Privacy Policy

Effective August 20, 2026

This policy explains what Book Ad Doctor collects, why, and what we do with it. It describes how the service actually works today. If something changes, this page changes with it.

Who we are

Book Ad Doctor is an advertising-analysis service for authors and advertisers. Questions about privacy can be sent to Mortichi@gmail.com.

What we collect and store

Account information. When you sign in with Google, we store your verified email address, the display name Google provides, and an internal account identifier we generate. We do not ask for your address, phone number, date of birth, or author biography.

Session information. We store a session token so you stay signed in, together with its expiry. It is kept in a cookie that your browser sends back to us; it is not readable by scripts on the page.

Uploaded advertising reports. When you upload a CSV or XLSX report, we read it to run your analysis. In one situation we also keep the uploaded file itself: when our universal importer is not fully confident how to read an unfamiliar report, the file (up to 5 MB) is stored so that your "Looks right" or "Fix one" answer can be applied without asking you to upload it again. Files kept for that reason are temporary: the file is deleted as soon as your answer has been applied and a valid analysis has been produced, and any file left unconfirmed is deleted automatically within 24 hours. Not everything we hold is deleted automatically — your finished analyses and your account records remain until you ask us to remove them.

Analysis results. We store the analysis we produce for you — the totals, per-row metrics, recommendations and explanations, along with the report's own campaign, ad, keyword and audience names, the file name, and the royalty-per-order figure you entered. This is what makes your result link work later.

Usage and entitlement records. We store whether your free analysis is available, reserved or used, your paid analysis credit balance, how many analyses you have completed, how many purchases you have made, and the dates of your most recent analysis and purchase.

Request identifiers. Each analysis submission carries a request identifier that we store with the resulting analysis id, so a refreshed, double-clicked or replayed request cannot run or charge twice.

Payment records. We store the Stripe checkout session id, the payment intent id, the amount and currency, the payment status, your account id and email, and the identifiers of the Stripe events we have already processed. We also store Stripe event ids so a repeated event cannot grant a second credit.

Learned report layouts. When we work out how to read an unfamiliar report, we save a fingerprint of its column structure — normalised column names and which metric each one represents — so the next upload of that layout is recognised automatically. Your advertising figures are not stored for that purpose.

Operational logs. Our servers keep the ordinary technical logs needed to run and secure the service, such as request paths, status codes and error details.

What we do not collect

We never receive or store your raw card number, card expiry or security code. Payments are handled by Stripe (including Link) on Stripe's own hosted checkout page.

We do not use advertising or remarketing trackers, cookie-based analytics, session recording or fingerprinting, and we do not track you across other websites. The only cookie we set is the one that keeps you signed in. Your browser's session storage is used briefly to hold a report you selected before signing in or paying, so you do not have to choose the file again; it is cleared as soon as the report is restored.

We do not sell your personal information.

Website analytics

Book Ad Doctor uses Cloudflare Web Analytics to understand general website usage, such as page views, visits, referral sources, and site performance. Cloudflare Web Analytics is designed to operate without using cookies or persistent browser identifiers for analytics and does not track individual visitors across websites. It does receive ordinary technical information about a page request, such as the page address, referrer, general location derived from the request, and browser and device type.

We do not send your account email address, your user or payment identifiers, the contents of your uploaded advertising reports, your analysis results, your share links, or any payment or card information to Cloudflare Web Analytics, and we do not create custom analytics events containing your data.

Cloudflare Web Analytics is the only analytics product we use. We do not use Google Analytics, advertising pixels, remarketing tags or session-recording tools.

How we use what we collect

To run the analysis you asked for and show you the results. To sign you in and keep you signed in. To know whether you have an analysis available. To take payment and grant the credit you paid for. To prevent duplicate charges, duplicate analyses and abuse. To find and fix faults in the service.

Who else sees it

We share information only with the providers needed to run the service: Google, for sign-in and verifying your email address; Stripe, for processing payments; and our hosting and database provider, which stores the data described above. We may also disclose information if the law requires it.

We do not send your advertising data to any provider that is not needed to deliver the analysis you requested.

Result links

Your own results are private to your account: signing in is required to open them, and another customer cannot open them by guessing an identifier.

If you choose to share a result, we generate a separate share link containing a long random token. Anyone who receives that unique link can view that one result without signing in — that is the point of sharing it, so treat the link as private if the report behind it is private. A shared result contains no account, entitlement or payment information.

Security

We take reasonable steps to protect your information: sign-in through Google rather than passwords we hold, session cookies that scripts cannot read, entitlement checks enforced on the server, and payments handled entirely by Stripe. No online service can promise perfect security, and we do not claim to.

Your choices

You can sign out at any time. You can ask us what we hold about your account, ask us to delete your account and its stored analyses and uploaded files, or ask a question about this policy, by emailing Mortichi@gmail.com. Some records connected to completed payments may be kept where we need them for accounting or fraud prevention.

Children

Book Ad Doctor is intended for adults running advertising campaigns, not for children.

Changes

If we change how the service handles information, we will update this page and the effective date above.

Contact: Mortichi@gmail.com