Privacy Policy

Last updated: 11 August 2026

This Privacy Policy explains how Terp Tech Pub, LLC ("Self-Publish.ai," "we," "us") collects, uses, stores, and protects your information when you use our platform and services. This policy applies to all users worldwide and complies with GDPR, CCPA, and other applicable privacy laws.

Our Key Commitments

  • We never sell your personal information
  • We never use your manuscripts or creative content to train AI or machine learning models
  • We collect only data necessary to provide the Platform
  • You can export or delete your data at any time
  • You own your content, always
  • We use industry-standard encryption to protect your data

1. Information We Collect

We collect what you give us (name, email, manuscripts), what is generated by your usage (feature clicks, page views), and basic device info (browser type). We never collect SSNs, biometric data, or info from children.

Information you provide

  • Account info: Name, email, password, profile details
  • Payment info: Billing address and payment method (processed by Stripe; we never store full card numbers)
  • Content: Manuscripts, covers, metadata, descriptions, and other materials you upload or create
  • Communications: Support messages and interactions with Dorothy (our onboarding assistant)
  • Publishing info: Book titles, author names, ISBNs, genre selections, preferences

Information collected automatically

  • Device info: Browser type, OS, device type, screen resolution
  • Log data: IP address, pages viewed, features used, referring URLs
  • Usage data: Features accessed, session duration, tool usage patterns
  • Cookies: As described in Section 6
  • Credit usage data: Features used, credit costs per operation, daily and monthly consumption patterns, top-up purchase history. Used solely to operate the billing system and detect abuse.

Before you have an account

If you send us the contact form without signing up, we store what you typed along with your IP address, browser user agent, and the page that referred you. We keep those three so we can tell a genuine enquiry from an automated one and rate limit abuse. This is the only case where we hold data about someone who has never had an account.

Information from third parties

  • Google Sign-In: Name, email, profile picture. Google is our only third-party sign-in; the alternative is a code emailed to you.
  • Payment processor (Stripe): Transaction confirmations, billing status
  • We do not receive anything from retailers. Sales and royalty data stay in your own retailer account.

2. How We Use Your Information

We use your data to run the platform, process payments, improve our tools, and send important updates. That is it.

  • Operate the Platform: Store and process your content, provide editing, design and publishing tools, and produce the files you export
  • Process payments: Subscriptions, credits, invoices, refunds, fraud prevention
  • Manage credits and billing: Track monthly credit pool usage, Daily Roulette bonus credits, top-up credit balances, and subscription tier entitlements.
  • Improve the Platform: Analyze aggregate usage patterns, fix bugs, develop features (we never use individual manuscripts or content for this)
  • Communicate: Account notifications, customer support, product updates and tips (you can opt out of non-essential emails)
  • Security: Detect fraud, prevent abuse, comply with legal obligations

3. How We Share Your Information

We share data only with service providers who help run the platform and distribution partners you choose. We never sell your data.

We do not sell, rent, or trade your personal information. We share it only with:

  • Service providers: Cloud hosting (AWS/Google Cloud), payment processing (Stripe), credit and billing infrastructure, email delivery, analytics. All bound by data processing agreements.
  • Retailers: nothing is sent by us. We have no server-side integration with Amazon KDP, IngramSpark, Apple Books or any other retailer, and our servers never contact one. If you install our optional KDP browser extension, it moves your book's metadata and files from your browser into the KDP form in your own signed-in session, at your instruction; that transfer happens on your machine, under your retailer account, and is never routed through us.
  • Advertising measurement: The Meta Pixel on our production site reports page views and conversion events to Meta, as described in Section 6.
  • Legal requirements: Court orders, government requests, or to protect rights/safety. We notify you when legally permitted.
  • Business transfers: In a merger or acquisition, your data may transfer with 30 days advance notice.
See the full sub-processor list

4. Data Retention

We keep data while you have an account. After you ask us to delete it, there is a 30-day grace period and then it is erased (except payment records kept 7 years for tax law).

