Legal

Privacy Policy

Effective: 10 May 2026 · Updated: 7 October 2026 · Version 1.3

This Privacy Policy describes how SOFTSURE LLC, the operator of SelfPub Go (“we”, “us”, “the platform”), collects, uses, shares, and protects personal data of users in the European Economic Area, the United Kingdom, the United States, and other regions we serve. We comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA / CPRA), and applicable state privacy laws.

1. Who we are (data controller)

The data controller is SOFTSURE LLC, a limited liability company registered in Georgia (ID 445788915), Angisa Street N 20-22, Building N 33, Batumi, Georgia, operating SelfPub Go at selfpubgo.com. We act as a data controller for account information and as a data processor for the Amazon Ads data we retrieve on your behalf and the book details and files you add. Your KDP royalty reports are not uploaded to us — see section 2. Contact: privacy@selfpubgo.com; the company directly: contact@softsureco.com.

2. What we collect, and the legal basis for each

  • Account data — email, full name, hashed password or OAuth provider id. Legal basis: contract performance (Article 6(1)(b)).
  • Workspace metadata — workspace name, primary marketplace, default currency, locale. Legal basis: contract performance.
  • Amazon Ads credentials— encrypted refresh tokens obtained via Amazon’s OAuth flow. We never see your Amazon password. Legal basis: contract performance + your explicit consent at OAuth grant time.
  • Amazon Ads data — campaigns, keywords, search terms and performance figures (including Kindle pages read from ads) that we retrieve from Amazon through your authorisation. Stored on your behalf, processed only for your workspace. Legal basis: contract performance.
  • KDP royalty reports — not collected. The desktop app reads them on your own computer and keeps the result in a local database there; royalty amounts, units sold and dates never reach our servers. To set up your books, the app sends us only the book identifiers it finds in a report — ASIN, marketplace, format, title and author name. Legal basis for those identifiers: contract performance.
  • Approximate location — the country (and, for a few regions, the region) worked out from the IP address of your requests, so that AI features stay off where our AI provider does not offer them. We keep only the country code with your account, not the IP address. IP Geolocation by DB-IP. Legal basis: legitimate interest (Article 6(1)(f)).
  • Manuscripts and book metadata — files and text you upload. Treated as your intellectual property. Legal basis: contract performance.
  • Usage analytics — page views, referring site, device and browser, and a small set of product events (sign-up, installer downloads), reported to Google Analytics 4. Opting in is what lets the tag store anything on your device and recognise you across visits: Google then assigns a random client ID kept in the _gacookie. That is pseudonymous rather than anonymous. Either way your IP address reaches Google’s servers as part of the request — section 5 explains what is and is not sent if you decline. We attach no name, email, or account ID to these events. Legal basis: consent (Article 6(1)(a)).
  • Referral source of your registration — the campaign tags a link carried (utm_source and friends, or agclid/msclkid from an ad click), the site that referred you (host and path, never its query string), and the first page you opened. Recorded by us, not by a third party, and sent to our own server only when you actually register. It carries no name, e-mail, account ID or device identifier. Where it is kept depends on your banner answer: accepting analytics stores it in our own spg_attrcookie for 90 days, otherwise it lives in your browser’s session storage and is gone when you close the tab. Legal basis: legitimate interest in knowing which channels bring authors to us (Article 6(1)(f)) — and, for the 90-day cookie, your consent to analytics storage.
  • Desktop app install records — when you run the desktop app it reports a random installation ID it generated itself, the app version, the operating system name, and the time it last started. Once you sign in, that record is linked to your account. No device identifier, serial number, MAC address or advertising ID is collected, and the ID means nothing outside our database. Purpose: knowing which builds are actually in use, so support and updates work. Legal basis: legitimate interest (Article 6(1)(f)).
  • Diagnostic logs — error reports, request traces. Personal data is redacted before logging. Retention: 30 days. Legal basis: legitimate interest in operating a reliable service.

We do not collect special-category data (race, religion, health), and we do not knowingly collect data from children under 16. If you believe a child has provided personal data, contact us immediately.

3. How we use your data

We process personal data to:

  • Provide the platform and the modules you have enabled.
  • Send transactional email (account verification, password reset, billing receipts, security alerts) — these cannot be opted out of while you have an active account.
  • Send product updates and educational content — opt-in at signup, opt-out anytime via email footer.
  • Improve the platform — aggregated usage analytics (see section 2), A/B tests on UI improvements.
  • Detect fraud, abuse, and policy violations.
  • Comply with legal obligations (tax, audit, lawful subpoena).

