# booklint Privacy Notice **Version:** 5 October 2026 **Governing law:** England and Wales **Controller:** booklint (a sole trader shop in England and Wales operated under the trading name booklint) **Contact:** hello@booklint.com **Service:** booklint.com (Verification Desk) This short notice explains what personal and book-related data booklint handles. It matches the locked product data-handling rules as of 5 October 2026. --- ## 1. Who is responsible **booklint** (a sole trader shop in England and Wales operated under the trading name booklint) is the data controller for personal data processed in connection with booklint. Contact: **hello@booklint.com**. booklint is a **separate shop**. It has **no access** to the operator’s live trading book or other operator systems. Customer submissions to booklint are not mixed into those systems. --- ## 2. What booklint does with books (process-and-discard) booklint is a **linter / verification desk**, not an adviser. When you submit a book (or related check inputs), or an agent's list of actions with the limits its owner wrote (each action's id, time, amount, currency, merchant, refundability and kind), or an offer an agent is looking at with its owner's limits (the offer's figures and, optionally, plain text copied from the offer page), booklint processes it to run the check and then discards it. Please don't include the names of private individuals. If an action list or page text contains them, they are processed and discarded in the same way and never kept. Page text copied from an offer page can contain personal data (for example a guest name); it is processed and discarded in the same way and never kept. booklint never fetches a web address (URL) sent to it or found in page text. - **Raw books are processed and discarded.** The customer book is **not kept** as a stored book. A submitted list of actions and its limits are handled the same way: processed and discarded, **not kept**. So are a submitted offer, its limits and any page text. - booklint keeps **no record of a check's content**: no Delivery Log exists. The records booklint does keep are: - for each paid API key, the key record described in section 4, including the time of the key's last authenticated call (`last_seen`, updated at most once a minute); - for each free API key, the key record described in section 3 (key hash, plan, optional label, issue time, `last_seen` and the count of its free checks); - a count of authenticated checks per plan per hour, not linked to a key, a book or a person; - the operational logs and traffic counts described in section 2A. - When a Delivery Log is introduced, the Log will hold only hashes / digests of inputs, the rulebook version, finding codes, key hashes, timestamps, check statuses and rule ids, **never the raw book**. It will be kept for 90 days (free) and 13 months (paid), and this notice will be updated before that happens. booklint does not use submitted books, actions or offers to give investment advice, assess suitability, approve trades or purchases, or execute orders or payments. The check compares a book, an action list or an offer only against the limits its owner wrote. It does not say whether a trade, purchase, payment, booking or subscription is safe, wise, lawful, allowed, fair or a good deal. --- ## 2A. Operational logs and network data Each HTTP request writes one log line: time, method, path (without query string) and HTTP status. booklint’s code does not log the request body, headers or your IP address. If the HTTP request line itself is malformed, that log line can record part of it (method, path and version as sent), but not the body. If a request causes an internal error, the log also records a random correlation id and technical error detail, which can include a fragment of the input that caused it. Logs are held in our host’s (Fly.io) log service for 7 days. **Traffic counts.** booklint keeps counts of requests in its own database on its host. For each response it adds one to a counter for the combination of: - the UTC date and hour; - the path, if it is one of booklint’s published routes; any other path is counted as “other” and is not stored; - the HTTP method and the status class (2xx, 4xx or 5xx); - the host name of the referring page only (no path or query), or “none”; - a client class derived from the User-Agent header: browser, crawler, HTTP library or agent, or unknown. The User-Agent itself is not stored. booklint also adds one, for each request except our host's health checks and its own operations traffic, to a daily counter for the UTC date, the client class and a User-Agent family: one name from a fixed list (ai-user-fetch, gptbot, claudebot, perplexitybot, googlebot, bingbot, other-bot, python, node, curl, go, java, other-library, browser, unknown), chosen by matching keywords. The User-Agent itself is still not stored. **Sample tries.