Privacy policy
Last updated 18 September 2026.
This policy explains what Finished does with your information. It is written to be read, not to be survived. If anything in it is unclear, ask us and we will explain it in plainer words.
Who we are
Finished is made by get wobbled ltd, a company registered in the United Kingdom (company number 11737525). Our registered address is The Cow Shed, Off Packwood Lane, Lapworth, West Midlands, England, B94 6AU.
For data protection law, get wobbled ltd is the data controller for the information described here. You can reach us at hello@thefinishedapp.com.
The short version
- You can use Finished without an account. If you never sign in, nothing you write leaves your phone.
- If you are signed in, a photo of a book cover is sent to an AI model to read which book it is. It is used for that and not kept.
- We have no analytics, no crash reporting, no advertising and no tracking of any kind.
- We do not collect your location, your contacts, your photo library or your email address.
- We do not sell your information, and we never will.
- If you sign in, the books you log, your star ratings, your written reviews and your comments become visible to other people using Finished. That is the point of signing in, but it is worth knowing before you do it.
How a photo of a cover is read
When you photograph a book cover, or pick a screenshot of one, the picture is read on your own device using Apple's Vision framework. It looks for a barcode and for the words printed on the jacket.
If you are signed in, a smaller copy of the picture is also sent, through our server, to an AI model that reads which book it is. That model is Google's Gemini, reached through Vercel's AI Gateway, which processes the request in the United States. The picture is used only to answer that one request. We do not store it, and it is not used to train anyone's models.
The title and author that come back, or an ISBN from the barcode, are sent to a book catalogue so we can check which book it is. A barcode is always read on your phone and never uploaded.
Our server counts how many covers each account has had read that day, to stop anyone misusing the service. It keeps the count, not the pictures. If you are not signed in, the picture stays on your phone.
What is kept on your phone
Your shelf lives on your device, in the app's own storage. It holds, for each book:
- the title, author, page count and ISBN
- the cover image the catalogue gave us, or the one you kept
- whether you have finished it, are reading it, or want to read it
- your star rating, from one to five
- your written review, up to 2,000 characters
- the dates you started and finished it
- whether you have pinned it to your profile
The app also keeps a plain copy of this list in a file beside the database, so your shelf can be rebuilt if the database is ever lost.
All of this is on your phone. It may be included in your iPhone backups, which are Apple's and are covered by Apple's own privacy policy, not ours. You can export the whole lot at any time, or delete it, from Settings in the app.
Notifications
Finished only sends notifications if you allow them, and you can turn them off at any time in your phone's Settings.
Reminders about your reading, such as asking how a book is going, are made on your phone from your own shelf. Nothing about them is sent to us.
If you are signed in and allow notifications, we keep your phone's push address, a code Apple gives the app so a notification can reach it, against your account. We use it to tell you when somebody follows you, likes one of your posts or comments on it. The notification goes through Apple's push service. We keep a record of each notification for a short time to know it was sent. Signing out removes this phone's push address from your account, and deleting your account removes all of them.
Accounts
Signing in is optional, and only needed for the parts of Finished that involve other people: profiles, following, the feed, comments and the AI finder.
We use Sign in with Apple, and nothing else. There is no password to create and we never see one.
When you sign in, we ask Apple for your name only. We do not ask Apple for your email address. Apple gives us an identifier that is unique to you and to this app, and our server keeps that so it can recognise you next time.
The name Apple gives us becomes the name on your profile, and we suggest a handle based on it. You can change both. If Apple gives us no name, your profile starts as "Reader".
Your sign-in tokens are stored in the iOS Keychain on your device, which is encrypted by the system. They are not stored anywhere else on your phone and they never leave it except to talk to our own server.
What we store on our server, and only if you sign in
Our server is a Supabase project run by get wobbled ltd. If you are signed out, none of this exists.
Your profile: your account identifier, your display name, your handle, your bio if you write one, the date you joined, your all-time favourite book if you name one, and the club or partner code you joined through if you used one.
Your profile picture, if you add one. It is stored in our image store under a name based on your account identifier. Profile pictures are publicly readable: anyone with the link can see the picture, whether or not they use Finished. Only you can replace or remove your own. If you would rather not have a picture out there, do not add one. Your initials are shown instead.
Your public shelf: for each book you log or change while signed in, the book's title and author, your reading status, your star rating, your written review, and your start and finish dates.
What you have done: an entry saying you started, finished or wrote about a book. This is what the feed is made of.
Who you follow, and who follows you.
Who you have blocked. Your block list is visible only to you.
Likes and comments you leave on other people's entries.
