Privacy Policy
Last updated: August 30, 2026
Effective date: August 30, 2026
1. Introduction
- This Privacy Policy describes how BookBlurb ("we", "us", "our", the "Service") collects, uses, retains, discloses, and protects your personal information when you visit bookblurb.org (the "Site") or use our AI-powered book-description generation tools (the "Service").
- For the purposes of the EU General Data Protection Regulation (GDPR), the UK GDPR, and equivalent data-protection laws, BookBlurb is the data controller for the personal data described in this Policy [GDPR Art. 4(7)]. We determine the purposes and means of processing your personal data, except where we act as a processor on behalf of a third-party controller (for example, payment data processed by our Merchant of Record — see §4.2).
- By using the Service, you confirm that you have read and understood this Policy. If you do not agree with any part of it, please discontinue use of the Service and contact privacy@bookblurb.org with any questions.
2. Information We Collect
- We collect personal data in three ways: (a) data you give us directly, (b) data collected automatically when you use the Service, and (c) data shared with us by third-party processors acting under our instructions.
2.1 Data you provide directly
- Account information — email address, display name (and, if you sign in with Google, your Google account id and profile picture URL).
- Authentication method — either Google OAuth or email magic link. We do not store passwords.
- Inputs — book title, genre, summary, length, age-range, optional comp-title hints, query-letter drafts, and any other text you submit to the generator.
- Generated outputs — blurbs, query letters, and AI-likeness scores we create for you.
- Feedback — any feedback you submit via the in-product feedback tool or the optional 14-day follow-up email.
2.2 Data collected automatically
- Edge logs — IP address (truncated where feasible), user agent, approximate country (from IP), request path, response status, and access timestamps (Cloudflare).
- Anonymous-run hashes — a one-way hash of the input you submit when you run a generation without logging in. This allows us to rate-limit and detect abuse without storing the raw input indefinitely.
- Session cookies — see our Cookie Policy for the full list.
2.3 Data shared with us by third parties
- Google LLC (if you sign in with Google): email address, Google account id, display name, profile picture URL — limited to the OAuth scopes we request (see §4.3).
- Payment processor — Creem (Armitage Labs OÜ, Estonia — Merchant of Record): order id, amount, currency, status, subscription state, last-4 card digits / card brand, refund history. We do not receive your full card number.
- LLM provider (US-based; opt-out from training confirmed): only the prompt content required to generate your output and the model response. See §4.4.
3. How We Use Your Information
Purpose Lawful basis (GDPR Art. 6) Provide and operate the Service (auth, generation, polish, score, export, history) Contract performance — Art. 6(1)(b) Process payments, issue invoices, handle refunds Contract + Legal obligation — Art. 6(1)(b) + (c) Send transactional emails (receipts, security alerts, refund confirmations) Contract + Legitimate interests — Art. 6(1)(b) + (f) Optional 14-day follow-up email ("How is the book performing?") Consent — Art. 6(1)(a); you can opt out at any time Detect abuse, prevent fraud, enforce rate limits Legitimate interests — Art. 6(1)(f) Aggregate, anonymised analytics (page paths only at launch) Legitimate interests — Art. 6(1)(f) Comply with legal requests from authorities Legal obligation — Art. 6(1)(c) - We do not use your inputs or generated outputs to train any AI model.
4. Third-Party Services — Detailed Disclosures
- We share personal data only with vetted sub-processors acting on our documented instructions [GDPR Art. 28]. A current, machine-readable sub-processor list is published on our Sub-processors page; we will notify you at least 30 days before adding any new sub-processor.
4.1 Cloudflare, Inc. (Hosting / Edge / Security)
- Purpose: Serve the Site, run API requests, edge compute (Cloudflare Workers), host our data layer (D1), protect against abuse.
- Identity: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.
- Privacy policy: https://www.cloudflare.com/privacypolicy/
- Data Processing Addendum: https://www.cloudflare.com/cloudflare-customer-dpa/ (Version 6.4, effective April 3, 2026; automatically incorporated into the Self-Serve Subscription Agreement).
- Sub-processors list: https://www.cloudflare.com/gdpr/subprocessors/
4.2 Creem — Armitage Labs OÜ, Estonia (Merchant of Record)
- Identity: Armitage Labs OÜ, registry code 16977866, Rotermanni 14, Tallinn 10111, Estonia.
