Privacy Policy

Roux Biblio, LLC Effective Date: [To be set at launch] Version: 4.0-draft (2026-06-19)

DRAFT — FOR ATTORNEY REVIEW PRIOR TO USE. Not in effect. Do not present to customers until reviewed by New Jersey counsel. This draft describes the target state at launch — the Category 1 must-fix items in privacy-readiness-report.md must be implemented before public signup, or this Policy will misstate the product.

Plain-English Summary (non-binding)

The legal text below controls if anything conflicts with this summary. It's here to help you understand what you're agreeing to.

  • We collect what we need to run the service: your account info, your books, your readers' applications and survey answers, billing data, and security logs.
  • We don't sell or share your personal information. We don't run analytics on our site or in our app. We don't load third-party advertising trackers.
  • We send transactional emails (not marketing). Those emails contain pixels that record when you open them and when you click links — disclosed in detail below.
  • Our payment processor is Stripe. Card data goes directly to Stripe; we never see it.
  • Your books are stored on Cloudflare R2 globally. Readers in the EU/UK are covered by standard data-transfer safeguards.
  • "Delete my account" usually means anonymize rather than hard-delete — because reader consent records and admin audit logs have to be retained for legal-defense reasons. We'll tell you in plain language which mode applies when you delete.
  • Administrative records of actions affecting your account are retained for 7 years in tamper-evident storage. This is a deliberate choice for accountability.
  • Readers must be 18 or older. We do not knowingly collect data from anyone younger.
  • New Jersey law applies. EU, UK, and Canadian residents have additional rights described below.

1. About this Policy

1.1 This Privacy Policy describes how Roux Biblio, LLC, a New Jersey limited liability company ("Roux Biblio," "we," "us," or "our"), collects, uses, shares, and protects personal information when you use the Roux Biblio Service.

1.2 This Policy applies to the marketing site at rouxbiblio.com, the application at app.rouxbiblio.com, the administrative tooling at admin.rouxbiblio.com (operations team only), and our transactional emails.

1.3 This Policy is part of and incorporated into the Terms of Service for paying Customers and the Reader Terms for Readers. Capitalized terms not defined here have the meanings given in those documents.

1.4 Roux Biblio is the controller (under GDPR and UK GDPR), the business (under CCPA/CPRA), and the organization (under PIPEDA) responsible for the personal information described in this Policy.

2. Personal Information We Collect

2.1 Information you give us as an Author

When you create or use an Author Account, we collect:

  • Account credentials. Email address, password (stored as an Argon2id hash; we never store your password in cleartext or recoverable form), pen name and account slug.
  • Profile information. Public author name, reader-facing tagline.
  • Branding. Logo, signup-page banner, color palette.
  • Books. Manuscript files, cover art, titles, blurbs, series information, content warnings, and any other metadata you upload.
  • Campaign configuration. Reader cap, timeline, survey questions, signup-form questions, consent text, watermark settings.
  • Communications. Subject lines and body content of any messages you schedule or send to Readers through the Service.
  • Notes about Readers. Private tags and internal notes you write about Readers who have applied to your Campaigns. These notes are subject to access by the Reader on request under applicable law (see §11).
  • Survey annotations. Sentiment overrides, highlight flags, and private tags you apply to individual Reader survey answers.
  • Payment information. Plan tier and subscription state. Your card number, expiration, and CVV are collected directly by our payment processor, Stripe, and are never sent to or stored on Roux Biblio servers. We retain the card brand, last four digits, and expiration date for display, as returned to us by Stripe.

We also receive the following automatically when you use the Service:

  • Account-creation IP address. The IP address of the device you used to sign up, retained for anti-abuse purposes.
  • Login activity. Date and time of last login.
  • Session data. A session cookie tied to your authenticated session.

