Skip to content

Privacy Policy

How E-BOOKA handles local files, accounts, billing data, Cloud Library projects, and analytics choices.

Last updated: August 1, 2026

Controller and scope

E-BOOKA is the data controller for personal data processed in connection with operating this website, optional accounts, and paid workflow features. Operator identification is available in the service operator section of the Terms of Service. Privacy requests: [email protected].

This policy explains what happens when you visit the site, use free local converter/editor pages, or choose optional account and Cloud Library workflows.

Optional accounts and paid access

Your files

When you choose cloud save or restore, the selected project payload is uploaded to user-owned cloud project storage as the latest saved project file so it can be reopened later. We do not sell, review for advertising, share, or use your source files or generated EPUBs to train AI models.

Cloud Library files are protected by account access checks and short-lived signed storage URLs. They are not end-to-end encrypted from E-BOOKA operators, so authorized operations staff and storage providers may be technically able to access stored project bytes when needed for security, support, legal compliance, or service operation.

Data we process

  • Technical request data needed to deliver the website, such as IP address, browser type, URL requested, and timestamp.
  • Local preferences stored in your browser, such as theme choice.
  • Optional product analytics event names and short non-identifying labels only when you explicitly enable that setting.
  • Catalog cache data stored in your browser so pricing and feature labels can load reliably.
  • Files you choose inside the app, processed locally by your browser for conversion or editing — not transmitted to our servers.
  • Optional account data for paid access, such as email, password hash, Google account identifier when linked, session state, CSRF state, and email verification state.
  • Billing-owned access state, checkout records, subscription/customer identifiers, provider event references, and scrubbed payment metadata needed to grant or revoke paid features.
  • Cloud project metadata, latest saved project files, duplicated project files, and quota usage when you explicitly use paid cloud storage.
  • Random backend request IDs plus identifier-redacted API path, method, response status, and duration for failed-request correlation. Request logs exclude query strings, request and response bodies, account identity, and book data.
  • When you select Copy details on an error toast, your browser creates a local diagnostic report with error code, release, coarse browser and operating-system family, locale, UTC offset, viewport, theme, online state, and available request ID. It is not sent automatically, does not deliberately read account identity, book state, cookies, browser storage, full user agent, or IP address, and redacts known sensitive patterns from error text. Review the report before sharing it with support.
  • Transactional notification records for email verification, billing, quota, export, deletion, and account workflows.
  • Messages you voluntarily send to us by email or support channels.

Where data comes from

  • Directly from you when you create an account, contact support, choose analytics, or save a cloud project.
  • From your browser and device when they request pages, use necessary security cookies, or call account and cloud APIs.
  • From Paddle when a checkout, subscription, refund, dispute, or other billing event relates to your account.
  • From Google when you choose Google sign-in or link a Google identity.
  • From storage, email, hosting, security, and monitoring providers when they deliver the requested service or report an operational event.

Purposes and legal bases

  • Contract: create and secure optional accounts; provide Cloud Library, paid features, project downloads, account controls, and support you request.
  • Legitimate interests: deliver and improve the service, prevent abuse and fraud, protect accounts, diagnose reliability problems, and defend legal claims without overriding your rights.
  • Consent: send optional product analytics only after you enable analytics; you can withdraw that choice in this policy page.
  • Legal obligation: retain or disclose limited records where tax, accounting, sanctions, court, law-enforcement, or other applicable rules require it.
  • Paddle processes buyer transactions under its own legal bases as Merchant of Record and explains them in Paddle's privacy notice.

Third-party services

  • Paddle acts as authorized reseller and Merchant of Record for paid orders and is an independent controller for buyer transactions. Paddle processes checkout, payment details, sales taxes, invoices, refunds, returns, fraud prevention, and payment support.
  • Paddle and E-BOOKA share limited buyer and transaction data as separate controllers for product fulfillment, account access, support, fraud prevention, and compliance. E-BOOKA receives verified webhook events and stores provider references plus billing access state, not full card numbers.
  • Google may process OAuth data when you choose Google sign-in or link a Google account.
  • Amazon Web Services hosts production infrastructure in the us-east-1 region. AWS services include CloudFront and S3 for delivery and storage, ECS and RDS for the account and cloud backend, SES for transactional email, and CloudWatch for operational logs and monitoring.
  • Cloudflare provides DNS, proxy delivery, traffic protection, and optional privacy-focused web analytics for the public domain.

Providers may process data outside your country. Where required, the relevant provider agreements use safeguards such as Standard Contractual Clauses or equivalent transfer mechanisms. Contact us for more information about a specific provider relationship. Paddle explains its independent buyer-data processing in its Privacy Notice.

Cookies and local storage

E-BOOKA does not use advertising cookies or cross-site tracking cookies. Signed-in flows use necessary session and CSRF cookies so the backend can authenticate requests securely. Your browser may use localStorage for interface preferences and analytics choice. IndexedDB may hold one local recovery draft for the active cloud project. You control browser storage through browser settings, but clearing it may remove preferences or recovery data.

