Privacy Policy
BookWorkz
Effective date: August 9, 2026 · Last updated: August 9, 2026
This Privacy Policy explains how AleWin Enterprises LLC, a Florida limited liability company doing business as BookWorkz (“BookWorkz,” “we,” “us,” or “our”), collects, uses, shares, and protects personal data in connection with the BookWorkz publishing workflow platform (the “Service”). It forms part of our Terms of Service.
A note on wording. We do not operate our own data centers. Your manuscripts are hosted on infrastructure operated by the subprocessors listed in Section 6, each of which is bound by contract to process data only on our instructions. We draw a distinction between that ordinary hosting and transmission to an AI model provider, which happens only when you run an AI action.
1. Our Role, and Whose Data This Is
1.1 Two relationships. For personal data about our own customers and prospects — account holders, billing contacts, people who email us — we act as a controller, and this policy describes what we do with it. For personal data contained within Customer Content that an organization uploads or creates in the Service — an author’s name in a manuscript, a freelance editor’s details in a project record, an email address in a comment — we act as a processor on that organization’s instructions. The organization is the controller of that data and is responsible for having a lawful basis to put it into the Service.
1.2 If you are a User, not the account holder. If you were invited into an organization by your publisher, client, or employer, that organization controls your work within the Service. Requests about content in their workspace should go to them first. We will assist them in responding.
1.3 Data Processing Addendum. Where we act as a processor and a controller requires a data processing agreement, our Data Processing Addendum applies and is available on request from admin@bookworkz.tech.
2. What We Collect
(a) Account and profile data. Name, email address, password hash, display preferences, organization name and role, and the identity of the person who invited you.
(b) Customer Content. Manuscripts, outlines, notes, editorial comments, character and story materials, cover and interior assets, metadata, pen names, and anything else you create in or upload to the Service. This may contain personal data about third parties that you have chosen to include.
(c) Billing data. Plan, subscription status, billing contact, invoice history, Credit balance and ledger, and a customer identifier issued by our payment processor. We do not receive or store full payment card numbers; checkout and the billing portal are hosted by our payment processor.
(d) Usage and technical data. Log records of actions taken in the Service, IP address, browser and device type, timestamps, page and feature usage, and error and performance diagnostics.
(e) AI usage records. Which AI action was run, by whom, when, on which manuscript, and the Credits charged. These records are how metering and spend ceilings work.
(f) Support and correspondence. Messages you send us, and any information you choose to include in them.
(g) Cookies and similar technologies. See Section 10.
3. How and Why We Use It
| Purpose | What it covers |
|---|---|
| Provide the Service | Authenticate you, host and display Customer Content, run the actions you request, render DOCX, EPUB, and print PDF output, deliver invitations and notifications. |
| Billing and metering | Process subscription and Credit payments, enforce seat and Credit limits, apply spending ceilings, produce invoices and usage records. |
| Security and integrity | Detect and prevent unauthorized access, abuse, fraud, and circumvention of technical limits; maintain audit trails. |
| Support | Respond to your requests, diagnose faults, and communicate about incidents. |
| Service communications | Send transactional messages about your account, billing, security, and material changes to our terms. These are not marketing and you cannot opt out of them while you hold an account. |
| Improve the Service | Analyze aggregated and de-identified usage patterns to prioritize engineering work. We do not use Customer Content for this. |
| Marketing | Send product news and offers, where you have opted in or where permitted by law. You may unsubscribe at any time. |
| Legal compliance | Meet tax, accounting, and other legal obligations, and respond to lawful requests. |
4. What We Do Not Do
(a) We do not sell personal data, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law.
(b) We do not use Customer Content to train, fine-tune, or improve any machine-learning model, and we do not authorize any subprocessor to do so on our behalf.
(c) We do not use Customer Content for advertising or profiling.
(d) We do not make Customer Content public except where you affirmatively direct us to, such as by publishing a public book link.
