Privacy policy
Last updated: 20 August 2026
This policy explains what personal data BookGlot ([COMPANY NAME], a company registered in England and Wales under company number [COMPANY NUMBER], registered office [REGISTERED ADDRESS]) collects, why, and what rights you have over it. It applies to everyone who uses bookglot.com, whether as a student, a tutor, or a visitor browsing clubs before signing up.
We are the data controller for the personal data described here. If you have a question this policy doesn't answer, contact us at privacy@bookglot.com.
Who this service is for
BookGlot is for adults. You must confirm you are 18 or over to create an account, and we don't knowingly offer the service to anyone younger. If we learn an account belongs to someone under 18, we'll close it.
Information we collect
Depending on how you use BookGlot, we collect:
- Account & profile data — name, email address, a hashed password (we never store your password itself) or, if you sign in with Google or Apple, the identifier and basic profile info they share with us; your bio, timezone, interface language, profile photo URL, and the languages you're learning or teaching and your level in each.
- Payment data — subscriptions, one-off lesson bookings, gifts and refunds are all processed by Stripe. We never see or store your card details; we hold a Stripe customer reference, membership/billing status, and transaction history for your own records.
- Tutor data — if you apply to teach, your application (experience, sample materials, the languages/levels you teach), and once approved, a Stripe Connect account reference for payouts (Stripe collects your bank details directly during onboarding — we never see them) and your payout status.
- Club & session data — the clubs you've joined or run, your reading progress and attendance, vocabulary you save, discussion posts and reactions, and reviews you write or receive.
- Video session data — when you join a live video session, we generate a short-lived access token via LiveKit (our video infrastructure provider) scoped to that one room. We do not currently record, store, or transcribe audio or video from sessions. If we introduce recording in future, it will require your explicit, informed consent before any capture begins, and you'll be able to request deletion of anything captured — we won't turn recording on retroactively or by default.
- Communications — emails we send you (verification, receipts, reminders, cancellations) are sent via Resend; support correspondence you send us.
- Technical data — standard web server logs (IP address, browser/device type, pages visited, timestamps) collected by our hosting provider for security and reliability, not for advertising or profiling.
What we don't do
We don't run advertising trackers, third-party analytics, or cross-site tracking cookies on BookGlot. We don't sell your personal data to anyone. We don't host or distribute copyrighted book text — clubs read public-domain editions or a book members buy themselves; BookGlot only stores the schedule and the discussion around it.
How we use your information
We use your data to:
- Create and run your account, and let you join, run, or book clubs and lessons.
- Process payments, subscriptions, payouts, refunds, and gifts.
- Show your name, photo, bio and (for tutors) reviews to other members of a club you share — book clubs are a group format, so fellow members and your tutor can see who else is in the cohort, unlike a private 1-on-1 lesson.
- Send session reminders, receipts, and service emails (you can turn reminders off).
- Investigate suspected abuse, enforce our Terms of Service, and keep the community safe.
- Meet our legal obligations, e.g. tax and accounting records for payments processed.
- Improve the product — understanding which features get used, in aggregate.
Our legal basis for processing
Under UK GDPR, we rely on:
- Contract — most processing (account creation, running clubs, billing) is necessary to provide the service you've signed up for.
- Legitimate interests — fraud prevention, service reliability, and understanding aggregate product usage, balanced against your right to privacy.
- Consent — for anything we ask you to opt into separately, such as any future session recording.
- Legal obligation — retaining financial records for tax and accounting purposes.
Who we share it with
We share data with the processors who help us run BookGlot, each under their own data processing terms, and never for their own marketing purposes:
- Stripe — payments, subscriptions, and tutor payouts (Stripe Connect).
- LiveKit — live video/audio session infrastructure.
- Resend — transactional email delivery.
- Neon and Vercel — database and application hosting.
- Google or Apple — only if you choose to sign in with one of them.
We may also disclose data if required by law, to protect BookGlot's or others' rights and safety, or as part of a merger, acquisition, or sale of assets (you'd be notified first).
International transfers
Some of our processors operate outside the UK/EEA. Where that happens, we rely on appropriate safeguards recognised under UK GDPR, such as Standard Contractual Clauses or an equivalent adequacy mechanism, before any personal data is transferred there.
How long we keep it
We keep account data while your account is active. If you delete your account, we delete or anonymise personal data within a reasonable period, except where we're required to keep it longer — for example, financial records are typically kept for six years to meet UK tax obligations, and we may retain limited records of a suspension or policy violation for trust-and-safety purposes even after an account closes.
Cookies
We only set two cookies, both first-party and neither used for advertising:
- A session cookie that keeps you signed in — strictly necessary, and set only once you sign in.
- A language preference cookie that remembers your chosen interface language for a year.
We don't use analytics, advertising, or third-party tracking cookies, so we don't currently show a cookie consent banner — both cookies above are exempt from consent requirements as strictly necessary/functional. We'll revisit this if that ever changes.
Keeping your data secure
Passwords are hashed, never stored in plain text. Traffic to BookGlot is encrypted in transit (HTTPS). Access to personal data is restricted to what a given role needs — for example, only admins can see suspension records, and card details never touch our servers at all. No system is perfectly secure, but we take reasonable technical and organisational steps to protect your data and will notify you and, where required, the ICO, if a breach puts your data at risk.
Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Ask us to delete your data, subject to the retention exceptions above.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time, where we rely on consent.
To exercise any of these, email privacy@bookglot.com. You can also complain to the UK's Information Commissioner's Office (ICO) at ico.org.uk if you think we've mishandled your data — we'd appreciate the chance to sort it out directly first.
Changes to this policy
We'll update this page if what we collect or how we use it changes, and update the date at the top. For material changes, we'll email registered users before the change takes effect.
Contact us
Questions about this policy or your data: privacy@bookglot.com.