2.2 Information you give us as a Reader

When you apply to an ARC Campaign or use the Reader area, we collect:

  • Account credentials. Email address, display name, password (Argon2id hash).
  • Application answers. Free-text and structured answers to questions posed by the Author whose Campaign you applied to. You should not submit information you would not want the Author to see.
  • Consent record. Each time you accept a Campaign's terms, we record (i) the consent text you accepted, (ii) the version of that text, (iii) the IP address from which you accepted it, and (iv) your browser user-agent string. This record is retained as the legal evidence that you consented.
  • Mailing address (physical-book Campaigns only). If you apply to a Campaign that mails you a printed book, we collect the postal address you enter (street, city, state or region, postal code, country) and validate it for deliverability through our address-validation subprocessor (see §6.1). We share it only with the one person who needs to mail a copy to you (the author, or in a Circulation chain the single reader immediately before you), store it encrypted, and delete it after the Campaign closes. You agree to this collection and sharing through a separate Mailing-Address Sharing Consent presented when you apply; digital (eARC) Campaigns never ask for an address.
  • Survey responses. Your answers to post-read surveys configured by the Author, including free-text long-form answers if the Author asked open-ended questions.
  • Reader profile. Genre preferences, heat level, tropes you love and hate, content sensitivities — as you configure them.
  • Reading behavior. When you started reading, when you finished, when you started and completed surveys, when you marked a book "did not finish," when you posted external reviews.
  • External review proof. URLs to reviews you post on Amazon, Goodreads, or similar platforms; screenshots if you upload them.

We also receive the following automatically:

  • IP address and user-agent at signup, login, and at each consent submission.
  • Email engagement events. When you open one of our transactional emails or click a link in it, your mail client typically fires a small pixel back to our email vendor. The vendor records the open or click event and stores the timestamp. See §4 (Cookies and Tracking) and §6.4 (Email vendor — Resend) for what flows where.
  • Watermark fingerprint. Every ARC file delivered to you is uniquely watermarked. The watermark mapping (your Reader ID, name, email, ARC ID, delivery timestamp, and a cryptographic fingerprint) is retained so that, if your copy is found redistributed, the watermark can be matched back to your Reader account.

2.3 Information about people who are not Authors or Readers

We collect personal information about non-users in three contexts:

  • DMCA claimants. When someone submits a copyright takedown notice, we record their name, email, optional organizational affiliation, and the content of their claim. See DMCA Policy.
  • Legal-process requestors. When we receive a subpoena, court order, or law-enforcement request, we record the requestor's name, jurisdiction, reference number, and the substance of the request.
  • Subjects of admin actions. Where an administrative action references an individual (for example, in an audit-log reason field), the individual's identifiers may be retained in that record.

2.4 Sensitive demographic information collected via the Sensitive Demographic survey question type

If an Author asks a sensitive-demographic question on their Campaign's survey, you will see a separate consent card before the question appears. The card discloses (i) the legal-sensitivity categories the question covers (e.g. health, sexual orientation, religious belief), (ii) the Author's framing of why they are asking, (iii) that the Author sees aggregate counts only and never your individual answer, (iv) that aggregate displays are suppressed until at least three readers have answered, (v) the retention window after which your individual answer is automatically deleted, and (vi) that you may withdraw consent and immediately delete your individual answer at any time via your reader settings. If you consent, we record the canonical consent text shown to you, the time of consent, your IP address, and your user-agent. If you decline, we record only the fact that you skipped the question.

The categories an Author may ask about are limited to a curated list aligned with GDPR Article 9 and CPRA §1798.140(ae): racial or ethnic identity; religious or philosophical belief; political view; sexual orientation; gender identity; sex life or sexual practices; health status or medical history; mental health; disability or accessibility lived experience; substance use or recovery; grief, bereavement, or trauma; and genetic or family medical history. Authors may not collect sensitive demographic information through any other field type; doing so is a violation of our Acceptable Use Policy.

2.5 Information you give us as an Operations User

If you are part of our operations team, we additionally collect:

  • Login email, name, password hash, WebAuthn credential material.
  • IP address and user-agent at each session establishment and each login attempt — including login attempts against unknown email addresses, retained for 90 days.
  • A tamper-evident chained log of every administrative action you take. See §7.5.

