BoundHive Privacy Policy
This policy explains what BoundHive processes, why it is needed, which providers support the service, and how to request access, correction, export, or deletion.
1. Scope
This policy covers boundhive.com, BoundHive accounts, the Book Studio, subscriptions, support, newsletters, and public editorial pages. BoundHive is independent from Amazon. When you later submit files to Amazon KDP, Amazon handles that submission under its own privacy terms.
2. Information we process
- Account data: email, name, profile image, authentication provider identifiers, verification state, preferences, and security/session records.
- Private project data: book briefs, configurations, manuscript sections, metadata, prompts, generated images, covers, validation results, revisions, exports, and usage history.
- Billing data: plan, status, provider customer and subscription references, billing interval, event history, and credit grants. Payment-card details are entered with and handled by Creem rather than stored by BoundHive.
- Content-screening data: the text of an image prompt submitted for screening, a screening reference identifier, the decision returned, and an internal request reference made of the project identifier, the image slot, and a hash of the prompt.
- Communications: newsletter choices, delivery events made available by Resend, and messages sent to support or editorial addresses.
- Technical data: IP address, user agent, request logs, errors, session timestamps, device/browser details, consent choices, and product events that do not intentionally contain manuscript text.
3. Why we use information
We use information to authenticate users; save and protect projects; run requested AI generation; calculate rules, credits, and exports; process verified subscription events; send transactional messages; provide opted-in newsletters; answer support; prevent abuse; diagnose failures; improve performance; and comply with applicable obligations.
4. AI processing and content screening
When you request generation, the relevant brief, project settings, manuscript context, or image prompt is sent to the configured AI provider, currently through OpenAI-compatible services used by the product. Send only material you are permitted to process. BoundHive does not turn a private manuscript into a public blog post.
Before an illustration, cover, or A+ banner image is generated, BoundHive sends the image prompt to the content-moderation service operated by Creem, the payment provider, to check it against the Acceptable Use Policy. This is separate from payment processing. Only the image prompt text and an internal request reference (project identifier, image slot, and a hash of the prompt) are sent; the manuscript, brief, uploaded images, account email, and payment details are not sent for screening, and manuscript text generated without an image request is not screened this way. Creem returns a decision and a reference identifier that BoundHive records with the generation job for support and audit purposes. Creem processes screened prompts under its own terms and privacy policy.
5. Service providers
BoundHive uses providers only for functions the product actually needs. These may include MongoDB infrastructure for application data, hosting and storage providers, OpenAI for requested generation, Google for optional OAuth, Creem for checkout, subscription management, and image-prompt content screening, and Resend for transactional or opted-in email. Optional analytics providers are loaded only through the consent rules described on the Cookie Settings page.
Providers process data under their own terms and security controls. Information may be processed in countries different from yours, with safeguards applied where required.
7. Retention
Account and project data is kept while the account is active and as needed to provide saved projects. Session, security, billing, transaction, consent, backup, and legal records may be kept longer for fraud prevention, accounting, dispute resolution, and legal duties. A deletion request removes or de-identifies eligible data from active systems; backups expire on their normal protected schedule.
8. Security
BoundHive uses access controls, ownership checks, hashed passwords and single-use token hashes, secure session cookies, validation, webhook signatures, restricted operational routes, and provider controls. No internet service can guarantee absolute security. Contact support immediately if you suspect unauthorized access.
9. Your choices and rights
Depending on where you live, you may request access, correction, export, deletion, restriction, objection, or information about processing. You can edit supported profile and newsletter choices in the account area, unsubscribe through email links, and manage optional storage through Cookie Settings. We may verify identity before fulfilling a request.
10. Age and publishing accounts
BoundHive is a professional publishing workspace. Do not create an account unless you can lawfully agree to the Terms in your location.
11. Changes
We update this policy when product processing or providers materially change. The effective date at the top identifies the current version. Where required, we will provide additional notice.
12. Contact
Send privacy and data requests from the account email to support@boundhive.com. Include the request and enough information to verify the account, but never send a password or payment-card number. You can also use the contact page.