Privacy Policy
Last updated: 3 September 2026
This policy explains what personal data Help This Book collects, why, and what you can do about it. We've kept it short and specific. If you have a question it doesn't answer, email hello@usefulbooks.com.
The short version
- We collect what we need to run a beta reading service: your email, your content, and your reading and feedback activity.
- Authors can see the feedback and reading progress of people reading their drafts.
- We don't sell your data and we don't use advertising trackers. The only cookie we set is the one that keeps you signed in.
- We use a small number of well-known providers (hosting, email, payments, analytics, support) to run the service.
- You can ask us to show, correct, export or delete your data at any time.
1. Who we are
Useful Books Limited (company number 13412402), 66 Paul Street, London, England, EC2A 4NA, is the data controller for Help This Book. Contact us at hello@usefulbooks.com.
2. What we collect
Your account
- Email address (required; it's how you sign in)
- Name and, optionally, a profile picture and a username for your public author URL
- Your roles (author, subscriber, reader) and when you signed up
If you're an author
- The manuscripts, images and other files you upload or import (Microsoft Word, Markdown, or Google Docs)
- Your book site content, cover design and settings
- Any custom domain you connect
- The readers you invite or approve, and the team members you add
- Subscription status and billing identifiers from Paddle (we never see or store your card details)
If you're a reader
- Comments, highlights and reactions you leave on a draft
- Reading activity: which chapters you open, how far through them you get, and when. This is recorded as you scroll and is used to show authors where readers engage and where they drop off
- If you request access to a gated draft or follow a book: the name and email you give, and the time you consented to the author contacting you
You can read some public drafts without an account. In that case we assign your browser a random reader ID so your reactions stay attached to you. If you later sign in, we link that activity to your account.
Everyone
- Support conversations, if you contact us through the in-app chat or by email
- Notification preferences and the notifications we've sent you
- Product analytics: pages viewed, features used, browser and device type, and rough location (country/region). See section 6
- Server logs, including your IP address, used for security and rate limiting. These are kept for a short time and aren't linked to your account for other purposes
3. What authors can see about readers
This is the bit that makes Help This Book different from a normal website, so we want to be explicit.
When you read someone's draft, the author (and anyone they've added to their project team) can see:
- your comments, highlights and reactions, and where in the text you left them;
- your reading progress: which chapters you've opened, how far you got, and roughly when;
- your name and email, if you provided them when requesting access, following the book, or being invited. If you're reading anonymously, the author sees an anonymous reader.
Authors can export this feedback to work on their book. Authors agree in our Terms of Service to use reader data only for developing and promoting their book, and not to share it further.
4. Why we use your data
Under UK data protection law we need a lawful basis for each use. Here they are:
| What we do | Why | Lawful basis |
|---|---|---|
| Create and run your account, host content, deliver drafts to readers, show feedback to authors | It's the service you signed up for | Performance of a contract |
| Send sign-in links, notifications about comments and replies, and service announcements | You need them to use the service | Performance of a contract |
| Take payment, manage subscriptions, and keep tax records | Required to bill you and by law | Contract; legal obligation |
| Understand how the product is used and fix problems | To improve Help This Book | Legitimate interests |
| Rate limiting, abuse prevention, security monitoring | To keep the service safe | Legitimate interests |
| Let an author contact you after you request access or follow their book | You asked for it | Consent (you can withdraw it by telling us or the author) |
| Respond to your support requests | You asked us to | Legitimate interests |
We don't send marketing emails unless you've opted in, and every notification email has an unsubscribe link.
5. Who we share it with
We don't sell your data. We share it only with the providers below, who process it on our behalf under contracts that restrict what they can do with it.
| Provider | What they do for us | Where |
|---|---|---|
| Vercel | Hosts the application and serves custom domains | USA, EU edge |
| Amazon Web Services (S3, CloudFront) | Stores uploaded files and images and serves them | USA/EU |
| Our database hosting provider | Stores the application database | USA/EU |
| Upstash | Caching and background job queue | EU |
| Postmark | Sends sign-in and notification emails | USA |
| Paddle | Payment processing and subscription billing (merchant of record) | UK/EU |
| PostHog (EU cloud) | Product analytics | EU |
| Fathom Analytics | Privacy-focused, cookieless website analytics | EU/Canada |
| Help Scout | Support chat and help articles | USA |
| Only if you import a Google Doc: we read the document you share with our import account | USA |
We also use Slack internally to alert our team when a new author signs in; that message contains only your account ID.
Beyond that, we'll disclose personal data only if the law requires it, to protect our rights or safety or those of our users, or as part of a sale or reorganisation of our business (in which case the new owner will be bound by this policy).
6. Cookies and analytics
We set one cookie: a secure, HTTP-only session cookie that keeps you signed in for up to 30 days. It's strictly necessary for the service to work.
We don't use advertising cookies or cross-site tracking. Our analytics are set up to be as light as possible:
- PostHog runs in memory-only mode and doesn't store cookies or identifiers on your device. If you're signed in, events are linked to your account so we can understand usage and support you.
- Fathom is cookieless and doesn't identify individuals.
- Help Scout's support widget may store its own data in your browser to keep a chat open. It loads across Help This Book, including on book sites.
Your browser's local storage is used for preferences like theme and reading settings. That data stays on your device.
7. International transfers
We're based in the UK. Some of the providers above process data in the United States or elsewhere outside the UK. When they do, we rely on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, or on an adequacy decision, so your data has protection equivalent to UK law.
8. How long we keep it
- Account data: for as long as your account exists. If you ask us to delete your account, we delete it within 30 days, apart from what we must keep for tax and legal purposes (up to 7 years for billing records).
- Author content: until you delete it or your account. After a subscription ends your projects and feedback stay in your account so you can export them.
- Reader feedback: stays with the author's project because it's part of their work. If you delete your account, we detach your feedback from your identity so the author sees it as coming from an anonymous reader.
- Reading activity: kept while the related project exists; we may aggregate it anonymously for product analytics.
- Support conversations: up to 2 years.
- Server logs: typically 30 days or less.
- Backups: expire on a rolling schedule of up to 30 days.
9. Your rights
You can ask us to:
- show you the personal data we hold about you;
- correct anything that's wrong;
- delete your data ("right to erasure");
- give you a copy of your data in a portable format;
- stop or restrict certain processing, or object to processing based on legitimate interests;
- withdraw consent where we rely on it.
Email hello@usefulbooks.com and we'll respond within one month. We may need to confirm your identity first. There's no charge unless a request is clearly excessive.
If you're not happy with how we've handled your data, you can complain to the UK Information Commissioner's Office at ico.org.uk. If you live in the EU, you can also contact your local data protection authority.
10. Security
All traffic is encrypted in transit. Sign-in is by one-time email link or code, so there's no password for anyone to steal. Access to production systems is restricted to the people who need it. No system is perfectly secure, so please keep your own copy of your manuscript and tell us straight away at hello@usefulbooks.com if you think your account has been compromised.
11. Children
Help This Book isn't intended for anyone under 16, and we don't knowingly collect data from them. If you think a child has given us personal data, let us know and we'll delete it.
12. Changes to this policy
We'll update this policy when our practices change. For significant changes we'll email account holders before they take effect; smaller changes will just be posted here with a new date at the top.
13. Contact
Useful Books Limited 66 Paul Street, London, England, EC2A 4NA hello@usefulbooks.com