Perennial Bookclub Privacy Policy
Effective August 15, 2026 · Prometheus Labs, Kitchener, Ontario, Canada · hello@prometheuslabs.ca
1. What we collect and why
- Email address and a password (stored only as a secure hash): to run your account and deliver your daily chapters.
- Your book choices and reading progress (which chapter each book is on, pauses): to send the right chapter each day and keep your place.
- A Stripe customer reference and subscription status: to know whether delivery is active. We never see or store card numbers; payment details go directly to Stripe.
- A log of which chapter emails were sent to you: to avoid duplicates and to answer support questions.
- Basic operational logs (errors, request metadata): to keep the service working. No advertising, no analytics trackers, no tracking pixels in our emails, no sale of data.
That is the whole list. We collect nothing else, and we do not use your data to train AI models.
2. Email
The daily chapter emails are the service you purchased, sent with your express consent from signup (Canada's Anti-Spam Legislation calls this express consent to a commercial electronic message; the emails also identify us and carry working unsubscribe links). Every chapter email includes one-click links to pause or stop that book, with no login needed. Account emails such as confirmation and receipts are transactional. We do not send marketing email; if that ever changes it will be a separate opt-in, never a default.
3. Retention and deletion
- Your account, book subscriptions and progress are kept while your account exists, including through cancellations, so resubscribing resumes where you left off.
- To delete your account and its data, email us from your account address. We delete the account row, book subscriptions, progress and send history; Stripe retains transaction records as required by financial regulations.
- Operational logs expire automatically on a short rolling window.
4. Where data lives (cross-border disclosure)
Perennial Bookclub runs on infrastructure provided by US companies; your data may be processed or stored outside Canada and is subject to the laws of those jurisdictions. Subprocessors:
- Supabase: database and sign-in (our database is hosted in their Montreal region; Supabase is a US company).
- Cloudflare (US): website hosting and delivery.
- Stripe (US): payments; we never see card numbers.
- Resend (US): sending the chapter and account emails.
- Anthropic (US): generating the companion summaries of the public-domain texts. The book text is what gets processed, not your personal information, and the commercial API we use does not train on the material.
Quebec readers: this section is designed to support your Law 25 cross-border assessment; contact us for our security summary.
5. Safeguards
Passwords hashed by Supabase Auth (we never see them), encrypted transit everywhere, row-level security on every user-facing table, session cookies that are signed and HTTP-only, least-privilege API keys, and two-factor authentication on our infrastructure accounts.
6. Your rights
You can ask us what we hold about you, ask for corrections, or ask for deletion at any time: hello@prometheuslabs.ca. You may also contact the Office of the Privacy Commissioner of Canada.
7. Changes
If this policy changes materially we will post the new version here with a new effective date, and note the change in the next chapter email.