# Security & privacy questionnaire — Infinite Library & Bindery

> Standing answers to the questions procurement and security teams ask: AI training, data location, encryption, access, backups, incident response, sub-processors, GDPR roles, SOC 2 status.

Last updated 2026-09-10. Trust Center: https://www.infinitelibrary.ai/trust · DPA: https://bindery.infinitelibrary.ai/trust/dpa.md · Contact: hello@infinitelibrary.ai

## Company

**Q: Who is the legal entity behind the service?**

Infinite Library SAS, a French simplified joint-stock company (SAS) with its registered office in Montrouge, just south of Paris, France. Publication director: Thomas A.Q.T. Truong. Registration details are on the legal notice (https://www.infinitelibrary.ai/legal-notice). Contact for security and privacy matters: hello@infinitelibrary.ai.

**Q: What does the service do with our content?**

Bindery writes, edits, typesets and prints books from what you give it — a brief, a manuscript, transcripts, notes, recordings or video links. Your content is stored in your book's workspace, sent to the AI vendors listed on the trust page only to perform the function you invoke, and never used to train models.

**Q: Where is our data stored and processed?**

The studio and the live book workspaces (manuscripts, sources, uploads, audio masters, chat history): California, United States (us-west2) (Railway) · Durable workspace snapshots and author portraits: Iowa, United States (us-central1) (Google Cloud Storage) · Accounts, plans and credits, notifications, support conversations, the audit log: United States multi-region (nam5) (Cloud Firestore) · The website (www.infinitelibrary.ai): United States, served from a global edge (Vercel)

## AI

**Q: Is our content used to train AI models?**

No by Infinite Library — we train no models — and no by contract for Anthropic, OpenAI, Google Gemini API. ElevenLabs trains by default unless the account opts out; that opt-out is being confirmed and the trust page shows its live status; Black Forest Labs trains by default unless the account opts out; that opt-out is being confirmed and the trust page shows its live status. Until it reads “set”, the affected feature (audiobook narration, the optional clone of your own voice, and album music., the author photo studio) can simply be left unused.

**Q: Which AI vendors receive our content, and what exactly?**

Anthropic: manuscript, transcripts, notes, prompts — training: Never — contractual default; retention: Inputs and outputs deleted within 30 days (longer only for confirmed policy violations or where the law requires). · OpenAI: cover and illustration briefs, uploaded recordings — training: Never — contractual default; retention: Abuse-monitoring logs up to 30 days; audio transcription requests are not retained. · Google Gemini API: picture-book briefs and reference images, pasted video links — training: Never — paid tier; retention: Logged for a limited period solely to detect abuse (paid tier). · ElevenLabs: narrated chapter text, voice samples, lyrics — training: Opt-out pending; retention: Request history is kept by default; zero-retention mode (enable_logging=false) is an enterprise-plan feature. · Black Forest Labs: a selfie and the portrait brief (only if you use the author photo studio) — training: Opt-out pending; retention: No fixed period published — “as long as is reasonably necessary”.

**Q: Can we avoid a specific AI vendor?**

Yes. Writing needs Anthropic; every other vendor is tied to an optional feature — narration and voice cloning (ElevenLabs), the author photo studio (Black Forest Labs), picture-book illustration and video sources (Google), cover art and transcription (OpenAI). Leave the feature unused and nothing reaches that vendor.

**Q: Do you use our content to improve your own product?**

We train no models. Product analytics are pseudonymous event counts (kept 190 days) and never include the text of a book, a prompt or an upload. The support concierge answers from a curated help corpus, not from other customers' conversations.

## Security

**Q: How is data encrypted in transit and at rest?**

TLS 1.2 or newer on every connection, with HSTS for one year including subdomains. Encryption at rest for accounts, backups and portraits — Google-managed AES-256 on Cloud Firestore and Cloud Storage.

**Q: How do users authenticate?**

Google sign-in, Sign in with Apple (iOS), or a one-time email code / magic link; an optional password can be added afterwards. Sessions are signed, HTTP-only cookies. Collaborators join a book through signed, revocable links with an explicit role.

**Q: Who at Infinite Library can access our content, and is that access logged?**

Only the operator, for support you have asked for or an incident. Operator actions run through a token-authenticated admin API whose every call is written to an append-only audit log kept 400 days.

**Q: Has the application been penetration-tested?**

Not yet by an independent third party. The last internal security review (31 August 2026) covered dependency vulnerabilities, input handling, abuse rails and payment flows; findings were fixed before release. We welcome coordinated disclosure through security.txt and will engage an external tester before the SOC 2 observation period.

**Q: How are vulnerabilities managed?**

Dependencies are audited on every release and pinned; every change passes a typecheck and a test suite before deploy; privacy-critical settings are pinned by tests that fail when code and policy diverge. Researchers can reach us via /.well-known/security.txt.

