Privacy Policy
Last updated: February 21, 2026
1. Information We Collect
When you create an account or use BookClub, we may collect:
- Account information: email address, display name, and password (hashed)
- Profile information: bio, trading style, and website (optional, provided by you)
- Usage data: reading progress, bookmarks, chapter completions, and reading streaks
- Community content: chat messages, questions, and reactions you post
- Payment information: processed securely by Stripe; we do not store card numbers
- Technical data: IP address, browser type, and device information collected automatically
2. How We Use Your Information
- Provide and maintain the BookClub service
- Process membership payments via Stripe
- Track your reading progress and display it to you
- Send transactional emails (account confirmation, password reset, new chapter notifications)
- Display your public profile to other members (display name, avatar, bio)
- Moderate community content for safety
- Improve the service through aggregate, anonymized analytics
3. Data Storage & Security
Your data is stored securely using Supabase (hosted on AWS) with row-level security policies. Authentication is handled by Supabase Auth with encrypted password storage. All connections use HTTPS/TLS encryption in transit.
Payment processing is handled entirely by Stripe. We store your Stripe customer ID for subscription management but never have access to your full card details.
4. Cookies
BookClub uses cookies for:
- Authentication: Session cookies to keep you logged in (essential)
- Preferences: Reader theme and font size settings (functional)
We do not use third-party advertising or tracking cookies.
5. Third-Party Services
We share data with the following services only as needed to operate BookClub:
- Supabase: Database hosting and authentication
- Stripe: Payment processing
- Vercel: Application hosting
- Resend: Transactional email delivery
We do not sell your personal data to any third party.
6. Your Rights
You have the right to:
- Access: View your personal data through your account page
- Correct: Update your profile information at any time
- Delete: Delete your account and all associated data from the account settings page
- Object: Contact us to opt out of non-essential data processing
Account deletion permanently removes your profile, reading progress, bookmarks, messages, and membership data. This action cannot be undone.
7. Data Retention
We retain your data for as long as your account is active. If you delete your account, all personal data is permanently removed within 30 days. Anonymized, aggregate data (e.g., total chapter completions) may be retained indefinitely.
8. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated via email or an in-app notification. Continued use of BookClub after changes constitutes acceptance of the updated policy.
9. Contact
For privacy-related questions or requests, contact us at support@kjbook.club.