- Role: Creem is the merchant of record. Creem is the legal seller of your purchase and independently handles billing data, VAT/sales tax, invoicing, and chargeback defence.
- Buyer data Creem collects: name, email address, billing address, payment details, order details, device ID, IP address, account number.
- We (BookBlurb) receive from Creem: transaction ids, product ids, subscription state, payout amounts, last-4 card digits and card brand. We do not receive your full card number.
- Creem Privacy Notice: https://www.creem.io/privacy
- Creem Merchant Terms: https://www.creem.io/terms
- Creem support: support@creem.io
4.3 Sign in with Google (Authentication)
- Purpose: Verify your identity so we can confirm you are a registered user of the Service. We use Sign in with Google only as a login credential — we do not store, analyse, or use Google user data for any other purpose [Google API Services User Data Policy — Limited Use Requirements].
- Provider: Google LLC.
- OAuth 2.0 Scopes used: only openid, email, and profile — the minimum required to identify a registered user. We do not request sensitive or restricted scopes.
- Compliance: Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use Requirements.
- Data we do NOT use Google for: advertising, marketing, user profiling, training of any model, syncing with other Google services, or sharing with any third party.
- Google Privacy Policy: https://policies.google.com/privacy
- User revocation: You can revoke our access to your Google account data at any time via https://myaccount.google.com/permissions.
4.4 LLM Provider (Generation)
- Purpose: Generate book blurbs, query letters, and children's-book blurbs at your request.
- Provider: Our US-based large-language-model provider. The provider is configured with opt-out from training on customer data per its data-processing terms.
- Data sent: only the prompt content required to fulfil your request and the model response.
- Data retention at provider: per the provider's standard API retention policy (typically ≤ 30 days for abuse monitoring; not used for training).
- Compliance: The provider acts as a sub-processor under a Data Processing Agreement that incorporates Standard Contractual clauses for cross-border transfer.
4.5 Resend (Transactional Email)
- Purpose: Send transactional emails (account notifications, receipts, refund confirmations, optional 14-day follow-up).
- Provider: Resend, Inc. (US).
- Privacy policy: https://resend.com/legal/privacy
5. Cookies and Tracking
- Strictly necessary (no consent required under ePrivacy Directive):
- — Session JWT (authentication); CSRF token (security); cookie-consent state (12 months); Cloudflare edge cookies __cf_bm and cf_clearance (bot detection and abuse prevention).
- Analytics (consent required; default OFF in EU/UK): if and when enabled, page-path-only analytics via a privacy-respecting provider.
- No marketing, advertising, or session-replay cookies at launch.
- See our Cookie Policy for the full cookie list and consent-management details.
6. International Data Transfers
- BookBlurb is operated from outside the European Economic Area. Some of our sub-processors are based in the United States. Where we transfer your personal data outside the EEA / UK / Switzerland, we rely on the following safeguards [GDPR Chapter V, Art. 46]:
- — Standard Contractual clauses (SCCs) adopted by the European Commission (Module 1: Controller-to-Controller; Module 2: Controller-to-Processor) — for transfers to Cloudflare, Google, our LLM provider, and Resend.
- — UK International Data Transfer Addendum — for transfers from the UK.
- — EU-US Data Privacy Framework — for transfers to US recipients that have certified under the DPF (where applicable).
- You may request a copy of the relevant safeguards by emailing privacy@bookblurb.org.
7. Data Retention
Category Retention Account data (email, google_id, profile) Account lifetime; deleted 30 days after account-erasure request (grace period for restoration) Inputs and generated outputs (anonymous runs) 30 days for abuse review, then irreversibly hashed or deleted Inputs and generated outputs (registered users) 1 year (per Author-tier promise); deletable on demand Payment records, invoices, refunds 7 years (tax / accounting) Webhook event payloads 24 months Email events 24 months, or until you unsubscribe (whichever is sooner) Edge / access logs 30 days - When the retention period expires we delete or irreversibly anonymise the data.
8. Your Rights
8.1 All users (regardless of jurisdiction)
- Access — request a copy of the personal data we hold about you.
