Privacy Policy

Effective date: [EFFECTIVE DATE]

Template notice — replace before launch. This page is a starting point, not legal advice. Have a lawyer review and customize it for your jurisdiction and the specifics of what Bibby actually does before relying on it. Replace every [BRACKETED] placeholder.

Bibby ("we", "us", "our") operates the Bibby website and service (the "Service"). This page explains what information we collect, how we use it, and the choices you have.

Information we collect

When you sign in or use the Service, we collect:

  • Account information from Google — when you sign in with Google OAuth, we receive your name, email address, profile picture URL, and Google account identifier. We never receive your Google password.
  • Network information — your IP address, derived approximate country and region, and the timestamp of your last sign-in. We use this for fraud and abuse prevention, geographic personalization, and audit logs.
  • Content you submit — anything you post to the Service, including blog content (if you're an administrator) and account settings.
  • Cookies — see the cookies section below.

How we use information

  • To create and authenticate your account.
  • To operate, maintain, and improve the Service.
  • To detect, investigate, and prevent fraud or abuse.
  • To comply with legal obligations and enforce our terms.
  • To send you essential service messages (e.g. security notices).

How we share information

We do not sell your personal information. We share limited information with:

  • Service providers who run infrastructure on our behalf (e.g. hosting, database, analytics, error reporting). They are bound by contract to use the data only to provide their service.
  • Legal and safety recipients when required by law, valid legal process, or to protect the rights, property, or safety of any person.
  • Successors in a merger, acquisition, or sale of all or part of our business.

Cookies and similar technologies

We use a small set of strictly necessary cookies:

  • auth_token — a signed JWT that keeps you logged in. HttpOnly, SameSite=Lax, secured in production.
  • oauth_csrf — a short-lived random nonce used during sign-in to defend against cross-site request forgery.

We do not use third-party advertising or cross-site tracking cookies.

Data retention

We retain account information for as long as your account is active. You can request deletion at any time by contacting us at [CONTACT EMAIL]; we will delete or anonymize your personal data within [RETENTION WINDOW, e.g. 30 days], except where we are required to keep it for legal, accounting, or security reasons.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete the personal information we hold about you, and to object to or restrict certain processing. To exercise any of these rights, contact [CONTACT EMAIL].

Children

The Service is not directed to children under [AGE, e.g. 13] . We do not knowingly collect personal information from children. If you believe we have, please contact us and we will delete it.

International transfers

Our infrastructure and service providers may be located in countries other than the one where you live. By using the Service, you acknowledge that your information may be transferred to and processed in [PRIMARY JURISDICTION] and other jurisdictions.

Security

We use industry-standard safeguards to protect your information, including TLS for data in transit and access controls on our infrastructure. No system is perfectly secure; we cannot guarantee absolute security.

Changes to this policy

We may update this policy from time to time. We will post the new effective date at the top of this page and, for material changes, provide additional notice (such as an in-app banner or email).

Contact us

Questions about this policy? Contact us at [CONTACT EMAIL] or [MAILING ADDRESS].