** Each request to `/v1/check` with `"sample": true`, `"sample": "spend"`, `"sample": "booking"` or `"sample": "subscription"` adds one to a daily counter for the UTC date and the client class. Beyond the counters described above, nothing about the request is kept: no body, no key and no book. Sample tries are counted for these aggregate statistics only and are never counted against the free caps (section 3). **MCP endpoint.** A `check_book` call to booklint’s MCP endpoint (`/mcp`) is handled and counted exactly like a request to `/v1/check`: the same key lookup, free caps, counters and sample-try counter apply, and its book is processed and discarded the same way. A `get_sample` call returns a public sample only and is counted as a request to `/mcp` in the per-request counters, like any other request; it is not a sample try, and nothing else about it is kept. A `get_free_key` call issues a free key exactly like `POST /v1/keys` with `{"plan":"free"}` (section 3): the same limits on new keys and the same stored key record; the key is shown once in the call’s result and is never logged. booklint’s MCP endpoint keeps no session or other state between calls. **MCP method counts.** Each request to `/mcp` also adds one to a daily counter for the UTC date, the client class and the kind of call: initialize, ping, tools list, a call to one of booklint’s listed tools (by tool name), a notification, or an error (by its JSON-RPC error code). A method or tool name that booklint does not list is counted only as an error. No tool arguments, key, book or other content of the call is kept. **Check kinds.** Each check that runs, through `/v1/check` or the MCP `check_book` tool, adds one to a daily counter for the UTC date, the route (`/v1/check` or `/mcp`), the client class and the kind of input: one of the four public samples (by name), or your own book, actions or offer. Nothing about the content of the check is kept. To count distinct visitors, booklint computes a keyed hash (HMAC-SHA256, shortened to 16 hexadecimal characters) of your IP address and User-Agent. The key is random, is held only in the running service’s memory, and is replaced every UTC day and whenever the service restarts. The old key is not kept anywhere, so hashes from different days cannot be linked to each other, and a hash cannot be turned back into an IP address. Your IP address is not stored. Each hash is stored with the date, the hour it was last seen and its client class, and is deleted after 8 days. The counters, including the User-Agent family, sample-try, MCP method and check-kind counters, are kept for 13 months. Our host’s own health checks are counted separately from other traffic. booklint sets no cookies. The counts are aggregate statistics about how people and agents use booklint. booklint publishes them, without any login, on its operations page (`/ops`), including the User-Agent family and sample-try counts, except for crawler traffic, which is counted but not published. The MCP method counts and check-kind counts are published there in the same way, without crawler traffic. The page also links to the operations page of booklint’s separate stamp service; booklint does not send it any data. That page also lists each paid API key, and in a separate Free section each free API key, as the first 8 hexadecimal characters of the key’s hash, with its plan, the day it was issued, the day of its last authenticated call and whether it is active. The page never shows a key, a free key’s label, a Stripe id, an email address, an IP address or a User-Agent. Fly.io, and Cloudflare for DNS, process your IP address and connection data to route and protect traffic. Request bodies (up to 1 MB) exist in memory only while the request is handled. If you email **hello@booklint.com**, we keep your address and message for 12 months (longer if a dispute needs it) to answer and keep records of it. --- ## 3. Free tier — what we store On the **free tier**: - No verification rows are stored today (section 2). - We **do not store email** on the free tier. - Free-tier requests are included in the traffic counts described in section 2A (counters and the daily-rotating hash), like any other request. - Free API keys: POST /v1/keys with {"plan":"free"} (or the MCP `get_free_key` tool, which runs the same code) returns a free key at once, with no payment and no email. booklint stores the key's hash, the plan, an optional label you choose, the issue time and the time of its last authenticated call (last_seen). New free keys are limited per client per day and across the service per day; the per-client limit is counted in memory with the daily-rotating keyed hash in section 2A and is never stored. - Free use is capped per key per day and in total, and without a key per client per day (the same in-memory hash); booklint stores a free key's