Privacy Policy
Last updated: July 20, 2026.
Who We Are
Bookshaper is operated by Bookshaper LLC, a Texas limited liability company. Throughout this Privacy Policy, “Bookshaper”, “we”, “us”, and “our” refer to that entity, which is the data controller for the personal data described below.
Data We Collect
Bookshaper collects four categories of data:
- Account data — email address, hashed password, subscription state.
- Billing data — handled exclusively by Stripe. Bookshaper never stores credit card numbers or payment credentials.
- Manuscript data — your uploaded manuscripts and creative content.
- Telemetry data — anonymized usage events for analytics (page views, feature usage, activation tracking).
How We Use Your Data
Your data is used to:
- Provide and maintain the Bookshaper service.
- Process your subscription and billing through Stripe.
- Analyze your manuscripts and power select generation features (back-cover blurbs, cover concepts) using Bookshaper’s AI engines.
- Improve the service through anonymized usage telemetry.
- Communicate with you regarding your account, subscription, and service updates.
How We Store Your Data
Your manuscripts are stored locally on your device. When cloud sync is enabled, manuscripts are encrypted on your device using AES-256-GCM before being uploaded. The Bookshaper server stores only the encrypted archive — it never has access to plaintext manuscript content. Encryption keys are derived from your account credentials and never leave your device.
We do not authorize AI providers to train on your manuscripts, and we configure available no-retention controls on every request; because analysis runs on third-party AI platforms, this protection relies on each provider honoring its default API terms. All data is transmitted over HTTPS. No credit card data is stored on Bookshaper servers — billing is handled entirely by Stripe.
Data Sharing
Bookshaper shares data only with the following third parties:
- Stripe — for payment processing and subscription management.
- Analytics providers — anonymized telemetry data only. No manuscript content or personally identifiable information is shared.
Your manuscript content is never shared with any third party.
AI Disclosure
Bookshaper uses AI for analysis and select generation features (such as back-cover blurbs and cover concepts). We do not authorize AI providers to train on your manuscripts, and we configure available no-retention controls on every request; because analysis runs on third-party AI platforms, this protection relies on each provider honoring its default API terms. AI analysis is deterministic, audit-friendly, and explainable. You retain full creative control and all rights to your manuscripts at all times.
Cookies and Tracking
Bookshaper uses cookies and similar technologies for analytics and session management. Analytics tracking is off by default: no analytics events are sent from this website until you explicitly accept the cookie banner. Declining the banner keeps analytics off, and you may change your choice at any time by clearing your browser’s site data for bookshaper.com. Essential cookies required for authentication and security cannot be disabled.
We use the following categories of cookies:
- Essential cookies — required for authentication, security, and core site functionality. These cannot be disabled.
- Analytics cookies — off by default; set only after you accept the cookie banner, to measure page views and feature usage.
- Affiliate / referral attribution — the Bookshaper Creator Program does not set an affiliate tracking cookie. Referrals are attributed by the personalized discount code a customer enters at Stripe Checkout, so attribution has no cookie or browser dependency. See the Affiliate Terms for details.
Bookshaper does not use fingerprinting or cross-site tracking.
Cookieless landing measurement. Independently of the cookie banner, we record an anonymous count of visits that arrive at a landing page, on a legitimate- interest basis, so we can reconcile advertising clicks against real page loads. This measurement sets no cookie and stores no persistent identifier: it captures only the landing page path, the referring URL, any advertising campaign parameters in the link you clicked (such as UTM tags), and a coarse country derived from your connection. It cannot be linked to you, to a session, or across pages, and it is stored separately from the consent-gated analytics described above.
Your Rights
Under applicable data protection laws (including GDPR and CCPA), you have the right to:
- Access your personal data.
- Request deletion of your account and manuscripts.
- Request correction of inaccurate data.
- Opt out of analytics and telemetry.
- Export your manuscripts.
- Export your account data.
You can export your account data and delete your account yourself from within the Bookshaper desktop app, under Settings → Account → Data & Privacy. For any other request — correcting data, opting out of analytics, or anything not covered by the in-app controls — contact us through the support channels listed on this site, and we will respond within the timeframe required by applicable law.
Non-discrimination. We will not discriminate against you for exercising any of these rights. Exercising a privacy right — including opting out of analytics or requesting deletion — will not result in denial of service, different pricing, or a reduced level or quality of service.
International Users and Data Transfers
Bookshaper is operated from the United States, and the data described in this policy is processed and stored in the United States. If you access Bookshaper from the European Economic Area, the United Kingdom, or another region with data protection laws, you consent to the transfer of your data to the United States for the purposes described above.
Where required, business and EU/UK customers may request a Data Processing Addendum (DPA) governing our processing of personal data on your behalf. To request a DPA, contact us through the support channels listed on this site.
Children’s Privacy
Bookshaper is a professional writing tool intended for adult authors. The service is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us through the support channels listed on this site and we will delete it.
Data Retention
Your manuscripts are stored locally on your device. Cloud-synced archives are stored in encrypted form and are deleted when you disable cloud sync or delete your account. Subscription records are retained per financial regulations. Telemetry data is retained for 12 to 24 months. Deleting your account removes your account data from our servers but does not affect your local manuscript files. Subscription records may be retained for legal compliance.
Data Breach Notification
We maintain an internal incident-response procedure for security incidents affecting personal data. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required under Article 33 of the GDPR. Where the breach is likely to result in a high risk to affected individuals, we will also notify those individuals without undue delay, in accordance with Article 34 of the GDPR and applicable state breach notification laws.