3. Sources of Personal Information

We collect personal information from the following sources:

  • Directly from you. When you sign up, configure your account, upload Books, create Campaigns, apply as a Reader, submit surveys, or contact us.
  • Automatically through your use of the Service. Cookies, session data, IP addresses, watermark fingerprints, email-engagement signals.
  • From our subprocessors. Stripe returns billing metadata (card brand, last four, billing address); Stripe Radar returns fraud-risk scores on individual transactions; Resend returns email-engagement events; our address-validation subprocessor returns a standardized, deliverability-checked form of a mailing address you enter for a physical-book Campaign.
  • From third parties who file claims about you. DMCA claimants, legal-process requestors.
  • From upstream lists for anti-abuse purposes. Our anti-abuse system uses a public list of disposable email-provider domains.

4. Cookies and Tracking

4.1 Cookies we set

We set the following first-party cookies. We do not load third-party analytics, advertising pixels, or marketing trackers anywhere on rouxbiblio.com, app.rouxbiblio.com, or admin.rouxbiblio.com.

Cookie Set by Purpose Lifetime Flags
rb-author-session app.rouxbiblio.com Author authenticated session 30 days HttpOnly, Secure, SameSite=Lax
rb-reader-session app.rouxbiblio.com Reader authenticated session 90 days HttpOnly, Secure, SameSite=Lax
__Host-rb-admin-session admin.rouxbiblio.com Operations-team authenticated session 8 hours absolute / 30 min idle HttpOnly, Secure, SameSite=Strict
__Host-rb-author-impersonation app.rouxbiblio.com Set when an operations user is signed in to your account for support purposes; persistent banner alerts you 15 minutes absolute / 5 min idle HttpOnly, Secure, SameSite=Lax
Authentication-library cookies app + admin CSRF protection, callback URL, sign-in state Session-scoped HttpOnly, Secure, SameSite=Lax

All of our cookies are strictly necessary for authentication and security. We do not require a consent banner for these under GDPR or UK PECR because they are exempt as "strictly necessary" cookies.

If we ever add analytics or marketing cookies, we will publish a categorized cookie banner with opt-in for non-necessary cookies in regions that require it.

4.2 Marketing site

The marketing site at rouxbiblio.com does not set any cookies and does not load any third-party scripts. We use self-hosted fonts (no runtime calls to Google or any other font provider).

4.3 Global Privacy Control (GPC)

We honor the Global Privacy Control signal (sec-gpc) sent by your browser. Because we do not sell or share personal information for behavioral advertising (see §5.3), GPC has no immediate effect on our processing today. We honor the signal preemptively as a record of your preference in case our practices ever change.

5. How We Use Personal Information

We use the personal information described in §2 for the following purposes:

5.1 To provide the Service

  • Authenticate you, maintain your session, and protect your account.
  • Process your subscription, billing, and renewals through Stripe.
  • Host your Books, transcode and watermark them, and deliver them to Readers you authorize.
  • Operate Campaigns, send invitations and reminders, run surveys, and surface results to Authors.
  • Send transactional emails (account confirmation, password reset, magic links, ARC delivery, survey reminders, account notifications, billing receipts).

5.2 To keep the Service safe

  • Detect and prevent abuse, fraud, and platform-integrity attacks. This includes our anti-abuse signals (signup-velocity, disposable-email detection, refund-velocity, deliverability monitoring) and Stripe Radar fraud scoring.
  • Investigate suspected violations of the Terms, AUP, or applicable law.
  • Maintain an immutable audit log of administrative actions for accountability and legal defense.
  • Preserve evidence in response to claims and legal process.

5.3 We do not use personal information for

  • Behavioral advertising or retargeting.
  • Sale or sharing for cross-context behavioral advertising (CCPA/CPRA definitions).
  • Marketing emails. We do not currently send marketing emails. If we ever add marketing email, we will offer opt-out at the point of collection and at every send.
  • Automated decisions that produce legal or similarly significant effects on you. Our anti-abuse signals flag potentially-problematic activity for human review by our operations team; they do not automatically suspend or terminate accounts. A human reviews and decides.

6. Who We Share Personal Information With

We share personal information only with the following parties, only for the purposes described.

