Legal
Privacy policy
What we collect, why, who else touches it, and how to get it back or have it erased.
Version 1.0 · Last updated January 2026
1. Who is responsible for your data
The controller of the personal data described here is [legal entity name], [registered address], reachable at [privacy contact email]. Where a data protection officer is appointed, their contact details are [DPO contact, or "not appointed"].
Two different relationships matter in this product, and they should not be confused:
- You, the author, are our customer. For your account data, we are the controller.
- Your readers are your visitors. If you install the BookPilot tracking script on your own website, you are the controller of the data it collects there, and we act as your processor. Your own privacy notice needs to cover it.
2. What we collect, and why
| Data | Why | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Name, email, country, currency, language | To run your account and show prices in your currency | Contract, Art. 6(1)(b) |
| Book details you enter: title, description, genre, price, sales link, cover, optional sample text, bio and reviews | To analyse your book and generate your marketing material — this is the service | Contract, Art. 6(1)(b) |
| Generated output: analysis, personas, angles, creatives, scores | To give you the product you asked for and let you return to it | Contract, Art. 6(1)(b) |
| Campaign and performance data imported from your connected ad account | To show you what your advertising did | Contract, Art. 6(1)(b) |
| Website tracking events from a site you own (event type, order value, UTM parameters, a session key) | To attribute sales to the ad that caused them | Your instruction as controller; we act as processor |
| Billing data | To take payment and meet accounting obligations | Contract and legal obligation, Art. 6(1)(b) and (c) |
| Security and audit logs (who did what, when — identifiers and outcomes, not content) | To detect abuse and investigate incidents | Legitimate interests, Art. 6(1)(f) |
| Product analytics | To see which features are used | Consent, Art. 6(1)(a) — off unless you switch it on |
| Product emails | To tell you about new features | Consent, Art. 6(1)(a) — off unless you switch it on |
We do not ask for, and the product has no field for, special category data under Art. 9. Reader personas are built from interests and life stage only; the AI is instructed never to build targeting or messaging on health, religion, ethnicity, sexual orientation, political affiliation or trade union membership.
3. What we do not collect
- The tracking script sets no cookies and stores no device or advertising identifier.
- It does not record your visitors' IP addresses, user agents, referrers or page content.
- We do not buy data about you, and we do not sell or rent anything about you.
- Your manuscript text is never used to train any AI model, ours or anyone else's.
4. AI processing
Your book details are sent to Anthropic to generate your analysis, personas, angles and creatives. That provider processes the text to return a result and, under the API terms applicable to this use, does not use it to train models. The details of that arrangement, including the processing location and the transfer mechanism, are at trust.anthropic.com.
No automated decision produces a legal or similarly significant effect on you within the meaning of Art. 22. Creative scores are advisory: you decide what to run.
5. Who else processes your data
Our sub-processors:
| Processor | Purpose | Location |
|---|---|---|
| Netlify | Hosting and serverless functions | United States (AWS us-east-2) |
| Supabase | Database and authentication | European Union |
| Anthropic | Text generation | United States |
| Stripe | Subscription billing | United States |
Where a processor is outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses, together with the EU–US Data Privacy Framework where the provider is certified under it. Connecting your Meta ad account sends data to Meta under your own relationship with them, not ours.
6. How long we keep things
- Account and book data: for as long as your account exists.
- After you delete your account: erased immediately, other than backups, which roll off within 30 days.
- Tracking events and performance data: 25 months.
- Billing records: as long as tax law requires, typically 10 years.
- Audit logs: 12 months.
7. Your rights
Under the GDPR you can ask for access, rectification, erasure, restriction, portability, and you can object to processing based on legitimate interests. Where processing rests on consent, you can withdraw it at any time without affecting what happened before.
Two of these are buttons rather than requests. In Settings → Your data you can export everything we hold about you as a JSON file, and delete your account permanently. Analytics and marketing consent are toggles in the same place, and every change is recorded with a timestamp. For anything else, write to [privacy contact email] — we answer within one month.
You can also complain to a supervisory authority, normally the one where you live or work.
8. Security
Access to your data is enforced in the database itself through row-level security, so a request can only ever return rows belonging to the account that made it. API keys and OAuth tokens are held server-side and are never sent to a browser. Ad-platform tokens are stored in a table that client applications have no access to at all. Transport is TLS throughout. We do not store your Meta or Amazon password, because we never ask for it — connections use OAuth.
9. Children
BookPilot AI is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 16.
10. Changes
We'll post any change here and, for anything material, tell you in the app before it takes effect. The version and date at the top always reflect the current text.