Data Deletion Policy
Last Updated: October 30, 2025
1. Your Right to Data Deletion
Under the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA), you have the right to request deletion of your personal data ("Right to be Forgotten"). BookEnds respects this right and provides a straightforward process for account and data deletion.
2. What Data Is Deleted
When you delete your BookEnds account, the following data is permanently removed:
2.1 Personal Information
- Account credentials: Email address, username, password hash
- Profile information: Display name, bio, profile picture
- Authentication data: OAuth tokens, session cookies
- Contact information: Any additional contact details you provided
2.2 User-Generated Content
- Stories: All alternative book endings you created
- Drafts: Unpublished stories and work-in-progress content
- Comments: Comments and interactions on stories
- Favorites: Saved stories and reading lists
2.3 Usage Data
- Activity logs: Login history, page views, feature usage
- Preferences: Theme settings, notification preferences
- Analytics data: Aggregated usage statistics
3. What Data May Be Retained
Certain data may be retained for legal, security, or operational reasons:
- Legal compliance: Data required to comply with legal obligations (e.g., tax records, dispute resolution)
- Security: Records of security incidents or Terms of Service violations
- Backup systems: Data in automated backups may persist for up to 90 days
- Aggregated data: Anonymous, aggregated statistics that cannot identify you
4. How to Request Data Deletion
Option 1: Self-Service Account Deletion (Recommended)
You can delete your account directly through your profile settings:
- Log in to your BookEnds account
- Go to Profile Settings (click your profile icon → Settings)
- Scroll to the "Danger Zone" section
- Click "Delete Account"
- Confirm your decision by typing your username
- Click "Permanently Delete My Account"
⚠️ This action is irreversible. All your data will be permanently deleted within 30 days.
Option 2: Email Request
If you cannot access your account, send an email to:
Include the following information:
- Subject line: "Data Deletion Request"
- Your username: The username associated with your account
- Email address: The email address registered to your account
- Verification: Any additional information to verify your identity
We will respond within 48 hours and complete the deletion within 30 days.
Option 3: OAuth Provider Data Deletion
If you signed up using GitHub, Google, or Amazon, you can also request data deletion through their platforms:
- GitHub: Revoke BookEnds app access at GitHub Settings → Applications
- Google: Revoke access at Google Account Permissions
- Amazon: Manage apps at Amazon Apps & Services
Note: Revoking OAuth access does not automatically delete your BookEnds account. Please use Option 1 or 2 above.
5. Data Deletion Timeline
6. Important Considerations
⚠️ Before You Delete
- Irreversible: Account deletion is permanent and cannot be undone
- Content loss: All your stories and content will be permanently lost
- No recovery: We cannot restore deleted accounts or content
- New account: You can create a new account later, but previous data will not be restored
Alternative: Account Deactivation
If you're unsure about permanent deletion, consider temporarily deactivating your account instead:
- Your account and content will be hidden but not deleted
- You can reactivate your account anytime by logging back in
- Your username will be reserved during deactivation
To deactivate instead of delete, contact us at [email protected]
7. Data Export Before Deletion
Before deleting your account, you have the right to export your data:
- Log in to your BookEnds account
- Go to Profile Settings → Privacy & Data
- Click "Download My Data"
- Receive a ZIP file containing all your data within 24 hours
The export includes: account information, profile data, all published and draft stories, and activity history.
8. Third-Party Services
BookEnds uses third-party services that may have separate data retention policies:
- OAuth Providers: GitHub, Google, Amazon retain their own authentication records
- Email Service: Gmail SMTP may retain email delivery logs
- AI Service: OpenRouter does not store your prompts or generated content
To delete data held by these services, please contact them directly through their respective platforms.
9. Contact Us
If you have questions about data deletion or need assistance:
- Email: [email protected]
- Subject line: "Data Deletion Inquiry"
- Response time: Within 48 hours
Related Legal Documents
- Privacy Policy - How we protect your data
- Terms of Service - User agreement and platform rules
© 2025 Paul M. Backus. All rights reserved.