6.1 Subprocessors

We use third-party service providers ("subprocessors") to operate the Service. Each subprocessor is bound by contract (a Data Processing Agreement) to use personal information only as instructed by us, to maintain appropriate security, and to assist us with privacy-rights requests. The current list:

Subprocessor Purpose Personal data categories Region
Vercel Application hosting All in-transit request data; access logs United States
Neon Database hosting (Postgres) All personal information described in §2 United States (us-east-2)
Stripe Payment processing; fraud-risk scoring (Stripe Radar) Author email, name, billing address, card data (directly entered by Author into Stripe; not via Roux Biblio), payment events Global, primarily United States
Resend Transactional email delivery; email engagement events Recipient email and name; email content; open/click events including recipient IP and email-client information United States (default; EU region available)
Cloudflare R2 Object storage for manuscripts, watermarked deliveries, branding assets File content (which may itself contain identifiers); object keys Global (no region pinning at this time)
Google (Address Validation API) Postal-address validation and standardization for physical-book ARC mailing Reader mailing address entered for a physical-book Campaign Global, primarily United States
Inngest Background-job orchestration Job payloads containing identifiers and references to objects in our database United States
Amazon Web Services (S3) Audit-log tamper-evident archival Administrative audit-log rows (admin actions, identifiers, before/after snapshots) United States (separate region from primary stack)

We may add or change subprocessors. We will update this list when we do. The list above is our current source of truth; substantive changes to it constitute a Material Change to this Policy under §15.

6.2 Email vendor — Resend specifically

When we send you a transactional email, the following data flows to Resend:

  • Recipient email address and display name.
  • Full email content (HTML and plain-text), including any merge variables we use (such as your name, links to your account, and ARC identifiers).
  • Header metadata identifying which template was sent and which Campaign it relates to.

Our transactional emails include open and click tracking by default. This means each email contains a small image (a "pixel") that loads when you open the message. When your mail client loads the pixel, your IP address and email-client user-agent are visible to Resend, and a timestamp is recorded. Similarly, links in our emails route through Resend's click-tracking layer, which records the click and forwards you to the destination. We use these signals to monitor deliverability, to power Reader-engagement features within the Author dashboard (so Authors can see when their ARC was opened), and to manage our sender reputation. We do not use them for advertising.

If you would prefer that we not track email opens, you can configure your mail client to block remote images, which prevents the pixel from loading. We do not currently offer a per-recipient opt-out at the platform level.

6.3 Legal process and protection

We may disclose personal information when we believe in good faith that disclosure is necessary to:

  • Comply with applicable law, subpoena, court order, or law-enforcement request.
  • Enforce the Terms, AUP, or DMCA Policy.
  • Protect the rights, property, or safety of Roux Biblio, our customers, our Readers, or others.
  • Investigate suspected fraud, security incidents, or other misconduct.

We record all legal-process requests we receive (including subpoenas and law-enforcement requests) and the substance of our response. Where we are legally permitted to notify you of a request affecting your account, we will do so before responding.

6.4 Business transfers

If we are acquired, merge with another business, or transfer substantially all of our assets, personal information may transfer with the business. We will give you reasonable advance notice if such a transfer affects how your personal information is handled.

6.5 With your consent

We may share personal information for purposes not described above with your explicit consent.

6.6 We do not sell or share personal information

We do not sell personal information to third parties, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under California's CCPA/CPRA or any similar state law. We have not done so in the past 12 months and have no plans to do so. The "Do Not Sell or Share My Personal Information" link in the footer of our site reflects this commitment and provides a record of your preference if our practices ever change.

7. International Data Transfers

7.1 Roux Biblio is based in the United States. Our primary subprocessors are based in the United States. If you access the Service from outside the United States, your personal information will be transferred to, stored, and processed in the United States.

7.2 If you are in the European Economic Area, the United Kingdom, or Switzerland, transfers of your personal information to the United States and to other regions outside the EEA, UK, or Switzerland are made under the European Commission's Standard Contractual Clauses (SCCs) and, for transfers to the United Kingdom, under the UK International Data Transfer Addendum to the SCCs. The SCCs are part of the Data Processing Agreement we have in place with each subprocessor.

7.3 Cloudflare R2 distributes object storage globally; manuscript files and other assets you upload may be served from regions outside the country where they were uploaded. Cloudflare's Data Processing Addendum and Standard Contractual Clauses cover these transfers.

