Privacy Policy
Effective 3 August 2026
This policy explains what UNLIKE ANOTHER LLC ("Vooka", "we", "us") does with personal information when you use vooka.studio and the Vooka platform.
We have written it to be read, not to be survived. If anything here is unclear, email privacy@vooka.studio and we will explain it in plain language.
1. The most important thing: we serve writers, not readers
Vooka is a tool for authors. That produces two different relationships, and they are governed differently.
Your data — we are the "controller". Your account, your books, your billing. We decide what to collect and why, and this policy governs it.
Your readers' data — we are only the "processor". If you build a mailing list or a landing page, the people who sign up are your audience, not ours. You decide what to collect and what to send them; we only carry out your instructions. We do not market to them, do not sell their details, and do not use them for anything except running the features you asked for.
This is deliberate. Emails to your readers go out through your own sending account, from your own domain, and replies land in your inbox. Your landing pages can run on your own domain. We never insert ourselves between an author and their audience.
If you are a reader who signed up through an author's page and you want your data removed, contact that author. You can also unsubscribe from any email using the link it contains, or write to privacy@vooka.studio and we will pass your request to the author and act on their instruction.
2. What we collect
You give us:
- Account — name, email address, password (stored by our authentication provider as a cryptographic hash; we never see it).
- Billing — handled entirely by Stripe. We store a customer reference, your plan, and your token balance. We never see or store your card number.
- Your work — the books, outlines, images, covers and marketing material you create, plus the prompts and instructions you give the AI.
- Connected accounts — where you choose to connect them: Amazon Advertising, Amazon KDP, your email sending provider, and social accounts. See section 4.
- Support messages you send us.
We collect automatically:
- Usage — which features you use, when, and whether they succeeded. Used to run the service, find faults, and bill token consumption accurately.
- Technical — IP address, browser and device type, and error reports (via Sentry).
- Cookies — see section 8.
We do not collect health data, biometrics, precise location, government identifiers, or anything about your race, religion, politics, sexuality or trade union membership. We do not knowingly collect data from anyone under 18.
3. Why we use it, and our lawful basis
| What we do | Why | Lawful basis (GDPR) |
|---|---|---|
| Run your account and the features you use | To provide what you signed up for | Performance of a contract |
| Generate books, images and marketing with AI | Same | Performance of a contract |
| Take payment, meter token usage | To charge you correctly | Performance of a contract |
| Act on Amazon, email and social on your behalf | Because you explicitly connected it | Consent, and performance of a contract |
| Keep the service secure, prevent abuse | To protect you and us | Legitimate interests |
| Diagnose faults and improve the product | To make it work properly | Legitimate interests |
| Send service notices (receipts, failures) | You need to know | Performance of a contract |
| Send product or marketing email to you | Only if you opt in | Consent — withdraw any time |
| Meet tax, accounting and legal obligations | Required by law | Legal obligation |
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done so.
4. Acting on your behalf
Several features work by acting as you on another platform. Each is off until you explicitly connect it, and each can be disconnected at any moment from Settings.
- Amazon Advertising — you authorise us through Amazon's own login screen. We then read your campaign performance and, in the autonomy mode you choose, adjust bids, keywords and budgets. We never see your Amazon password.
- Amazon KDP (the Vooka KDP Sync browser extension) — set out in full below, because it handles authentication and financial information and you should know exactly what it does.
- Your email provider — you supply credentials for your own sending account (for example Resend, or any SMTP provider). We use them only to send the emails you create. They are encrypted at rest.
- Social accounts — where connected, we post only what you schedule, only to the accounts you pick.
All connected credentials are encrypted at rest. Deleting the connection deletes them.
The Vooka KDP Sync browser extension
Amazon publishes no API for KDP sales data. The only way to show you your own numbers is to read the reports as you, using your own signed-in session. The extension exists for that and for nothing else.
What it reads. It reads your Amazon authentication/session cookies from your browser — a fixed, published list of eight names (session-id, session-id-time, session-token, ubid-main, x-main, at-main, sess-at-main, i18n-prefs) written into the extension's source, not a pattern that could quietly widen. It reads nothing else from your browser: no browsing history, no other sites, no page content, no keystrokes.
When it reads them. When you click Sync; shortly after Amazon replaces any of those eight cookies; and on a six-hourly check in case a replacement was missed while your browser was closed. Amazon rotates your session periodically, and without this our stored copy goes stale and your sales figures silently stop updating until you notice and click Sync again.
The automatic refresh sends the same eight cookies to the same place for the same purpose — it changes when they are read, never what is read or where it goes. It stops the moment you disconnect the extension or sign out of Amazon.
What it accesses with them. Our server uses that session to call Amazon's KDP Reports service and read your KDP sales, orders, royalties and KENP (Kindle Unlimited page-read) reporting information — the same figures you see on your own KDP dashboard.
