How your workspace data is handled.
Updated September 21, 2026. This page describes the catalog workspace’s current data handling. Edition-specific order terms are shown before you submit an order.
Account and company information
The workspace stores your sign-in email, account name, company profile and team memberships. Account email is used for verification, password recovery and service updates. Published staff can access company information to support orders and production.
Orders, artwork and proofs
We store order requests, the prices and edition terms attached to those requests, payment references entered by staff, author and book details, uploaded artwork, proof versions, approvals and support conversations. Only upload material you are authorized to provide for catalog production.
Files require an authenticated, authorized account to upload or download. Members of your publishing company and authorized Published staff can access the company’s materials. Approved catalog content is intended to appear in the printed or digital edition; private workspace records are separate from that publication.
Services and browser storage
The website is hosted on Vercel. Convex provides account sessions, the database and file storage. When email delivery is configured, Resend processes recipient email addresses and the verification codes, invitation links or service notices being sent. Provider acceptance does not establish inbox delivery.
Your browser stores the sign-in session and a temporary unfinished order selection. Signing out ends your session. Order, artwork and approval records are saved on the server.
ISBN lookup and imported book details
Entering a valid ISBN can start a lookup automatically. The ISBN is used to search Open Library, Google Books and publisher bookstores, including Xulon Press, Liberty Hill Publishing, Mill City Press and FaithGateway. Available covers may be retrieved from those sources or Amazon image services. When AI enrichment is configured, the ISBN and retrieved public book details are also sent to OpenAI to research matching sources and draft ad copy. Uploaded artwork, account details and company records are not included in that ISBN request.
Available details can fill untouched fields and import a cover. You can edit or replace them before submitting the placement. We cache book metadata and record lookup attempts against the signed-in user and placement to limit usage. A lookup or imported cover does not establish that the details are complete or the image is suitable for print.
AI assistants
OpenAI processes the text and context supplied to each assistant:
- The book copy assistant sends the book title, author, description and any sample text you provide when requesting a draft.
- The selling coach sends the conversation and your selected catalog, placement format and optional author price. It does not automatically read your company’s orders or placements.
- The economics assistant sends the conversation, current valid calculator inputs and calculated results, earlier options being discussed, and results of calculations requested during the chat.
These requests use the API’s response-storage setting of false. This is not a promise of zero provider retention. AI providers process requests under their applicable data policies. Do not enter passwords, payment credentials or information you are not authorized to share. Review generated copy and advice before using it.
To limit automated requests, our website servers derive a daily keyed identifier from the requesting IP address. The shared limiter in Convex stores that identifier, the assistant used and request timestamps, rather than the raw IP address or conversation. For signed-in ISBN enrichment, these usage records use your account ID. Client usage records expire two days after their last accepted request. Site-wide daily request and reserved output-token totals expire three days after the start of that UTC day. An hourly cleanup removes expired records; recovery pauses, service interruptions or a cleanup backlog can delay removal, and backups may retain earlier records. Hosting and service providers may separately retain ordinary service logs.
Catalog links
A catalog QR link takes the reader to the approved book purchase page. We record daily totals of successful link opens for that placement, visible to its publisher and Published staff. Repeated visits and automated traffic may be included. These totals do not establish a reader’s identity, a book sale or delivery of a catalog. This feature does not store visitor IP addresses, device profiles or tracking cookies. Hosting providers may separately retain ordinary service access logs.
Optional recipient suggestions are stored as organization/address review notes with the placement. Submit business receiving addresses; a suggestion does not guarantee mailing or automatically join a list.
Payments and questions
This website does not collect card numbers or charge a card. Published may record an external payment reference against an order.
For help with account data, access or a correction, open Support in your publisher workspace. A public support contact and the final retention and deletion policy must be confirmed before customer launch. No fixed retention period is promised here.
Read about ordering and workspace use →