Privacy Policy
What we hold, and why.
Last updated 31 July 2026
We collect what the platform needs to work and little else. This page lists it item by item, says why each is held, and tells you how to get it deleted.
1. Who is responsible
The controller of your personal data is GenerationIX LLC. For questions or requests: ov@generationix.net.
2. What we collect
| Account | Email address, password hash, display name, and the bio you choose to show. | To sign you in and to credit your books. |
| Books you publish | Your manuscript file, the converted text, cover choices, price, and metadata. | To convert, screen, sell, and display your book. |
| Screening records | The verdict on each manuscript, the category scores, and any passages the classifier cited. | So a decision can be explained and appealed. Retained even after a book is removed. |
| Purchases | What you bought, when, the amount, and a payment reference from Helcim. | To give you access to the book, and for tax and accounting. |
| Earnings | The royalty ledger for each sale, and your payout details. | To pay you and to show you where the money went. |
| Reading position | Which chapter you last read in a book you own. | So the reader resumes where you left off. |
We do not hold your card details. Payment is handled by Helcim; card numbers go to them, never to us. We keep only a transaction reference and the amount.
3. Why we are allowed to hold it
Account data, books, purchases, and earnings are processed to perform our contract with you — without them the platform cannot do what you asked of it.
Screening records and fraud checks rest on our legitimate interest in running a safe store and being able to justify a moderation decision. Tax and accounting records are kept to meet a legal obligation.
4. Who else sees it
We do not sell your data and we do not share it for advertising. It reaches these processors only because the platform needs them:
| Supabase | Database, authentication, and file storage. | Hosting the data itself. |
| Helcim | Payment processing. | Handles card details; we never see them. |
| xAI | Content screening. | Manuscript text is sent for policy classification when you publish. |
| Hostinger | Runs the application. | Server logs, including IP addresses. |
We may also disclose data where the law requires it, or to establish or defend a legal claim.
5. What is public
When you publish a book, your display name and bio become public, alongside the book itself. Your email address, your earnings, your purchases, and your reading position are never shown to anyone else.
Author earnings are enforced as private at the database level, not merely hidden in the interface: one author cannot read another’s figures.
6. How long we keep it
| Account and books | Until you delete them, plus 30 days in backups. |
| Orders and ledger entries | 7 years, as tax law requires. Retained even after an account closes. |
| Screening records | Kept while the book exists, and for the appeal window after. |
| Server logs | 90 days. |
7. Your rights
You can ask us to show you what we hold, correct it, delete it, or hand it over in a portable format. You can object to processing based on legitimate interest. Where we rely on consent, you can withdraw it at any time.
Most of this you can do yourself: unpublish a book from your dashboard, or close your account to remove your profile. For anything else, email ov@generationix.net and we will respond within 30 days.
Deletion cannot remove records we must keep for tax, or copies of a book already downloaded by a reader.
If you are in the UK or EU and think we have handled your data badly, you may complain to your local data protection authority.
8. Cookies
We set a session cookie so you stay signed in, and nothing else. There is no advertising network, no analytics profile, and no third-party tracker on this site — which is why you have not been asked to dismiss a consent banner.
9. Where your data lives
GenerationIX LLC is a US company. Your data is stored in the United States — the database in Oregon (Supabase, US West) and the application on Hostinger.
If you are in the UK or EU that means your data leaves your region. The transfer mechanism we rely on is to be confirmed — Standard Contractual Clauses or the EU–US Data Privacy Framework, which needs settling before taking EU customers.
10. Changes
If we change this policy in a way that materially affects you, we will tell you before it takes effect. The date at the top always reflects the current version. See also our terms of service and content policy.