Reports you make about a profile, a review or a comment, including the reason you chose and any note you add. We keep these so we can act on them.
A count of AI finder searches, per person per day, so we can enforce the daily limit. It is a number, not a record of what you asked. We keep these counts for about a week and then delete them.
A shared list of books. Titles, authors, page counts, ISBNs and cover links, shared by everybody who uses the app. It is about books, not about people.
We also store nothing about you that you have not put into the app yourself. There is no hidden profile of your behaviour.
Important: logging a book while signed in publishes it
While you are signed in, adding a book, changing its rating, changing its dates or writing a review sends that book to your public shelf and puts it in the feed. There is no separate "post" button.
Books you logged before you signed in stay on your phone until you change one of them.
Who can see what you write
Be clear about this before you write anything personal in a review.
- Signed out: nothing. Your reviews and ratings are on your phone only.
- Signed in: your profile, the books on your public shelf, your ratings, your written reviews, your likes and your comments can be seen by other people who use Finished. The feed shows them to the people who follow you, and anyone signed in can look at your profile and the books on your shelf. Treat anything you post while signed in as public.
- There are no private profiles in this version of the app. If you would rather something stayed private, do not write it while signed in, or delete it.
- Blocking works both ways. Once you block somebody, neither of you can see the other anywhere in the app. They are not told.
- Reports cannot be read by other users. Only we can see them.
We can see everything on the server, because we run it. We look only when we have a reason to: dealing with a report, fixing a fault, or answering a legal obligation.
The AI finder
The AI finder is the one feature that sends anything to another company.
When you ask it for something, we send:
- the words you typed, for example "like these but darker"
- up to twelve books you pointed at, as title and author
- the titles and authors of the books on your shelf, so it never suggests one you already have
That is all. We do not send your name, your handle, your account identifier or your email address.
The request goes from our server to Vercel's AI Gateway, which passes it to an AI model provider. As of the date of this policy the model is provided by OpenAI. We may change the model or the provider, and we will keep this policy up to date when we do.
The question is not used to train models under the arrangements we have with those companies, and we do not keep a copy of your questions on our server. The AI providers keep their own short-term records of requests for abuse monitoring, under their own terms.
The finder needs an account, because it costs money to answer. It is limited to twenty searches a day per person.
Book information and cover images
Book details and covers come from third-party catalogues:
- Open Library, run by the Internet Archive. No account or key is needed.
- Apple's iTunes Search API, which is where the high resolution jackets come from. No account or key is needed. The app tells it your device's country setting so results suit your region.
- Google Books is written into the app but switched off, and stays off unless an API key is added to a future version.
When the app looks a book up or fetches a jacket, that request reaches those companies from your phone. They will see your IP address and the words being searched for, and they handle that under their own privacy policies. We do not control what they keep.
We have deliberately kept your search words out of the app's own logs on your phone.
Payments
The subscription is sold through Apple's App Store, using Apple's In-App Purchase. We never see your card details, your billing address or your Apple Account.
Apple tells the app whether you currently have a subscription, and whether you are inside the free trial. That is all we receive. If we later add a subscription analytics service in order to work out what launch partners are owed, we will update this policy before we do it.
If you signed up through a partner code, such as a book club code, that code is stored on your account and a badge appears on your profile. We use it to work out what the partner is owed. Partners are given totals only. We do not tell them who used their code.
What we do not do
- No third-party analytics. We keep our own daily counts, described above, and they hold nothing about you.
- No third-party crash reporting. Crash reports come from Apple, and only if you have agreed to share them with developers in your iPhone settings.
- No advertising, no advertising identifiers, no ad networks.
- No tracking across apps or websites, so the app does not ask for tracking permission.
- No location collection, at any accuracy.
- No access to your contacts, your calendar, your health data or your microphone.
- No reading of your photo library. The photo picker hands the app only the one picture you choose, and the app asks only for permission to *add* your Finished card to Photos.
- No selling, renting or sharing of your information for anyone else's marketing.
Sharing a card
When you share a Finished or Started card:
- Save to Photos asks your permission to add the image, and nothing more.
- Instagram Stories works by putting the image on the iOS clipboard and opening Instagram, which reads it from there. The clipboard entry expires after five minutes.
- The share sheet hands the image to whichever app you pick.
Once a card is in another app, that app's privacy policy applies. The card contains what you can see on it: the cover, the book, and your own stats.
Who can see your profile
Your profile is public by default: anybody signed in to Finished can see your shelf, your posts and your reading year. You can make it private in Settings. A private profile shows only your name, picture and counts to anybody who does not follow you, and a new follower has to be allowed by you first.
