Start now

PRIVACY

PRIVACY

Privacy policy

Last updated: August 5, 2026 Β· Version 1.0

This policy explains what personal data we process when you use ZodBook, for what purpose, for how long, and what rights you have. It is written without ambiguity: if anything is unclear, write to us and we will clarify it before you continue.

Your books do not train AI

Your manuscript content is never used to train models without your consent.

You decide where the AI runs

You can use your own AI keys or the plan's. You are always told before data is sent.

Your rights, for real

Access, rectification, erasure, portability and opposition work without opaque forms.

Contents

1. Identification and legal framework

ZodBook is a module of ZodHub, operated by ZodHub. The data controller for your personal data is ZodHub, as defined by Regulation (EU) 2016/679 (GDPR) and applicable national data protection law.

This policy applies to all personal data processed when using ZodBook: account creation, subscription, generation, editing, export and book publishing, as well as data received from the AI providers you integrate with your instance.

If you reside outside the European Economic Area, international transfers are carried out under adequate safeguards (adequacy decisions, standard contractual clauses or equivalent certifications), and this policy applies to you regardless of your jurisdiction.

2. Data controller and data protection officer

The data controller for your personal data is ZodHub, with registered office and tax ID indicated in the footer of this website. Any communication regarding data protection can be sent to the contact address listed at the end of this policy.

If your account or instance handles an especially high volume of data or sensitive data, you may appoint an internal data protection officer (DPO); in that case, the DPO's contact details are shown in your account panel and take precedence over ZodHub's for privacy communications.

ZodHub operates in compliance with the GDPR and the applicable national data protection laws in each jurisdiction where it provides service, and maintains a register of processing activities that you can request at any time.

3. What data we collect

The data we process when you use ZodBook is limited to what is necessary to operate the service:

Account data: email, name, language, password hash and authentication options you enable (passkeys, OTP, OAuth).

Payment data: managed by the provider (Stripe, PayPal, etc.); we never store the full card number or CVV.

Book data: title, premise, bible, chapter summaries, manuscript, layout, and publication metadata.

Usage data: AI generation logs (prompt, response, model, credits consumed), exports and downloads.

Support data: messages you send through contact forms and the ticket system.

Minimum technical data: IP address, user agent, and security events, for security and fraud prevention.

UI preferences: language, theme, menu position, reader font size, and last open tabs.

Reading bookmarks and notes: if you buy a book with reading rights, they sync across devices if you enable the option.

AI audit: date, model, credits consumed, prompt and response of each AI interaction β€” yours, exportable at any time.

Session logs: sign-ins, duration, approximate IP and device type, for security purposes.

Billing data: tax ID, fiscal address, and concept of each issued invoice β€” we retain them for five years by legal obligation.

4. How we use your data

We process your data for one purpose: to run the service and improve it. Specifically, we use it for the purposes described below.

Operate the account, process the subscription and issue invoices.

Run AI generations, keep consistency between chapters, and save your manuscript.

Show your progress and enable restoration and revision of the text.

Detect and prevent abuse, fraud, and uses prohibited by these terms.

Handle your support requests and comply with legal and accounting obligations.

We do not use it to train any AI model, nor do we sell it or pass it to third parties without your explicit consent. This promise also applies when you enable an external AI engine: the send is made with your explicit action and the provider receives only what is necessary for the requested generation.

5. Legal basis of processing

Each processing of personal data has a specific legal basis. For the account and billing, the basis is the execution of the subscription contract; for AI generations, the execution of the service contract; for security audits and fraud prevention, ZodHub's legitimate interest in keeping the service secure; for compliance with legal obligations (billing, tax withholdings), the applicable legal obligation.

When a specific feature is based on your explicit consent (for example, accepting training a model with your manuscript or enabling sending to an external AI engine not included in your plan), you can revoke that consent at any time from your panel without affecting the lawfulness of prior processing.

6. Automated decisions and AI providers

ZodBook uses artificial intelligence as a writing assistance tool. Decisions about manuscript content (what is published, what is sold, what is shown to the reader) are always yours.

No automated decisions with legal effects are made on personal data, except in two very limited cases: (a) automatic moderation of prompts containing terms blocked for legal reasons (CSAM, incitement to violence, etc.) and (b) automatic fraud detection in payments.

In these two cases, the automated decision is reviewable by a human at your request. To request review, open a ticket with the 'human review' tag and it will be assigned to an agent within 72 hours.

7. Your rights as a user

You have the rights recognised by the GDPR and applicable law:

Access: obtain a copy of the personal data we process about you.

Rectification: correct inaccurate or incomplete data.

Erasure: request the deletion of your data, unless there is a legal obligation to retain it.

Restriction: ask us to restrict processing in certain circumstances.

Portability: receive your data in a structured, commonly used format and transmit it to another controller.

Objection and withdrawal of consent: object to processing based on legitimate interest or withdraw prior consents at any time.

8. How we protect your manuscript

Your manuscript is yours and we do not use it to train any AI model without your explicit consent. This promise applies to the generated text, the images you upload, and the layout you design; together, they form your work and are treated as a single data unit.

The AI keys you configure in your account are stored encrypted at rest and are only decrypted at the moment of making a call to an external provider on your behalf; they are never exposed to other users, not even ZodHub administrators.

