
Legal
Privacy Policy
Last updated: 11 July 2026
In short
Your story belongs to you. We collect what we need to build your book, we never sell your personal information, we never let AI invent facts about your life, and anything you share stays inside your own book unless you choose to share it. The rest of this page explains exactly what we collect, why, and where it goes.
1. Who we are
Human Books is operated by Human Books (ABN 83 432 174 196) ("Human Books", "we", "us", "our"), based in Western Australia, Australia.
Contact: yourstory@humanbooks.com
2. Scope of this policy, and our approach to privacy law
This policy covers humanbooks.com and the Human Books application, for everyone who uses it, wherever they're located.
A note on which laws apply, in plain terms:
- Under the Privacy Act 1988 (Cth), businesses with annual turnover under A$3 million are generally exempt from the Australian Privacy Principles (APPs), unless they fall into specific excluded categories (health services, trading in personal information, credit reporting, etc.). Human Books currently falls under this threshold and isn't required to comply with the APPs as a matter of law.
- We've chosen to follow the APPs anyway. What people share with us, their life stories, deserves that standard regardless of a revenue threshold, and it's consistent with the no-fabrication trust commitment at the centre of this product.
- Because we accept customers globally through Stripe, we've also drafted this policy to line up with internationally recognised privacy practices (including rights modelled on the EU General Data Protection Regulation), even where those laws don't strictly apply to a business of our size and reach.
- This is a statement of policy and practice, not a claim that a specific law binds us. If that changes (e.g. Australia's small business exemption is repealed, which is currently under government review), this policy will be updated accordingly.
3. The personal information we collect
- Account information: name, email address, password (managed securely by our authentication provider, Better Auth (we never see or store your raw password), profile image if you add one.
- Your book content: your answers to intake and chapter questions, follow-up answers, chapter and cover photos you upload, book design choices, dedication/foreword/front-and-back-matter text, and (only transiently; see section 7) voice recordings if you use Focus mode.
- Payment information: handled directly by Stripe. We never receive or store your card number, only settled transaction records (amount charged, order reference, date).
- Print and shipping information: the recipient's name, delivery address, and phone number for any printed copy (yours or a share-link recipient's) passed to our print-on-demand partner purely to produce and ship the book.
- Co-creator/contributor information: if you invite someone to contribute their own perspective to a chapter, we collect their name and email to send the invite, their answers, and the passage they write (credited to them).
- Bug reports: if you use the in-app bug reporter, we collect the description you write, the page URL (with invite/claim/OAuth tokens stripped), optional contact email, technical details that help us debug (browser, viewport, recent on-page errors, and optionally a screenshot of the page — which may include story text visible on screen), and a rough IP address used only to limit spam. Reports are deleted after 180 days.
- Share-link and gift recipient information: if you share or gift a book, we collect the recipient's email (for an email-bound link) and, where relevant, their delivery address.
- Technical and usage information: standard server logs, and aggregated, cookie-free analytics (see section 16).
4. Sensitive information
Some categories of personal information (health information, sexual orientation, religious beliefs, criminal record, and similar) get extra protection under the APPs, called "sensitive information." Because Human Books is a memoir platform, the story you choose to write about your own life may include sensitive information: about yourself, and where you write about family members, about them too.
We only ever collect this because you've chosen to include it in your own book. It's used for no purpose beyond producing that book, and it's protected with the same account-level access controls as everything else you write.
5. How we collect personal information
- Directly from you: creating an account, answering questions, uploading photos, using Focus mode, placing an order.
- From co-creators/contributors: when they accept your invite and answer their own questions.
- From our payment and fulfilment partners: confirmation that a payment or print/shipping event occurred.
- Automatically: standard server logs and cookie-free analytics.
6. Why we collect, use, and hold personal information
- To create and operate your account.
- To generate your book's chapters, strictly and only from the answers you (or your invited co-contributors) provide. Our generation system is built around a no-fabrication rule: the AI is not permitted to assert facts about you that you didn't state, and every chapter requires your explicit approval before it's considered final.
- To let you review, edit, approve, and regenerate chapters.
- To fulfil a print order: production and shipping through our print-on-demand partner.
- To process payment via Stripe.
- To send transactional emails: draft-ready notices, invites, order and shipping updates, receipts.
- To investigate and fix problems you report via the in-app bug reporter (including optional screenshots of the page you were on).
- To improve the product:
- Per-user only, on by default: your own feedback on a chapter (why you asked for changes) is used to improve your own next draft of your own book.
- Cross-user, opt-in, off by default: only if you explicitly turn this on in Account → Settings, a structured, de-identified signal (e.g. "too formal," "missing facts") may contribute to a general product-quality pool. Any free-text notes you write are never included in this pool, even if you've opted in. Free text can contain personal detail that a structured tag can't capture, so it stays private to your project.
- To detect and prevent fraud, abuse, and misuse of the invite and share-link systems (rate limiting, consent checks on unsolicited invites).
- To comply with our legal obligations.
7. How AI is used to write your book
- Chapter generation (Anthropic/Claude): your answers are sent to Anthropic's API to generate a chapter draft. Generation is grounded strictly in what you've said. Nothing is invented, and every draft requires your approval. This is a cross-border disclosure of your information (Anthropic's infrastructure is based in the United States); see section 11.
- Focus mode (voice input, OpenAI): if you use voice input, your recording is sent to OpenAI for transcription and discarded immediately afterward. We never store the audio. The on-screen question text is separately sent to OpenAI to generate a spoken read-aloud version, streamed to your device and not stored. You'll see a one-time notice the first time you open Focus mode explaining this, and you can switch to typed answers at any time. Voice is never mandatory.
