Legal

Privacy Policy

Last updated: April 22, 2026

1. Overview

BookSculpt ("we", "us") respects your privacy. This Privacy Policy explains what personal information we collect, how we use it, and the choices you have. It applies to booksculpt.pro and all related services (the "Service").

By using the Service you acknowledge that your information will be processed as described below.

2. Information We Collect

Account data: name, email, hashed password, profile picture, timezone, author bio, website, writing goals.

Content you create: manuscripts, chapters, outlines, notes, project covers, team-member email addresses you invite.

Payment data: we do not store payment card numbers. Stripe (our PCI-compliant processor) handles all card data; we only store Stripe customer IDs, subscription status, and transaction history.

Usage data: pages visited, features used, AI word counts, export events, device/browser info, IP address, and timestamps.

Support data: messages you send to support@booksculpt.pro or via the Contact form.

Cookies: authentication cookies (HTTP-only, secure) for session management; limited first-party analytics cookies; no third-party advertising cookies.

3. How We Use Your Information

  • To provide, personalise, and improve the Service.
  • To process payments and manage subscriptions.
  • To send transactional emails (account, password reset, invites, subscription confirmations). We use Resend as our email delivery provider.
  • To respond to support requests.
  • To detect, prevent, and investigate fraud, abuse, or security incidents.
  • To comply with legal obligations.

4. AI Processing

When you use AI features, your prompts and relevant chapter context are sent to our AI providers (currently Anthropic Claude via Emergent Integrations) solely to generate the requested output. Providers are contractually bound not to use your content to train their models.

We do not use Your Content to train any machine-learning models.

5. Sharing and Disclosure

We share personal data only with:

  • Service providers acting on our behalf: Stripe (payments), Resend (email), Anthropic/Emergent (AI), MongoDB Atlas (database), Cloudflare (CDN).
  • Team members you invite: team members you add can see projects you share with them.
  • Legal authorities when required by valid legal process.
  • Corporate transactions: if BookSculpt is acquired or merged, your data may transfer to the successor, subject to this Privacy Policy.

We do not sell or rent your personal information.

6. Data Retention

We retain account data while your account is active. After account deletion, manuscripts and project data are deleted within 30 days (except anonymised logs retained for security/audit purposes up to 12 months). Payment records are retained for 7 years to comply with tax law.

7. Your Rights

Depending on your location (EEA/UK/Switzerland under GDPR, California under CCPA/CPRA, or similar regimes), you may have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate data;
  • Delete your data ("right to be forgotten");
  • Export your data in a portable format;
  • Restrict or object to processing;
  • Withdraw consent where processing is based on consent;
  • Lodge a complaint with a data-protection authority.

To exercise any of these rights, email privacy@booksculpt.pro. We will respond within 30 days.

8. Data Security

We use industry-standard safeguards including TLS/HTTPS for data in transit, bcrypt hashing for passwords, HTTP-only secure cookies, role-based access control, rate limiting, and encrypted database backups. No system is 100% secure; notify us immediately at security@booksculpt.pro if you suspect a breach.

9. International Transfers

BookSculpt is operated from the United States. If you access the Service from outside the U.S., your data will be transferred to and processed in the U.S. We rely on Standard Contractual Clauses where applicable for transfers from the EEA, UK, and Switzerland.

10. Children

BookSculpt is not directed to children under 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@booksculpt.pro and we will delete it promptly.

11. Do Not Track

The Service does not currently respond to Do Not Track browser signals. We do, however, honour the Global Privacy Control (GPC) signal for California residents.

12. Changes

We may update this Privacy Policy periodically. Material changes will be notified via email or in-app notice at least 14 days in advance. Continued use after the effective date constitutes acceptance.

13. Contact

Questions or concerns? Email privacy@booksculpt.pro. For general support, use support@booksculpt.pro.

Made with Emergent