Privacy Policy
Last updated: August 16, 2026
Bespoke Books ("we", "us", "our") operates www.bespokebookstore.com and app.bespokebookstore.com. This policy explains what data we collect and how we use it.
1. Information We Collect
- Account information: name and email address when you sign in with Google OAuth, email/password, or email magic link / one-time code
- Usage data: books created, pipeline runs, feature usage, and product analytics events
- Payment information: processed by Stripe; we do not store card details
- Content you provide: seed documents, story inputs, preferences, and generated book artifacts
2. How We Use Your Information
- To provide and operate the Bespoke Books service
- To process payments via Stripe
- To send transactional emails (account, billing) — no marketing without consent
- To improve the service
- To measure advertising performance (Meta Pixel and Conversions API) when campaigns are running
3. Data Storage
Your content and generated books are stored in Cloudflare R2 object storage. Account data, ownership records, sessions, and billing metadata are stored in Supabase. We do not sell your personal information.
4. Third-Party Services
- Google OAuth, email/password, and magic-link authentication (via Supabase Auth)
- Stripe (payments)
- Cloudflare R2 (file storage) and Cloudflare (DNS/CDN)
- Supabase (database and auth)
- Anthropic API and OpenRouter (AI generation — your seed content is sent to these services to generate your book)
- Google Analytics 4 (product analytics; see Cookies & analytics)
- Meta Pixel and Conversions API (advertising measurement; see Cookies & analytics)
5. Data Retention & deletion
You may delete your account from Account settings (Delete account) or by contacting [email protected]. When you delete your account in-app, we cancel active Stripe subscriptions, remove your books and storage objects under your account, wipe associated Supabase account rows, and delete your Auth user. Residual backups or logs may take up to 30 days to fully expire.
6. California privacy rights (CCPA / CPRA)
We do not sell personal information. We use Meta (Facebook) to measure and optimize advertising campaigns, which can count as “sharing” under California law. California residents may request access, deletion, or opt-out of this advertising measurement by emailing [email protected]. We will not discriminate against you for exercising these rights.
7. Cookies & analytics
We use a session cookie (bb_token) for authentication.
We also use Google Analytics 4 for product analytics (page views and funnel
milestones such as starting ideation, viewing pricing, and completing checkout),
as described in this policy. When we run advertising campaigns, we use Meta Pixel
in the browser and Meta’s Conversions API on our servers to measure those ads
(PageView, ViewContent, CompleteRegistration, checkout, and purchase, plus
custom BlueprintCompleted / SampleChapterCompleted events). Browser and server
copies of the same conversion share an event id so Meta can deduplicate them.
Analytics events never include story text, prompts, book titles, or names.
When we already have an account or checkout email, the Conversions API may send
a SHA-256 hash of that email for match quality — never the raw address.
In the European Economic Area, United Kingdom, and Switzerland, we ask for your
consent before enabling analytics and advertising measurement (Accept / Decline).
Elsewhere, analytics is enabled by default under this Privacy Policy. Declining
(where offered) does not affect your ability to use Bespoke Books. Meta may set
_fbp / _fbc cookies used only for ads measurement when
analytics is enabled.