What We Collect
- Account information — name, email address, and profile image from your sign-in provider (Google, Apple, or Amazon).
- Project data — book titles, author names, descriptions, and cover attribute selections you create.
- Generated images — cover images produced by AI based on your prompts and attributes.
- Uploaded files — custom fonts and reference images you upload.
- Payment data — subscription and purchase information processed by DodoPayments. We never store or see your card numbers.
- Credit history — records of credit grants, usage, and refunds for billing purposes.
- Feedback — text and optional screenshots you submit through the feedback form.
How We Use Your Data
- Authentication — to sign you in and maintain your session.
- AI image generation and attribute suggestions — your prompts, descriptions, and attribute selections are sent to Google Gemini to generate cover images and suggest attributes.
- File storage — generated images and uploaded assets are stored on Cloudflare R2.
- Billing — subscription and credit pack purchases are processed by DodoPayments.
We do not sell your data, use it for marketing, or build advertising profiles.
Third-Party Services
- Google — OAuth sign-in and Gemini AI for image generation and attribute suggestions.
- Apple — OAuth sign-in (email and name).
- Amazon — OAuth sign-in (email and name).
- DodoPayments — payment processing for subscriptions and credit packs.
- Cloudflare R2 — file storage for generated images and uploaded assets.
- Google Analytics — website analytics to understand how visitors use BookClad. Collects page views, device type, browser, referrer, and approximate location (country/city). You can opt out via the cookie consent banner or use the Google Analytics Opt-out Browser Add-on.
Cookies & Local Storage
We use a single authentication cookie to maintain your session. It is HttpOnly and Secure in production.
If you accept analytics cookies via our consent banner, Google Analytics sets the following cookies:
- _ga — identifies unique visitors, expires after 2 years.
- _ga_* — maintains session state, expires after 2 years.
We also store the following in your browser's localStorage:
- cookie-consent — your cookie preference ("accepted" or "declined"). No expiry.
- UI preferences — panel height, per-project image count. No personal data.
Data Retention
Your data is kept for as long as your account exists. When you delete a project or image, it is permanently removed from our storage. Credit transaction records are retained for billing purposes.
Your Rights
- Delete individual projects and images at any time from the editor.
- Export your covers as high-resolution images.
- Delete your entire account from Settings. This permanently removes all your data including projects, images, fonts, presets, and credit history.
Security
- Sessions are stored in our database (not client-side tokens).
- Payment webhook signatures are verified before processing.
- File download URLs expire after one hour.
- OAuth tokens are stored securely in our database.
Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top will reflect the most recent revision.
Contact
Questions about your data or this policy? Email us at [email protected] or use the feedback form inside the app.