Last updated: 9/11/2026
Account data (email, authentication tokens), manuscript content you create or upload, generated assets (chapters, covers, illustrations), usage metadata (AI token counts, export events), and payment metadata received from Stripe (never full card details).
To operate the Service, generate AI outputs on your behalf, sync your library across devices, process payments, and improve reliability. Manuscripts and generated content are stored in your workspace and used to fulfil your requests — they are not sold and are not used to train shared models.
We rely on: Supabase (database, storage, auth), Stripe (payments), OpenAI and Google (AI generation), Cloudflare (hosting/edge). Content sent to AI providers is subject to their zero-retention or short-retention API terms.
Your books and assets are retained while your account is active. On account deletion we remove your workspace within 30 days, except for records we must keep for tax, fraud, or legal reasons (typically up to 7 years for payment records).
You can access, export, or delete your data at any time. Email support@booksmithai.app to submit a request under GDPR, CCPA, or similar laws.
We use only essential cookies for authentication and session management. No third-party advertising trackers.
Data in transit is encrypted with TLS. Passwords are hashed and salted. Row-level security is enforced at the database layer so users can only read their own content.
Data requests and questions: support@booksmithai.app