  • Account and content data: Duration of account, then erased 30 days after you request deletion
  • Payment records: 7 years (tax/financial law requirement)
  • Usage/analytics data: Up to 3 years, anonymized
  • Support communications: 2 years after resolution

5. Data Security

We encrypt everything in transit and at rest, limit employee access, and will notify you within 72 hours of any breach.

We protect your data with TLS 1.2+ encryption in transit, AES-256 encryption at rest, role-based access controls, regular security audits and penetration testing, and a documented incident response plan with 72-hour breach notification. No system is 100% secure, but we take every reasonable precaution.

6. Cookies

Two cookies sign you in and keep that sign-in safe. Our production site also loads the Meta Pixel, which is an advertising cookie and is not strictly necessary.

  • authn_session: Holds your signed session so the Platform knows you are logged in. Expires after 8 hours. HttpOnly, so no script can read it.
  • authn_oauth_state: Set only while you are being redirected to and from Google sign-in, to prove the sign-in finished in the same browser that started it. Expires after 10 minutes and is deleted as soon as the redirect completes.

Both cookies above are strictly necessary to provide a service you asked for, so they are exempt from the consent requirement under GDPR and the ePrivacy Directive.

Meta Pixel

Our production site loads the Meta Pixel from Meta Platforms, Inc. It sets Meta's own _fbp and _fbc cookies and reports events to Meta: page views, and whether you completed signup, started checkout, subscribed, or purchased. We use it to measure whether our advertising works. It is not loaded in development or preview environments.

The Meta Pixel is an advertising cookie, not a strictly necessary one, so unlike the two above it is not exempt from consent. We are changing how it is loaded so that it runs only where we have a lawful basis to run it. Until that ships, you can block it with your browser's tracking protection or an ad blocker, and it will simply never load. Meta is listed on our sub-processor page.

Payments happen on Stripe's own hosted checkout page. Any cookie Stripe sets there belongs to Stripe's domain, not ours, and is covered by Stripe's privacy policy.

7. Your Rights

You can access, correct, delete, and export your data anytime. EU and California users have additional specific rights.

All users

  • Access, correct, or delete your personal data
  • Export your content and data in standard formats
  • Ask us to stop emailing you anything that is not essential to your account

EEA and UK users (GDPR)

  • Right to restriction of processing and data portability
  • Right to object to processing based on legitimate interests
  • Right not to be subject to solely automated decisions
  • Right to lodge a complaint with your local data protection authority

California residents (CCPA)

  • Right to know what personal info is collected and how it is used
  • Right to delete and correct personal info
  • Right to opt out of sale or sharing. We do not sell your data. The Meta Pixel described in Section 6 does count as sharing for cross-context advertising, and the opt-out switch in Settings does not yet stop it, so email us and we will action it by hand until that is wired up.
  • Right to non-discrimination for exercising privacy rights

To exercise any rights, email support@terptechpub.com. We respond within 30 days.

8. International Data Transfers

Self-Publish.ai is US-based. If you are outside the US, your data transfers to our US servers. We use Standard Contractual Clauses to protect EU user data.

The Platform operates from the United States. International users consent to data transfer to the US. For EEA/UK/Swiss users, transfers are protected by EU-approved Standard Contractual Clauses and data processing agreements with all service providers.

9. Children

The Platform is not intended for anyone under 18. We do not knowingly collect data from minors. If we discover we have, we will delete it immediately. Contact support@terptechpub.com to report.

10. Changes to This Policy

We may update this policy from time to time. For material changes, we will email you at least 30 days before they take effect and post a notice on the Platform. Continued use after the effective date means you accept the updated policy.

11. Contact Us

Terp Tech Pub, LLC Andy Symonds and Pouya Barrach-Yousefi 2361 Vista Parkway, Unit 1, West Palm Beach, FL 33411 Email: support@terptechpub.com By using Self-Publish.ai, you acknowledge that you have read and understood this Privacy Policy.