Loading…

BookSeeking Privacy Notice

Last updated: 14 July 2026

Version 1.0

BookSeeking is an early-access reading and book-recommendation service. This notice explains what information BookSeeking (“we”, “us”) handles, why we handle it, and the services we use to do so.

The short version

  • We use your account details and reading library to operate BookSeeking and produce recommendations.
  • We do not sell your personal information, serve targeted advertising, or use session replay.
  • Book analysis can use OpenAI's API. We send information about the book, not your email, name, BookSeeking account ID, ratings, feedback, or a copy of your full library.
  • We use Microsoft Azure for hosting and operational telemetry. Browser analytics, where enabled, is deliberately limited and uses no analytics cookies or stable account identifier.
  • A necessary session cookie keeps you signed in. Some display preferences are stored locally in your browser.
  • You can ask to access, correct, or delete your account information by contacting us.

Information we collect and hold

Account and sign-in information

We collect your email address for passwordless sign-in. We also hold verification and session records needed to authenticate you and let you revoke a session. If you choose an available social sign-in provider, we receive the details that provider supplies, which can include your name, email address, profile image, provider account identifier, and the tokens needed to keep the account linked.

Your reading information

We store the books in your library and information you add about them, such as reading status, rating, dates, and a personal title correction. We also store recommendations and the evidence behind them, recommendation feedback, and reports you submit when something looks wrong.

A reading library can indirectly reveal interests in areas such as health, politics, religion, or other sensitive subjects. We do not ask you to declare those characteristics, but we treat your library as private account data.

Book-analysis information

For books in the catalogue, we hold bibliographic metadata, extracted concepts, people, places, periods and events, appeal factors, evidence, embeddings, and processing results. Much of this is shared catalogue data rather than information about one user. The fact that a particular book is in your library remains linked to your account.

Technical and operational information

We collect technical information needed to keep the service reliable and secure. Server and worker telemetry can include a timestamp, normalised or concrete request route, status and timing, error details, and pseudonymous internal user, book, job, request, or trace identifiers. A processing log can also identify the book or concept involved in a failure. These records are not intended to contain passwords, authentication tokens, session cookies, request bodies, or your email address.

Where privacy-minimised browser analytics is enabled, it records a sanitised route category or template, the deployed app version, browser and device technical information, page timing, and redacted errors. It does not send your email, account ID, library contents, search or form text, book or concept identifiers, recommendation content, or session-replay recordings. The analytics component does not use cookies or persistent browser identity. It does not start when your browser sends Global Privacy Control or Do Not Track.

Microsoft Azure can use the sending IP address transiently to derive coarse location information such as country or region. Under our current Application Insights configuration, the stored IP address is then masked to 0.0.0.0.

How we use information

We use this information to:

  • create and secure your account and send sign-in links;
  • maintain your library and show where your reading has built knowledge;
  • analyse books into concepts and related entities;
  • calculate and explain reading recommendations;
  • record and respond to feedback or reports that something is wrong;
  • enforce usage limits, investigate abuse, and protect users and the service;
  • diagnose errors, measure performance, understand aggregate site traffic, and improve BookSeeking; and
  • comply with legal obligations and valid legal requests.

Recommendations are currently calculated inside BookSeeking from stored concepts, book evidence, and related ranking signals. We do not ask an external language model to profile your full library and choose books for you. Recommendations are informational and do not make decisions about access to employment, credit, insurance, education, or similar services.

How language models are used

When a book needs analysis, BookSeeking can send OpenAI's API some or all of the following: title, author, description, categories, table of contents, index, chapter headings, existing concept labels, and portions of lawfully available book text. OpenAI returns structured material such as concepts, facets, summaries, classifications, appeal factors, canonical-match judgments, or embeddings.

We do not include your email address, name, BookSeeking user ID, reading status, rating, feedback, or full library in those requests. BookSeeking separately keeps an internal usage record that can link model cost and token counts to a pseudonymous user, book, and processing job. That internal link supports budgets, troubleshooting, and abuse prevention; it is not added to the OpenAI prompt.

OpenAI states that API inputs and outputs are not used to train or improve its models by default unless the API customer explicitly opts in. Under OpenAI's standard API controls, prompts and outputs can be retained in abuse-monitoring logs for up to 30 days, or longer where required by law. BookSeeking does not claim that Zero Data Retention applies unless that setting has been separately verified for the active OpenAI project.

Service providers and disclosures

We use service providers only where needed to operate BookSeeking:

  • Microsoft Azure hosts the application, database, queues, secrets, and Application Insights telemetry. Our primary application and telemetry resources are configured in Azure's Australia East region.
  • OpenAI processes the bounded book-analysis requests described above.
  • Resend receives your email address and sign-in-link content to deliver passwordless authentication emails. When the operator report digest is enabled or run, Resend also receives the affected item, route, reason, and bounded details from new “Report as wrong” submissions so it can deliver that digest.
  • Open Library, Google Books, and Wikidata receive bibliographic or entity lookup queries such as ISBN, title, author, concept label, or public identifier. We do not include your BookSeeking email address or account ID in those lookups.
  • A social sign-in provider, if you choose one and it is enabled, processes that sign-in under its own privacy terms.

We do not sell or rent personal information, and we do not share it for targeted advertising. We can disclose information where reasonably necessary to protect BookSeeking or others, investigate misuse, comply with law or a valid legal process, or complete a business transfer subject to appropriate protections.

Overseas processing

Our primary Azure resources are in Australia East. Some providers process information outside Australia. In particular, OpenAI and Resend can process information in the United States, and they and other providers can use subprocessors in other countries. Bibliographic services operate internationally. We minimise what is sent: for example, external book lookups do not carry your BookSeeking identity, and OpenAI book-analysis requests do not carry your account identity.

Retention

We retain your account and library information while your account is active or until it is no longer needed for the purposes above. Self-service account deletion is not yet available; a verified deletion request is handled through the contact address below. Some records can be de-identified or retained where reasonably necessary for security, accounting, dispute resolution, legal obligations, or service integrity.

Current operational periods include:

  • magic sign-in links expire after 24 hours;
  • Azure database backups use a seven-day rolling retention period;
  • Application Insights request, page-view, and exception telemetry is currently retained for 30 days; and
  • OpenAI's standard API abuse-monitoring retention can be up to 30 days as described above.

Deleting live account data does not instantly remove copies already present in a rolling backup or a provider's bounded operational log. Those copies expire through their normal retention cycle unless a longer period is legally required.

Security

We use authenticated sessions, access controls, encrypted network connections, restricted cloud resources, and operational monitoring to protect information. No internet service or storage system can be guaranteed completely secure. Please contact us promptly if you believe your account or information has been compromised.

Your choices and requests

You can use the public website and read-only demo without creating an account. Signing in requires a necessary session cookie. Browser analytics does not use an analytics cookie and is disabled when Global Privacy Control or Do Not Track is present.

You can update some library and profile information within BookSeeking. To request a copy of information linked to your account, correct it, ask for deletion, or make a privacy complaint, email robbie.coombs@verveed.com with Privacy in the subject line. We may need to verify that you control the account before acting on a request. We will investigate privacy complaints and explain the outcome. If an Australian privacy complaint remains unresolved, you may also contact the Office of the Australian Information Commissioner.

Changes to this notice

We will update this notice when our information handling changes materially and will change the date and version above. Where appropriate, we will also provide an in-product or email notice.

Privacy contact: robbie.coombs@verveed.com