- Neither Anthropic nor OpenAI are permitted to use this data to train their general models, under their respective commercial API terms.
8. If you invite a co-creator
Inviting a family member or friend to contribute their own perspective to a chapter is optional. Before they can contribute, they must acknowledge:
"Contributions you make become part of [owner]'s book and stay credited to you, even if you later delete your account. The book owner may keep or remove your contribution but cannot edit your words."
If you (the book owner) remove a contributor, their answers and passage for your book are permanently deleted. If a contributor deletes their own Human Books account elsewhere, any approved passage they wrote for your book stays in your book, credited by name, exactly as they wrote it. This is disclosed to them up front via the consent line above.
Contributors must currently be 18 years or older. We don't yet have a parental/guardian consent flow for minors, so a minor cannot presently be invited as an active contributor.
9. Sharing and gifting a book
You can share a finished book two ways:
- You pay: you pre-pay for a copy and send a link; the recipient supplies their delivery address.
- They pay: you send a link and the recipient pays for their own copy (a limited teaser only, unless the link is bound to their specific email, in which case they can preview the full book before buying).
All share-link pages are excluded from search engines. Sending a link to a public, non-specific "anyone with the link" audience requires your explicit consent at creation time. Every invite is rate-limited, and every invite email includes an unsubscribe link.
If a sent link goes unclaimed and expires, you receive account credit (never a refund) that you can use on a future order. See our Refund Policy for how refunds and credit work.
10. Who we share your information with
We don't sell your personal information, and we don't share it with advertisers. We do share specific, limited data with the service providers who help us operate:
| Provider | What they receive | Purpose |
|---|---|---|
| Stripe | Payment details (handled directly by Stripe, not by us) | Payment processing |
| Print partner | Recipient name, delivery address, phone number, and the finished book files | Print production and shipping |
| Anthropic | Your answer text | Chapter generation |
| OpenAI | Voice recordings (discarded after transcription) and question text | Focus mode (voice input, read-aloud) |
| SendGrid | Your email address, relevant transactional content | Sending emails (invites, receipts, order updates) |
| Vercel | Account data, uploaded photos (via Vercel Blob), aggregated usage data | Application hosting, file storage, performance monitoring |
| Neon | Your account and book data | Database hosting |
| Better Auth | Your account credentials | Authentication and session management |
11. Sending information overseas
Most of the providers above are based overseas (primarily the United States). Sending your information to them is a "cross-border disclosure" under Australian privacy law (APP 8).
In plain terms: once your information leaves Australia, we can't guarantee the recipient handles it exactly as Australian law would require, and no countries have yet been formally "whitelisted" by the Australian Government as offering equivalent protection. Our approach to managing this:
- We only send what each provider actually needs to do its job (e.g. voice audio is discarded immediately after transcription; Stripe and our print partner never see your book content).
- Each provider operates under its own commercial terms, which include data protection and security commitments.
- By creating an account and using features that rely on these providers (chapter generation, Focus mode, print fulfilment, payment), you understand and accept that your information will be processed overseas as described in this policy.
12. Storage and security
Your account and book data is stored in a managed PostgreSQL database (Neon) and file storage (Vercel Blob), both accessed only through our authenticated application. There's no public access to raw data. Your password is never stored by us directly; it's handled by our authentication provider using industry-standard hashing.
No system is 100% secure. If we become aware of a data breach likely to result in serious harm, we'll assess and respond in line with the principles of the Notifiable Data Breaches scheme, notifying affected individuals as soon as practicable.
13. How long we keep your information
- If you delete your account, your access is revoked immediately and your email address is released immediately (so you, or anyone else, can sign up again with that email right away).
- Your underlying data is retained for 24 months after deletion, then permanently and irreversibly removed by an automated process.
- Before deleting your account, you can export your answers and assembled book.
- A few things are handled differently: settled financial records (orders, account credit) are retained for the full 24-month window as an audit trail; a contributor's approved passages in someone else's book survive that contributor's own account deletion (credited by name, per the consent line in section 8); a gift you've given survives your own account deletion; in-app bug reports (and any screenshots) are deleted after 180 days, or sooner if you delete your account.
14. Your rights
- Access and correction: you can view and correct your account details and book content at any time through your account.
- Export: you can export your answers and assembled book before deleting your account.
- Deletion: you can delete your account and data at any time (see section 13 for what that means in practice).
- Opt out of the product-improvement pool: the cross-user feedback pool (section 6) is off by default and can be turned off again at any time.
- Unsubscribe: every invite and notification email includes an unsubscribe link.
- Complain: see section 18.
15. Family members and children in your book
We don't knowingly collect personal information directly from children. If your book includes a chapter about your children, grandchildren, or other family members, the information about them is provided by you, the account holder, not collected directly from them.
The one exception is co-creator contributions (section 8), where the contributor provides their own information directly. As noted there, contributors must currently be 18 or older.
16. Cookies and analytics
We use a strictly necessary session cookie to keep you signed in. Nothing works without it.
For traffic and performance, we use Vercel Analytics and Speed Insights, which are cookie-free and report only aggregated, anonymised data (e.g. page views, load times). We don't use advertising cookies, third-party trackers, or cross-site tracking, and we don't run ads.
17. Changes to this policy
If we make a material change to this policy, we'll update the "last updated" date at the top and notify account holders by email.
18. Contact us
Questions or concerns about how your information is handled: yourstory@humanbooks.com
If you're not satisfied with our response, you can also contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. Even though Human Books currently sits below the Privacy Act's small-business threshold, we think you should have a real complaints path.