Last updated: June 2026
The Palace Project is an open-source digital library platform operated by Lyrasis, a nonprofit organization, that provides public libraries, schools, and other institutions with access to ebooks and audiobooks through a single app. This document describes the limited patron data that the Palace Project handles and identifies the third-party service providers (subprocessors) that may access or process that data while operating the app.
It is intended to help partner libraries and institutions with their own compliance and recordkeeping. For a complete description of our privacy practices, please refer to our Privacy Policy.
Lyrasis collects only the limited information necessary to enable access to library resources, maintain functionality, and provide technical support. In its standard configuration, the Palace Project does not collect or store patron names, postal addresses, phone numbers, demographic data, educational records, or content created by patrons. The one exception is the optional Virtual Library Card described below.
The primary patron identifier we retain is the value contained in the patron's authentication ID; a patron's account may have more than one identifier associated with it. Depending on how the partner library or institution configures authentication, that value may be a barcode, email address or a student or employee ID. We use this identifier solely to create a patron record so that loans and holds can be associated with the correct account.
This identifier may also appear in diagnostic and error logs and in crash reports that are generated for troubleshooting purposes.
Where a library uses institutional single sign-on, a role or affiliation value supplied by the institution may be forwarded to a content distributor at fulfillment, as described under "Patron identifiers shared with content providers." This value originates from the patron's institution and is used only to fulfill the request.
Some libraries ask Lyrasis to enable an optional Virtual Library Card, which lets a patron register for a library account directly through the app. Where a library has requested this option and a patron chooses to create a virtual card, we collect the patron's name and email address in order to create the account and assign a library barcode.
This option is never enabled by default; it applies only at libraries that have specifically requested it, and patrons who do not opt in are never asked for this information. The name and email are used to administer the patron's account — including sending account-related email such as the assigned library barcode — and are not shared with content distributors.
The following third parties may access or process the limited patron identifiers described above in the course of providing services for the Palace Project. Each is engaged under a written agreement requiring it to protect data consistent with our Privacy Policy and to use it only for the limited purpose of supporting the app.
| Provider | Function | Patron data accessed or processed |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting and infrastructure | Patron records — including the authentication identifier — are stored and processed within our AWS environment. AWS is also used to send transactional email, such as password resets and Virtual Library Card details, so a patron's email address is processed within AWS where one is on file. |
| Google LLC (Firebase Crashlytics) | Crash and error reporting | The patron identifier may appear in diagnostic logs and crash reports used to troubleshoot app issues. |
| Content providers and distributors | Fulfillment of loans and holds | When a patron borrows or places a hold, the app may transmit an identifier to the applicable distributor to fulfill the transaction. For most distributors this is an anonymized identifier; the specifics vary by integration — see "Patron identifiers shared with content providers" below. |
| Adobe / Wipro | Ebook DRM and fulfillment | Receives only an anonymized patron token used to authorize ebook downloads and apply digital rights management (DRM). |
We keep the patron data shared with distributors to a minimum. To fulfill a loan or hold, the app may send an identifier to the relevant distributor. What is shared depends on the integration: