Simplebooklet AI Usage & Data Protection Policy
Simplebooklet AI Usage & Data Protection Policy
Simplebooklet Marketing Inc. | Effective January 2026
Last updated: January 2026
1. Purpose
This policy describes how Simplebooklet uses artificial intelligence (AI) services, including the OpenAI API, in a secure, privacy-respecting, and compliant manner. It is intended to support customer security reviews, vendor risk assessments, and internal governance.
2. Scope
This policy applies to:
- All Simplebooklet products and features that leverage AI
- All employees, contractors, and systems involved in AI-enabled processing
- All customer content processed using AI services
3. AI Use Cases
Simplebooklet uses AI strictly to enhance user-initiated document experiences. Current AI-enabled features include:
- PDF and document summarization
- Automatic table of contents generation
- Language detection and translation
- Accessibility and structural analysis of documents
AI is not used for autonomous decision-making, user profiling, advertising targeting, or behavioral prediction.
4. Data Flow Overview
- A user explicitly initiates an AI-powered action (e.g., generate a summary).
- Only the minimum necessary document content is securely transmitted to the OpenAI API.
- The AI service processes the content and returns structured output (e.g., summary text).
- Results are stored within Simplebooklet and associated with the user's account.
No AI processing occurs without an explicit user action.
5. Data Minimization & Handling
- Only content required to perform the requested AI task is sent to the AI provider.
- Metadata unrelated to the task (billing data, user lists, analytics, etc.) is never shared.
- Customer content is transmitted over encrypted channels (TLS 1.2+).
6. Data Retention & Training
- Simplebooklet does not use customer content to train its own AI models.
- Customer content sent to OpenAI is processed under OpenAI's API data usage terms, which prohibit training on API data by default.
- Simplebooklet does not retain AI prompt payloads beyond what is necessary to deliver the feature and support auditability.
7. Security Controls
Simplebooklet applies the following controls to AI integrations:
- API keys are securely stored and rotated according to internal security policy
- Least-privilege access to AI-related systems
- Network-level encryption in transit
- Access logging and monitoring
- Separation of customer data between tenants
8. Privacy & Compliance
- Simplebooklet acts as a data processor; customers remain the data controller for their content.
- AI processing complies with applicable privacy regulations, including GDPR, PIPEDA, and other relevant data protection frameworks.
- AI features respect existing data deletion, retention, and access controls.
9. Customer Controls
Customers maintain full control over their content:
- AI features are optional and user-initiated
- Customers may delete content and associated AI outputs at any time
- Standard account deletion processes apply equally to AI-generated data
10. Prohibited Use
AI services may not be used to:
- Process content without user authorization
- Extract or infer sensitive personal data beyond the provided content
- Perform surveillance, monitoring, or automated enforcement actions
11. Risk Management & Review
- AI integrations are reviewed as part of Simplebooklet's regular security and vendor risk assessments
- Changes to AI providers or usage patterns trigger a security and privacy review
- This policy is reviewed and updated at least annually
12. Transparency
Simplebooklet is committed to transparency in its use of AI. Customers may request additional information about AI processing practices as part of security or compliance reviews.
13. Contact
For security or compliance questions related to AI usage, contact: security@simplebooklet.com
This policy is provided for security review and due diligence purposes and reflects Simplebooklet's current AI usage practices.
Updated on: 08/09/2026
Thank you!
