Skip to content

Legal

Privacy policy

What we collect, why, who else touches it, and how to get it back or have it erased.

Version 1.0 · Last updated January 2026

!
Complete before launch
This document describes how the BookPilot AI software actually handles data, and it is written to be usable — but the highlighted fields must be filled in with the operating company's real details, and the whole document reviewed by a qualified adviser, before the service is offered to the public. BookPilot AI does not provide legal advice.

1. Who is responsible for your data

The controller of the personal data described here is [legal entity name], [registered address], reachable at [privacy contact email]. Where a data protection officer is appointed, their contact details are [DPO contact, or "not appointed"].

Two different relationships matter in this product, and they should not be confused:

2. What we collect, and why

DataWhyLawful basis (GDPR Art. 6)
Name, email, country, currency, languageTo run your account and show prices in your currencyContract, Art. 6(1)(b)
Book details you enter: title, description, genre, price, sales link, cover, optional sample text, bio and reviewsTo analyse your book and generate your marketing material — this is the serviceContract, Art. 6(1)(b)
Generated output: analysis, personas, angles, creatives, scoresTo give you the product you asked for and let you return to itContract, Art. 6(1)(b)
Campaign and performance data imported from your connected ad accountTo show you what your advertising didContract, Art. 6(1)(b)
Website tracking events from a site you own (event type, order value, UTM parameters, a session key)To attribute sales to the ad that caused themYour instruction as controller; we act as processor
Billing dataTo take payment and meet accounting obligationsContract and legal obligation, Art. 6(1)(b) and (c)
Security and audit logs (who did what, when — identifiers and outcomes, not content)To detect abuse and investigate incidentsLegitimate interests, Art. 6(1)(f)
Product analyticsTo see which features are usedConsent, Art. 6(1)(a) — off unless you switch it on
Product emailsTo tell you about new featuresConsent, Art. 6(1)(a) — off unless you switch it on

We do not ask for, and the product has no field for, special category data under Art. 9. Reader personas are built from interests and life stage only; the AI is instructed never to build targeting or messaging on health, religion, ethnicity, sexual orientation, political affiliation or trade union membership.

3. What we do not collect

4. AI processing

Your book details are sent to Anthropic to generate your analysis, personas, angles and creatives. That provider processes the text to return a result and, under the API terms applicable to this use, does not use it to train models. The details of that arrangement, including the processing location and the transfer mechanism, are at trust.anthropic.com.

No automated decision produces a legal or similarly significant effect on you within the meaning of Art. 22. Creative scores are advisory: you decide what to run.

5. Who else processes your data

Our sub-processors:

ProcessorPurposeLocation
NetlifyHosting and serverless functionsUnited States (AWS us-east-2)
SupabaseDatabase and authenticationEuropean Union
AnthropicText generationUnited States
StripeSubscription billingUnited States

Where a processor is outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses, together with the EU–US Data Privacy Framework where the provider is certified under it. Connecting your Meta ad account sends data to Meta under your own relationship with them, not ours.

6. How long we keep things

7. Your rights

Under the GDPR you can ask for access, rectification, erasure, restriction, portability, and you can object to processing based on legitimate interests. Where processing rests on consent, you can withdraw it at any time without affecting what happened before.

Two of these are buttons rather than requests. In Settings → Your data you can export everything we hold about you as a JSON file, and delete your account permanently. Analytics and marketing consent are toggles in the same place, and every change is recorded with a timestamp. For anything else, write to [privacy contact email] — we answer within one month.

You can also complain to a supervisory authority, normally the one where you live or work.

8. Security

Access to your data is enforced in the database itself through row-level security, so a request can only ever return rows belonging to the account that made it. API keys and OAuth tokens are held server-side and are never sent to a browser. Ad-platform tokens are stored in a table that client applications have no access to at all. Transport is TLS throughout. We do not store your Meta or Amazon password, because we never ask for it — connections use OAuth.

9. Children

BookPilot AI is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 16.

10. Changes

We'll post any change here and, for anything material, tell you in the app before it takes effect. The version and date at the top always reflect the current text.