TTaste Shelf
PrivacyTermsSign in

Privacy

Your shelf should stay yours.

This policy explains what Taste Shelf stores, why it is needed, how WebMCP shares data with an AI you choose, and the controls available to you.

Effective and last updated September 3, 2026

1. Scope

This Privacy Policy applies to the hosted Taste Shelf application and its account, shelf, recommendation, activity, and WebMCP features. A separately operated fork of the open-source code is controlled by its own operator and should publish its own policy.

2. Information Taste Shelf stores

Account and authentication data

When you sign in with a connected provider, Taste Shelf stores the name, email address, email-verification state, profile image, provider account identifier, and account timestamps needed to create and secure your account. OAuth tokens are encrypted at rest. Existing legacy password accounts store a salted password hash, never the password in readable form.

Essential session and security records may include a session token, expiry, IP address, user-agent string, and rate-limit counters. Taste Shelf does not currently use advertising or analytics cookies.

Your shelf content

Taste Shelf stores the memories and settings you choose to save. This can include titles, categories, status, ratings, progress, summaries, reactions, notes, cover images or public cover URLs, taste-preference proposals, accepted preferences, memory canvases, Tonight shortlists, recommendation contexts and outcomes, tags, saved views, collections, structured progress and diary entries, theory and memory-patch proposals, catalog identifiers, import history, AI access choices, display settings, and timestamps.

Operational records

Activity, idempotency, revision, storage-usage, and quota records are stored to make changes traceable, prevent duplicate writes, protect newer edits, support Undo where available, and keep the hosted service within its operating limits. A recoverable delete-all action also creates a temporary snapshot as described below.

3. How the information is used

  • Authenticate you and keep each shelf separated by account.
  • Display, sync, export, update, and delete the state you request.
  • Return evidence-backed shelf context to WebMCP tools you choose to use.
  • Prevent abuse, duplicate writes, stale overwrites, and unsafe access.
  • Operate rate limits, recovery, and essential diagnostics.

Taste Shelf does not sell or rent personal information and does not use shelf content for targeted advertising.

4. WebMCP and the AI you choose

Taste Shelf does not run a hidden assistant or send your shelf to an AI model in the background. In a compatible browser, WebMCP exposes a focused set of tools only after your authenticated shelf has loaded. Your chosen AI can receive a tool result when you ask it to use those tools. The AI provider processes that request and result under its own terms and privacy policy.

Tool responses are limited by purpose. Private uploaded image data is excluded from agent context. Global and per-memory controls determine whether notes, progress, canvases, and a memory itself may be shared. Canvas and theory reads are filtered to your saved progress and fail closed when that boundary is unknown. Notes are returned only when a tool explicitly requests them and your sharing setting permits it. An AI may propose a taste preference, memory patch, or theory but cannot accept it for you.

A compact receipt records which kinds and counts of data were shared with a tool without retaining the private response body. Read receipts remain only in the current browser tab and are cleared when that tab closes. Mutation records remain in Activity so you can inspect the change and use Undo when it is still safe.

Do not ask an AI provider to process shelf content you do not want that provider to receive. You can keep using the manual Taste Shelf interface in a browser that does not expose WebMCP.

5. Service providers and disclosures

Cloudflare hosts the application, Worker, and D1 database and may process network and operational data needed to provide and secure the service. A connected identity provider such as Google processes sign-in data. A compatible AI provider processes WebMCP requests only when you use that provider with Taste Shelf.

Information may also be disclosed when reasonably necessary to comply with law, protect users, investigate abuse, or defend the service. These providers may process data in countries where they operate.

6. Retention, export, and deletion

Shelf content is retained while your account is active unless you delete it. Settings lets you export your owned shelf data, including the Library Desk workspace. Import files are read for preview in your browser; confirmed rows and their bounded import record are stored in your account. An unchanged import batch can be rolled back from the Library Desk. Removing all shelf data creates one recovery snapshot for seven days; restoring it is available from Activity during that window. A later delete-all replaces the earlier recovery snapshot.

Deleting your account permanently removes the active Taste Shelf account, shelf content, recovery snapshot, sign-in connections, and sessions. It does not delete your account with Google or another provider. Limited copies can remain temporarily in provider backups or security logs until their normal expiration.

7. Security and your choices

Taste Shelf uses server-validated sessions, per-account database scoping, encrypted OAuth tokens, hashed legacy passwords, origin and input checks, rate limits, and secure cookies on HTTPS deployments. No online service can guarantee absolute security.

You can inspect and change shelf data in the application, export it, remove all shelf data, disconnect supported sign-in providers, or delete the account. Depending on where you live, you may also have legal rights to access, correct, delete, or restrict processing of personal information.

8. Children

Taste Shelf is not directed to children under 13. If local law requires a higher minimum age to use an online service without parental consent, that higher age applies.

9. Changes and contact

Material changes will be reflected by updating the date at the top of this page. For a privacy question or request, contact the project owner through the public repository or the Devpost project page linked to this deployment. You can also delete your data directly from Settings.

See the Terms of Service for the conditions that apply when using Taste Shelf.

Taste Shelf · Human-curated memory for personal AI.

Back to home