5. AI Features and Your Manuscripts
AI features are disabled by default and are enabled only by a deliberate act of an organization admin. While disabled, no Customer Content is transmitted to any model provider for AI processing.
When a User runs an AI action, the relevant portion of Customer Content is transmitted to an AI model provider, processed, and returned. What is sent depends on the action: most actions send the story materials you have created — an outline, character notes, settings — rather than your prose. A synopsis or a reverse outline sends the manuscript, because those actions cannot be performed without it. Under our agreements with these providers, that content is used only to fulfill the request and is not used to train or improve any model. Every AI model provider we use is named in Section 6. Where we reach a provider through an intermediary or routing service, both the routing service and the provider that performs the processing are named there.
We retain a record of each AI action for metering and audit — who ran it, when, on which manuscript, and the Credits charged. Those records do not contain the text of your manuscript.
6. Subprocessors
We use the following service providers to operate the Service. Each is engaged under a written agreement that limits their processing to what we instruct. We do not authorize any of them to use Customer Content to train or improve a machine-learning model. Each provider’s own practices are governed by its published terms, and we encourage you to review those of any provider that matters to your assessment.
| Subprocessor | Function | Data processed |
|---|---|---|
| Supabase | Database, authentication, file storage | Account data, Customer Content, usage records |
| Vercel | Application hosting, edge delivery, PDF rendering | Request data, Customer Content in transit and during rendering |
| OpenRouter | AI routing service — reaches the model provider for an AI action (only when AI is enabled and an action is run) | The portion of Customer Content submitted with the request, in transit |
| Stripe | Payment processing, subscription and billing portal | Billing contact, payment method (held by Stripe), transaction records |
| Sentry | Error and performance monitoring | Diagnostic data, IP address, technical context |
| Resend | Transactional email delivery | Email addresses and message content for invitations and notifications |
AI processing is reached through a routing service. When AI features are enabled and a User runs an AI action, the request is sent to OpenRouter, which routes it to one of the model providers below. OpenRouter is a subprocessor in its own right: the request passes through it in transit. It is instructed not to retain content for training, and it may route only to the providers we have permitted.
| AI model provider | Service |
|---|---|
| Anthropic | Anthropic PBC |
| OpenAI | OpenAI |
| Google Cloud | Vertex AI |
| Amazon Web Services | Amazon Bedrock |
| Microsoft Azure | Azure AI |
| Mistral | Mistral AI |
| Together | Together AI |
| Fireworks | Fireworks AI |
| DeepInfra | DeepInfra |
| Groq | Groq |
| BaseTen | BaseTen |
Every provider in that list may receive the portion of Customer Content submitted with an AI action, and none of them receives anything while AI features are off. The list is the complete set we permit — not only the ones currently selected — because a request can be routed to any of them. Under our agreements, content sent for an AI action is used only to fulfill that request and is not used to train or improve any model.
These two lists name every subprocessor that processes Customer Content or account data, including every AI model provider. We do not publish contract terms, infrastructure regions, model versions, or configuration details, none of which are necessary to understand how your data is handled.
We update this list before a new subprocessor begins processing. If we add an AI model provider, or reach one through a routing service, both the routing service and the provider are added here before any Customer Content is sent to them. Where a signed order form or Data Processing Addendum provides for advance notice or a right to object, those terms govern for that customer.
7. Sharing and Disclosure
We disclose personal data only:
(a) to the subprocessors listed above, for the functions described;
(b) within your organization, to other Users, according to the roles and permissions your admins configure;
(c) to professional advisers — accountants, auditors, lawyers — bound by duties of confidentiality;
(d) where required by law, subpoena, or governmental order, or to establish or defend legal claims. Where we are legally permitted to do so, we will notify the affected customer before disclosing;
(e) to protect the rights, safety, or property of BookWorkz, our customers, or the public; and
(f) to a successor in connection with a merger, acquisition, reorganization, or sale of all or substantially all of our assets. Personal data transferred in that context remains subject to this policy until the successor provides notice of a change.