check counts (today's count and the total) with its record so the caps can be applied. Counting distinct free users or agents is **imperfect**; we do not claim verified unique agents from key counts alone. - booklint counts refusals at the free caps in aggregate: for each UTC day and each cap (daily, lifetime, keyless daily, new keys per client, and the service-wide pause on new keys), the number of refused requests and the number of distinct keys or clients refused that day. To count each key or client once a day, a keyed hash under the daily-rotating key described in section 2A is used in memory only and is never stored. The stored counts hold no key, key hash, IP address, User-Agent, label or book. Test, synthetic and operator keys and requests from crawlers are left out. The counts are kept for 13 months and are published on the operations page (`/ops`). - Once the Delivery Log exists, free-tier rows will be kept for **90 days**, then deleted or anonymised. --- ## 4. Paid tier — Stripe and email (when live) Email arrives **only at paid conversion via Stripe**, and only once paid checkout is enabled. After successful payment: - a **post-payment email / plan mapping** exists so we can identify your paid plan and contact you about billing and service; - that mapping is **separate from free-tier privacy** (free tier has no stored email). booklint stores one record per paid API key: a SHA-256 hash of the key (the key itself is shown to you once and is not kept after that), the plan, Stripe’s customer, subscription and checkout session identifiers, the time the key was issued, whether it is active, and the time of its last authenticated call (`last_seen`, updated at most once a minute). booklint also counts authenticated checks per plan per hour; those counts are not linked to a key. Once the Delivery Log exists, paid rows will be kept for **13 months** (section 2). Stripe processes payment card and related billing data under Stripe’s own terms and privacy notice. booklint receives what Stripe provides for subscription status, email, and plan mapping after payment — not full card numbers for ordinary shop operation. --- ## 5. Sample traffic Requests marked `sample:true` use the **public sample book only**, and their responses carry `"sample": true`; requests marked `"sample": "spend"` use the **public sample actions and limits only**, and their responses carry `"sample": "spend"`; requests marked `"sample": "booking"` or `"sample": "subscription"` use the **public sample offers only**, and their responses carry that name. They are not processing of a customer’s private book or actions. They are counted in aggregate as sample tries (section 2A) and never against the free caps. --- ## 6. Calendar data Calendar-dependent coverage is **not** sold until a **commercial calendar licence** exists. Until then, a calendar rule returns **`not_in_plan`** on the free tier and **`not_licensed`** on Desk; it never runs and is never counted as run, and **Watch is withheld**. This notice does not imply that any particular calendar vendor is live. When calendar data is later licensed, dates from that licence **may not be copied out** beyond what the published interface returns for the check. --- ## 7. Why we process data (purposes) We process the data above to: - run check_book and audit_claims and return verdicts (FLAGGED / CLEAN / NOT_VERIFIED / REFUSED); - enforce plans and, once introduced, rate limits, refuse stale or invalid requests, and operate the desk as vending-machine software; - bill paid plans via Stripe and map email to plan after payment (when Stripe is live); - count visits and use of the service in aggregate (section 2A) and see when each paid and free key was last used; - monitor whether the service is up, investigate abuse, and answer **account / billing / documentation** mail at hello@booklint.com; - comply with law where applicable. We do **not** process data to provide investment advice, suitability assessments, or trade execution. --- ## 8. Lawful bases Under UK GDPR / Data Protection Act 2018, booklint relies on these bases as applicable: - **Contract / steps to enter a contract** — operating free and (when live) paid verification you request. - **Legitimate interests** — security, abuse prevention, service integrity, rate-limiting imperfect free-key counting, and aggregate traffic and usage statistics (balanced against your rights; the statistics use a daily-rotating hash rather than your IP address, section 2A). - **Legal obligation** — where retention or disclosure is required by law. - **Consent** — only if a specific optional processing later needs it (none locked in product facts today beyond ordinary shop use). --- ## 9. Sharing We do not sell personal data. We share only as needed with: - **Stripe** — payment and paid-account email / plan mapping (when paid checkout is live); - **infrastructure / hosting providers** necessary to run the desk: **Fly.io** (application hosting, United States); **Cloudflare** (domain and DNS, and traffic proxying if enabled); **Better Stack** (uptime checks of `/health` and `/` only, no customer data); Cloudflare Email Routing to the operator’s inbox; - a **licensed calendar vendor** — only if and when a commercial calendar licence is live and the feature requires it; - **professional advisers** (for example accountants or lawyers) under confidentiality, if engaged; - authorities where law requires. Customers may submit **third parties’ books**. booklint cannot tell and does not try. The submitting customer warrants they have the right to submit. If you believe your data was submitted without authority, contact **hello@booklint.com**. --- ## 10. Retention summary | Category | Retention | | --- | --- | | Raw customer books, and submitted actions, offers, page text and limits | Processed and discarded — **not kept** | | Request body (up to 1 MB) | In memory for the request only | | Operational and error logs (Fly.io log service) | 7 days | | Traffic counters (UTC date and hour, published path or “other”, method, status class, referrer host only, client class) | 13 months | | Daily-rotating keyed hash of IP address and User-Agent (16 hex characters, with date, hour last seen and client class) | 8 days | | IP address and User-Agent | Not stored by booklint (used in memory only, to compute the hash and the client class) | | Free API key record (key hash, plan, optional label, issue time, last_seen, check counts) | 90 days after its last authenticated call (or after issue if never used), then deleted automatically | | Paid API key record (key hash, plan, Stripe customer / subscription / checkout session ids, issue time, active flag, deactivation time, `last_seen`) | While the paid relationship lasts, then up to 13 months afterward, unless a longer period is required by law; the service deletes the record automatically (checked hourly) once 13 months have passed since deactivation | | Authenticated check counts per plan per hour (no key, book or person) | 13 months | | Free-cap refusal counts per UTC day and cap (refused requests and distinct keys or clients refused; no key, key hash, IP address or person) | 13 months | | MCP method counts per UTC date, client class and kind of call (no arguments, key or content) | 13 months | | Check counts per UTC date, route, client class and input kind (no content) | 13 months | | Real free use per UTC day (distinct real free keys that ran an own-book check, and their checks; no key, key hash or person) | 13 months | | Email correspondence to hello@booklint.com | 12 months (longer if a dispute needs it) | | Delivery Log (hashes / digests / flag metadata / key hash / timestamps / check statuses / rule ids) — free (when introduced) | 90 days, once introduced; nothing is stored today | | Delivery Log rows — paid (when introduced) | 13 months, once introduced; nothing is stored today | | Free-tier email | Not stored | | Paid email / plan mapping (via Stripe conversion, when live) | While the paid relationship lasts, then up to 13 months afterward (aligned with paid Delivery Log retention), unless a longer period is required by law | Internal operator scoreboards or kill-clock thresholds, if any, are **not** customer personal-data products and are **not** published in this notice. --- ## 11. Your rights Depending on applicable law (including UK GDPR where it applies), you may have rights to access, rectification, erasure, restriction, portability, and objection, and to complain to the **ICO** (Information Commissioner’s Office). Contact **hello@booklint.com** to exercise rights. We may need to verify identity and may refuse or limit requests where law allows (for example, where we cannot identify you on the free tier because no email is stored, or from a traffic hash, which cannot be matched to you once its day’s key is gone). --- ## 12. International transfers booklint runs on Fly.io in its Ashburn, Virginia (**United States**) region, so submitted data is processed in the US. For transfers of personal data from the UK to Fly.io, the operator relies on Fly.io’s Standard Contractual Clauses (SCCs). --- ## 13. Children booklint is aimed at operators of trading and other agents and professional or adult users. It is not directed at children. --- ## 14. Changes We may update this notice. The version date will change. Material changes affecting paid accounts may also be notified to the Stripe-mapped email where we hold one. --- ## 15. Contact Account, billing, documentation, and privacy questions: **hello@booklint.com**. This mailbox is the human shop contact for those topics. It is not an investment-advice or trade-desk channel. --- *End of Privacy Notice — version 5 October 2026 (Rev L). Operator-written for booklint.com.*