Privacy Policy

Last updated: 23 June 2026.

1. Who we are

George Georgiev operates https://thehandbook.ai and is the data controller for personal data described herein. Contact: support@thehandbook.ai.

2. What we collect

Data Source Storage Location
Email address Account registration, checkout, or OAuth provider Secure VPS (Germany)
Password hash (bcrypt) Account registration Secure VPS (Germany); never stored in plaintext
Display name Profile settings Secure VPS (Germany); public on comments and reviews
Avatar URL Profile settings Secure VPS (Germany)
Linked social account (provider + provider ID) OAuth sign-in (Google, X, TikTok) Secure VPS (Germany)
Passkey credentials (public key only) WebAuthn registration Secure VPS (Germany); private key never leaves your device
Stripe session/payment IDs Stripe webhook Secure VPS (Germany)
Purchase amount/currency Stripe webhook Secure VPS (Germany)
Marketing opt-in preference Optional checkbox at checkout Secure VPS (Germany); encrypted for marketing use
First access timestamp Recorded upon first access to purchased content Secure VPS (Germany); determines refund eligibility
Reading progress Recorded as you read chapters Secure VPS (Germany)
Activity logs Recorded on login, purchases, downloads, comments, and other actions Secure VPS (Germany); visible to you in your profile
Blog comments, reactions, and reviews Submitted by you Secure VPS (Germany); public as described
Gift keys you issue or redeem Generated or redeemed in your account Secure VPS (Germany)
Payment card details Stripe Not stored by us
hbk_session cookie Browser HttpOnly cookie (30 days, or 30 days with remember-me)
CSRF token Browser Session cookie

3. Why we collect it

  • Contract: Create and manage your account, deliver content access, issue gift keys, send transactional email, and record first access for refund eligibility.
  • Consent: Optional marketing email when you opt in at checkout.
  • Legitimate interest: Security, fraud prevention, rate limiting, error monitoring, and maintaining the integrity of community contributions.

4. Payment processing (Stripe)

Payments are processed by Stripe, Inc. We do not store full payment card details. Stripe's policy applies to payment data: https://stripe.com/privacy.

5. Cookies

We use strictly necessary cookies:

  • hbk_session: Authenticated session for account and reader access.
  • CSRF token: Protects form submissions from cross-site request forgery.

6. Marketing communications

Marketing email is opt-in only. The checkout checkbox defaults unchecked; no bundled consent is used. All marketing emails include an unsubscribe link. Unsubscribing halts marketing mail; transactional account and purchase messages continue.

7. Retention

Purchase records are retained for the product life cycle and legal compliance, and are included in daily backups (14-day retention). Activity logs, reading progress, and community contributions are retained until you delete them or your account. Erasure requests are subject to the limits below.

8. Your rights (GDPR / UK GDPR)

EEA/UK residents may have the right to:

  • Access data.
  • Rectify inaccurate data.
  • Erasure ("right to be forgotten") where applicable.
  • Data portability.
  • Object to processing based on legitimate interest.
  • Lodge a complaint with a supervisory authority.

You can exercise several of these rights directly from your account:

  • Data export: Download a copy of your profile, purchases, activity logs, and reading progress from your profile page.
  • Account deletion: Permanently disable your account from your profile page (requires password confirmation). Your personal data is cleared and sessions revoked; purchase records are retained for legal compliance.
  • Erasure without an account: Request erasure by email without logging in; a verification link is sent to your address.

9. How to exercise your rights

Email support@thehandbook.ai from your account email address, or use the self-service tools in your profile. We aim to respond within 30 days.

10. Limits on erasure

Stripe retains payment records per their policy and legal obligation. Backups retain deleted data until the rotation cycle completes.

11. International transfers

Data is processed on a VPS in Germany. The controller is based in Bulgaria. Transfers outside this base rely on appropriate safeguards.

12. Changes to this policy

This policy is subject to updates. Material changes will be posted on this page with a revised "Last updated" date. When we make a material change, we will notify registered users by email and show a notice in your account prompting you to review the updated policy. Continued use of the service after a material change constitutes acceptance of the updated policy.

13. Processors

  • Stripe, Inc.: Payment processing.
  • Resend: Transactional and marketing email delivery.
  • Cloudflare: DNS and TLS.
  • VPS hosting provider: Application infrastructure (Germany).