Home / Privacy policy
Privacy policy
Last updated: 30 September 2026
This policy describes the personal data processing carried out on escapegamebook.com, in accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act.
1. Data controller
The data controller is Escape Game Book, publisher of escapegamebook.com. For any question about your data: contact@escapegamebook.com.
2. Data collected
We only collect the data needed to run the service:
- Account: email address, name and profile picture provided by Google or Microsoft when signing in, technical account identifier.
- Books: chosen parameters (level, puzzle style, language, visual style, number of pages, title, description) and generated content (texts, illustrations, PDF).
- Subscription and billing: Stripe customer identifier, plan, subscription status, credits, invoices. Card data is processed exclusively by Stripe and is never sent to us.
- Correspondence: emails you send us and notifications we send you.
- Technical data: IP address, browser type, pages viewed and timestamps (server logs), plus audience-measurement data if you accept the corresponding cookies.
We recommend that you do not enter personal data about third parties, nor your own beyond what is necessary, in a book’s title or description: these texts are sent to AI model providers for generation.
3. Purposes and legal bases
- Providing the service (account creation, generation and storage of books, PDF downloads): performance of the contract.
- Managing subscriptions, payments, invoices and accounting: performance of the contract and legal obligations.
- Sending you notifications about your books and subscription: performance of the contract.
- Securing the site, preventing fraud and abuse, producing internal statistics: legitimate interest.
- Measuring the site’s audience with Google Analytics: your consent, given through the cookie banner and withdrawable at any time.
- Informing you about new features: legitimate interest for our customers (with an unsubscribe link in every email), consent otherwise.
4. Recipients and processors
Your data is accessible to the publisher’s authorised staff and to the following providers, who act on our instructions:
- Hosting provider of the site and data.
- Google and Microsoft: authentication when signing in to your account.
- Stripe: payments, subscriptions and invoices.
- AI model providers (OpenAI, Stability AI, Google): generation of texts and illustrations from your book’s parameters. Only these parameters are sent to them, never your identity or email address.
- Google Analytics: audience measurement, only with your consent.
- Email delivery provider: delivery of notifications.
We neither sell nor rent your data. It may be disclosed to authorities where the law requires it.
5. Transfers outside the European Union
Some providers (Google, Microsoft, Stripe, OpenAI, Stability AI) are established in or process data in the United States. These transfers are governed by the EU–US Data Privacy Framework where the provider is certified under it, or by the standard contractual clauses adopted by the European Commission.
6. Retention periods
- Account data and generated books: for as long as you are registered, then 3 years after your last activity, or as soon as the account is deleted at your request.
- Invoices and billing data: 10 years (accounting obligation).
- Technical logs: 12 months at most.
- Audience-measurement cookies: 13 months at most; your consent choice is kept for 6 months.
7. Cookies and trackers
The site uses a strictly necessary session cookie (sign-in, language, book draft), exempt from consent, and, only if you accept them, Google Analytics audience-measurement cookies.
You can accept or decline the latter through the banner shown on your first visit and change your choice at any time with the “Manage cookies” link at the bottom of the page. Declining has no effect on your use of the service.
8. Security
Exchanges are encrypted (HTTPS), authentication is delegated to Google or Microsoft (we store no password) and payments are entrusted to Stripe, which is PCI DSS certified. Access to data is restricted to authorised persons.
9. Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability of your data, as well as the right to give instructions about its fate after your death. You may withdraw your consent at any time.
To exercise them, write to contact@escapegamebook.com from your account’s email address; proof of identity may be requested in case of doubt. We reply within one month. You may also request the deletion of your account and books.
If you believe your rights are not respected, you may lodge a complaint with the CNIL (French data protection authority), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr.
10. Changes
This policy may be updated; the last update date appears at the top of the page. In the event of a significant change, you will be informed by email or by a message on the site.