Privacy Policy
Last updated: 10 August 2026
Who we are
The Living Library ("the Service") is operated by Nexlify Studios Ltd, a company registered in England and Wales with its registered office at 128 City Road, London, United Kingdom, EC1V 2NX. For the personal data described in this Policy, Nexlify Studios Ltd is the data controller and is responsible for deciding how it is processed. You can reach us at jasonplant44@gmail.com.
What we collect
- Account info — email address and display name when you sign up.
- Conversations — the book title and author you search for, and the full text of your messages and the replies, stored so you can return to them later.
- Billing info — handled securely by Stripe. We never see or store your card details; we receive only the subscription status, plan, and customer identifiers we need to grant access.
- Usage data — basic counters (e.g. number of replies) used for limits and improvements.
- Technical data — IP address, device and browser information collected automatically to keep the Service secure and reliable.
How we use it
We use your information to:
- Provide and personalize the Service.
- Generate AI responses. Your messages are sent to AI providers only as needed to produce the reply.
- Process payments and manage subscriptions.
- Communicate with you about your account or important updates.
- Detect abuse, prevent fraud, and improve reliability.
Your messages and content
Anything you type, paste, or otherwise send to the Service — including any book excerpts, quotes, or copyrighted material you choose to provide — is transmitted to our AI model sub-processors on a per-request basis to generate the response you see. We do not use the content of your messages to train AI models.
Your conversations are stored on our servers. We save the full text of your messages and of the replies you receive, together with the book title and author you searched for, so that you can return to a conversation later and continue it across devices. This happens whether or not you have created an account, because a session is created for every visitor. Conversations are also cached in your own browser's local storage; you can clear that at any time from your browser settings.
Because conversations are stored, please avoid sharing information you would not want kept — such as sensitive personal, health, or financial details. The Service is a creative and educational tool and is not a substitute for professional medical, legal, mental health, or financial advice.
Who can read your conversations
We do not carry out routine human review of conversations. There is no moderation team, no quality-assurance review of message content, and no automated scanning of what you write for copyright, safety or any other purpose on our side.
Because conversation text is stored without application-level or field-level encryption, it is technically readable by the small number of people and systems with administrative access to our database: the operator of the Service (Nexlify Studios Ltd) via the backend console, and the infrastructure staff of our hosting and database provider under their own access controls. In practice a person would only look at the content of a conversation to investigate a technical fault, to respond to a support request that refers to a specific conversation, or where we are compelled to by law or valid legal process.
Our own storage of your chat history is separate from, and governed by different rules than, the short-term retention that AI Providers apply for their own abuse monitoring. The retention periods further below apply to our storage; each AI Provider's own published policy applies to theirs.
AI sub-processors
To generate responses, we transmit your prompts to one or more third-party AI model providers acting as our sub-processors, which currently include OpenAI, Anthropic, and Google (collectively, "AI Providers"). The set of AI Providers may change over time as the Service evolves.
AI Providers process your input only to return a response and are contractually restricted from using API-submitted content to train their foundation models. Each AI Provider may temporarily retain inputs for abuse-monitoring and safety purposes in accordance with its own published policies. Aside from that provider-side retention, the AI Providers do not keep your content. This is separate from our own storage: we do save your conversations on our servers, as described above and subject to the retention periods below.
Legal basis for processing
Where data protection law applies (such as the UK GDPR or EU GDPR), we rely on the following legal bases:
- Performance of a contract — to create your account, deliver the Service, and process subscription payments.
- Legitimate interests — to keep the Service secure, prevent abuse, debug issues, and improve the product — balanced against your rights and expectations.
- Consent — for any optional communications you have specifically opted into. You can withdraw consent at any time.
- Legal obligation — to comply with tax, accounting, and other legal requirements.
Who we share with
We share data only with trusted recipients needed to run the Service:
- Hosting and database providers — to store your account, subscription status, usage counters, and recent book metadata.
- AI model providers — to generate the responses you see, on a per-request basis.
- Stripe — for checkout, subscription management, payments, invoicing, and refunds.
- Professional advisers — such as accountants or lawyers, where reasonably necessary.
- Authorities — where required by law, regulation, or valid legal process.
We do not sell your personal data.
International transfers
Some of our service providers are based outside the UK and EEA. When we transfer your data internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or equivalent UK transfer mechanisms.
Security
We use appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS/HTTPS) for all traffic between your device and our servers and between our servers and our providers; row-level security policies in the database so each account can only reach its own records; strict access controls and principle of least privilege for staff and systems; and regular review of our infrastructure. Our database and file storage provider encrypts data at rest at the disk/volume level. We do not apply any additional application-level or field-level encryption to conversation content, so you should assume your messages are readable by our database provider and by the limited staff with administrative access. No system is perfectly secure, but we work continuously to keep your information safe.
Your rights
Depending on your location, you may have the right to access, correct, delete, restrict, port, or object to our processing of your personal data, and to withdraw consent where processing is based on consent. To exercise any of these rights, email jasonplant44@gmail.com and we will respond within one month.
- UK and EEA (UK GDPR / GDPR) — in addition to the rights above, you may lodge a complaint with your local supervisory authority; in the UK this is the Information Commissioner's Office.
- United States — residents of California, Colorado, Connecticut, Virginia and other states with comparable laws may opt out of the sale or sharing of personal information and of targeted advertising, request access to or deletion of their data, and are protected from discrimination for exercising those rights. Use the "Do Not Sell or Share My Personal Information" link in the footer, or the button above. We honour Global Privacy Control signals as an opt-out.
- Canada (PIPEDA and Quebec Law 25) — you may access and correct your personal information and withdraw consent. Visitors in Quebec are asked for consent before any analytics or advertising technology is used.
- Australia (Privacy Act) — you may access and correct your personal information and complain to the Office of the Australian Information Commissioner.
Data retention
We retain account data, subscription status, usage counters, and your conversations for as long as your account is active, subject to the automated deletion rules below. These rules run daily and are enforced automatically:
- Dormant conversations — any conversation that has not been opened for 6 months is automatically deleted, along with all of its messages.
- Cancelled or lapsed subscriptions — if a subscription is cancelled or lapses, stored conversations are deleted 90 days after the last successful payment. Billing records are kept where we are legally required to retain them.
- Deletion requests — if you delete your account or ask us to delete it, all associated conversations and personal data are purged within 30 days, except where we are legally required to retain records (for example, billing records for tax purposes).
To request deletion, email us at jasonplant44@gmail.com from the address associated with your account. We will record the request and complete the purge within 30 days.
We do not currently offer an in-app setting to switch off conversation storage, or a button to delete an individual conversation — if you use the Service, your conversations are saved. You can ask us by email to delete your account and all associated conversations, and you can clear the copies cached in your own browser at any time from your browser settings.
Changes
We may update this Policy from time to time. Material changes will be posted here with a revised "Last updated" date.
Contact
Questions about your privacy? Reach Nexlify Studios Ltd at jasonplant44@gmail.com.