Security and delivery providers may use necessary technologies to protect the site and deliver pages reliably.

Sharing and retention

  • We do not sell personal information.
  • Free conversion and editing files are not stored on E-BOOKA servers.
  • Optional cloud project files, metadata, duplicate projects, and quota records remain until you delete the project or account, subject to backup and legal-retention limits.
  • When an account with active billing is deleted, E-BOOKA first requests immediate subscription cancellation from Paddle. If cancellation cannot be confirmed, account deletion stops so billing is not orphaned from the account.
  • Deleted cloud projects remain in Trash and count toward quota until you restore them, delete them forever, empty Trash, or delete the account. No automatic Trash expiry is currently promised.
  • Account deletion removes the account, Cloud Library projects, stored files, product access, and account notifications after active subscription handling. Paddle may retain buyer and transaction records under its own legal obligations. Sanitized E-BOOKA payment event records may be retained without direct account links for legal, tax, security, and abuse-prevention obligations.
  • Account, billing access, verification, export, deletion, and notification records are retained while needed to operate the account and afterwards only for legal, accounting, security, fraud-prevention, dispute, or audit needs.
  • Optional product analytics are retained only while needed for aggregate product and reliability analysis, then deleted or anonymized. Disabling analytics stops future optional event collection.
  • Production infrastructure currently defaults to 30 days for application logs and seven days for database backups and non-current project-object versions; deployment settings and legal holds may change those periods.
  • Emails you send may be retained as long as needed to answer, troubleshoot, or keep a record of the request.

Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal data. You may also have the right to complain to a data protection authority.

For free browser-only tools, most file-related rights are satisfied by design because files are not uploaded. For paid accounts, rights may apply to account data, project metadata, cloud project objects, billing access records, emails you sent us, or technical data held by infrastructure providers.

To exercise any right, contact [email protected]. We may need enough information to verify the request and match it to an account. We will not discriminate against you for exercising applicable privacy rights.

GDPR — European Union

Where GDPR applies to our processing of people in the European Union or European Economic Area, these rights and disclosures apply.

  • Data Controller: the E-BOOKA operator identified in the Service operator section of the Terms of Service. Contact: [email protected].
  • Lawful basis: Legitimate interest (GDPR Art. 6(1)(f)) for site security and reliability; contract (Art. 6(1)(b)) for optional account and paid features; legal obligation (Art. 6(1)(c)) where required.
  • Recipients: infrastructure, security, payment, storage, authentication, email, logging, monitoring, and support providers needed to operate the service.
  • International transfers: providers may process data outside the EU or EEA using Standard Contractual Clauses or equivalent safeguards where required.
  • Right to Access (Art. 15): Request account, project, email, or technical details at [email protected].
  • Right to Erasure (Art. 17): Free browser-only files are not uploaded. Paid account and project data can be deleted subject to legal, security, billing, and backup-retention limits.
  • Right to Portability (Art. 20): Account export controls are available for signed-in accounts where applicable.
  • Right to Object (Art. 21): We do not build advertising profiles; contact us for applicable objections.
  • Right to lodge a complaint with your national supervisory authority.

United States state privacy rights

Some US state privacy laws grant rights when their applicability thresholds and other conditions are met. Where such a law applies, we will honor the rights it requires.

  • We do not sell or share personal information with third parties for advertising or cross-context behavioral tracking.
  • Free browser-only tools do not require personal information. Optional paid accounts process identifiers, internet activity, commercial information, account records, billing access, and cloud project data.
  • Sources include you, your browser/device, payment provider events, Google OAuth when you choose it, storage providers, and operational service providers.
  • Purposes include site delivery, security, account operation, paid access, cloud storage, support, compliance, fraud prevention, and service reliability.
  • Applicable rights may include access, deletion, correction, portability, or appeal of a denied request.
  • You may use an authorized agent where applicable. We may verify the request before acting on it.
  • To submit a request, contact [email protected].

Privacy contact

For privacy questions or requests, contact [email protected].

Children

E-BOOKA is not directed to children. Do not create an account or use paid workflows if you are not old enough to enter an online service contract in your location without parent or guardian consent.

Do Not Track

E-BOOKA does not build advertising profiles or use cross-site behavioral tracking. Because Do Not Track (DNT) is not a uniform technical standard, the site does not change behavior in response to DNT browser signals.

Changes

We may update this Privacy Policy when tools, infrastructure, or legal requirements change. The date above shows the latest revision.

Optional product analytics

Off by default. If enabled, E-BOOKA sends limited product events such as pricing views, checkout outcomes, and Cloud Library save results. Current event payloads contain only approved event names and short operational labels. They do not send book contents, filenames, book titles, email or account IDs, passwords, or payment details. Analytics requests still contain ordinary technical request data, such as IP address, as described in this policy.