How Bookae protects your stories.
This page explains what data Bookae uses, how sharing works, and what controls students have.
Bookae Privacy Statement
Effective October 1, 2026 · Version 2026-10-01
Bookae provides a student-owned writing and application workspace at bookae.ai. Contact Bookae at bookae.ai@gmail.com about privacy, access, corrections, withdrawal of consent, or deletion. This statement covers the student pilot and existing accounts.
Information we use
We process account details (name, username, email, password authentication), eligibility age band (14–17 or 18+), and your policy acknowledgements. We do not request a full birth date, identity document, or parent account for the pilot. Password authentication is handled by Supabase.
We store the writing and materials you choose to provide: journals, profile and academic records, activities, essays, college lists, messages, attachments, photos, and saved versions. These can contain sensitive personal information. Avoid uploading identifiers, financial documents, health records, or other people's private information unless necessary and you have permission.
We also process technical information needed for security and reliability, such as session identifiers, hashed admission-rate-limit identifiers, error diagnostics, device/browser information, and AI usage totals. We do not record browser session replays during the pilot.
Purposes and AI processing
We use this information to authenticate you, save and retrieve your work, provide requested features, generate AI assistance, enforce usage allowances, prevent abuse, and respond to support requests. Some AI processing runs in the background after saving or importing material, including extraction, search embeddings, insights, and journal artwork. Your account's AI-context controls explain which information can inform assistance.
AI requests send relevant text, extracted material, images, or audio to configured AI providers. We may store resulting summaries, embeddings, suggestions, and conversations in your account. AI is fallible; review advice and drafts before relying on them or submitting an application. Bookae is an educational tool, not an admissions decision-maker or a professional health service.
Privacy and sharing
Your journal is private by default. Sharing a journal entry is an explicit, per-entry action. Connecting a counselor can expose the profile and application materials described by the connection and sharing controls; journal access still requires explicit sharing. Counselor notes provided through Bookae are visible to the student.
Friends/directory features can expose your display name, username, profile photo, and connection information appropriate to that feature. Private close-friend preferences are not published. Material you intentionally post or share is visible to the audience shown in the product. Revoking access prevents future authorized access but cannot retract downloaded copies or instantly expire an already-issued short-lived download link.
Bookae operators may access information when necessary to maintain the service, investigate incidents, or answer a support request. Maintainer access to shared admissions content does not itself grant access to private student writing. We do not sell your personal information or provide private writing to advertisers.
Providers and processing outside mainland China
Bookae uses Supabase for authentication, database, and file storage; Vercel for application hosting and performance diagnostics; OpenAI, and Anthropic when selected for a supported feature, for AI processing; and Sentry for scrubbed reliability diagnostics. Authentication emails are delivered through Resend, which processes your email address and authentication message. Providers receive only information relevant to their service and may process security logs under their own policies.
Production's Supabase database is hosted in the United States (US East). Hosting and AI providers may process information in the United States and other countries outside mainland China. Before enrolling, students separately acknowledge overseas processing and consent to AI processing of the materials they provide, which can contain sensitive information. Contact Bookae to ask about recipients or exercise your rights.
OpenAI's API documentation states that API inputs and outputs are not used for training by default, unless the customer opts in; its default abuse-monitoring retention can be up to 30 days, with exceptions. Other providers' applicable contracts and policies govern their processing. Bookae does not promise zero provider retention or blanket deletion from their backups. See our Data retention statement.
Eligibility and choices
The pilot is for high-school students aged 14 or older. Students under 18 must have a parent or guardian review and agree to the Terms on their behalf. We do not knowingly enroll children under 14. Contact us if an ineligible child has enrolled.
You can edit your information, change available AI-context controls, revoke sharing, and request account deletion in your account. You can also email bookae.ai@gmail.com to request a copy, correction, deletion, or withdrawal of consent. We may need to verify account ownership. Withdrawing consent may make dependent features unavailable; we will explain the effect before acting on a support request.
Changes and contact
We will notify account holders of material changes through the product or their account email and obtain additional consent where required. If Bookae is discontinued, we will notify account holders and explain retrieval and deletion arrangements. Questions: bookae.ai@gmail.com.