**Q: What are your backup and disaster-recovery arrangements?**

Every change to a book is snapshotted to Google Cloud Storage within seconds (recovery point: seconds). A replacement server re-hydrates every workspace from those snapshots on boot, so recovery time is the time to redeploy — typically under an hour. Accounts live in Cloud Firestore, a managed multi-region database.

**Q: How do you handle security incidents and breaches?**

Health checks, disk-pressure and vendor-failure alerts page the operator. A confirmed personal-data breach is notified to affected customers — and, where required, supervisory authorities — within 72 hours, with what happened, what was affected and what we did. The runbook is in docs/trust/incident-response.md.

**Q: How are secrets and credentials managed?**

Secrets live only in the hosting provider's variable store, never in the repository; each token class (print assets, listen links, unsubscribe, sessions, admin) has its own signing key.

**Q: What network and application controls are in place?**

Origin checks on every state-changing request (CSRF) and rate limits on checkout, sign-in, publishing and import routes. Sign-up abuse rails: disposable-domain refusal, velocity caps, and device keys that never store a raw IP address. A CORS allow-list limits browser origins.

## Privacy

**Q: Are you a controller or a processor for our data?**

For the content you bring and create (manuscripts, transcripts, uploads, generated works) we act as your processor under the DPA. For the account and billing data of the people who sign in, we are the controller as described in the Privacy Policy.

**Q: Do you offer a Data Processing Addendum?**

Yes — read it at https://bindery.infinitelibrary.ai/trust/dpa and accept it online from the account dialog (Privacy & data). It incorporates the Standard Contractual Clauses and names every sub-processor; the acceptance record carries the version and a fingerprint of the exact text.

**Q: How are sub-processor changes communicated?**

The register at https://bindery.infinitelibrary.ai/trust#subprocessors is the live list. Companies that accepted the DPA are emailed at least 30 days before a new sub-processor receives their content, with a right to object.

**Q: How are data-subject requests handled?**

Export and deletion are self-serve in the account dialog and complete without a ticket. Other requests (rectification we cannot do in-product, restriction, objection) go to hello@infinitelibrary.ai and are answered usually within 1–2 business days.

**Q: What is your data retention and deletion process?**

Your books — manuscript, sources, uploads, covers, audio masters, chat history: For as long as your account exists — A book you delete is removed at once and its backup tombstoned; everything else is erased 14 days after you confirm account deletion (the undo window) · Account profile — email, name, plan, credits, orders: For as long as your account exists — 14 days after confirmed deletion, replaced by a PII-free tombstone (amounts tax law requires stay, anonymised) · The writing agent's session memory (its working transcript per book): Only the current session of each book — Superseded sessions swept every 6 hours; a session past 256 MB is rotated · Usage telemetry — pseudonymous product events: 190 days — Raw events deleted; only aggregate counters remain · Audit log — operator actions, data exports, DPA signatures: 400 days — Deleted

**Q: How are international transfers protected?**

Processing happens in the United States. Transfers rest on the Standard Contractual Clauses (2021/914) incorporated in our DPA and, where a vendor is certified, the EU-US Data Privacy Framework. Each sub-processor's location is stated in the register below.

**Q: What cookies and trackers do you use?**

A signed session cookie, a consent-choice cookie, and — only after consent in Europe, the UK and Switzerland — Google Analytics 4 and Google Ads tags in Consent Mode v2. Global Privacy Control and Do-Not-Track are honoured. No advertising pixels from social networks.

**Q: Is the service directed at children?**

No. Accounts are for adults; picture books are made by adults for the children in their lives, and a child's first name in a brief is treated as the author's content.

## Compliance

**Q: Are you SOC 2 certified?**

The controls on this page map to the Trust Services Criteria in a control map we share on request. A formal Type II report needs an observation period with an independent auditor; until it exists we answer security questionnaires by email, with the evidence linked here.

**Q: Are you ISO 27001 certified?**

We are not ISO 27001 certified and are not currently seeking certification; the SOC 2 track above is our compliance program.

**Q: What is your PCI DSS position?**

Payments are handled entirely by Stripe (PCI DSS Level 1). Card data is entered into Stripe's hosted or embedded elements and never transits or rests on our systems, which keeps us in the smallest scope (SAQ A).

**Q: What is the key-person and business-continuity risk?**

Infinite Library is a founder-led company. The infrastructure is entirely on managed providers (Railway, Google Cloud, Stripe, Vercel), every workspace is snapshotted off-server, and the operational runbooks live in the repository, so the service does not depend on any one machine or memory.

**Q: Where can we get evidence, reports or answers to our own questionnaire?**

Everything on https://bindery.infinitelibrary.ai/trust is written from the running code and dated. The SOC 2 control map, incident-response runbook and records of processing are shared on request. Send your questionnaire to hello@infinitelibrary.ai; we answer by email.
