Crux Monographic History

Privacy Notice

Version 1.0
Last Updated: 3 August 2026


In short

CRUX is a history reading app run by one person. We hold as little about you as we can get away with: an account identifier, your email address, and a record of what you have read so the app can show you your bookmarks, keep your place in an article, and suggest what to read next.

We do not sell your data. We do not advertise. We do not share your reading with anyone. You can delete everything we hold, from inside the app, at any time.

The rest of this page explains that properly.


Who we are

CRUX Monographic History is operated by Robert O'Sullivan, trading as CRUX Monographic History. Under UK data protection law we are the "data controller" for the information described here, which means we are the ones responsible for it.

You can contact us about anything on this page at feedback@cruxhistory.com.

We are registered with the Information Commissioner's Office (the UK's data protection regulator) under registration reference ZC207133.


You can read CRUX without an account

You do not need to sign in to read CRUX. You can open the app and read without giving us anything at all.

Signing in is required only if you want to keep reading beyond your first article, or if you want to bookmark something. If you never sign in, we hold no personal information about you whatsoever.


What we collect, and why

If you sign in

CRUX uses Sign in with Google and Sign in with Apple. There is no password to create and no registration form to fill in. When you sign in, we receive two things:

An account identifier. A long string of characters that identifies your account to our systems. It is not your name and it means nothing outside CRUX.

Your email address. We ask Google and Apple for your email address and nothing else. We deliberately do not request your name or your profile photo, because nothing in CRUX displays either.

We use your email address for one purpose: identifying your subscription if something goes wrong with it. If you contact Apple, Google or us about a billing problem, your email address is how your purchase gets matched back to your account. We do not send you marketing. We do not add you to a mailing list.

Your email address is stored in the authentication system and is not copied anywhere else in our database.

If you sign in with Google, your email address refreshes automatically each time you sign in, so it stays current. If you sign in with Apple, it is captured once when you first sign in.

What you read

To make the app work, CRUX records:

This is what lets the app show you your bookmarks, put you back where you left off, and tell us in aggregate which articles people are actually reading. It is how we decide what to write next.

We want to be straightforward about this rather than pretend it does not happen. It is a record of your reading, attached to your account.

Suggested reading

CRUX also uses your reading history to suggest articles and collections you might want to read next. If you have been reading about the Napoleonic Wars, the app will put related pieces in front of you rather than a random selection.

That means CRUX does form a picture of what interests you, within the app. We would rather say so plainly than describe it as something else.

Two things are worth knowing about how this works:

If you would rather not see personalised suggestions, email us at feedback@cruxhistory.com and we will switch them off for your account. You will get general recommendations instead, and nothing else about the app will change.

What we do not do with any of it

We do not use your reading to target you with advertising, we do not share it with anyone, and we do not sell it. It is deleted in full when you delete your account.

If you subscribe

CRUX offers a paid subscription. All payments are handled entirely by Apple and Google through their own payment systems.

We never see your card details, your billing address, or any payment credentials. Those go to Apple or Google, not to us. We could not access them if we wanted to.

We use a service called RevenueCat to tell us whether your subscription is active. It reads the purchase receipt from Apple or Google and reports back a yes or a no. No money passes through it, and it receives your account identifier so it knows which subscription belongs to which account.

If the app crashes

We use a service called Sentry to tell us when the app crashes, so we can fix it. A crash report contains technical information about what the app was doing when it failed — the screen, the error, the line of code.

Crash reports include your account identifier, so that we can see when the same person is hitting the same fault repeatedly. Your email address is removed before the report is sent.


What we do not collect

To be explicit, CRUX does not collect or hold:

We do not use advertising networks, we do not track you across other apps or websites, and we have no analytics vendor watching your behaviour on our behalf.


Our legal basis for holding this

UK data protection law requires us to have a specific reason for processing your information. Ours are:

Performance of a contract. We need your account identifier and your subscription status in order to give you the service you have signed up for. Without them, we cannot let you into the app or know whether you have paid.