We do not sell personal data. We do not use your data, your ad campaigns, or your manuscripts to train AI models — ours or any third party’s.

4. Sub-processors

We use the following sub-processors, each bound by Data Processing Agreements aligned with GDPR Article 28:

  • Supabase(US / EU regions) — authentication, database, file storage. EU-region tenants are routed exclusively to Supabase’s EU region.
  • Vercel(US / EU regions) — application hosting, CDN. Personal data stays in the user’s region; CDN edge nodes cache only public marketing pages.
  • Anthropic (US / EU) — Claude API for AI Tools features. EU-region tenants route to the Anthropic EU endpoint. Anthropic does not train on our API data per its enterprise terms.
  • Resend (US) — transactional and marketing email delivery.
  • Google LLC (United States) — Google Analytics 4, property G-BS9DPNB333, for the usage analytics described in section 2. Loaded on every page but restricted by Google Consent Mode v2: it stores nothing and sends only cookieless pings until you accept analytics. Processing takes place on Google infrastructure in the United States.
  • Cloudflare (global) — DNS, DDoS mitigation, R2 object storage for large file uploads.
  • Amazon Advertising API — read/write to your Amazon Ads account. We act on your behalf via your OAuth grant and submit data only to Amazon.

A current sub-processor list with version history is maintained at /security. Material additions are notified by email at least 30 days in advance with a right to object.

5. International transfers

For EU users, account and content data primarily stays in the EU. Analytics is the exception, and it is opt-in: Google Analytics 4 is operated by Google LLC in the United States, so accepting analytics cookies sends your page views, device information, and IP address to servers in the US. If you decline, the tag stores nothing on your device and sends only cookieless pings with no identifier that can single you out — though the request itself still reaches Google.

For other third-country transfers we rely on Standard Contractual Clauses (Commission Decision 2021/914) with supplementary measures including encryption at rest and in transit.

6. Retention

  • Active account data — for the lifetime of your account.
  • Account deletion — from the app (Settings → Account → Delete account) sign-in closes at once and your data is erased within minutes; a request by email is completed within 30 days. Backups roll off within 90 days.
  • Record of a deletion — your email address, account number and the dates of sign-up and deletion, kept for 2 years to show the request was honoured. Used for nothing else and not shared.
  • Billing records — 7 years (legal obligation in most jurisdictions).
  • Diagnostic logs — 30 days.
  • Referral source — 90 days in your browser (or one visit without the cookie); the copy stored with your registration is deleted with your account.
  • Install records — deleted with your account. A record never linked to any account holds no personal data (a random ID, version, OS) and is kept as long-term product statistics.
  • Audit logs (Amazon Agent compliance) — 12 months minimum, longer if required by law.

7. Your rights

Under GDPR / UK GDPR, you have the right to:

  • Access — request a copy of all personal data we hold.
  • Rectify — correct inaccurate data.
  • Erase — delete your account in the app, or request deletion (subject to legal retention obligations).
  • Port — receive data in machine-readable format.
  • Restrict / object to specific processing.
  • Withdraw consent at any time.

Exercise any of these by emailing privacy@selfpubgo.com. We respond within 30 days. If you are unsatisfied, you have the right to lodge a complaint with your supervisory authority.

California residents have equivalent rights under CCPA / CPRA, including the right to know what we collect, the right to delete, and the right to opt out of any sale (we do not sell). Submit requests to the same address; we verify identity before processing.

8. Security

See Security & Compliance for the full technical posture. In summary: TLS 1.3 in transit; AES-256-GCM at rest; envelope encryption for OAuth tokens; row-level security on every multi-tenant table; CSP and HSTS; daily encrypted backups; no service-role keys in client bundles; quarterly restore drills.

9. Cookies

See Cookie Policy for the full list. In short: strictly necessary cookies for auth, opt-in cookies for Google Analytics 4 plus our own 90-day spg_attr cookie that remembers which channel brought you (set only if you accept analytics), and no advertising cookies at present.

10. Changes to this policy

We update this policy when we add sub-processors, change retention windows, or expand processing purposes. Material changes are notified by email at least 30 days before they take effect. Minor clarifications are versioned in the change log at the bottom of this page (link below).

11. Contact

privacy@selfpubgo.com — all privacy requests, including DSARs, breach notifications, and DPO inquiries.