Privacy Policy
Last updated: 23 June 2026.
1. Who we are
George Georgiev operates https://thehandbook.ai and is the data controller for personal data described herein. Contact: support@thehandbook.ai.
2. What we collect
| Data | Source | Storage Location |
|---|---|---|
| Email address | Account registration, checkout, or OAuth provider | Secure VPS (Germany) |
| Password hash (bcrypt) | Account registration | Secure VPS (Germany); never stored in plaintext |
| Display name | Profile settings | Secure VPS (Germany); public on comments and reviews |
| Avatar URL | Profile settings | Secure VPS (Germany) |
| Linked social account (provider + provider ID) | OAuth sign-in (Google, X, TikTok) | Secure VPS (Germany) |
| Passkey credentials (public key only) | WebAuthn registration | Secure VPS (Germany); private key never leaves your device |
| Stripe session/payment IDs | Stripe webhook | Secure VPS (Germany) |
| Purchase amount/currency | Stripe webhook | Secure VPS (Germany) |
| Marketing opt-in preference | Optional checkbox at checkout | Secure VPS (Germany); encrypted for marketing use |
| First access timestamp | Recorded upon first access to purchased content | Secure VPS (Germany); determines refund eligibility |
| Reading progress | Recorded as you read chapters | Secure VPS (Germany) |
| Activity logs | Recorded on login, purchases, downloads, comments, and other actions | Secure VPS (Germany); visible to you in your profile |
| Blog comments, reactions, and reviews | Submitted by you | Secure VPS (Germany); public as described |
| Gift keys you issue or redeem | Generated or redeemed in your account | Secure VPS (Germany) |
| Payment card details | Stripe | Not stored by us |
hbk_session cookie |
Browser | HttpOnly cookie (30 days, or 30 days with remember-me) |
| CSRF token | Browser | Session cookie |
3. Why we collect it
- Contract: Create and manage your account, deliver content access, issue gift keys, send transactional email, and record first access for refund eligibility.
- Consent: Optional marketing email when you opt in at checkout.
- Legitimate interest: Security, fraud prevention, rate limiting, error monitoring, and maintaining the integrity of community contributions.
4. Payment processing (Stripe)
Payments are processed by Stripe, Inc. We do not store full payment card details. Stripe's policy applies to payment data: https://stripe.com/privacy.
5. Cookies
We use strictly necessary cookies:
hbk_session: Authenticated session for account and reader access.- CSRF token: Protects form submissions from cross-site request forgery.
6. Marketing communications
Marketing email is opt-in only. The checkout checkbox defaults unchecked; no bundled consent is used. All marketing emails include an unsubscribe link. Unsubscribing halts marketing mail; transactional account and purchase messages continue.
7. Retention
Purchase records are retained for the product life cycle and legal compliance, and are included in daily backups (14-day retention). Activity logs, reading progress, and community contributions are retained until you delete them or your account. Erasure requests are subject to the limits below.
8. Your rights (GDPR / UK GDPR)
EEA/UK residents may have the right to:
- Access data.
- Rectify inaccurate data.
- Erasure ("right to be forgotten") where applicable.
- Data portability.
- Object to processing based on legitimate interest.
- Lodge a complaint with a supervisory authority.
You can exercise several of these rights directly from your account:
- Data export: Download a copy of your profile, purchases, activity logs, and reading progress from your profile page.
- Account deletion: Permanently disable your account from your profile page (requires password confirmation). Your personal data is cleared and sessions revoked; purchase records are retained for legal compliance.
- Erasure without an account: Request erasure by email without logging in; a verification link is sent to your address.
9. How to exercise your rights
Email support@thehandbook.ai from your account email address, or use the self-service tools in your profile. We aim to respond within 30 days.
10. Limits on erasure
Stripe retains payment records per their policy and legal obligation. Backups retain deleted data until the rotation cycle completes.
11. International transfers
Data is processed on a VPS in Germany. The controller is based in Bulgaria. Transfers outside this base rely on appropriate safeguards.
12. Changes to this policy
This policy is subject to updates. Material changes will be posted on this page with a revised "Last updated" date. When we make a material change, we will notify registered users by email and show a notice in your account prompting you to review the updated policy. Continued use of the service after a material change constitutes acceptance of the updated policy.
13. Processors
- Stripe, Inc.: Payment processing.
- Resend: Transactional and marketing email delivery.
- Cloudflare: DNS and TLS.
- VPS hosting provider: Application infrastructure (Germany).