Legal
Privacy Policy
Last updated: 29 July 2026
This policy explains, in accordance with Articles 13 and 14 GDPR, how personal data is processed when you visit ManuBook.com, use public content, complete checkout or use the ManuBook application.
1. Controller
Denis Hoeger Caballero Consulting e.K.
Nobelstraße 3-5
41189 Mönchengladbach
Germany
Email: support@manubook.com
2. Scope and roles
This policy covers visitors, prospective customers, private and business customers, authors, invited beta readers and support contacts. We generally act as controller for the website, accounts, billing, security and support. Where a business customer processes third-party personal data through ManuBook and we act only on documented instructions, we may act as processor under Article 28 GDPR.
3. Website access and security logs
We process connection data such as IP address, timestamp, requested URL, referrer, browser, device, operating system, status code and transferred volume to deliver and secure the service. The legal bases are Article 6(1)(b) and (f) GDPR.
4. Cookies and language preference
Essential cookies and local storage are used for sessions, security, consent and your manually selected language. Optional audience measurement is activated only after consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR. You may change your choice through “Cookies” in the footer.
5. Accounts and author content
Depending on your use, we process account details, roles, language, subscription status, manuscripts, chapters, plot and character data, notes, comments, correction decisions, design settings, cover files, exports, social-media drafts and author-profile content. Processing is necessary to provide the service under Article 6(1)(b) GDPR. Manuscripts are not used to train generative AI models.
6. Beta readers
For invitations we process email address, invitation status, the books shared with that reader and later account, reading and comment data. Readers can access only books explicitly shared with them. Legal bases are Article 6(1)(b) and, for initiating the requested collaboration, Article 6(1)(f) GDPR.
7. Contact, transactional email and contract declarations
For support, withdrawal and cancellation requests we process contact data, message, contract reference, request type and timestamp. This is required for performance and documentation of the contract under Article 6(1)(b) and (f) GDPR.
8. Payments
Paid plans are processed with Stripe. We process the details required for contract, activation, invoices and payment status; full card data is generally handled directly by Stripe. Legal bases are Article 6(1)(b) and (c) GDPR. International transfers are protected by an adequacy decision or appropriate safeguards under Chapter V GDPR where required.
9. Retention
Account and working content is kept until confirmed account deletion, unless legal retention duties apply. Cancellation of a plan does not itself delete the account. Billing records are retained for statutory commercial and tax periods. Rolling backups are overwritten within the documented backup cycle.
10. Your rights
Subject to the statutory conditions, you have rights of access, rectification, erasure, restriction, data portability and objection under Articles 15–21 GDPR, and may withdraw consent prospectively under Article 7(3). Contact support@manubook.com. You may lodge a complaint with a supervisory authority, in particular the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia.
11. Security and changes
We use appropriate technical and organisational measures including encrypted transport, password hashing, role-based access, tenant separation, two-factor authentication and protected uploads. No technical system can guarantee absolute security. We update this policy when functions, providers or the legal framework change.
Language note: This English version explains the same processing activities as the German privacy policy. The German text remains the primary legal version.