Most reading platforms are advertising businesses that happen to involve books. This one is a desk that reviews them and a shop that links to them. It does sell advertising, and the distinction worth having is that it sells space rather than knowledge of you: every advertisement here is served from our own database and chosen by the date and the page, never by anything we have learned about the person reading. No advertising network is in the room, so there is no second party collecting anything.
Here is the complete inventory of what this site can know about you, published because it is short enough to publish.
If you subscribe to a desk’s letter, we hold your email address, which desk you chose, and the dates you consented and confirmed. That is the entire record. Every letter carries one-click unsubscribe, and erasure is immediate on request.
If you keep a shelf, we hold your saved book titles against your email, and only if you chose the sign-in link; until then the shelf lives in your own browser and we hold nothing at all. Sign-in is a one-time emailed link. There are no passwords here and none are coming.
If you import your Goodreads library, the file is read inside your browser and never uploaded. We could not retain your reading history if we wanted to, and we built it that way on purpose.
How the advertising works, since it is the part readers are right to ask about. Advertisements are stored, chosen and counted by this site alone. No third-party script runs in the slot, no advertising cookie is set, and no profile of you is built, bought or borrowed. Which advertisement appears depends on the date and the page, so two readers on the same page on the same day see the same one. Advertisers are told a daily count: how many times their advertisement appeared, and how many people clicked it. They are not told who, because we do not know. The table holding those counts has no column that could identify a reader, and a test in our code fails the build if one is ever added.
What we never do, in writing: no advertising networks, no advertising pixels, no data brokers, no sale or sharing of reader data, ever. The reader features, the shelf, the sign-in, the importer, run on aggregate counters alone, how many saves happened rather than who saved what, displayed on our own admin screen where the publisher watches the same totals you would.
One standard tool, disclosed plainly: we use Google Analytics to count visits and learn which essays get read, as most independent sites do. It sets its own cookies under Google’s policies. Ours is the shorter promise. Its numbers steer editorial decisions, and in aggregate they answer an advertiser asking how large the audience is; they are never used to choose which advertisement you see, never joined to your shelf, your email, or anything you do as a signed-in reader, and never handed to an advertising network. Block it and everything on this site still works.
If you join The Reader’s Desk, payment is handled by an external processor and your card details go straight to it, never touching this site. What we keep is the order record, your email, the membership, and the dates, and the same one-click erasure rights apply to it. Cancelling is one click from your account. The processor in use is named on the checkout page itself rather than here, so this paragraph cannot go stale the way a hardcoded name would, and no payment has been taken by this site yet in any case.
Your rights need no form and no waiting period. Use the delete button on your shelf, the standard export and erasure tools, or an email to the desk; all three end the same way, with us holding nothing.
This page is enforced rather than decorative. Our admin area carries a Privacy desk that checks each claim above against the running code, and a claim we cannot verify is a claim we take down. Saving is never subscribing; the letters remain their own explicit choice; and the shelf is yours, which on most platforms would be a slogan and here is an architecture.
One more thing, for exactness. This page is the plain-English companion to our formal Privacy Policy, which carries the legal detail: who the data controller is, the lawful bases we rely on, international transfer, the retention periods, and your rights in full. The two are written to agree in every particular. If you ever catch them apart, the Privacy Policy governs — and we would like to hear about the difference, because it is a bug. Nothing on this page grants you less than the policy promises.