What we count
We keep a daily tally of how often things happen in the app: how often it is opened, how often a cover is scanned, a book is added or finished, a card is shared, the finder is asked, and so on. It is a count and nothing else. No name, no account, no book title and no words are kept with it, and nothing in it can be traced back to you. We use it to see which parts of Finished people actually use.
Where your information is kept, and who helps us run the service
| Who | What they do | Where |
|---|---|---|
| get wobbled ltd | Runs Finished | United Kingdom |
| Supabase | Hosts the database, sign-in and server functions | London, United Kingdom (eu-west-2) |
| Vercel | AI Gateway for the finder | United States |
| OpenAI | The AI model behind the finder | United States |
| The AI model that reads a cover photo | United States | |
| Apple | Sign in with Apple, App Store payments, book search | United States and elsewhere |
| Internet Archive (Open Library) | Book data and covers | United States |
Some of these are outside the United Kingdom. Where information reaches a country without a UK adequacy decision, we rely on the UK International Data Transfer Addendum to the European Commission's standard contractual clauses, or on another safeguard permitted by UK data protection law, as set out in that supplier's terms.
Our hosting provider keeps technical logs of requests to the server, which include IP addresses, for a short period as part of running and protecting the service.
How long we keep things
- Your account and everything attached to it: until you delete it. Deleting your account removes it immediately.
- Your shelf on your phone: until you delete the app or delete it from Settings.
- Reports: kept after they are dealt with, so a pattern of behaviour can be recognised. We review them periodically and delete what we no longer need.
- Finder search counts: about a week.
- Server request logs: the short period set by our hosting provider.
Why we are allowed to use your information
Under UK data protection law we need a lawful basis. Ours are:
- Performance of a contract. To give you the app, your account, your shelf, the feed and the finder, because that is what you asked us for.
- Legitimate interests. To keep the app working and safe: the comment filter, blocking, reports, the daily finder limit, and stopping abuse. We have weighed this against your privacy and think it is fair and expected.
- Legal obligation. Where the law requires us to keep or hand over information.
Where we rely on legitimate interests you can object, and we will look at it properly. See your rights below.
The comment filter refuses a comment automatically if it contains words on a blocked list. That is the only automated decision the app makes about anything you do, and you can rewrite the comment and try again.
Children
Finished is not for children under 13. We do not knowingly collect information from anyone under 13. If you believe a child under 13 has an account, tell us at hello@thefinishedapp.com and we will delete it.
Keeping it safe
- Everything travels over HTTPS.
- Your sign-in tokens live in the iOS Keychain, set so they can only be read on your own device after it has been unlocked.
- The database enforces who can read and write each row, at the database itself, rather than trusting the app to behave.
- The keys that could bypass those rules are never shipped inside the app. They stay on the server.
- The comment word filter runs both on your phone and again on the server, so a modified app cannot walk past it.
No system is perfect. If something does go wrong and it puts your rights at risk, we will tell the Information Commissioner's Office within 72 hours, and we will tell you where the law requires it.
Your rights
Under UK GDPR and the Data Protection Act 2018 you have the right to:
- Access. Ask for a copy of the information we hold about you.
- Rectification. Have anything wrong put right. Most of it you can edit yourself in the app.
- Erasure. Have your information deleted. Deleting your account does this.
- Restriction. Ask us to stop using your information while something is being sorted out.
- Portability. Get your information in a form you can take elsewhere. The Export button in Settings gives you your shelf as a plain JSON file.
- Objection. Object to us using your information where we rely on legitimate interests.
- Withdraw consent, where we ever rely on consent, such as the camera or Photos permissions, which you can change at any time in iOS Settings.
To exercise any of these, email hello@thefinishedapp.com. We will reply within one month. There is nothing to pay.
Deleting your account: open Settings in the app and choose to delete your account. Everything attached to it goes with it: your profile, your public shelf, your events, your likes, your comments, your follows and your blocks. It cannot be undone. Your shelf stays on your phone unless you also choose "Delete everything", which wipes the local copy.
If you are unhappy with us, please tell us first so we can try to fix it. You also have the right to complain to the Information Commissioner's Office, the UK regulator, at ico.org.uk, by calling 0303 123 1113, or by writing to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
Changes to this policy
If we change what the app does with your information, we will update this policy and change the date at the top. The current version is always at thefinishedapp.com. If a change matters to you, for example a new company handling your information, we will say so in the app as well.
Contact
hello@thefinishedapp.com get wobbled ltd, The Cow Shed, Off Packwood Lane, Lapworth, West Midlands, England, B94 6AU
---