7.4 Where required by applicable law, we conduct transfer-impact assessments and supplement the SCCs with appropriate technical and organizational measures.

8. How Long We Keep Personal Information

We retain personal information for as long as needed for the purposes described in §5 and as required by applicable law. Specific retention periods:

Category Retention
Account and profile data (Author and Reader) For the life of your account, plus any period required to resolve disputes or comply with legal obligations
Books, Campaigns, applications, survey responses For the life of your account; survey responses and applications may be retained longer in anonymized form (see §10 on "Anonymized retention")
Reader consent records At least 7 years from the date of consent, for legal-defense purposes; may be retained longer if a related dispute or legal hold is in effect
Reader mailing addresses (physical-book Campaigns) Encrypted at rest; deleted after the Campaign closes (subject to any legal hold). The consent record that you agreed to share your address is retained per the row above, without the address itself.
Watermark mapping (Reader ID, name, email, fingerprint, delivery timestamp) For as long as the watermarked file may circulate, plus 7 years
Sensitive-demographic answers (the Author's individual reader rows) The Author selects a retention window between 30 and 90 days after their Campaign closes; default 30 days. Individual rows are hard-deleted by an automated job at the end of the window. Withdrawn rows are deleted immediately.
Sensitive-demographic consent records (the row stating consent was given, withdrawn, or purged — without the answer itself) Indefinite, as evidence that the consent + retention + revocation framework was followed
Transactional email events (delivered, opened, clicked, bounced, complained) Indefinite, for deliverability hygiene and Reader-engagement features
Payment records (the structured Subscription / Payment rows we keep in our database, plus your invoice history at Stripe) 7 years
Raw Stripe webhook payloads (used for webhook idempotency and short-window forensic debugging; the structured payment records above are the long-term retention path) 90 days
Account-creation, reader-creation, and consent IP addresses 7 years
Admin login attempts (including failed attempts against unknown email addresses) 90 days
Administrative audit log Indefinite in our primary database; 7 years in tamper-evident archival storage with Object Lock COMPLIANCE mode (cannot be deleted by anyone, including by our cloud provider's administrators, before the 7-year expiry)
DMCA notices and counter-notices Indefinite
Subpoenas, law-enforcement requests, court orders, and our responses Indefinite
Erasure-request final-snapshot data (your account name, slug, owner email, plan tier, creation date, captured at the moment of erasure) Indefinite — retained as evidence that an erasure was performed, even after the rest of the account is deleted
Rate-limit records (some of which contain IP addresses) 24 hours
Backups Per our cloud provider's default backup retention; backups are restored only in the event of operational incident

If you exercise a right of erasure, we delete or anonymize personal information as described in §10. Some categories above are excepted from erasure because they are needed to comply with legal obligations or to establish, exercise, or defend legal claims; we will tell you which categories were retained in the deletion confirmation email.

9. Security

We use commercially reasonable technical and organizational measures to protect personal information. We do not claim or commit to any specific security certification, standard, or audit posture in this Policy. We make no warranty that the Service is or will remain free from unauthorized access, breach, or compromise.

If a security incident materially affects your personal information, we will notify you and any required regulatory authority as required by applicable law and without undue delay.

10. Your Rights

This section describes the rights you have in your personal information. Specific additional rights for residents of California, the EEA/UK, and Canada follow.

10.1 Rights available to all users

  • Access. You may request a copy of the personal information we hold about you. Authors and Readers can run a self-serve export from their account settings at any time.
  • Correction. You may correct inaccurate personal information through your account settings or by contacting us.
  • Erasure. You may request deletion of your account and associated personal information.
  • Portability. Your self-serve export is provided in a structured, machine-readable JSON format.
  • Withdraw consent. Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect lawfulness of processing before the withdrawal.
  • Object or restrict. You may object to or request restriction of certain processing, as further described in the jurisdiction-specific sections below.

