Privacy Policy

Privacy Policy

Last updated: June 17, 2026

Unjacketed (“we,” “us,” or “our”) operates unjacketed.com and the Unjacketed ARC platform (app.unjacketed.com). This policy explains what information we collect, how we use it, and your choices.

1. What We Collect

Chapter Review Submissions

When you submit a chapter for review at unjacketed.com/submit/, we collect:

  • Book title
  • Author name
  • Cover art image
  • Chapter text
  • Email address (optional — only if you want us to be able to contact you)

We use this information solely to evaluate and potentially feature your work in our editorial reviews. We do not share it with third parties or use it for marketing.

ARC Reader Accounts

When you sign up for an ARC (Advance Reader Copy) campaign through an author’s landing page powered by Unjacketed, you authenticate using Login with Amazon. Amazon provides us with your user ID, display name, and email address during this flow.

What Unjacketed stores centrally (on our servers):

  • Your Amazon user ID — an opaque, Amazon-assigned identifier (e.g. amzn1.account.ABC123). This is not your name or email address.
  • Your participation data: which ARC campaigns you have signed up for, whether you have confirmed leaving a review, how many reminder emails you have received and when, and a randomly generated token used to identify your reminder and download links.

Your display name and email address are passed through our servers briefly during the login flow (for less than 5 minutes, in an encrypted token that is deleted the moment it is consumed) and are then stored only on the individual author’s WordPress site — not on Unjacketed’s servers.

This participation data is stored centrally so that it persists across different authors’ ARC campaigns. For example, if you sign up for two different authors’ ARCs, both are recorded under the same Amazon user ID. This is how your reviewer reputation (ratio of signups to confirmed reviews) is calculated.

ARC Plugin Installations (Authors)

When an author registers the Unjacketed ARC WordPress plugin, we store:

  • A randomly generated API key and secret for that installation
  • The WordPress site URL

We do not collect personal information from authors beyond what is needed to operate the plugin.

Automatic Data

Like most web services, our servers record standard access logs (IP address, timestamp, page requested, HTTP status code). Logs are retained for up to 30 days and are used only for security and debugging. We do not use them for tracking or advertising.

2. How We Use Your Information

DataStored wherePurpose
Chapter submissionUnjacketed serversEditorial review and potential feature on unjacketed.com
Amazon user IDUnjacketed serversIdentify you across ARC campaigns; calculate reviewer reputation
Participation dataUnjacketed serversCalculate reviewer reputation; track reminder emails; confirm reviews
Display name, email addressAuthor’s WordPress site onlyPersonalise emails; deliver download links
Plugin install credentialsUnjacketed serversAuthenticate API requests from author WordPress sites

We do not sell your data. We do not use your data for advertising.

3. Third-Party Services

Amazon (Login with Amazon): Reader authentication is handled by Amazon’s OAuth service. When you click “Login with Amazon,” you are redirected to Amazon’s servers and subject to Amazon’s Privacy Notice. We receive only the data described in Section 1 above.

Brevo: Authors who use the Unjacketed ARC plugin may send emails to their readers through Brevo (formerly Sendinblue). Your email address is passed to Brevo for the purpose of delivering those emails. Brevo’s privacy policy is available at brevo.com.

Author WordPress sites: ARC campaign landing pages are hosted on individual authors’ WordPress websites. Those sites have their own privacy policies and may set their own cookies.

4. Data Retention

  • Chapter submissions are retained as long as they are relevant to our editorial process. You can request deletion at any time.
  • ARC reader data is retained for as long as you have an active presence on the platform. If you unsubscribe (see Section 5), your record is flagged and you will no longer receive emails or be able to sign up for new campaigns. Your historical participation data is retained for platform integrity.
  • Plugin install credentials are retained until an author requests removal.

5. Your Rights and Choices

Unsubscribe from ARC emails: Every reminder email contains an unsubscribe link. Clicking it removes you from all future ARC campaign emails platform-wide and prevents you from signing up for new campaigns.

Request deletion: To request deletion of your data, use our contact form with the line “Data Deletion Request.” We will delete your records within 30 days, except where retention is required for legal or fraud-prevention purposes.

Access your data: To request a copy of the data we hold about you, use our contact form.

6. Applicability of U.S. State Privacy Laws

Laws like the California Consumer Privacy Act (CCPA), Virginia’s CDPA, Colorado’s CPA, and similar state privacy statutes impose obligations only on businesses that meet specific thresholds — typically annual gross revenues exceeding $25 million, or processing the personal data of 100,000 or more consumers per year, or deriving a majority of revenue from selling personal data.

Unjacketed is a small independent business. We do not meet any of those thresholds. We do not sell personal data. Accordingly, we are not legally required to comply with the CCPA or the majority of other U.S. state online privacy laws.

That said, we have chosen to offer voluntary data access and deletion rights (see Section 5) because we think it is the right thing to do, regardless of legal obligation.

7. Children

Unjacketed is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has submitted information to us, please contact us and we will delete it promptly.

8. Security

We use HMAC-SHA256 authentication for all API communication between author WordPress sites and our servers. Sensitive credentials are never logged. That said, no system is perfectly secure, and we cannot guarantee absolute security.

9. Changes to This Policy

We may update this policy from time to time. The “Last updated” date at the top of this page will reflect any changes. Continued use of the platform after a change constitutes acceptance of the updated policy.

10. Contact

Questions about this policy: Use our contact form.