Privacy
Privacy Policy
This policy explains how NOOK processes personal data in the mobile app and on this website.
Last updated: 10 August 2026
1. Who we are
NOOK is operated by Joonsung Lee, an individual trading as NOOK. Joonsung Lee is the controller responsible for personal data processed through the NOOK mobile application and website. Contact: support@official-nook.com.
2. Data we collect
We collect the personal email used for sign-in, verified university email and affiliation, nickname, optional profile photo and biography, and content or academic data you choose to add, such as posts, comments, reviews, timetables and grades.
We also process security and service data such as the network address used for an OTP request, an installation identifier used for abuse prevention, push tokens and App Check signals. Our OTP quota store retains only a secret-keyed representation of the network address, not the raw address.
If you contact us through the website, we process the name, email address, enquiry category, subject and message you provide. With consent, optional diagnostics can include app or device details, crash stack traces, events preceding a crash and device or installation identifiers. NOOK does not intentionally attach your name, email or post content to a crash report.
3. Legal bases
We process personal data where necessary to provide the service, based on our legitimate interests in security, abuse prevention and service reliability, where you consent to optional crash reporting, and where processing is necessary to comply with law. You may withdraw crash-reporting consent at any time in the app.
4. How we use data
We use data to create and protect your account, verify university access, provide community and academic features, deliver notifications you enable, answer enquiries, investigate reports, prevent abuse and fraud, meet legal duties, and diagnose service failures.
5. Anonymous posting
Anonymous posts do not display your nickname to other users. We retain a restricted internal link to the account so we can investigate abuse and comply with valid legal obligations. We disclose identifying information only where we have a lawful basis to do so; anonymity is not protection for illegal conduct.
6. Data sharing and service providers
We do not sell personal data or use it for third-party advertising. We use service providers only to operate and protect NOOK.
- Google Firebase: authentication, database, storage, functions, notifications, App Check and optional crash reporting.
- Algolia: tenant-filtered search.
- Resend: one-time-code and website contact-form email delivery.
- Vercel: hosting and delivery of the public website.
- Apple or Google: identity services when you choose that sign-in method.
- Authorities or another organisation: only where disclosure is required or otherwise permitted by law.
7. International transfers
Our service providers may process personal data outside the United Kingdom. Where UK data-protection law treats this as a restricted transfer, we use an applicable transfer mechanism, such as an adequacy regulation or approved contractual safeguards, as appropriate to the provider and destination.
8. Retention and deletion
Account data is retained while your account is active and according to our retention schedule. In-app deletion begins immediately and cannot be cancelled. Authentication, profile, memberships, private academic data, uploads and direct identifiers are erased. Posts and comments may remain only after account links and identifying author fields are removed so existing discussions remain coherent.
Contact enquiries are kept only as long as needed to answer the enquiry, maintain necessary support records and resolve disputes. Moderation evidence is kept only as long as operationally or legally necessary. Administrator audit records are kept for no more than 12 months unless an active investigation or legal hold requires longer. Provider-side backup and diagnostic expiry follows the relevant provider retention cycle.
9. Required and optional information
A sign-in email is required to create and protect an account, and supported university verification is required to enter that university community. Optional profile fields, photo uploads, notifications and crash reporting can be declined, although the related optional feature may then be unavailable.
10. Automated processing
NOOK may use automated security signals and content-report thresholds to prevent abuse or temporarily limit visibility. We do not use solely automated decision-making that produces legal or similarly significant effects. Material account and moderation actions are subject to authorised human review.
11. Your rights
Subject to UK data-protection law, you may ask to access, correct, export, restrict or erase personal data, and object to processing based on legitimate interests. Delete your account in My Page > Delete Account or contact support@official-nook.com for another rights request. You may also complain to the Information Commissioner's Office at ico.org.uk.
12. Local storage
The app stores preferences and cached content inside the operating system's app sandbox. Private account-scoped cache is cleared on logout and account deletion; onboarding state and a non-secret abuse-prevention installation identifier remain on the device. No third-party advertising cookies are used.
13. Children's privacy
The service is for people aged 18 or over. Signup requires an explicit 18+ confirmation without collecting a date of birth. If you believe a child is using the service, contact support@official-nook.com so we can assess and take appropriate action.
14. Changes and contact
We may update this Privacy Policy and will notify users of material changes as required. Privacy requests, moderation complaints, illegal-content complaints and appeals can be sent to support@official-nook.com. Include enough information to locate the account or report, but do not send passwords or one-time codes.
Questions, privacy requests and moderation appeals can be sent to support@official-nook.com.