8. International Transfers
We are based in the United States, and our subprocessors process data in the United States and, in some cases, elsewhere. If you are in the European Economic Area, the United Kingdom, or Switzerland, your personal data will be transferred outside your jurisdiction. Where required, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, and we require our subprocessors to do the same. A copy of the relevant clauses is available on request from admin@bookworkz.tech.
9. Retention
| Category | Retention |
|---|---|
| Customer Content | For the life of the account. After termination, available for export for at least 30 days, then deleted or irreversibly anonymized within 90 days. |
| Account and profile data | For the life of the account, then deleted within 90 days of termination. |
| Billing and tax records | Retained for 7 years as required by tax and accounting law, regardless of account status. |
| Usage, audit, and AI metering records | Retained for 24 months for security, dispute resolution, and audit, then deleted or aggregated. |
| Error and diagnostic data | Retained per our monitoring provider’s configured window, currently 90 days. |
| Encrypted backups | Overwritten on our ordinary backup cycle, currently 30 days. Deleted data may persist in backups until overwritten and is not restored to active systems. |
| Support correspondence | Retained for 24 months after the matter is closed. |
10. Cookies
We use cookies and similar technologies that are strictly necessary to operate the Service — to keep you signed in, maintain your session, remember your theme preference, and protect against abuse.
We use privacy-friendly analytics on our public website to count visits and page views. It does not use cookies, does not track you across sites, and does not build a profile of you. We use no advertising or marketing cookies of any kind.
11. Security
We protect personal data with measures appropriate to the risk, including encryption in transit and at rest, row-level access controls enforced at the database layer, role-based permissions within organizations, least-privilege access for our personnel, private storage buckets with path-scoped access, and logging of security-relevant events. No system is perfectly secure, and we cannot guarantee absolute security. If a breach affecting your personal data occurs, we will notify you and any relevant supervisory authority as required by law and without undue delay.
12. Your Rights
12.1 Everyone. You may access, correct, export, or delete your account data at any time from within the Service, or by contacting us at admin@bookworkz.tech. Manuscripts and other Customer Content can be exported in DOCX, EPUB, and print-ready PDF formats.
12.2 EEA, UK, and Switzerland. Where the GDPR or UK GDPR applies, you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent where processing is based on consent. Our legal bases are: performance of a contract, for providing the Service and billing; legitimate interests, for security, fraud prevention, service improvement, and direct marketing to business contacts; consent, for optional marketing where required; and legal obligation, for tax and compliance records. You have the right to lodge a complaint with your supervisory authority.
12.3 California. Under the CCPA as amended by the CPRA, you have the rights to know, delete, correct, and to limit the use of sensitive personal information, and the right not to be discriminated against for exercising them. We do not sell personal information and do not share it for cross-context behavioral advertising. To exercise a right, contact admin@bookworkz.tech. An authorized agent may submit a request with proof of authorization.
12.4 Other US states. Residents of states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Texas, and Oregon — have comparable rights of access, correction, deletion, and portability, and may appeal a denied request by replying to our response. We will honor these rights for all US residents regardless of state.
12.5 How we respond. We will verify your identity before acting on a request and will respond within the period required by applicable law, normally 30 days for GDPR requests and 45 days for US state requests, and will tell you if we need an extension.
13. Children
The Service is not directed to children. Users must be at least 18 years old, or the age of majority in their jurisdiction if higher. We do not knowingly collect personal data from children. If we learn that we have, we will delete it. If you believe a child has provided us personal data, contact admin@bookworkz.tech.
14. Changes to This Policy
We may update this policy. For changes that materially affect how we handle personal data, we will give at least thirty (30) days’ notice by email to account admins and by notice within the Service before the change takes effect. The “last updated” date above reflects the current version, and we maintain prior versions on request.
15. Contact Us
Questions, requests, and complaints about privacy should go to:
AleWin Enterprises LLC, d/b/a BookWorkz
We will acknowledge your message and respond within the period required by applicable law.
© 2026 AleWin Enterprises LLC. All rights reserved.