- Correction — update inaccurate data via account settings or by emailing us.
- Deletion — delete your account and associated data (GDPR Art. 17 / CCPA).
- Export — download your generation history as JSON (GDPR Art. 20).
8.2 EEA / UK / Swiss users (GDPR / UK GDPR)
- In addition to the rights above:
- — Right to restrict processing (Art. 18).
- — Right to object to processing (Art. 21), including objection to processing based on legitimate interests.
- — Right to data portability (Art. 20).
- — Right to withdraw consent at any time, where processing is based on consent (Art. 7(3)).
- — Right to lodge a complaint with your local data-protection supervisory authority (Art. 77).
8.3 California users (CCPA / CPRA)
- Right to know what personal information is collected, used, shared, or sold.
- Right to delete personal information.
- Right to opt out of sale or sharing — we do not sell your data.
- Right to limit use of sensitive personal information — not applicable; we do not collect sensitive PI.
8.4 How to exercise your rights
- Email privacy@bookblurb.org. We respond within:
- — GDPR Art. 12(3) — without undue delay, and at most within one month (extendable by two further months for complex requests, with notice).
- — CCPA / CPRA — 45 days, extendable by 45 days where permitted.
- We do not charge for exercising your rights, unless the request is manifestly unfounded or excessive.
9. Children's Privacy
- The Service is intended for adult authors and editors. We do not knowingly collect personal data from children under 16 (or the age of digital consent in your jurisdiction, if higher). The children's-book mode on the Service is a tool for adults who write children's books — it does not target children as users.
- If you believe we have collected data from a minor in error, contact privacy@bookblurb.org for immediate deletion.
10. Security
- We implement industry-standard security measures [GDPR Art. 32]:
- — TLS 1.3 for all data in transit.
- — Encryption at rest in our database (provider-managed).
- — HTTP-only, signed session cookies.
- — Signature-verified, idempotent webhooks.
- — Principle of least privilege for staff access.
- — Reliance on Creem's PCI-DSS-compliant payment infrastructure for billing data.
- — Cloudflare edge security (DDoS protection, bot detection).
- However, no system is 100% secure. Use a strong email password and protect your Google account credentials. If we discover a breach affecting your personal data, we will notify you and the relevant supervisory authorities within the time limits required by law [GDPR Art. 33 / Art. 34].
11. Automated Decision-Making
- The Service does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you [GDPR Art. 22]. The AI-likeness score is an informational heuristic only — it never automatically denies you service or restricts your account on its own.
12. Changes to This Policy
- We may update this Privacy Policy. Material changes will be posted on this page with a new "Last updated" date and, where required by law, a re-consent prompt in the cookie banner or by email.
13. Contact
- Privacy / data-protection requests: privacy@bookblurb.org
- General / support: support@bookblurb.org
- Transactions / refunds: transaction@bookblurb.org
- Data Controller: BookBlurb (operated by the individual operator of bookblurb.org)
- Payment Processor (Merchant of Record): Creem — Armitage Labs OÜ, registry code 16977866, Rotermanni 14, Tallinn 10111, Estonia — support@creem.io
- Country of operation (for data-protection purposes): For European users, the operator is treated as established in Estonia (the country of our Merchant of Record, Creem — Armitage Labs OÜ). This convention follows the disclosure practices of independently-operated SaaS sites that route through an EU Merchant of Record.
- EU representative under GDPR Art. 27: We have not appointed an EU representative because we do not systematically target EU users and our processing does not meet the thresholds that trigger an Art. 37 DPO or Art. 27 representative obligation at launch scale. If you are an EU user and require EU-representative contact, write to privacy@bookblurb.org and we will respond via the same channel.
Disclaimer
- BookBlurb is an independent tool. We are not affiliated with Amazon.com, Inc., Kindle Direct Publishing (KDP), Barnes & Noble, Kobo, Publisher Rocket, Book Bolt, or any third-party tools referenced on the Service. All trademarks belong to their respective owners.
- Our AI-generated outputs are provided for informational and creative-assistance purposes only and do not constitute publishing, legal, financial, or business advice. AI-likeness scores are informational heuristics only and do not guarantee any outcome from external AI-detection tools or retail-platform review.