Last updated 17 September 2026
Shelfo turns your own writing and reading into audiobooks. The voice is generated on your iPhone, so the text you feed it does not have to leave the device. This page says exactly what is kept, what is sent, and how to get rid of it.
| What | Why | Where it is kept |
|---|---|---|
| Your Apple account identifier, and the name and email address Apple chooses to share | So the shelf is yours and can follow you to a new phone | On your device, and on our server once you sign in |
| Your books: title, the text itself, category, chapters | They are the shelf | On your device. Also on our server if backup is on |
| The audio Shelfo generates for each book | So a book only has to be made once | On your device only — never uploaded |
| How far you have listened, your highlights, and daily listening totals | To pick up where you left off and show your totals | On your device. Position also on our server if backup is on |
| Cover images you pick or take | So a book looks like something on the shelf | On your device. Also on our server if backup is on |
| Whether you have an active subscription | To unlock Pro on every device you sign in on | With Apple and RevenueCat — see Subscriptions below |
Shelfo carries its own speech model and runs it on your iPhone. The text of a book is not sent to any service to be read aloud — not ours, not anyone else's. The audio file that comes out stays on the device and is never uploaded, which is also why a book is only converted once.
Backup is off unless you have Shelfo Pro and are signed in. With it on, the details of your books — title, category, chapters and your listening position — are stored in our Supabase project, and the book's text and its cover image are stored in Cloudflare R2 through a small service of ours that checks your sign-in first. Every row and every file is confined to your own account; no other user can reach them.
Without backup, none of this is sent anywhere and the shelf lives only on the phone.
When you make a book from a link, your iPhone fetches that page directly, the way a browser would. The site you linked to sees the request; we do not see it and the page is not routed through us.
When you make a book from a PDF or a photograph, the text is pulled out on the device — the PDF's own text layer, or Apple's on-device text recognition for a picture. The file itself is never uploaded.
If you search for a cover image, the words you type are sent to Openverse, which finds openly licensed pictures. Nothing else about you goes with the search. Taking a photo or choosing one from your library does not involve any service at all.
Shelfo Pro is bought through Apple. Payment details are handled entirely by Apple and never reach us. We use RevenueCat to keep track of whether a subscription is active; it receives the purchase record from Apple along with an identifier for your account, so that Pro follows you to a new phone. It receives no book, no text and no listening data.
The notice telling you a book has finished converting is created on your own phone. No notification service is involved and nothing is sent anywhere to produce it.
Deleting a book removes it from the shelf and its audio from the phone. If backup is on, it is removed from the server on the next sync as well.
Profile → Delete account erases every book, highlight and listening total held on this iPhone and signs you out. Your sign-in record with Apple is not removed by this, and anything already backed up stays on the server. To have the backed-up copy erased too, write to the address below and it will be removed.
Deleting the app without deleting the account leaves your account intact, so signing in again on a new phone brings a backed-up shelf back.
Shelfo is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, write to us and it will be removed.
If this policy changes in a way that affects what is kept or where it goes, the date at the top changes with it, and the app will say so before the change takes effect.
Questions about this policy, or about the data held for your account: ridebluewater@gmail.com