Privacy Policy
Last updated: June 17, 2026
Unjacketed (“we,” “us,” or “our”) operates unjacketed.com and the Unjacketed ARC platform (app.unjacketed.com). This policy explains what information we collect, how we use it, and your choices.
1. What We Collect
Chapter Review Submissions
When you submit a chapter for review at unjacketed.com/submit/, we collect:
- Book title
- Author name
- Cover art image
- Chapter text
- Email address (optional — only if you want us to be able to contact you)
We use this information solely to evaluate and potentially feature your work in our editorial reviews. We do not share it with third parties or use it for marketing.
ARC Reader Accounts
When you sign up for an ARC (Advance Reader Copy) campaign through an author’s landing page powered by Unjacketed, you authenticate using Login with Amazon. Amazon provides us with your user ID, display name, and email address during this flow.
What Unjacketed stores centrally (on our servers):
- Your Amazon user ID — an opaque, Amazon-assigned identifier (e.g. amzn1.account.ABC123). This is not your name or email address.
- Your participation data: which ARC campaigns you have signed up for, whether you have confirmed leaving a review, how many reminder emails you have received and when, and a randomly generated token used to identify your reminder and download links.
Your display name and email address are passed through our servers briefly during the login flow (for less than 5 minutes, in an encrypted token that is deleted the moment it is consumed) and are then stored only on the individual author’s WordPress site — not on Unjacketed’s servers.
This participation data is stored centrally so that it persists across different authors’ ARC campaigns. For example, if you sign up for two different authors’ ARCs, both are recorded under the same Amazon user ID. This is how your reviewer reputation (ratio of signups to confirmed reviews) is calculated.
ARC Plugin Installations (Authors)
When an author registers the Unjacketed ARC WordPress plugin, we store:
- A randomly generated API key and secret for that installation
- The WordPress site URL
We do not collect personal information from authors beyond what is needed to operate the plugin.
Automatic Data
Like most web services, our servers record standard access logs (IP address, timestamp, page requested, HTTP status code). Logs are retained for up to 30 days and are used only for security and debugging. We do not use them for tracking or advertising.
2. How We Use Your Information
| Data | Stored where | Purpose |
|---|---|---|
| Chapter submission | Unjacketed servers | Editorial review and potential feature on unjacketed.com |
| Amazon user ID | Unjacketed servers | Identify you across ARC campaigns; calculate reviewer reputation |
| Participation data | Unjacketed servers | Calculate reviewer reputation; track reminder emails; confirm reviews |
| Display name, email address | Author’s WordPress site only | Personalise emails; deliver download links |
| Plugin install credentials | Unjacketed servers | Authenticate API requests from author WordPress sites |
We do not sell your data. We do not use your data for advertising.
3. Third-Party Services
Amazon (Login with Amazon): Reader authentication is handled by Amazon’s OAuth service. When you click “Login with Amazon,” you are redirected to Amazon’s servers and subject to Amazon’s Privacy Notice. We receive only the data described in Section 1 above.
Brevo: Authors who use the Unjacketed ARC plugin may send emails to their readers through Brevo (formerly Sendinblue). Your email address is passed to Brevo for the purpose of delivering those emails. Brevo’s privacy policy is available at brevo.com.
Author WordPress sites: ARC campaign landing pages are hosted on individual authors’ WordPress websites. Those sites have their own privacy policies and may set their own cookies.
4. Data Retention
- Chapter submissions are retained as long as they are relevant to our editorial process. You can request deletion at any time.
- ARC reader data is retained for as long as you have an active presence on the platform. If you unsubscribe (see Section 5), your record is flagged and you will no longer receive emails or be able to sign up for new campaigns. Your historical participation data is retained for platform integrity.
- Plugin install credentials are retained until an author requests removal.
5. Your Rights and Choices
Unsubscribe from ARC emails: Every reminder email contains an unsubscribe link. Clicking it removes you from all future ARC campaign emails platform-wide and prevents you from signing up for new campaigns.
Request deletion: To request deletion of your data, use our contact form with the line “Data Deletion Request.” We will delete your records within 30 days, except where retention is required for legal or fraud-prevention purposes.
Access your data: To request a copy of the data we hold about you, use our contact form.
6. Applicability of U.S. State Privacy Laws
Laws like the California Consumer Privacy Act (CCPA), Virginia’s CDPA, Colorado’s CPA, and similar state privacy statutes impose obligations only on businesses that meet specific thresholds — typically annual gross revenues exceeding $25 million, or processing the personal data of 100,000 or more consumers per year, or deriving a majority of revenue from selling personal data.
Unjacketed is a small independent business. We do not meet any of those thresholds. We do not sell personal data. Accordingly, we are not legally required to comply with the CCPA or the majority of other U.S. state online privacy laws.
That said, we have chosen to offer voluntary data access and deletion rights (see Section 5) because we think it is the right thing to do, regardless of legal obligation.
7. Children
Unjacketed is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has submitted information to us, please contact us and we will delete it promptly.
8. Security
We use HMAC-SHA256 authentication for all API communication between author WordPress sites and our servers. Sensitive credentials are never logged. That said, no system is perfectly secure, and we cannot guarantee absolute security.
9. Changes to This Policy
We may update this policy from time to time. The “Last updated” date at the top of this page will reflect any changes. Continued use of the platform after a change constitutes acceptance of the updated policy.
10. Contact
Questions about this policy: Use our contact form.
