Privacy Policy
Last updated: May 11, 2026
Boughly is a product operated by Babu & Booshik LLC, a California limited liability company ("Babu & Booshik," "we," "us," or "our"). This Privacy Policy explains how we collect, use, and protect your information.
1. Information We Collect
Account Information
When you create an account, we collect your email address and any profile information you provide (display name, avatar, bio).
Content Data
Boughly stores the stories, books, and other content you create on the Platform. For users who have not signed in, content is generally stored in the browser's local storage and is not transmitted to Boughly's servers unless you sign in or enable sync functionality.
Usage Data
Boughly collects basic analytics about Platform usage, including pages visited, features used, and reading activity. Analytics are generally aggregated and designed to minimize the use of personally identifying data. Analytics tooling may process technical identifiers (such as IP address, device identifiers, or pseudonymous session IDs) as part of normal operation.
Age Data
When you complete our age-gate prompt, we collect and store your date of birth, along with a derived “is 18+” flag and the timestamp of your most recent attestation. Your date of birth is used to enforce our 13+ platform minimum and to verify eligibility for age-restricted (Mature 18+) content; our access checks rely on the derived flag. We retain this age data for as long as your account is active and as reasonably necessary for safety, fraud prevention, and legal compliance.
Payment Data (Coin Purchases)
When you buy a coin bundle, the actual card details (number, CVC, expiry) are collected and processed by our payment processor, Stripe, through Stripe's hosted Checkout. Boughly does not receive, store, or transmit raw card details.
After a successful purchase, Boughly stores a purchase record containing:
- The Stripe transaction ID (e.g.,
pi_…) - The coin bundle purchased and the number of coins credited
- Amount paid and currency
- Status (paid / refunded / disputed)
Your billing address and country are collected at checkout by Stripe for payment, tax, and fraud-prevention purposes; raw card data stays within Stripe's PCI-DSS environment.
Boughly does not retain CVC values or full card numbers, and is designed to minimize handling of payment card data subject to PCI requirements.
Tax Data (for Paid Stories)
Stripe Tax requires location information to determine the correct sales tax for your purchase. Boughly collects your country and (in jurisdictions where required) state and postal code from the Stripe Checkout flow. This data is used for tax calculation and reporting and may also be used for fraud prevention, payment verification, and applicable compliance purposes.
Creator KYC Information (for Paid-Story Creators)
If you enable paid stories as a creator, you complete Stripe Connect Express onboarding. During this process, Stripe collects identity verification information (such as legal name, date of birth, address, government ID, and tax ID) directly. Boughly does not directly collect or store the underlying identity documents. Boughly receives the Stripe Connect account ID (e.g., acct_…) and a small set of onboarding status flags returned by Stripe, such as details_submitted, charges_enabled, and payouts_enabled.
For U.S. creators, applicable tax forms (such as Form 1099-K) may be issued directly by Stripe based on current law and Stripe's tax-reporting configuration; reporting thresholds are set by tax authorities and may change. Boughly does not generate or distribute these forms.
2. How We Use Your Information
- To provide and maintain the Platform
- To display your published content to other users
- To process Paid Story purchases and route payouts to creators
- To calculate and remit applicable sales tax
- To verify age for Paid Mature purchases
- To send you transactional emails (purchase receipts, refund confirmations, moderation notifications)
- To improve the Platform through aggregated analytics
- To enforce our Terms of Service and Community Guidelines
- To comply with legal obligations (tax reporting, AML, sanctions screening)
3. Data Sharing & Third-Party Processors
Boughly does not sell your personal information as that term is defined under applicable law (including the California Consumer Privacy Act / California Privacy Rights Act). Boughly shares information with the following service providers as necessary to operate the Platform:
- Supabase — primary database, authentication, file storage. Hosted in the United States.
- Vercel — application hosting and CDN.
- Stripe — web payment processing, payout management, sales tax (Stripe Tax), KYC for creators (Stripe Connect).
- Resend — transactional email delivery (purchase receipts, account notifications).
- Sentry — error monitoring (non-personal stack traces and performance data).
- PostHog — product analytics. PostHog is configured to focus on aggregated usage patterns; depending on event configuration, technical identifiers (such as IP address or session IDs) may be processed as part of normal analytics operation.
When iOS and Android apps launch, we will additionally share purchase metadata with RevenueCat (entitlement sync) and the relevant store (Apple App Store or Google Play) for in-app purchases.
We may also share information when required by law or legal process, or to protect the safety of our users or the public.
4. Data Security
Boughly implements technical and organizational security measures designed to protect your data, including encryption in transit, encryption at rest, database-level access controls, and access-management practices for internal systems. Card data is handled within Stripe's PCI-DSS environment; Boughly is designed to minimize its handling of payment card data subject to PCI requirements.
No system is fully secure. You are responsible for maintaining the security of your account credentials and the device on which you access the Platform.
5. Your Rights
- Access — You can access all your data through your account dashboard, including purchase history and entitlements.
- Correction — You can update your profile information at any time. Your date of birth is set during the age-gate prompt and is locked afterwards; corrections to your date of birth can be requested through the age change request process, which may require additional verification.
- Deletion — You can delete your account and request deletion of associated profile and story data. Certain records may be retained as reasonably necessary for legal and regulatory compliance, fraud prevention, tax and accounting requirements, security, dispute resolution, and to preserve access to Paid Stories for readers who unlocked them, consistent with the Terms of Service. Identifying purchase records may be anonymized on request to the extent permitted by applicable retention obligations.
- Export — You can export your stories in JSON or EPUB format at any time. Buyers can re-download EPUB copies of Paid Stories from their library, where available; availability of downloadable copies may vary by platform.
6. Cookies & Local Storage
We use cookies for authentication and session management. We use browser local storage to save stories and preferences for users who are not signed in. We do NOT use third-party advertising cookies. You can clear local storage at any time through your browser settings.
7. Children's Privacy
Boughly is not intended for children under 13. Boughly does not knowingly collect personal information from children under 13. If Boughly becomes aware that personal information has been collected from a child under 13, Boughly will take reasonable steps to delete it within a reasonable period, in accordance with applicable law. Paid Stories rated Mature require buyers to represent that they are at least 18 years old and legally permitted to access such material in their jurisdiction.
8. International Users
Boughly currently operates primarily in the United States. Paid Story purchases are currently restricted to US billing addresses. Non-US visitors may browse and read available free content. As Boughly expands to additional jurisdictions, this Privacy Policy and related disclosures will be updated to reflect applicable data-protection rights (including, where relevant, the EU and UK GDPR, the EU Digital Services Act, and similar frameworks), legal bases for processing, cross-border data transfer mechanisms, and any required cookie consent or opt-out flows.
9. Contact
For privacy-related inquiries, contact us at privacy@boughly.com.
© 2026 Babu & Booshik LLC. All rights reserved.