Legal
Privacy Policy
Last updated August 9, 2026. Questions, access or deletion requests go to support@createebook.com.
1. Who this covers
This policy covers CreateEbook (“CreateEbook”, “we”, “us”) and two different people who use it. First, the person who creates an account and writes a book — you, if you are signed in. Second, a reader who visits a book’s public opt-in page and types in an email address to download it. Those two get different treatment below, because our relationship to their data is different: for you, we decide what we collect and why, so we are the data controller. For a reader who hands their address to an author’s page, the author decides that, and we are only the data processor carrying out their instructions — Section 5 covers what that means in practice.
2. What we collect from you
- Account. Your email address. We do not ask for or store a password — signing in sends a six-digit code to that address instead.
- Profile. Anything you choose to add: display name, account name, bio, timezone, brand color, logo or avatar. A display name and handle are shown publicly on any book you publish.
- Book content. What you paste or upload to write a book — notes, source documents, briefs — and everything the tool produces from it: titles, outlines, chapters, cover art, listing copy. This is stored so your project is there when you come back to it.
- Billing. Our payment processor, Polar, holds your card details — we never see or store a card number. We keep a record of what you bought, your credit balance, and the history of how it was spent.
- Technical data. IP address and browser information, used to keep sign-in and free-credit limits from being abused, and, where enabled, to measure whether an ad we ran led to a signup or a purchase (Section 6).
- Usage data. Product analytics on how the tool is used — pages visited, actions taken, errors encountered — tied to your account so we can find and fix what is broken.
3. How we use it
- To run the account you asked for and keep your work saved.
- To generate your book’s text and artwork, which requires sending the relevant part of your input to the third-party AI providers listed in Section 6 — see Section 4 for what that involves.
- To process payments and keep your credit balance accurate.
- To measure and improve the product, and, where you have not opted out, to measure whether our own advertising is working.
- To answer support requests and enforce our Terms of Service.
- To meet legal obligations — responding to a lawful request, or keeping records tax and accounting law requires us to keep.
Where GDPR applies, our basis is one of: performing our contract with you (running the account and generating your book), our legitimate interest in keeping the service secure and improving it, your consent (advertising measurement, where asked for), or a legal obligation.
4. AI-generated content
Writing your book means sending your notes, brief, and the draft as it develops to third-party AI model providers, which generate the text and artwork back. We do not control how those providers otherwise process what they receive beyond our instructions to them, though we do not authorize them to use your content to train their own models for other customers. Avoid pasting sensitive personal data about other people — health information, government ID numbers, financial account details — into a book’s source material unless you have a lawful basis of your own for putting it there.
5. If you collect email addresses through a published book
Publishing a book can include a hosted page that trades a free download for a reader’s email address. If you use that feature, youare the data controller for the addresses you collect — you decide to collect them, you are the one a reader is handing their address to, and you are responsible for having a lawful basis to do so and for what you do with the list afterward (including any marketing law that applies where your readers live). We act only as your processor: we store what is submitted, hand you an export, and do not use your subscriber list for our own purposes, with one exception we want to be direct about — where advertising measurement is enabled on your page (Section 6), a hashed version of a submitted email and standard technical identifiers (IP address, browser identifiers) are sent to our advertising partner to measure whether our own ads led to that download. If you would rather your readers’ information never touched that pipeline, contact us and we will turn it off for your account.
6. Who we share data with
We do not sell personal data, in the ordinary sense or in the sense California law uses the word. We share it with the service providers that make CreateEbook work, each bound to use it only to provide their service to us:
- Supabase — database, authentication, and file storage. Holds essentially everything described in Section 2.
- Polar — payment processing, as merchant of record. Receives your email and purchase details; card data goes directly to them and never reaches us.
- DeepSeek — generates chapter, title, and outline text from what you provide.
- OpenAI, Google (Gemini), and Vercel AI Gateway — generate cover and section artwork from prompts derived from your book.
- Meta — advertising measurement. Receives a hashed (not plaintext) version of your email, browser identifiers, IP address, and event data such as a signup or purchase, so we can tell whether an ad led to it.
- PostHog — product analytics and error tracking, tied to your account so we can see what broke and for whom.
- Vercel — hosting, content delivery, first-party web analytics, and, if you connect one, managing a custom domain on your behalf.
- Our email provider — delivers the sign-in code to your inbox. Sees your email address and nothing else.
We may also disclose data where the law requires it, to defend a legal claim, or in connection with a merger, sale, or transfer of the business, subject to this policy continuing to apply to data transferred that way.
7. Public by design
A book you publish is meant to be seen: it is served at a public web address, and by default listed in CreateEbook’s own directory of published guides. Search engines are free to index it. Your display name and handle are public wherever your published work is shown. If you would rather a book were not listed in our directory, you control that from the dashboard; if you want it unpublished entirely, that removes it from public view.
8. Cookies and similar technology
We use a small number of cookies and comparable identifiers: one that keeps you signed in, one that tracks a free credit balance for someone trying the product before creating an account, and, where not opted out, analytics and advertising identifiers from PostHog, Vercel Analytics, and Meta. None of these are used to build an advertising profile of you across other, unrelated websites beyond standard ad-platform measurement. You can block cookies in your browser; the sign-in cookie is required for the product to function.
9. How long we keep it
Account and book data for as long as your account exists, plus a reasonable period afterward for backups, fraud prevention, and legal recordkeeping. Billing records are kept as long as accounting and tax law requires. Raw visitor identifiers used to count traffic to a published page are kept briefly and then discarded — we do not build a long-term log of who read what. If you delete your account, we delete or anonymize what we are not legally required to retain.
10. Your rights
Wherever you are, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it — email support@createebook.com and we will act within 30 days, or explain why we cannot. Depending on where you live, you may also have the right to:
- Get your data in a portable, machine-readable format.
- Object to or restrict certain processing.
- Withdraw consent at any point, for anything based on it.
- Know what categories of data we have collected, used, and disclosed in the past twelve months, and opt out of any sale or share of it (California and similar state laws) — as stated above, we do not sell personal data.
- Lodge a complaint with your local data protection authority, if you believe we have mishandled your request.
We will not charge you a fee or treat you differently for exercising any of these rights.
11. International transfers
Our service providers operate in the United States and elsewhere, which means data described in this policy is processed outside the country you are in. Where that requires a transfer mechanism under GDPR or a similar law, we rely on our providers’ standard contractual clauses or equivalent safeguards.
12. Children
CreateEbook is not directed at children, and you must be at least 18, or the age of majority where you live, to create an account. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will remove it.
13. Security
We use reasonable technical and organizational measures to protect the data described here, including encryption in transit and access controls on our infrastructure. No method of storing or transmitting data is completely secure, and we cannot guarantee absolute security.
14. Changes to this policy
If this policy changes in a way that matters, we will update the date at the top and, for a material change, make a reasonable effort to let account holders know. Continuing to use CreateEbook after a change takes effect means you accept the update.
15. Contact
Questions, requests, or complaints about this policy: support@createebook.com. See also our Terms of Service.