Privacy Policy
Effective: 10 May 2026 · Version 1.0
This Privacy Policy describes how SelfPub Go (“we”, “us”, “the platform”) collects, uses, shares, and protects personal data of users in the European Economic Area, the United Kingdom, the United States, and other regions we serve. We comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA / CPRA), and applicable state privacy laws.
1. Who we are (data controller)
The data controller is SelfPub Go, operating from selfpubgo.com. We act as a data controller for account information and as a data processor for content you upload (manuscripts, ad reports, royalty data). Contact: privacy@selfpubgo.com.
For EU users, we have appointed an EU representative as required by GDPR Article 27. Their contact details are available on request.
2. What we collect, and the legal basis for each
- Account data — email, full name, hashed password or OAuth provider id. Legal basis: contract performance (Article 6(1)(b)).
- Workspace metadata — workspace name, primary marketplace, default currency, locale. Legal basis: contract performance.
- Amazon Ads credentials— encrypted refresh tokens obtained via Amazon’s OAuth flow. We never see your Amazon password. Legal basis: contract performance + your explicit consent at OAuth grant time.
- Ad and royalty data — campaign reports, KENP reports, royalty exports. Stored on your behalf, processed only for your workspace. Legal basis: contract performance.
- Manuscripts and book metadata — files and text you upload. Treated as your intellectual property. Legal basis: contract performance.
- Usage analytics — page views, button clicks, time on page (via PostHog). Anonymized; opt-in only. Legal basis: consent (Article 6(1)(a)).
- Diagnostic logs — error reports, request traces. Personal data is redacted before logging. Retention: 30 days. Legal basis: legitimate interest in operating a reliable service.
- Billing data — handled by Stripe, not stored on our servers. We retain only Stripe customer ID, plan, and last-4 of card. Legal basis: contract performance + legal obligation (tax records).
We do not collect special-category data (race, religion, health), and we do not knowingly collect data from children under 16. If you believe a child has provided personal data, contact us immediately.
3. How we use your data
We process personal data to:
- Provide the platform and the modules you have enabled.
- Send transactional email (account verification, password reset, billing receipts, security alerts) — these cannot be opted out of while you have an active account.
- Send product updates and educational content — opt-in at signup, opt-out anytime via email footer.
- Improve the platform — anonymized aggregate analytics, A/B tests on UI improvements.
- Detect fraud, abuse, and policy violations.
- Comply with legal obligations (tax, audit, lawful subpoena).
We do not sell personal data. We do not use your data, your ad campaigns, or your manuscripts to train AI models — ours or any third party’s.
4. Sub-processors
We use the following sub-processors, each bound by Data Processing Agreements aligned with GDPR Article 28:
- Supabase(US / EU regions) — authentication, database, file storage. EU-region tenants are routed exclusively to Supabase’s EU region.
- Vercel(US / EU regions) — application hosting, CDN. Personal data stays in the user’s region; CDN edge nodes cache only public marketing pages.
- Stripe (US / EU) — payment processing, billing, subscription management.
- Anthropic (US / EU) — Claude API for AI Tools features. EU-region tenants route to the Anthropic EU endpoint. Anthropic does not train on our API data per its enterprise terms.
- Resend (US) — transactional and marketing email delivery.
- PostHog (EU) — anonymized usage analytics. Self-hosted EU instance; no data transfer to the US.
- Cloudflare (global) — DNS, DDoS mitigation, R2 object storage for large file uploads.
- Amazon Advertising API — read/write to your Amazon Ads account. We act on your behalf via your OAuth grant and submit data only to Amazon.
A current sub-processor list with version history is maintained at /security. Material additions are notified by email at least 30 days in advance with a right to object.
5. International transfers
For EU users, data primarily stays in the EU. When a transfer to a third country is necessary (e.g. you opt into US-only analytics), we rely on Standard Contractual Clauses (Commission Decision 2021/914) with supplementary measures including encryption at rest and in transit.
6. Retention
- Active account data — for the lifetime of your account.
- Account deletion — personal data hard-deleted within 30 days; backups roll off within 90 days.
- Billing records — 7 years (legal obligation in most jurisdictions).
- Diagnostic logs — 30 days.
- Audit logs (Amazon Agent compliance) — 12 months minimum, longer if required by law.
7. Your rights
Under GDPR / UK GDPR, you have the right to:
- Access — request a copy of all personal data we hold.
- Rectify — correct inaccurate data.
- Erase — request deletion (subject to legal retention obligations).
- Port — receive data in machine-readable format.
- Restrict / object to specific processing.
- Withdraw consent at any time.
Exercise any of these by emailing privacy@selfpubgo.com. We respond within 30 days. If you are unsatisfied, you have the right to lodge a complaint with your supervisory authority.
California residents have equivalent rights under CCPA / CPRA, including the right to know what we collect, the right to delete, and the right to opt out of any sale (we do not sell). Submit requests to the same address; we verify identity before processing.
8. Security
See Security & Compliance for the full technical posture. In summary: TLS 1.3 in transit; AES-256-GCM at rest; envelope encryption for OAuth tokens; row-level security on every multi-tenant table; CSP and HSTS; daily encrypted backups; no service-role keys in client bundles; quarterly restore drills.
9. Cookies
See Cookie Policy for the full list. In short: strictly necessary cookies for auth, opt-in cookies for analytics and attribution, no third-party advertising cookies.
10. Changes to this policy
We update this policy when we add sub-processors, change retention windows, or expand processing purposes. Material changes are notified by email at least 30 days before they take effect. Minor clarifications are versioned in the change log at the bottom of this page (link below).
11. Contact
privacy@selfpubgo.com — all privacy requests, including DSARs, breach notifications, and DPO inquiries.