Privacy Policy
How [COMPANY LEGAL NAME] collects, uses and protects personal data when you use Publixy AI. Effective [EFFECTIVE DATE].
Who we are
Publixy AI ([https://YOUR-DOMAIN]) is operated by [COMPANY LEGAL NAME], [REGISTERED ADDRESS]. We are the controller of the personal data described here, except where this policy says we process data on your behalf.
Questions and requests about your data: [PRIVACY CONTACT EMAIL].
What we collect
- Your account: when you sign in with Google we receive your name, email address, profile picture and Google account identifier.
- Your business address, when you add one. It is printed in the footer of every campaign email, because the law requires a postal address in marketing email.
- What you create: eBook projects, drafts, store pages and campaign drafts are kept in your browser on your device. eBooks are generated on our servers, which keep the project details the build needs and the finished book. Books you publish for sale (the manuscript and its images), products, prices and revenue agreements are stored on our servers.
- Contact lists and campaign activity: the names, email addresses and companies of the contacts you upload, the emails sent to them, their replies, bounces and unsubscribes. We store these to send and manage your campaigns.
- Instagram analysis: when you analyse a public Instagram profile we fetch publicly available data about it (profile details, recent posts and captions, public comments, and transcripts of public videos). Transcripts are kept so the same video is not processed twice. When you confirm a creator, their analysis is kept with your account for 30 days so your eBook can be built from it.
- Sales and purchases: orders, amounts, payment status and PayPal merchant identifiers. Payments are made on PayPal; we never see card or bank details.
- Technical data: IP addresses and request details in server logs, and counts of the AI requests made by each account, used for security and to enforce usage limits.
Cookies and local storage
- A session cookie set by our sign-in system, which keeps you signed in. Required.
- A functional cookie (publixy.scope) that tells this browser which account's saved drafts to show. Required.
- Browser local storage, which holds your projects and drafts on your device.
- We do not use advertising or analytics cookies.
How we use it
- To provide the service: generating books, store pages and email sequences, analysing creators you choose, sending your campaigns and showing your replies.
- To process sales: creating PayPal orders, recording who bought what, giving buyers access and keeping the ledger of each sale.
- To keep the service safe: preventing abuse, enforcing usage limits and investigating problems.
- To meet legal obligations, such as keeping financial records.
Legal bases
Where the GDPR or similar law applies, we rely on: performing our contract with you (running your account and the features you use); our legitimate interests (security, abuse prevention, and analysing public profiles you ask us to analyse); legal obligations (financial and tax records); and consent where the law requires it.
Data you give us about other people
When you upload a contact list or send a campaign, you decide whose data is processed and why. For that data you are the controller and we process it on your behalf, only to provide the service to you. You must have a lawful basis to email every contact you upload, and you confirm this before each campaign is published.
Anyone who receives a campaign email can unsubscribe with the link in every message. Anyone whose data is processed through Publixy AI can contact us at [PRIVACY CONTACT EMAIL].
Who we share data with
We use these service providers to run the service. Each receives only what its job needs:
- Google: sign-in.
- Vercel: hosting.
- Upstash: our database.
- Hugging Face and the inference providers it routes to: AI text and image generation.
- Perplexity: web search for market research.
- OpenRouter: AI text generation, when enabled.
- Apify: fetching public Instagram data.
- Resend: sending campaign email and receiving replies.
- PayPal: payments, payouts to sellers, and refunds.
AI processing
What you submit for generation (prompts, research, book text and analysed public data) is sent to the AI providers above to produce the result. We do not use your content to train models of our own. [CONFIRM EACH PROVIDER'S TRAINING AND RETENTION TERMS.]
International transfers
Some providers process data outside your country, including in the United States. Where required, transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. [CONFIRM FOR EACH PROVIDER.]
How long we keep it
- Account data: while your account is open.
- Published editions: for as long as buyers have access to what they bought.
- Financial records: [N YEARS], as tax law requires.
- Campaign data: until you ask us to delete it. Unsubscribes and bounces are kept so that address is never emailed again.
- A confirmed creator's Instagram analysis: 30 days.
- Server logs: [N DAYS].
- Drafts in your browser: until you clear them from your browser.
Your rights
Depending on where you live, you can ask to access, correct, export or delete your personal data, to restrict or object to how it is used, and to withdraw consent. Write to [PRIVACY CONTACT EMAIL] and we will answer within 30 days. Some records, such as completed sales, must be kept by law even after an account is deleted. You can also complain to your data protection authority.
Security
Data is encrypted in transit. Access to production data is limited to the people who need it to run the service. No system is perfectly secure; if a breach affects your data we will tell you as the law requires.
Children
Publixy AI is not for anyone under 18.
Changes
If we change this policy we will update the date below, and tell you in the app or by email before a significant change takes effect.