10.2 Erasure — what "delete my account" actually means

Account deletion is more nuanced than a single "wipe" because of legal-defense requirements. When you request deletion of your Author Account:

  • Always deleted: Your login credentials, password hash, branding assets, payment-method identifiers stored locally, and any cookies set by your session.
  • Conditionally deleted: If no Reader has ever consented to a Campaign you operated, your entire Account is hard-deleted along with all Campaigns, Books, applications, survey responses, and email-event history. If any Reader has ever consented to a Campaign you operated, your Account is anonymized in place: identifying fields on the Account are replaced with generic markers ("Deleted Account"), but Campaigns, Books, applications, and survey responses are retained because they reference consent records that we are required to preserve as evidence of consent.
  • Always retained: A minimal final snapshot of your account (name, slug, owner email, plan tier, creation date, campaign count, consent count) for legal-defense purposes; the immutable administrative audit log; any DMCA notices, counter-notices, and legal-process records that reference your account.

In the confirmation email we send when your erasure is processed, we will tell you in plain language which mode (hard-delete or anonymize-in-place) applied to your account.

Reader account deletion follows a similar pattern: your login credentials, profile, and reading history are removed; your consent records and the watermark mapping for any ARC you received are retained as required for legal-defense purposes, with identifying fields scrubbed where retention is permitted.

10.3 California residents (CCPA/CPRA)

If you are a California resident, you have the following rights:

  • Right to know. You may request that we disclose the categories of personal information we have collected, the sources, the business or commercial purposes of collection, the third parties with whom we have shared the information, and the specific pieces of personal information we hold about you.
  • Right to delete. You may request that we delete personal information we have collected from you, subject to the carve-outs in CCPA §1798.105(d). The carve-outs we rely on include compliance with legal obligations, exercise or defense of legal claims, and processing required for security and integrity of the Service.
  • Right to correct. You may request that we correct inaccurate personal information.
  • Right to opt out of sale and sharing. We do not sell or share personal information. You may exercise this right preemptively through the "Do Not Sell or Share My Personal Information" link in our footer.
  • Right to limit use of sensitive personal information. Where Authors collect sensitive personal information via the Sensitive Demographic survey question type (see §2.4), they do so only with your explicit opt-in consent recorded at the per-question consent gate. The Author sees aggregate counts only; we do not infer additional categories from your sensitive answers or use them for any purpose beyond the Author's stated framing. You may withdraw consent at any time via your reader settings — withdrawal hard-deletes your individual answer immediately. By design, we do not collect SPI through any other field type or context.
  • Right of non-discrimination. We will not discriminate against you for exercising any of these rights.

Categories of personal information collected, sold, or shared in the prior 12 months:

CCPA category Collected? Sold? Shared?
Identifiers (name, email, IP) Yes No No
Customer records (billing) Yes No No
Commercial information (subscription) Yes No No
Internet activity (session, click events on our own emails) Yes No No
Geolocation (general, derived from IP) Yes No No
Audio/visual (uploaded cover art, screenshots) Yes No No
Professional or employment-related No — —
Education No — —
Inferences Limited (Reader fit-score; abuse-flag scoring) No No
Sensitive personal information (collected via the Sensitive Demographic survey question type, with explicit per-question opt-in consent) Yes (with consent) No No

We do not have actual knowledge of selling or sharing the personal information of any consumer under 16 years of age.

10.4 EEA, UK, and Swiss residents (GDPR / UK GDPR)

If you are in the EEA, the UK, or Switzerland, you have the following rights:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17), subject to the exceptions in Article 17(3) including compliance with legal obligations and establishment, exercise, or defense of legal claims
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21), including the right to object to processing based on legitimate interests
  • Right to withdraw consent (Article 7(3))
  • Right to lodge a complaint with your supervisory authority

Lawful bases. We process personal information on the following lawful bases:

  • Performance of a contract (GDPR Article 6(1)(b)) — to provide the Service, process billing, and deliver ARCs.
  • Legitimate interests (Article 6(1)(f)) — to detect and prevent fraud and abuse, to maintain the audit log for accountability, to operate the Service securely, and to operate Reader-engagement features. We have conducted balancing assessments for each of these purposes; you have the right to object to processing on this basis.
  • Legal obligation (Article 6(1)(c)) — to respond to DMCA notices, subpoenas, court orders, and other legal process.
  • Consent (Article 6(1)(a)) — for Reader application acceptance, and (Article 9(2)(a) — explicit consent for special-category data) for the Sensitive Demographic survey question type, captured per-question at the consent gate described in §2.4.

