Legal
Privacy policy
Effective September 2, 2026
1. Scope and who we are
Sidewave Digital Inc. operates EBookBrew (“EBookBrew,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, disclose, and keep personal information when you use ebookbrew.com, the EBookBrew application, its AI and export features, MCP access, support, and related services (together, the “Service”).
Sidewave Digital Inc. is the organization responsible for personal information covered by this policy. Our Privacy Officer can be reached at privacy@ebookbrew.com.
This policy does not govern a third-party site, publishing platform, retailer, or MCP client that you choose to use. Its own policy applies to its processing.
2. Information we collect
We collect the following categories of information:
- Account and identity information: name, email address, authentication identifier, login method, session and security data, and account settings.
- Book and AI content: ideas, prompts, notes, instructions, audiences, tones, titles, author names, outlines, chapters, edits, revision requests, cover directions, generated text and images, exports, and other material that you submit or create.
- Billing and credit information: Stripe customer and transaction references, plan, purchase, amount, currency, tax information, payment status, receipt links, subscription status, credit grants and use, refunds, and chargebacks. Stripe processes full payment-card details. We do not store complete card numbers.
- Usage and device information: IP address, date and time, requested page or operation, referring page, approximate location from IP, browser, operating system, device type, cookies, session identifiers, feature interactions, and performance data.
- AI and diagnostic information: model and provider, prompts and output, token and credit use, generation state, error messages, traces, logs, latency, and other data used to operate, monitor, and troubleshoot AI requests.
- Agent and integration information: OAuth identifiers, connected-client name and version, operation, scope, request time, result type, status, duration, credits used, and security hashes. Our agent request audit log is designed not to store manuscript text, prompts, responses, or bearer tokens, but the project content that an agent reads or changes remains stored with the project.
- Communications: support requests, legal or privacy requests, feedback, email delivery records, and any information that you include in a message to us.
You can put information about yourself or another person in book content. This can include sensitive information. Do not submit personal, confidential, health, financial, or other sensitive information unless it is necessary and you have the legal authority and required consent to process it with the Service.
3. Where information comes from
We collect information directly from you, from your browser or device, and from your use of the Service. We also receive information from WorkOS and a social sign-in provider when you sign in, from Stripe when you make or manage a payment, from an MCP client that you connect, and from service providers that report security, delivery, analytics, or technical events.
4. How we use information
We use information to:
- create and secure your account and authenticate requests;
- generate, edit, save, display, format, and export books;
- send content to AI services and return their output;
- process payments, subscriptions, taxes, credits, refunds, and receipts;
- provide support and send service, security, billing, and account messages;
- measure product use, maintain performance, diagnose errors, and improve the Service;
- detect fraud, abuse, prohibited content, security threats, and violations of our Terms of Use;
- protect users, EBookBrew, our providers, and the public;
- establish, exercise, or defend legal claims and enforce agreements; and
- meet tax, accounting, legal, regulatory, and law-enforcement duties.
Authorized personnel can access information when reasonably needed for support, security, abuse review, legal compliance, or service operations. We can use aggregated or de-identified information for analytics, research, planning, and improvement where law permits.
5. AI processing
When you request generation, we send the content needed for the request to Vercel AI Gateway and to an AI model or inference provider. This can include your idea, brief, chapter plan, prior chapter summaries, revision instructions, book metadata, and generated content. Cover and coloring-book requests also send image instructions.
Models and inference providers can change by feature, availability, routing, cost, or performance. A request can be processed outside Canada. The provider’s retention, abuse-review, and model-training practices depend on the provider and the data controls available for that request. EBookBrew does not train its own foundation model. We do not promise zero retention or no provider training unless we state that protection for a feature in writing.
We use AI observability to find errors and measure performance. Our analytics and observability provider can receive AI request and response content, account or project identifiers, model data, token use, cost, timing, and error data. Do not use the Service for secrets or sensitive data that is not suitable for this processing.
AI can infer information about a person and can produce inaccurate personal information. EBookBrew does not use AI output to make decisions about your eligibility, credit, employment, housing, health, insurance, education, or legal rights.
6. When we disclose information
We disclose information only as described in this policy or with your direction:
- Service providers: Vercel for hosting, private file storage, web analytics, and AI Gateway; Neon for database hosting; WorkOS for authentication and OAuth; Stripe for checkout, billing, tax, and fraud controls; PostHog for product analytics, error tracking, logs, session replay, feature flags, and AI observability; Postmark for transactional email; and the model and inference providers selected through AI Gateway.
- Connected services: an MCP client, agent, social sign-in provider, or other service that you choose to connect. Your instructions determine what it can receive.
- Professional advisers: lawyers, accountants, auditors, insurers, and other advisers that need information to provide their services.
- Legal and safety recipients: courts, regulators, law enforcement, rights holders, affected people, or other parties when we reasonably believe disclosure is required by law or is needed to protect rights, safety, property, users, the Service, or the public.
- Business transaction recipients: a prospective or actual buyer, investor, lender, affiliate, or successor in a financing, reorganization, merger, sale, insolvency, or transfer of all or part of our business or assets.
Providers can use their own subprocessors. We require service providers to process information for contracted purposes, subject to applicable law and their agreements with us.
7. No sale or targeted advertising
We do not sell personal information as “sale” is defined by applicable privacy law. We do not share personal information for cross-context behavioural advertising, and we do not use it to show third-party targeted ads. We do not knowingly use or disclose sensitive personal information to infer characteristics about you.