Where it goes. Only to your own Vooka account, over HTTPS, to power the sales and analytics features you asked for. The cookies are encrypted at rest with a separate key; in production the service refuses to store them at all if that key is missing. Your KDP figures are visible only to you and are never sent to our AI providers.
What we never do with it. We do not sell it, rent it, or share it with data brokers. We do not use it for advertising, for profiling, or for any purpose unrelated to showing you your own publishing performance. We do not use it to train AI models. We do not read, modify or publish anything in your KDP account — the access is read-only reporting.
Ending it. Disconnect in Settings → Integrations, or uninstall the extension, and the stored session is destroyed immediately. Signing out of Amazon also invalidates it.
5. Who we share it with
We share personal data only with service providers who help us run Vooka, each bound by contract to use it only on our instructions. Current subprocessors:
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, authentication | US |
| Railway | Backend hosting | US |
| Vercel | Website hosting and CDN | Global edge |
| Upstash | Caching, rate limiting | US |
| Stripe | Payments (holds your card details, we don't) | US / global |
| Anthropic | AI text generation | US |
| OpenAI | AI text and image generation | US |
| Google (Gemini, Veo) | AI text and video generation | US |
| fal.ai | AI image generation | US |
| DeepL | Translation | EU |
| DocRaptor | PDF generation | US |
| Inngest | Background job orchestration | US |
| Novu | In-app notifications | US |
| Sentry | Error monitoring | US |
| Keepa | Amazon market data (no personal data sent) | EU |
Our AI providers are contractually barred from training their models on your content, and neither do we. Your book is yours.
We also disclose data if the law requires it, to enforce our Terms, to prevent fraud or harm, or to a buyer if the business is ever sold — in which case you will be told before your data moves.
6. Where your data goes
We are based in the United States and most of our providers are too. If you are in the European Economic Area, the UK or Switzerland, your data will be transferred to the US. We rely on the EU-US Data Privacy Framework where our provider is certified, and on the European Commission's Standard Contractual Clauses otherwise.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account and your books | While your account is open |
| After you delete your account | Erased within 30 days |
| Amazon advertising performance data | 13 months, then deleted automatically |
| Record of advertising changes we made for you | 24 months, then deleted automatically |
| Connected-service credentials | Destroyed the moment you disconnect |
| Billing and tax records | 7 years (legal requirement) |
| Error logs | 90 days |
| Backups | Up to 35 days, then overwritten |
8. Cookies
We use only what the service needs to work: a session cookie to keep you signed in, and security cookies to prevent forgery. We use no advertising cookies and no third-party trackers. Because we set no non-essential cookies, there is nothing to consent to and nothing to opt out of.
Landing pages you publish set no cookies at all unless you add something that does — which is your responsibility as their controller.
9. Your rights, and how to use them
Wherever you live, you can ask us to:
- See the personal data we hold about you
- Correct anything wrong
- Delete your account and data
- Export your data in a portable format
- Object to or restrict how we use it
- Withdraw consent at any time, without affecting what happened before
In the EEA/UK these are your GDPR rights, and you may also complain to your national data protection authority — in Spain, the Agencia Española de Protección de Datos (aepd.es).
In California you may additionally ask what categories we collected, disclosed and to whom, and you are entitled not to be discriminated against for exercising any right. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.
How to delete your data
Two ways, both free and neither requiring you to ask permission:
- By email — write to privacy@vooka.studio from your account address, and we erase your account and content within 30 days.
- In the app, for connected services — Settings → Integrations → Disconnect destroys the stored credentials for that service immediately, and you can delete the advertising data we synced from it at the same time.
A one-click "delete my whole account" button in the app is not built yet. Until it is, the email route above is the way, it is free, and we do not ask you why.
We never charge for a deletion request and never require you to speak to anyone first. Deleting your account also disconnects every linked service and destroys the stored credentials. Data we must retain for tax law (invoices) is kept, and nothing else.
We respond to all requests within 30 days.
10. How we protect it
Encryption in transit (TLS) and at rest; credentials for connected services encrypted with a separate key; row-level database isolation between organisations; least-privilege access; rate limiting and abuse protection; audit logging on sensitive actions. No system is perfectly secure, and we will not pretend otherwise — but if a breach affects you, we will tell you and the relevant regulator within 72 hours.
11. Children
Vooka is for adults. We do not knowingly collect data from anyone under 18, and will delete it promptly if we discover we have.
12. Changes
If we change this policy materially we will email you and post a notice in the app at least 14 days before it takes effect. The date at the top always shows the current version.
13. Contact
UNLIKE ANOTHER LLC
Privacy questions and requests: privacy@vooka.studio Everything else: support@vooka.studio