← Bookae

Bookae Data Retention Statement

Effective October 1, 2026 · Version 2026-10-01

Your account and writing do not expire at the end of the pilot. We retain active-account content to provide the service until you delete it or close the account. If we discontinue the service, we will notify account holders about retrieving their work and the deletion schedule.

Account closure and live-system deletion

You can request account deletion from your account settings or contact bookae.ai@gmail.com. Once an in-product request is accepted, account access and new writes are blocked. We remove account-owned files, primary records, stored versions, derived search/AI information, and queued work from our live systems. Cleanup normally completes promptly; retries target completion within seven days. Contact us if a request remains unresolved.

Deleting individual content may retain versions or recovery copies while the account remains active where the feature offers recovery. Account deletion includes those account-owned copies. Copies another person already downloaded cannot be recalled. Short-lived file links issued before a sharing change can remain valid until expiry.

Backups, providers, and diagnostics

Production uses Supabase Pro daily database backups with a seven-day retention window, verified on October 1, 2026. Point-in-time recovery is not enabled. Backups are separate from live records and may retain deleted records until expiry. They are restricted to recovery use. When restoring a backup, operators must reapply accepted deletion requests before reopening access. File storage has its own recovery arrangements; database backups do not contain stored file bytes. Bookae does not claim immediate removal from backups.

AI providers can retain request data for security or service operation under their applicable policies. For example, OpenAI documents default abuse-monitoring retention of up to 30 days, with exceptions. Anthropic documents deletion of API inputs and outputs within 30 days, subject to contractual, safety and legal exceptions. Account deletion does not automatically erase independently retained provider security records. See OpenAI data controls and Anthropic API retention.

We minimize operational diagnostics and exclude session replay. The current provider plans and their published retention periods are:

InformationCurrent retention
Supabase API/database logs (Pro)Seven days
Vercel application runtime logs (Pro)One day
Sentry error/event diagnostics (Developer)30 days
Resend authentication email and delivery logs30 days; provider recovery backups last seven days

These windows concern diagnostic or delivery records, not the lifetime of your account or writing. Deployment/build records and operator audit trails are separate: they can remain longer and should not contain private writing. Sentry organization audit history is retained indefinitely by that provider. We do not extend log retention to preserve private writing. Provider security, legal-preservation and abuse-investigation exceptions can apply.

Sources: Supabase plans, Vercel runtime logs, Sentry retention, and Resend security and retention. The Sentry Developer plan was confirmed in the organization dashboard on October 1, 2026.

The hash-only authentication-email quota and retry ledger is removed after 35 days, covering the current monthly sending allowance. It contains no email body, password, or verification link. Unused admission grants expire after ten minutes and are removed by the cleanup worker. Admission-rate-limit records are removed after their window is older than one day. A minimal account-deletion marker containing the account identifier and processing timestamps is retained to prevent stale sessions or background jobs from restoring deleted information; it contains no writing or files.

Your rights

Contact bookae.ai@gmail.com for access, correction, withdrawal of consent, or deletion requests. We may retain a narrowly necessary record where applicable law requires it or to resolve an existing dispute; we will explain that exception when permitted. Please do not email private documents unless we agree they are needed to resolve your request.

Privacy statement