This policy explains what data KDP Book Niche Finder ("we", "us") collects when you use our website and Chrome extension, how we handle, store and share it, and your rights. Short version: we collect the minimum needed to run the service, we never sell your data, and the extension uses no affiliate links.
Email address, a hashed password (bcrypt — we can never read it), your license key, plan tier and subscription status.
Per-tool daily usage counts (e.g. how many pages you scanned today) so we can enforce plan limits. These are numbers only — we do not store your search keywords or the books you research.
When you open an Amazon product or search page, the extension reads the page content shown on it — book title, Best Sellers Rank, price, review count and similar public listing data — to compute its on-page analysis (sales/BSR estimates, keyword and profit tools). This processing happens locally in your browser. We do not send this page content to our servers and we do not store it; only the anonymous usage counters described above are recorded.
IP-based rate-limit counters (to block brute-force attacks) and standard server logs kept for a short period for security and debugging.
Research requests (AI checks, price/BSR history, quota checks) are sent to our server with your license key so we can authorize and meter them. AI queries are cached on our server so a repeated question doesn't cost another credit; the cache stores the query content, not your identity.
The website uses functional storage that keeps you logged in and remembers your preferences (this is required for the site to work).
For traffic statistics we use Google Analytics 4. It loads only after you accept the cookie banner shown on your first visit — if you decline, no analytics cookies or scripts are loaded. When enabled, IP addresses are anonymized. We do not use advertising or cross-site retargeting trackers. You can change your choice any time by clearing the site's storage in your browser.
We keep account data while your account is active. You can ask us to export or permanently delete your account and its data at any time — just contact us from your registered email. We answer within 30 days (usually much faster).
Passwords are hashed with bcrypt, API keys are stored encrypted (AES-256-GCM), all traffic is HTTPS, and login endpoints are rate-limited against brute force.
The service is not directed at children under 16 and we do not knowingly collect their data.
If we materially change this policy we'll update this page and the date above. Significant changes will be announced by email.
Privacy questions or requests: see the Contact page.