Historical versions of this policy are retained at /privacy/v1, /privacy/v2, etc. so you can see the version you originally agreed to.
1. Who we are
invoke is an AI audiobook generation service operated from Serbia. The service runs at invoke-books.com and via our mobile application.
- Operator / data controller. Operating entity details will be added to this policy once company registration is complete. For all current purposes, please use the contact channels below.
- Primary privacy contact.
privacy@invoke-books.com - Copyright concerns.
copyright@invoke-books.com - EU representative (Art. 27 GDPR). We do not currently have a designated EU representative. If you have a privacy concern, please contact us at
privacy@invoke-books.com. - Data Protection Officer. Not designated at this time.
2. What this policy covers
This policy covers all personal data we process when you use invoke — the website, the mobile app, and the audiobook-generation backend. It does not cover third-party services we may link out to.
3. What data we collect
3.1 Data you give us directly
- Account data. Email address, your password (handled by our authentication provider; we do not see the plaintext), birthdate (used to check the minimum-age requirement), and optional display name.
- Uploaded content. Source documents you upload for audiobook generation (e.g. PDF, EPUB).
- Payment metadata. When you purchase coins or a subscription, the store-side identifiers and transaction details associated with your purchase. Payment card details are handled by your platform store (Apple or Google), not by us.
3.2 Data we generate from your use of the service
- Generated audiobooks. The audio output produced from your uploads.
- Wallet history. Coin balance and related transactions.
- Catalog ownership. Records of which audiobooks you own.
- Operational records. Request metadata, performance metrics, and error reports used to keep the service running.
3.3 Data we collect automatically
- Device and network metadata. IP address (used for rate limiting and security), user-agent, and mobile device tokens for delivering notifications you opted into.
- Logs. Hosting-layer access logs and operational events used to run the service.
We do not use marketing analytics, advertising trackers, web beacons, fingerprinting, or behavioural profiling tools.
4. Why we process your data + lawful basis
| Activity | Why we do it | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Account creation, sign-in, account management | To give you access to the service you signed up for | (1)(b) contract |
| Generating audiobooks from your uploads | To deliver the core service you requested | (1)(b) contract |
| Wallet, coin grants, and payment processing | To deliver paid features + meet our accounting and tax obligations | (1)(b) contract + (1)(c) legal obligation (tax records) |
| Catalog browsing | To deliver the catalog feature | (1)(b) contract |
| Operational metrics, error tracking, uptime monitoring | To keep the service running and debug failures | (1)(f) legitimate interest |
| Internal quality assurance — limited review of generated audiobooks to evaluate output quality | To improve and validate the service | (1)(f) legitimate interest, subject to a balancing test and internal access controls |
| Mobile push notifications (device tokens are personal data) | To deliver notifications you opted into at the OS level | (1)(f) legitimate interest, with OS-level + in-app opt-out |
| Confirmation email when you request account deletion | To prevent accidental or impersonated deletion requests | (1)(f) legitimate interest |
| Abuse, copyright complaints, and account suspension review | To respond to legal complaints and protect the service | (1)(f) legitimate interest, and (1)(c) where the law requires it |
| Maintaining internal access records for accountability | Art. 5(2) accountability principle | (1)(f) legitimate interest |
Handling data-subject requests received at privacy@invoke-books.com | To respond to your privacy rights | (1)(c) legal obligation |
We do not rely on consent for any processing today. If we introduce processing that requires consent, we will ask for it separately and clearly, and you can refuse without losing access to the service.
5. Who we share data with (categories of recipients)
We rely on third-party service providers to operate invoke. The current categories:
| Category | Data processed | Region |
|---|---|---|
| Authentication provider | Email, birthdate, session tokens | EU |
| Managed database provider | Account, wallet, library, and generation-request metadata | EU |
| Cloud infrastructure provider | Compute, storage, logs | EU |
| Subscription-management provider | Subscriber ID, purchase history | Outside the EEA — see § 6 |
| Transactional email provider | Email address used to deliver service emails | EU |
| Error-tracking provider | Error reports with anonymised user identifiers | EU |
| Marketing-website hosting provider | IP at edge for invoke-books.com | EU |
| Mobile push-notification platforms | Device tokens, notification payloads | Outside the EEA — see § 6 |
| AI inference providers (LLM and text-to-speech / GPU compute) | Uploaded text passed transiently for audiobook generation | Outside the EEA — see § 6 |
The current list of specific providers is maintained internally and is available on request via privacy@invoke-books.com, as well as to supervisory authorities on request. When we make a material change to the categories of providers or to the categories of data processed, we update this policy and notify you in advance (see § 12).
6. International transfers
Some of the categories of providers listed in § 5 process data outside the European Economic Area (EEA). When that happens, we rely on appropriate safeguards as required by Chapter V GDPR — for example, the EU–US Data Privacy Framework where applicable, EU Standard Contractual Clauses, and additional measures where appropriate.
If you have any questions about international transfers, please email privacy@invoke-books.com.