Legitimate interests. Crash reports and reading records are held because we have a genuine interest in the app working properly, in knowing which articles are worth writing, and in recommending things you are likely to want to read.

We have weighed this against your own interests. The reading data stays inside CRUX, is never combined with anything from elsewhere, and is used only to recommend articles — not to advertise to you, price differently for you, or restrict what you can see. We think a reader would expect a reading app to remember what they have read and suggest more of it. If you disagree, you can object, and we will turn the suggestions off for your account.

Legal obligation. We keep certain records where the law requires it, for example for tax purposes.


Who else touches your data

We are one person, so CRUX relies on a small number of established service providers. Each one is bound by a contract that permits them to use your data only to provide their service to us, and never for their own purposes.

Provider What they do What they hold
Supabase Our database, sign-in system and file storage Account identifier, email address, bookmarks, reading progress
Sentry Crash reporting Account identifier and technical crash data. Email removed
RevenueCat Subscription status Account identifier and subscription state
Apple Sign in with Apple, and all payments on iOS Governed by Apple's own privacy policy
Google Sign in with Google, and all payments on Android Governed by Google's own privacy policy
Expo Builds and delivers app updates No personal data
GitHub Hosts the CRUX website No personal data

Our Supabase database and our Sentry account are both hosted in the European Union. Where data is transferred outside the UK, it is protected by the safeguards required under UK data protection law, such as standard contractual clauses.

We will never sell your data. We will never share it with advertisers or data brokers. The only circumstance in which we would disclose your information to anyone else is if we were legally required to.


How long we keep it

We keep your information for as long as your account exists.

There is no fixed expiry date and we will not quietly delete an inactive account — if you come back to CRUX in three years, your bookmarks will still be there.

Your data is removed in two circumstances:

You delete your account. Everything goes, immediately. See below.

CRUX shuts down. If the app is permanently withdrawn, we will give at least 60 days' notice and then delete all user data. Nothing is retained, sold, or transferred to anyone else.


Deleting your account

You can delete your account from inside the app, under Profile. You do not need to email us or ask permission.

When you do, the following happens automatically:

  1. Any active subscription is detached, so you are not billed again
  2. Your bookmarks, reading progress and reading records are deleted from our database
  3. Any files associated with your account are removed from storage
  4. Your account record, including your email address, is erased from the authentication system
  5. You are signed out

This is permanent and cannot be undone. If you sign in again afterwards, you get a brand new account with nothing in it.

One thing we cannot delete for you: if you have an active subscription, you must also cancel it through your Apple or Google account settings, because that is where the billing relationship sits. Deleting your CRUX account stops us from providing the service, but only Apple or Google can stop the payment. There are instructions in the app.


Your rights

Under UK data protection law you have the right to:

To exercise any of these, email feedback@cruxhistory.com. We will respond within one month. There is no charge.

If you are unhappy with how we have handled your information, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first so we can put it right, but you are not obliged to.


Children

CRUX is not intended for children under 13, and you should not create an account if you are under 13.

The app contains serious historical subject matter, some of which covers war, violence and other difficult material. It is written for adults and older readers.

If we become aware that we hold data belonging to a child under 13, we will delete it.


The CRUX website

The CRUX website exists to tell you about the app and to host this policy and our Terms of Service.

It uses no tracking cookies, no advertising, and no analytics. We do not know who visits it.


Security

Access to our database is controlled at the database level, so that your bookmarks and reading progress are visible only to your own account. Credentials are held in secure storage rather than written into the app.

No system is perfectly secure, and it would be dishonest to claim otherwise. If a breach occurred that put your information at risk, we would report it to the Information Commissioner's Office within 72 hours of discovering it, and we would tell you directly if there were a serious risk to you.


Changes to this policy

If we change how we handle your data, we will update this page and change the date at the top. If the change is significant, we will tell you in the app rather than expecting you to notice.


Contact

feedback@cruxhistory.com

Robert O'Sullivan, trading as CRUX Monographic History ICO registration: ZC207133