Back to home

Privacy Policy

Last updated: August 31, 2026

1. We take your privacy seriously

We take your privacy seriously. This page explains exactly what data we collect, why, how we protect it, and what rights you have.

2. What data we collect

2.1 What data we collect

  • Account information: email, name (if provided), hashed password
  • Authentication data: when you sign in with Google, we receive your name, email, and profile photo from Google
  • Payment information: billing details handled by Stripe. We never see your full card number.
  • User content: books you upload (PDF, EPUB, TXT), conversations, highlights, bookmarks, and glossary entries
  • Support communications: messages you send us when contacting support

2.2 Usage data: pages visited, features used, timestamps, click patterns

  • Device & browser: IP address, browser type, operating system, device type
  • Usage data: pages visited, features used, timestamps, click patterns
  • Cookies and similar: see our Cookie Policy Cookie Policy
  • Error logs: crash reports and error messages for debugging

2.3 Embeddings: we generate mathematical representations of your book content to enable search and AI features. Embeddings are stored encrypted and never shared.

  • Embeddings: we generate mathematical representations of your book content to enable search and AI features. Embeddings are stored encrypted and never shared.

3. How we use your data

  • <strong>Provide the Service:</strong> Process your books, generate AI responses, store your progress and notes
  • <strong>Improve the Service:</strong> Analyze usage patterns, fix bugs, develop new features
  • <strong>Process payments:</strong> Via Stripe; we do not store your full payment details
  • <strong>Communicate with you:</strong> Service updates, security alerts, support responses (you can opt out of marketing)
  • <strong>Enforce our Terms:</strong> Detect abuse, fraud, and violations
  • <strong>Comply with law:</strong> Respond to legal requests when required

4. Legal basis (EEA / UK)

If you are in the European Economic Area (EEA) or the United Kingdom, our legal bases for processing are:

  • Contract: To provide the Service you signed up for
  • Legitimate interests: To improve the Service, prevent abuse, secure our systems
  • Consent: For marketing emails, optional features
  • Legal obligation: To comply with applicable laws

5. Who we share data with

  • Service providers: Service providers: Supabase (hosting, database, auth), Stripe (payments), OpenRouter / AI providers, Microsoft / Edge TTS. Each is bound by a Data Processing Agreement.
  • Legal requests: Legal requests: we may disclose data if required by valid legal process. We'll notify you when permitted.
  • Business transfers: Business transfers: if we're acquired or merge, your data may transfer to the new entity under this same policy.
  • International data transfers: By using the Service, you consent to the transfer of your information outside your country.

6. How long we keep your data

We keep your data as long as needed to provide the Service. After you delete your account, data is removed within 30 days, except where we must keep it longer (e.g. for accounting obligations).

7. Your rights

  • Access: Access: you can download all your data anytime from your account
  • Rectification: Rectification: correct inaccurate personal data
  • Erasure: Erasure: delete your account and all associated data
  • Restriction: Restriction: pause processing of your data while we resolve a complaint
  • Portability: Portability: receive your data in a machine-readable format
  • Objection: Objection: object to processing based on legitimate interests
  • Withdraw consent: Withdraw consent: at any time, for any consent-based processing
  • Complaint: Complaint: lodge a complaint with your local data protection authority

8. Security

We apply encryption in transit (TLS) and at rest (AES-256), strict access control, and regular security audits. No system is perfect — if a data breach occurs, we will notify you in accordance with applicable law.

9. Children's privacy

The Service is not intended for children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us with data, contact us to remove it.

10. Changes to this policy

We may update this policy. We will notify you by email at least 30 days before any material changes.

11. Contact

Questions about this policy? Email privacy@talk-to-the-book.app.