Privacy Policy

Last updated: September 8, 2026

1. Introduction

Welcome to Wowzo ("we," "our," or "us"). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered book generation service.

Data Controller: Wowzo
Company registration details are available on request — see Contact.
Contact: Contact Us

This policy applies to all users of our website and services, including those in the European Union (EU), European Economic Area (EEA), United Kingdom, and California, USA.

2. Information We Collect

Account Information

  • Email address (used for authentication and communication)
  • Password (securely hashed and stored via AWS Cognito)
  • Account status (trial status, subscription tier)

Payment Information

  • Stripe Customer ID (for payment processing)
  • Transaction amounts and dates
  • Subscription status and billing cycle
  • Note: Credit card details are handled directly by Stripe and never stored on our servers

Book Content

  • Book parameters (title, genre, themes, characters)
  • Generated content (outlines, chapters)
  • User feedback on chapters (TIPS/TOPS format)
  • Note: All book content is stored securely in AWS S3

Security Logs

  • Hashed IP addresses (for fraud prevention)
  • Truncated user agent strings (device/browser type)
  • Authentication timestamps

Cookies and Local Storage

  • Essential authentication cookies (httpOnly, secure)
  • Session storage for temporary UI state
  • Local storage for user preferences
  • Optional product analytics (PostHog) — only loaded after you accept the cookie-consent banner. See Cookie Policy below.

3. Lawful Basis for Processing (GDPR Article 6)

We process your personal data based on:

Contract Performance (Art. 6(1)(b))

Processing necessary to provide our book generation service, manage your account, and process payments.

Legitimate Interests (Art. 6(1)(f))

Fraud prevention, security monitoring, service improvement, and responding to support requests.

Consent (Art. 6(1)(a))

Marketing communications (where applicable) and optional analytics. You can withdraw consent at any time.

4. How We Use Your Data

  • Book Generation: Processing your parameters through AI to create personalized books
  • Payment Processing: Managing subscriptions and pay-per-book transactions via Stripe
  • Account Management: Authentication, password recovery, and account settings
  • Service Communications: Sending notifications about your book status, account updates, and support responses
  • Security: Detecting and preventing fraud, unauthorized access, and abuse
  • Service Improvement: Analyzing usage patterns to improve our AI and user experience

5. Third-Party Services

We use the following third-party services:

The table below lists our sub-processors — the third parties who process personal data on our behalf.

Sub-processorPurposeRegionDPA / policy
Amazon Web Services — CognitoUser authentication and account managementeu-central-1 (Frankfurt)AWS GDPR Center
Amazon Web Services — DynamoDBStoring book metadata and user preferenceseu-central-1 (Frankfurt)
Amazon Web Services — S3Secure storage of generated book contenteu-central-1 (Frankfurt)
Amazon Web Services — SESTransactional email deliveryeu-central-1 (Frankfurt)
Amazon Web Services — Bedrock (Claude by Anthropic)AI model access for content generationEU where available; Bedrock may route inference through other AWS regions for model availabilityAWS GDPR Center
StripePayment processingEU/US (per Stripe's DPA)Stripe DPA / Privacy Policy
PostHog (optional, consent-based)Product analytics to understand which steps of the book-creation journey users complete or abandonEU (PostHog Cloud EU)PostHog DPA / Privacy Policy

PostHog analytics only loads if you accept analytics cookies in the cookie-consent banner; you can withdraw consent at any time.

6. International Data Transfers

Some of our service providers process data in the United States. For transfers outside the EU/EEA, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements with all service providers
  • EU-US Data Privacy Framework (where applicable)

7. Data Retention

We retain your data for the following periods:

Data TypeRetention Period
Account InformationUntil account deletion requested
Book ContentUntil account deletion (or 2 years after last activity)
Payment Records7 years (legal/tax requirements)
Security Logs7-365 days (depending on sensitivity)
Support Communications2 years after resolution

8. Your Rights (GDPR Articles 15-22)

If you are in the EU/EEA or UK, you have the following rights:

  • Right of Access (Art. 15): Request a copy of your personal data
  • Right to Rectification (Art. 16): Correct inaccurate personal data
  • Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten")
  • Right to Restriction (Art. 18): Limit how we process your data
  • Right to Data Portability (Art. 20): Receive your data in a machine-readable format
  • Right to Object (Art. 21): Object to processing based on legitimate interests
  • Right to Withdraw Consent (Art. 7): Withdraw consent at any time where processing is based on consent

To exercise these rights, please contact us. We will respond within 30 days.

You also have the right to lodge a complaint with your local data protection authority (e.g., Autoriteit Persoonsgegevens in the Netherlands).

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights:

  • Right to Know: Request what personal information we collect, use, and disclose
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt out of the sale or sharing of personal information
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights

Important: We do not sell your personal information to third parties.

11. Security Measures

We implement appropriate technical and organizational measures to protect your data:

  • HTTPS encryption for all data in transit
  • Encryption at rest for stored data (AWS S3, DynamoDB)
  • Secure password hashing (AWS Cognito)
  • IP address hashing for privacy-preserving security logs
  • JWT token validation with algorithm verification
  • Regular security audits and monitoring
  • Access controls and principle of least privilege

12. Children's Privacy

Our service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe we have collected data from a child under 16, please contact us immediately.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by email and/or by posting a prominent notice on our website. Your continued use of the service after such modifications constitutes your acknowledgment of the modified policy.

14. Contact Us

For any questions about this Privacy Policy or to exercise your data protection rights, please contact us:

Email: support@wowzo.com
Contact Form: wowzo.com/contact

We aim to respond to all data protection requests within 30 days.