10.5 Canadian residents (PIPEDA)

If you are in Canada, you have the rights granted under the Personal Information Protection and Electronic Documents Act (PIPEDA), including the right to access and correct your personal information and to challenge our compliance. Contact privacy@rouxbiblio.com to exercise these rights or to file a complaint, and you may also contact the Office of the Privacy Commissioner of Canada.

10.6 How to exercise your rights

For access, correction, deletion, and export, use the self-serve tools in your account settings (Author: /settings → Danger zone; Reader: /reader → Settings).

For all other requests — including objections, restrictions of processing, requests by Readers we cannot route through self-serve tools, requests by third parties whose personal information we hold (DMCA claimants, etc.), and complaints — email privacy@rouxbiblio.com. We will respond within the timelines required by your applicable law (generally 30 days under GDPR, 45 days under CCPA, with one permissible extension where the request is complex).

We may need to verify your identity before processing certain requests. For Authors and Readers, signing in to your account is generally sufficient verification.

11. Authors' Notes About Readers — Specific Disclosure

Authors who manage Campaigns can write private "internal notes" and apply private "tags" about individual Readers. These notes are not visible to the Reader in the application UI. However, your data-access rights include access to these notes when they reference you. If you are a Reader and you submit a right-of-access request, our SAR fulfillment includes any internal notes and tags Authors have written about you. We make this disclosure here so that both Authors writing such notes and Readers exercising rights understand the trade-off in advance.

12. Children's Privacy

The Service is not directed to anyone under 18. Readers must be at least 18 years old. Authors and operations users must also be at least 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected such information, we will delete it promptly.

13. Marketing Communications

We do not currently send marketing emails. We send only transactional emails related to your use of the Service (account confirmations, password resets, ARC delivery, survey reminders, account notifications, billing receipts, legal notices).

If we ever introduce marketing emails, we will:

  • Offer opt-out at the point of collection.
  • Include a clear unsubscribe link in every marketing message.
  • Honor your opt-out promptly (within 10 business days, as required by CAN-SPAM; sooner where required by other applicable law).

You cannot opt out of transactional emails while you maintain an active account, because they are operationally necessary.

14. Automated Decision-Making

We do not use automated decision-making, including profiling, to make decisions that produce legal or similarly significant effects on you within the meaning of GDPR Article 22.

Our anti-abuse systems automatically flag potentially-problematic activity (signup velocity, disposable-email matches, refund velocity, deliverability concerns, Stripe Radar fraud scores). Flags surface to our operations team for human review. A human reviews and decides before any account-level consequence (suspension, termination, refund denial) is applied.

15. Changes to This Policy

We may modify this Policy from time to time.

For Material Changes that materially decrease your rights or materially increase how your personal information is processed, we will provide at least 30 days' advance notice by email and by in-Service notice, and we will require re-acceptance for continued use. Other modifications (clarifications, corrections, additions to our subprocessor list, changes in our cookie inventory) take effect upon posting.

The current version and effective date of this Policy are stated at the top. Prior versions are available on request at privacy@rouxbiblio.com.

16. Contact

For all privacy questions or requests:

Roux Biblio, LLC [Registered office address — to be set on formation] Attn: Privacy Email: privacy@rouxbiblio.com

16.1 EU Representative

For users in the European Economic Area, our EU representative under GDPR Article 27 is:

[EU Representative — to be appointed before EEA users are onboarded]

16.2 UK Representative

For users in the United Kingdom, our UK representative under UK GDPR Article 27 is:

[UK Representative — to be appointed before UK users are onboarded]

16.3 Right to lodge a complaint

If you are in the EEA, the UK, or Switzerland, you have the right to lodge a complaint with your local data-protection authority. If you are in Canada, you may contact the Office of the Privacy Commissioner of Canada. If you are in California, you may contact the California Privacy Protection Agency.

We would prefer that you contact us first so that we have the opportunity to address your concern directly.


Roux Biblio, LLC — New Jersey limited liability company privacy@rouxbiblio.com