Privacy Policy
Last updated: August 1, 2025
1. Information We Collect
Account & Billing
- Email, password (hashed), name (optional), profile details you add
- Billing data (handled by processors like Stripe/Creem); we store limited tokens/IDs
Content You Provide
- Text, images, audio, book files, metadata, prompts, templates
- Support requests, feedback, attachments
Usage & Device
- IP, device/browser type, events, crash logs, feature usage, approximate location (IP)
- Cookie IDs and similar identifiers (see Cookies & Tracking)
2. How We Use Your Data
- Provide and improve BookCraftly features (editing, exports, credits, publishing helpers)
- Authenticate accounts, prevent abuse/fraud, secure the Service
- Process payments, subscriptions, license entitlements
- Operate AI features (when you trigger them) and deliver outputs to your account
- Offer support, send service notices, product updates, and transactional email
- Run analytics and A/B tests to improve reliability and UX
- Comply with legal obligations and enforce Terms
5. AI Providers & Content Handling
When you invoke AI features, your prompts/content may be sent to third-party AI APIs to generate outputs. Depending on your plan, you might connect your own API keys and pay your provider directly.
- You must follow each provider’s terms and content policies.
- We may switch default models/providers to maintain quality and uptime.
- Review AI outputs before publishing; you are responsible for accuracy and rights clearance.
6. Security
- Encryption in transit and at rest (where applicable)
- Role-based access and least-privilege controls
- Audit logging, monitoring, and incident response
- Vendor risk reviews and data processing agreements
No system is 100% secure, but we take commercially reasonable measures and review controls regularly.
7. Data Retention
- Account & content: kept while you maintain an account (and short backups after deletion)
- Billing & tax records: typically 7 years (or as required by law)
- Analytics/logs: generally 12–24 months
We may retain data longer if legally required (e.g., disputes, fraud, audits).
8. Your Rights & Choices
General
- Access, correct, delete, or export your data (where applicable)
- Object or restrict certain processing
- Manage email preferences (unsubscribe links in non-transactional emails)
GDPR (EU/UK)
Legal bases include consent, contract necessity, legal obligations, and legitimate interests. You may withdraw consent and lodge a complaint with your supervisory authority.
CCPA/CPRA (California)
- Right to know/access, delete, correct, and non-discrimination
- We do not “sell” personal information as defined by CCPA. For cross-context behavioral advertising, you may opt out via cookie settings where available.
9. International Data Transfers
We may process data in countries outside your own. Where required (e.g., EU→US), we use appropriate safeguards such as Standard Contractual Clauses and additional security measures.
10. Children’s Privacy
BookCraftly is not directed to children under 13 (or older minimum as required locally). If you believe a child provided personal data, contact us to remove it.
11. Changes to This Policy
We may update this Policy. Material changes will be announced in-app or via email. Your continued use after an update signifies acceptance.
12. Contact & DPO
Privacy: privacy@bookcraftly.com · DPO: dpo@bookcraftly.com
Support: support@bookcraftly.com • bookcraftly.featurebase.app
Mailing Address: 100ft, Bypass Road, Velachery, Chennai, India