8. Cookies, storage, analytics, and replay
WorkOS and EBookBrew use necessary cookies for sign-in, security, sessions, and account functions. The site uses session storage to carry an idea through the sign-in flow.
PostHog can use cookies and browser storage to recognize a browser, measure product use, capture page and feature interactions, report errors, and support feature settings. Depending on our PostHog project settings, it can also create a playback of a user session. Form inputs are masked by default, but visible page text and interactions can be recorded. Vercel Web Analytics collects aggregated page, referrer, device, and approximate-location data without third-party cookies.
You can block or delete cookies and browser storage in your browser. The Service might not sign you in or work correctly if you block necessary storage. Some browsers and networks can also block analytics. “Do Not Track” is not a common legal standard. We respond to legally required opt-out preference signals when they apply to our processing.
9. Legal bases for processing
Where European, UK, or similar law requires a legal basis, we process information as needed to perform our contract with you, including to create your account, generate content, provide exports, and process payments. We also process information for our legitimate interests in operating, securing, supporting, measuring, and improving the Service; preventing fraud and abuse; and protecting legal rights. We process information to comply with legal duties and, where required, with your consent. We can process information to protect a person’s vital interests in an emergency.
You can withdraw consent where consent is the legal basis. This does not affect earlier processing. If information is required to provide the Service or meet a legal duty, we might not be able to provide the affected function without it.
10. International processing
We are based in Canada. Our providers and their subprocessors can process information in Canada, the United States, and other countries where they operate. These countries can have different privacy laws, and their courts or authorities can lawfully access information.
Where required, we use contracts or other approved safeguards for an international transfer. Contact our Privacy Officer for information about safeguards that apply to your data.
11. Retention and deletion
We keep personal information only as long as reasonably needed for the purposes in this policy. The period depends on the type of information, account status, sensitivity, legal duties, security needs, disputes, limitation periods, and whether deletion is technically practical.
- We normally keep account and book content while your account is active so that you can continue to edit and export it.
- After an account or content deletion request, information can remain for a reasonable period in backups and recovery systems before it is overwritten.
- We keep transaction, tax, payment, credit-ledger, consent, security, fraud, and legal records for the periods required or permitted by law and for audit and dispute purposes.
- We keep operational, analytics, AI, and agent logs for periods suited to security, support, product analysis, and cost control. We can keep a record of a prohibited event after related content is deleted.
- We can keep aggregated or de-identified information where it can no longer reasonably identify a person.
Providers keep information under their own retention schedules. Files that you download, publish, sell, or send to another service are outside our control. Closing your account does not remove those copies.
12. Security
We use administrative, technical, and physical measures that are designed for the nature of the information. These include managed infrastructure, encrypted transport, access controls, authentication, private file storage, signed download access, logging, and provider security controls.
No system is completely secure. We cannot guarantee that information will never be lost, accessed, used, or disclosed without permission. You are responsible for strong account security, secure connected clients, and your own backups. Contact privacy@ebookbrew.com if you believe that an account or data security event has occurred.
13. Your privacy rights
Depending on where you live, you can have the right to:
- know whether we process your personal information and access a copy;
- correct inaccurate or incomplete information;
- delete information;
- receive portable information that you gave us;
- withdraw consent;
- object to or restrict some processing;
- opt out of a sale, targeted advertising, or qualifying profiling;
- appeal a refusal of a request; and
- make a complaint to a privacy regulator.
Send a request to privacy@ebookbrew.com. State the right that you want to use and the account email. We can ask for information to verify your identity and authority. An authorized agent can make a request where law permits, but we can require proof of authority and direct identity verification. We will not discriminate against you for using a privacy right.
A right can have legal exceptions. For example, we can keep information that is needed for billing, security, fraud prevention, a legal duty, or a claim. If we deny a request, we will explain the reason and any appeal right that applies.
In Canada, you can contact our Privacy Officer first about a concern. If it is not resolved, you can contact the Office of the Privacy Commissioner of Canada or the privacy regulator in your province.
14. Additional US state disclosures
This section applies only where a US state privacy law applies to us and to your information. In the preceding 12 months, we collected the categories described in section 2. These can map to identifiers; customer-record information; commercial information; internet or network activity; approximate geolocation; audio, electronic, visual, or similar information; professional or education information that a user puts in content; inferences from product choices; and sensitive information that a user chooses to submit.
We collect these categories from the sources in section 3, use them for the purposes in sections 4 and 5, and disclose them for business purposes to the recipients in section 6. We do not sell or share them for cross-context behavioural advertising. We do not offer a financial incentive for personal information.
Residents can have rights to know, access, correct, delete, or obtain a copy of information and to opt out of sale, targeted advertising, or qualifying profiling. Because we do not conduct those opt-out activities, an opt-out request will confirm our practice. You can also have a right to limit some uses of sensitive information and to appeal a decision. Use the request method in section 13.
15. Children
The Service is for adults and is not directed to a person under 18. We do not knowingly collect personal information directly from a child. If you believe that a child gave us personal information, contact contact[at]ebookbrew.com. If you put information about a minor in book content, you are responsible for having all required authority and consent.
16. Changes to this policy
We can update this policy as the Service, providers, or laws change. We will post the new version and change the effective date. We will give additional notice before a material change when law requires it. If a change needs consent, we will ask for it.
17. Contact us
Send a privacy question, request, or complaint to: contact[at]ebookbrew.com
See our Terms of Use for the rules that apply to use of EBookBrew.