1. Privacy Commitment
At EbookAI Inc. (“EbookAI,” “we,” “us,” or “our”), we recognize that writing a book requires deep trust. Whether you are drafting an executive leadership guide, proprietary coaching methodology, or commercial novel, your words and intellectual property are your most valuable asset.
This Privacy Policy explains what information we collect when you use our website, web application, and publishing tools, how we protect it, who we share it with, and your legal rights under international data protection laws, including the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
2. Information We Collect
We collect information strictly necessary to provide our digital publishing services:
A. Account Information
When you register, we collect your email address and optional display name. If you register via Google OAuth, we receive your verified email address and basic profile avatar from Google. Password hashes are securely managed via InsForge Authentication with bcrypt/Argon2 hashing; we never store plain-text passwords.
B. User Authoring Content
To draft and format your books, we collect and store the manuscript data you provide: topic inputs, raw bullet notes, audio transcripts, target reader demographics, outline structures, chapter drafts, custom cover typography, and export preferences.
C. Billing & Payment Data
All credit and subscription payments are processed by PCI-DSS compliant third-party payment facilitators (Creem.io and Stripe). EbookAI never stores or has access to your full credit card numbers, CVVs, or bank account details. We retain only transaction IDs, billing contact emails, and credit balance records.
D. Technical & Telemetry Data
When you interact with our editor, we automatically record technical log data, including IP address (for rate limiting and defense against brute force attacks), browser user agent, operating system, and anonymous feature usage analytics via PostHog.
3. Zero-Training AI Policy
Non-Negotiable
We do not train AI models on your work.
A major concern for authors and publishers is whether their unpublished drafts will be absorbed into large language models. Under our API terms and data processing agreements with our AI inference providers (DeepSeek):
- Zero Training: Prompts, notes, chapter drafts, and outlines transmitted to the inference API are never used to train, retrain, or improve foundational AI models.
- Zero Public Exposure: Your manuscripts are not indexed by public web search engines or accessible by other users of the platform.
- Ephemeral Inference: Text generation occurs via encrypted, stateless API requests that discard context tokens immediately upon generation stream completion.
4. How We Use Information
We process your data exclusively for the following operational purposes:
- Providing and maintaining your book projects, chapters, and bookshelf library.
- Executing architectural reasoning outlines and streaming chapter drafts to your browser.
- Compiling validated ePub 3.2 binary packages and 6x9” print-ready PDFs.
- Calculating spine widths and generating 3D realistic marketing mockups.
- Managing your available credit ledger and processing top-up transactions.
- Providing responsive customer, billing, and technical support.
- Detecting and mitigating malicious traffic, brute-force attacks, and service abuse.
5. Security & Data Isolation
We implement defense-in-depth architectural safeguards to protect your manuscripts:
- PostgreSQL Row-Level Security (RLS): Every database query in our InsForge backend is strictly governed by cryptographic user tenancy checks (
auth.uid() = user_id). No user can query, inspect, or modify another user's books, chapters, or files. - Encryption in Transit: 100% of web application traffic is encrypted with Transport Layer Security (TLS 1.3) with HTTP Strict Transport Security (HSTS) preloading.
- Encryption at Rest: All database volumes and S3 storage buckets storing your covers, exports, and mockups are encrypted with enterprise AES-256 encryption.
6. Third-Party Subprocessors
We partner with trusted infrastructure and cloud providers to operate the Service. Each subprocessor is bound by strict Data Processing Addendums (DPAs):
| Subprocessor | Service Purpose | Location |
|---|
| InsForge BaaS | PostgreSQL database, user authentication, S3 object storage | United States |
| DeepSeek | AI architectural reasoning & chapter drafting (Zero-training API) | Global / Secure Cloud |
| Stripe / Creem.io | Payment facilitation and subscription billing (PCI-DSS Level 1) | United States / EU |
| PostHog | Anonymous error tracking & UI telemetry | United States / EU |
7. Data Retention & One-Click Deletion
We retain your book data for as long as your account remains active. Because you own your data, you have total control over its lifecycle:
- Single Book Deletion: Deleting a book from your Library triggers an immediate cascading deletion that removes all associated chapter records, marketing kits, and S3 assets (covers, PDFs, ePubs).
- Complete Account Deletion: Initiating account deletion from your Profile page permanently erases your profile, authentication records, and all bookshelf assets across all storage clusters within 48 hours.
8. Your Rights (GDPR & CCPA)
Depending on your location, you hold statutory data rights regarding your personal information:
- Right to Access: Request a complete copy of the personal data we hold about you.
- Right to Rectification: Update inaccurate or incomplete profile information.
- Right to Erasure (“Right to Be Forgotten”): Request permanent deletion of all your records.
- Right to Data Portability: Export your books as standard ePub 3 and PDF files at any time.
- Right to Opt-Out: Opt out of non-essential analytics tracking.
To exercise any of these rights, please email our Data Protection Officer at privacy@ebookai.com.
9. Cookies & Tracking Technologies
We use only essential cookies required for session authentication, security verification, and CSRF protection. We do not utilize third-party advertising cookies or cross-site tracking pixels.
10. Privacy Officer Contact
If you have any questions, concerns, or data privacy requests regarding this Privacy Policy, please contact our Data Protection Officer directly:
EbookAI Inc. — Data Protection Office