7. How long we keep your data
| Data class | Retention | Notes |
|---|---|---|
| Source documents you upload | About 10 days | Removed automatically by our storage lifecycle policy |
| Analysis records | About 30 days | Removed automatically by our storage lifecycle policy |
| Generated audiobooks (user-owned) | 1 year from generation | Renewable; see in-app library |
| Public-catalog audiobooks | Indefinite | Survives individual user deletions |
| Wallet transactions | Anonymised on account deletion; the anonymised record is retained until 7 years from the date of the transaction for tax purposes | Art. 17(3)(b) and (e) |
| Account record | Removed on account deletion | |
| Operational metrics | About 90 days | |
| HTTP request logs | About 30 days | |
| Administrative audit logs | Up to ~400 days | Retained for security and accountability purposes |
| Error-tracking events | About 90 days | |
| Short-term database backups | About 7 days | Ages out naturally |
| Subprocessor-side delivery logs | Varies | Operates on each subprocessor's own retention cycle |
A more detailed retention breakdown is available on request via privacy@invoke-books.com.
8. Your rights
Under GDPR you have the following rights, all of which we honour without charge. We respond within one month of the request (Art. 12(3)); complex requests may extend by two further months with notification.
| Right | How to use it |
|---|---|
| Access (Art. 15) | Email privacy@invoke-books.com. In-app and self-service options may also be available; see our help section. |
| Rectification (Art. 16) | Update editable fields in your account, or email privacy@invoke-books.com for fields you cannot edit yourself. |
| Erasure / right to be forgotten (Art. 17) | Use the in-app account-deletion option where available, or email privacy@invoke-books.com. A wallet-history retention carve-out applies (see § 7). |
| Restriction of processing (Art. 18) | Email privacy@invoke-books.com. |
| Portability (Art. 20) | Same channel as Access. |
| Objection (Art. 21) | Email privacy@invoke-books.com. You may object to processing we carry out on the basis of legitimate interests. |
| Withdrawal of consent | Not applicable today, as we do not rely on consent for any current processing. |
| Complaint to a supervisory authority | You may complain to your local DPA in the EU member state where you live or work. Contacting us first at privacy@invoke-books.com is appreciated but not required. |
8.1 What account deletion involves
When you confirm account deletion we:
- Delete your account with our authentication provider.
- Delete your uploaded content, analysis records, generation requests, and library ownership records.
- Anonymise your wallet transaction history for the tax-retention period (see § 7).
- Initiate the removal of your identifiers at our subprocessors.
Some downstream systems operate on their own retention cycles (summarised in § 7) and complete naturally within those cycles. If you re-sign-up with the same email after deletion, you start with a fresh account.
9. Automated decision-making (Art. 22)
Article 22(1) GDPR applies to decisions based solely on automated processing that produce legal or similarly significant effects on the data subject. invoke's automated processing (audiobook generation from your uploads, catalog metadata for public-domain titles) does not produce such effects.
Decisions that could produce significant effects on you — such as account suspensions or content-removal decisions on the public catalog — are not based solely on automated processing; they involve human review. If we change this in the future, we will provide the safeguards required by Article 22(3) (the right to obtain human intervention, to express your point of view, and to contest the decision) before doing so.
10. Children
invoke is not intended for users under 16. By signing up, you warrant that you are 16 or older. We collect birthdate at signup and refuse accounts below the threshold.
If you believe an account belongs to a user under 16, please contact privacy@invoke-books.com and we will handle the matter promptly.
11. Security
We use industry-standard security controls — encryption in transit and at rest, database row-level security, short-lived signed access tokens for content delivery, secret rotation, least-privilege access controls, dependency scanning, and a pre-launch security audit.
If you discover a vulnerability, please email privacy@invoke-books.com. We do not currently operate a paid bug-bounty program, but responsible disclosure is appreciated and we will respond.
12. Changes to this policy
We update this policy when our processing changes — new features, new subprocessors, new data classes.
- Material changes (such as a new processing activity, a new category of data, or a new category of subprocessor) are notified at least 30 days in advance via in-app banner and email to your account email. New legitimate-interest processing offers pre-activation opt-out, not just post-hoc objection. Operational changes within existing categories (for example, replacing one provider with another in the same category for service-continuity reasons) are reflected in this policy without undue delay (and in any event with the next policy revision), but do not trigger the 30-day-in-advance window.
- Non-material changes (e.g. typo fixes, clearer wording of existing posture) are published with the "Last updated" date bumped at the top.
- Historical versions are retained at
/privacy/v1,/privacy/v2, etc. so you can see the version you originally agreed to.
13. What we do not do today
To make our practices clear, the following are not part of how we operate today:
- We do not use marketing analytics, advertising trackers, or behavioural profiling.
- We do not share your uploads or generated content with other users.
- We do not use your uploaded content or generated audiobooks to train AI models without your separate, explicit opt-in.
- We do not sell or rent your personal data to third parties.
- We do not set non-essential cookies and do not display a cookie banner.
If any of these change, we will notify you in advance via the channels described in § 12.
14. Contact
| For | Use |
|---|---|
| Privacy questions, rights requests, complaints | privacy@invoke-books.com |
| Copyright concerns about content in our catalog | copyright@invoke-books.com |
| General product support | (see in-app Help or the website footer) |
If anything in this policy is unclear, or if you have questions about how we handle your data, please contact us at privacy@invoke-books.com.