Your ideas deserve a private space.
This policy explains how the AI Book Writer Android app and its supporting services handle your information. App Collection operates the app. Version 2.x supports Google sign-in or an email verification code, with Google Play purchases for ordinary book creation. Dedicated review accounts use separately provisioned password access. The older version 1.0.5 is described separately below.
Information we use
- Account details: your account identifier, email address, and name associate your private library with your account. Google sign-in also supplies a Google account identifier and profile image URL. Email sign-in verifies access to the email address you enter.
- Email verification and review credentials: our authentication database stores a keyed hash of each email code, a hashed email identifier, challenge expiry and attempt records, and whether a code was used. It does not store the plain-text code. Dedicated review account passwords are stored as password hashes, not plain-text passwords. Authentication records and server-side account permissions distinguish ordinary sign-in from separately provisioned review access.
- Book requests: your book idea and author name, along with generated books, covers, and related files. The current form asks only for the idea and author name. Older requests may retain language, audience, and chapter instructions, including when recovering an earlier paid purchase. Unfinished drafts are kept on your device until submission after a verified payment or an authorized review submission.
- My Books searches: search text is sent to our API to find matching books in your account; these searches are not processed only on your device.
- Purchase records: the Google Play purchase token, product and order references, verification and consumption status, and their connection to your book. Google processes payment information; we do not receive your full payment card details. Authorized review submissions are recorded separately and do not create a Google Play purchase.
- Firebase installation and notification data: Firebase initializes automatically when the app starts and may generate an installation identifier and messaging registration token before you enable notifications. Firebase processes these identifiers and configuration data to operate its messaging service. When notifications are enabled for your account, our service uses a device notification token and delivery status to let you know when a book is ready.
- Support and service records: reports you submit, account deletion requests, generation usage, operational status, and administrator audit records. Authentication timestamps, hashed email identifiers, and request-rate records are used to limit repeated sign-in attempts and maintain service reliability.
How your information is used
We use this information to authenticate your account, verify and recover purchases, send paid or authorized review requests to the book generator, deliver your books, handle retries and support requests, and protect against unauthorized access. Administrators can review book requests and generated content when operating the service or resolving a report.
Services that process information
Google provides sign-in, Google Play billing, and Firebase Cloud Messaging. Our hosting service stores account and book data. OpenAI processes the instructions and content sent to the AI book generator. Avoid including passwords, financial credentials, or other sensitive information in your prompts. These providers process information according to their own applicable terms and privacy policies, including the Google Privacy Policy and Firebase privacy information.
When you request an email code, our email delivery service receives your email address and the code so it can deliver the sign-in message. The code expires after ten minutes and is usable once. Dedicated review accounts use a server-provisioned email and password without requiring a Google account or email code; only that authorized access can submit review books without a Google Play charge.
We do not sell your personal information. Version 2.x does not include advertising or ad-tracking SDKs. Your app library requires account authorization. When you choose Download or Share, copies leave the private library and are controlled by your device and the recipients or apps you select.
Older app version 1.0.5 (version code 5)
Version 1.0.5 uses older third-party advertising, analytics, and notification SDKs: Google Mobile Ads, Facebook Audience Network, Firebase Analytics, and OneSignal. These integrations automatically collect and share device identifiers, app and advertising interactions, and diagnostic and performance information for advertising, analytics, and fraud prevention or security. They also process IP addresses that can be used to estimate approximate location. Provider processing is not limited to the immediate request. Notification services also use interaction information to deliver and measure communications. These services operate under their provider policies, including the Google Privacy Policy, Meta Privacy Policy, and OneSignal Privacy Policy. This legacy-version notice does not describe advertising in version 2.x, which has no advertising or ad-tracking SDKs.
Storage, security, and your choices
Account sessions are protected using secure device storage and server verification. Purchases are verified on the server. Generated app books are served through authorized endpoints. The generation API key stays on the server and is never included in the Android app.
You can disable notifications in the app or Android settings. The app's notification option controls notification permission requests and whether the notification token is registered or enabled for your account; it does not prevent all Firebase initialization or identifier processing. You can sign out, remove downloaded copies from your device, and request account deletion. Book generation uses AI and may produce inaccurate or inappropriate content; you can report a book from its details screen.
Retention and account deletion
Account information, submitted requests, and generated files remain available while your account is active. A verified deletion request starts the account removal process. We remove the account’s identifying profile information, email sign-in identity, associated code-verification records, any review password credential, active sessions, notification tokens, support content, submitted prompts, and generated files as part of processing the request. A running generation or outstanding purchase reconciliation may need to finish before final deletion. Expired email-verification records are also removed by scheduled maintenance.
Limited purchase and audit records may be retained to reconcile payments and prevent duplicate redemption or fraud. We also retain non-public markers identifying former app book files so deleted content cannot become accessible through legacy download routes. These retained records are not an active library. Device downloads, shared copies, and provider records must be managed separately.
See Delete your account for the in-app and web request options.
Contact and changes
Contact the app team at subrat@appcollection.in. Never send passwords, full card details, or API keys.
We may update this page as the service changes. The effective date above identifies the current policy.
