Privacy policy

Draft for review — not yet effective. Operator details, contact information and the items marked for confirmation must be completed before publication.

Who is responsible

Kenkui is operated by [legal operator name, business address and country — confirm]. Contact [privacy email — confirm] for privacy questions and requests. This policy covers kenkui.fm and hosted Kenkui Studio. A separately operated, self-hosted server has its own operator and practices.

Information we process and why

  • Account and authentication information, such as your email address and account identifiers, to sign you in and control access.
  • Uploaded EPUB files, text, book metadata, cover images, narration settings and generated audio, to inspect and convert your book and deliver your download.
  • Job status, errors and usage information, to operate the service, resolve failed conversions and calculate credit charges.
  • Credit balances, purchase identifiers and transaction records, to fulfill purchases, handle refunds and meet accounting obligations.
  • Support messages and technical request information, such as IP addresses and service logs, to answer questions, diagnose problems and protect the service. Rendering diagnostics can include short excerpts of processed text.

Providing account and book information is necessary to use the corresponding hosted features. Do not upload sensitive personal information unless you have the authority to provide it for processing.

Hosted processing and service providers

Hosted conversion runs on our servers and service providers, not on your device. Our current infrastructure uses Cloudflare for website delivery and object storage, Render for the API and database, Modal for rendering, and WorkOS for authentication. Stripe and Link handle payment information and transaction support; card details are entered on their checkout, not stored by Studio.

When you choose full-cast narration on a server that supports it, book text is sent to the configured language-model provider for character discovery and dialogue attribution. Staging currently uses OpenRouter with DeepSeek; the production provider and its data-use/retention settings must be confirmed before full-cast production launch. Single-narrator synthesis does not require that attribution step.

[Confirm provider processing countries, contractual safeguards for international transfers, and model-provider retention/training settings before publication. Do not describe hosted books as staying on the customer’s device.]

Legal bases where applicable

We process information to provide the service you request and fulfill our contract with you; to meet applicable legal and accounting obligations; and for legitimate interests in operating, securing and improving service reliability. Where processing requires consent, we will request it separately and you may withdraw it. These bases and any local additions must be confirmed for the operator’s jurisdiction.

Retention and deletion

  • Completed audiobooks: available for download for 30 days after completion, then eligible for deletion. Save your M4B locally.
  • Uploaded sources: eligible for deletion 24 hours after all conversions using them finish. Uploads never submitted for conversion become eligible 24 hours after upload.
  • Temporary render objects: eligible for deletion 24 hours after their processing attempt finishes.

Scheduled cleanup removes eligible files; it does not run at the exact moment a retention period ends. Keep your original EPUB and downloaded audio. Removing a book from Studio’s local library does not itself request deletion of server records.

File cleanup does not erase account, job or billing records. We retain account and job records as needed to operate your account, and transaction records as needed for accounting, legal obligations and dispute handling. [Confirm specific account, job, log, support and backup retention periods and deletion procedures before publication.]

Cookies and device storage

Authentication uses session cookies. Studio stores preferences, drafts and library information in browser storage. Clearing browser storage can remove those local records without deleting files held by the hosted service. [Confirm the production cookie inventory and any analytics before publication.]

Your choices and rights

Contact the privacy address above to request access, correction or deletion of your information. Depending on applicable law, you may also request portability or restriction, withdraw consent, and complain to your local data protection authority. You may object to processing based on legitimate interests. We may need to verify your identity, and some records may need to be retained to meet legal obligations.

Payment and Link account data may also be managed through Link; a request to Link does not automatically delete every Kenkui account or book record.

Updates

We will date policy changes and communicate material changes affecting existing users. [Effective date — confirm after review.]