Internal access to your manuscript is limited to authorised personnel with explicit support needs, and each access is recorded in the audit log visible to you. If you find an access you do not recognise, report it and it will be investigated within 48 hours.

Your manuscript at rest: encrypted with AES-256 at the storage layer and TLS 1.2+ in transit.

Your manuscript during generation: transmitted to the AI provider only during the active call and discarded from the model context when finished.

Your manuscript in cache: cached versions are stored with a user-derived key and expire according to the retention policy.

Your manuscript in backup: encrypted backups are kept for 30 days and cryptographically destroyed upon expiry.

Your manuscript in export: PDF and EPUB are generated locally on your instance when possible; when done on server, the file is deleted from temporary storage after download.

Your manuscript in support: if a technician needs to access your manuscript to resolve an incident, the access is logged and removed when the ticket is closed.

9. Security measures

ZodHub applies technical and organisational measures to protect your data: encryption at rest and in transit, optional two-factor authentication, network segmentation, encrypted backups and annual penetration testing.

Internal access to personal data is limited to personnel with explicit support needs, and each access is logged. Passwords are stored with bcrypt (cost 12) and never stored in clear. API keys you configure are encrypted with AES-256-GCM before being written to disk.

In the event of a security incident affecting your personal data, we will notify you within 72 hours of detection, together with the nature of the incident, the data affected, and the measures we have taken. This notification is sent by email to the address associated with your account.

10. Data retention

Personal data is kept while you maintain an active account and for the applicable legal period after cancellation. By default: invoices are kept for five years (tax regulations), AI audit logs are kept for three years (operational justification) and account data is deleted one year after cancellation, unless there is a legal obligation to keep it longer.

Account data: up to 1 year after cancellation, unless legally required.

Invoices: 5 years by tax obligation.

AI audit logs: 3 years for operational justification.

Manuscript and associated files: up to 30 days after requested deletion (active purge).

Support tickets and encrypted backups: up to 2 years after closure or 90 additional days before overwrite, unless you request earlier deletion.

The content of your manuscript is kept until you delete it. If you delete a book, the row is marked as deleted and the associated files are purged in the next maintenance cycle (maximum 30 days). Encrypted backups may retain references for up to 90 additional days before being overwritten.

If you want to request immediate deletion of your entire account and all your data without waiting for the maintenance cycle, open a ticket with the 'immediate deletion' tag and it will be executed within 48 hours after verifying your identity.

11. Cookies and similar technologies

ZodBook uses strictly necessary technical cookies for the session to work and to keep your preferences (language, theme, menu position). We do not use advertising or cross-site tracking cookies.

12. Children

The service is not directed at children under 14. Creating an account and signing up to subscriptions requires legal majority in the user's jurisdiction.

If we detect that a child under 14 has created an account or is using the service, we will close the account and delete the associated data without delay. If you are the legal guardian of a minor and detect unauthorised use, write to us so we can act immediately.

13. AI providers as data processors

When you enable an external AI provider (OpenAI, Anthropic, Google, Mistral, Ollama, etc.), that provider acts as a data processor for the data you send to it. ZodHub has signed standard contractual clauses of the European Commission or equivalent with each provider, regulating the processing, retention and security of data transiting through their infrastructure.

14. Sub-processors and international transfers

You can view the list of sub-processors that process personal data on behalf of ZodHub at any time from your account panel, under 'Privacy and sub-processors'. The list is updated within 48 hours of any change.

International transfers outside the EEA are carried out under European Commission standard contractual clauses or equivalent, depending on the sub-processor's destination country.

15. Audit and traceability

Every action that affects personal data (account creation, AI generation, export, cancellation, support request, etc.) is logged with date, type of action and reference to the affected data. This log is yours and you can export it at any time from your panel.

16. Changes to this policy

We may update this policy to reflect changes in the service or in the law. You will be notified by email and via an in-panel notice at least 14 days before they enter into force.

17. Governing law and jurisdiction

This policy is governed by the law of your country of residence, for consumers, and by the legislation the parties have designated in their contract, in all other cases; for any dispute arising from this policy, the parties submit to the competent courts of your place of residence if you are a consumer, or to the courts of ZodHub's registered office otherwise β€” this clause does not affect your right to lodge a complaint with the supervisory authority.

18. Complaints to the supervisory authority

If you consider that we have not properly handled your request, you may lodge a complaint with the competent supervisory authority in your jurisdiction. In the European Economic Area, the main supervisory authority is the one of the country where you reside; in other jurisdictions, the equivalent authority designated by local law.

Before lodging a complaint, we encourage you to write to us through the contact channel described below: most discrepancies are resolved within 14 days without needing to escalate to a regulatory authority.

19. Main supervisory authority

For users in the European Economic Area, the main supervisory authority is the Spanish Data Protection Agency (AEPD), with registered office at C/ Jorge Juan, 6, 28001 Madrid. For users in other jurisdictions, the applicable supervisory authority is the one designated by local law.

20. Contact and DPO

For any question about privacy, to exercise your rights, or to request information about sub-processors, write to us through the ZodHub contact page identifying yourself as a ZodBook user; we will respond within the applicable legal period (maximum 30 calendar days, extendable to 60 days in complex cases with prior notification).