Privacy Policy
Last updated: September 8, 2026
1. Introduction
Welcome to Wowzo ("we," "our," or "us"). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered book generation service.
Data Controller: Wowzo
Company registration details are available on request — see Contact.
Contact: Contact Us
This policy applies to all users of our website and services, including those in the European Union (EU), European Economic Area (EEA), United Kingdom, and California, USA.
2. Information We Collect
Account Information
- Email address (used for authentication and communication)
- Password (securely hashed and stored via AWS Cognito)
- Account status (trial status, subscription tier)
Payment Information
- Stripe Customer ID (for payment processing)
- Transaction amounts and dates
- Subscription status and billing cycle
- Note: Credit card details are handled directly by Stripe and never stored on our servers
Book Content
- Book parameters (title, genre, themes, characters)
- Generated content (outlines, chapters)
- User feedback on chapters (TIPS/TOPS format)
- Note: All book content is stored securely in AWS S3
Security Logs
- Hashed IP addresses (for fraud prevention)
- Truncated user agent strings (device/browser type)
- Authentication timestamps
Cookies and Local Storage
- Essential authentication cookies (httpOnly, secure)
- Session storage for temporary UI state
- Local storage for user preferences
- Optional product analytics (PostHog) — only loaded after you accept the cookie-consent banner. See Cookie Policy below.
3. Lawful Basis for Processing (GDPR Article 6)
We process your personal data based on:
Contract Performance (Art. 6(1)(b))
Processing necessary to provide our book generation service, manage your account, and process payments.
Legitimate Interests (Art. 6(1)(f))
Fraud prevention, security monitoring, service improvement, and responding to support requests.
Consent (Art. 6(1)(a))
Marketing communications (where applicable) and optional analytics. You can withdraw consent at any time.
4. How We Use Your Data
- Book Generation: Processing your parameters through AI to create personalized books
- Payment Processing: Managing subscriptions and pay-per-book transactions via Stripe
- Account Management: Authentication, password recovery, and account settings
- Service Communications: Sending notifications about your book status, account updates, and support responses
- Security: Detecting and preventing fraud, unauthorized access, and abuse
- Service Improvement: Analyzing usage patterns to improve our AI and user experience
5. Third-Party Services
We use the following third-party services:
The table below lists our sub-processors — the third parties who process personal data on our behalf.
| Sub-processor | Purpose | Region | DPA / policy |
|---|---|---|---|
| Amazon Web Services — Cognito | User authentication and account management | eu-central-1 (Frankfurt) | AWS GDPR Center |
| Amazon Web Services — DynamoDB | Storing book metadata and user preferences | eu-central-1 (Frankfurt) | |
| Amazon Web Services — S3 | Secure storage of generated book content | eu-central-1 (Frankfurt) | |
| Amazon Web Services — SES | Transactional email delivery | eu-central-1 (Frankfurt) | |
| Amazon Web Services — Bedrock (Claude by Anthropic) | AI model access for content generation | EU where available; Bedrock may route inference through other AWS regions for model availability | AWS GDPR Center |
| Stripe | Payment processing | EU/US (per Stripe's DPA) | Stripe DPA / Privacy Policy |
| PostHog (optional, consent-based) | Product analytics to understand which steps of the book-creation journey users complete or abandon | EU (PostHog Cloud EU) | PostHog DPA / Privacy Policy |
PostHog analytics only loads if you accept analytics cookies in the cookie-consent banner; you can withdraw consent at any time.
6. International Data Transfers
Some of our service providers process data in the United States. For transfers outside the EU/EEA, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with all service providers
- EU-US Data Privacy Framework (where applicable)
7. Data Retention
We retain your data for the following periods:
| Data Type | Retention Period |
|---|---|
| Account Information | Until account deletion requested |
| Book Content | Until account deletion (or 2 years after last activity) |
| Payment Records | 7 years (legal/tax requirements) |
| Security Logs | 7-365 days (depending on sensitivity) |
| Support Communications | 2 years after resolution |
8. Your Rights (GDPR Articles 15-22)
If you are in the EU/EEA or UK, you have the following rights:
- Right of Access (Art. 15): Request a copy of your personal data
- Right to Rectification (Art. 16): Correct inaccurate personal data
- Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten")
- Right to Restriction (Art. 18): Limit how we process your data
- Right to Data Portability (Art. 20): Receive your data in a machine-readable format
- Right to Object (Art. 21): Object to processing based on legitimate interests
- Right to Withdraw Consent (Art. 7): Withdraw consent at any time where processing is based on consent
To exercise these rights, please contact us. We will respond within 30 days.
You also have the right to lodge a complaint with your local data protection authority (e.g., Autoriteit Persoonsgegevens in the Netherlands).
9. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights:
- Right to Know: Request what personal information we collect, use, and disclose
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt out of the sale or sharing of personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
Important: We do not sell your personal information to third parties.
10. Cookie Policy
We use essential cookies required for the service to function, plus one optional analytics cookie that only loads if you accept it in the cookie-consent banner:
| Cookie | Purpose | Duration |
|---|---|---|
| Authentication Tokens | Keep you logged in securely | Session / 30 days |
| CSRF Token | Prevent cross-site request forgery | Session |
| PostHog analytics (opt-in only) | Understand how visitors move through the book-creation journey, to improve the product | Up to 1 year |
The PostHog analytics cookie is not strictly necessary and requires your prior consent (opt-in) — it never loads until you accept it, and you can withdraw consent at any time by clearing your browser's local storage for this site. We do not use advertising cookies or social media cookies.
11. Security Measures
We implement appropriate technical and organizational measures to protect your data:
- HTTPS encryption for all data in transit
- Encryption at rest for stored data (AWS S3, DynamoDB)
- Secure password hashing (AWS Cognito)
- IP address hashing for privacy-preserving security logs
- JWT token validation with algorithm verification
- Regular security audits and monitoring
- Access controls and principle of least privilege
12. Children's Privacy
Our service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe we have collected data from a child under 16, please contact us immediately.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email and/or by posting a prominent notice on our website. Your continued use of the service after such modifications constitutes your acknowledgment of the modified policy.
14. Contact Us
For any questions about this Privacy Policy or to exercise your data protection rights, please contact us:
Email: support@wowzo.com
Contact Form: wowzo.com/contact
We aim to respond to all data protection requests within 30 days.