibility choices.
- Catalog requests and corrections. If Sibyl cannot find a known book, the title, author, ISBN, publication year, and other details you submit may be stored with a catalog ingestion job and its source evidence. Selected request details may also appear in service logs used to diagnose that workflow.
- Product and safety records. Coarse page, search, recommendation, and outbound-link events used to understand product health and prevent abuse. Rate-limit identifiers derived from network information are hashed before storage.
- Membership records. Sibyl Supporter plan, billing interval, and membership status. Stripe handles payment-card details; Sibyl does not store full card numbers.
- Browser storage. Essential authentication cookies and local or session storage used for signed-out preferences, book actions, and per-tab experience state.
How Sibyl uses information
Sibyl uses this information to create and secure accounts, honor privacy choices, provide Find Books and For You recommendations, maintain Stacks and comments, personalize the taste profile, prevent abuse, improve catalog quality, measure product health, process memberships, and answer support requests.
Affiliate relationships do not determine which books Sibyl recommends, whether a book is included, its visible match type, or its recommendation ranking.
Services that process limited information
Sibyl uses service providers for hosting, authentication, database storage, account email, payments, and selected book-discovery processing. Those providers receive only the information needed for their part of the service, subject to their own service terms and privacy practices.
When a new semantic search needs an embedding, its exact search text may be sent to OpenAI. Sibyl's semantic-search cache stores a query hash and vector rather than the raw or normalized search text.
If you choose to generate a Reader Signature, Sibyl sends OpenAI a structured shelf summary. Depending on whether the signature is for you or your public profile and which profile stats are visible, that summary can include your display name; central, unusual, and example book titles; reading totals, pace, and average book length; taste balances and map labels; and top authors, genres, themes, and clusters. The generated signature is stored with your Sibyl profile.
When you submit a known-book request or catalog correction, structured book details may be sent to external catalog and metadata sources to find, verify, or improve the record.
Messages go to the person who runs Sibyl, and replies come from support@sibylbooks.com. Email service providers process the sender and recipient addresses, message contents, and delivery metadata needed to route and deliver the correspondence under their own terms and privacy practices.
Cloudflare Turnstile helps protect account creation, confirmation-email resend, and password-recovery forms from automated abuse. On those forms, Cloudflare processes security signals such as IP address, TLS fingerprint, user-agent header, and the Turnstile site key and origin to distinguish people from bots. Turnstile does not receive your form entries through Sibyl's integration. Sibyl sends the resulting single-use token to Cloudflare for verification and uses the returned result, action, and hostname to decide whether to continue. See Cloudflare's Turnstile Privacy Addendum.
Sibyl does not use third-party advertising or third-party analytics services and does not intentionally enable third parties to track readers across unrelated sites for those purposes. Remote book-cover hosts, external sellers, and other linked services still receive ordinary request information, such as IP address and browser details, when your browser loads their content or you follow a link. Those services may use their own technologies to recognize activity over time or across services under their own privacy policies.
Public content
Content you mark public—including public profile fields, Stacks, and comments—can be viewed by other readers and may appear in search engines. Changing a Stack or profile setting to private removes it from Sibyl's public surfaces, although search-engine copies and ordinary caches may take time to update.
Do not publish personal information in a public Stack, note, profile, or comment unless you want other people to see it.
Sale, targeted advertising, and browser signals
Sibyl does not sell personal information, use it for targeted advertising, or share it for cross-site behavioral advertising. Sibyl also does not use third-party advertising trackers.
Because Sibyl does not engage in those practices, Global Privacy Control and Do Not Track signals do not change how the service currently handles data. This policy will be updated before that changes.
How long information is kept
Account information and reader content remain while your account is active unless you delete them sooner. Raw operational events are generally kept for limited periods of 90 to 180 days before deletion or reduction to aggregate counts.
Catalog requests, ingestion jobs, and source evidence may be kept longer than those event windows to prevent duplicate catalog work, trace corrections, and explain how a book record was created or changed. Service-provider logs follow the retention settings verified for the production provider.
Limited billing, security, fraud-prevention, moderation, support, and legal records may be kept longer when reasonably required. Deleted information can remain in protected backups until those backups expire through their normal schedule.
Your account choices
Account controls let you review and correct your profile information, change privacy and notification settings, download your data, and delete your account. If you cannot use those controls, email Sibyl from the address associated with your account when possible.
Sibyl may verify account ownership before disclosing, correcting, exporting, or deleting private information. The Data Deletion page explains what deletion covers and what limited records may remain.
Age requirements
Sibyl is not for children under 13. Readers ages 13 through 17 may use Sibyl only with permission from a parent or legal guardian. If Sibyl learns that it collected personal information from a child under 13, it will take appropriate steps to delete it.
Security and policy changes
Sibyl uses reasonable administrative and technical safeguards to protect reader information, but no online service can promise absolute security.
Material changes to this policy will be posted here with a new effective date and, when appropriate, communicated through your account or by email. Earlier policy versions will be archived as part of Sibyl's launch and change-management process.
