Legal
Last updated: 15 September 2026
BetaReadIt is a hosting and access-management tool for authors and publishers running beta reads of their manuscripts. This policy explains what we collect, why, who can see it, how long we keep it, and what you can do about it. It applies to author and publisher accounts, their team members, the beta readers they invite, and visitors to this website.
Who operates this service
BetaReadIt is operated by Diletta Micieli (sole trader, ABN: 29 550 057 310), based in North Ward, QLD, Australia. For any privacy question or request, write to support@betareadit.com.
What we collect
- Account details: your email, name or pen name, organisation name, password (stored only as a secure hash) or the Google or GitHub account you sign in with, and your settings and display preferences.
- Sign-in and security records: your sessions, when you last signed in and were active, and a log of security-relevant actions with a partly masked network address.
- Reading activity (beta readers): which manuscripts you were given, how far you have read, time spent reading each chapter or page, bookmarks and favourite pages, highlights, notes, tags, chapter ratings, survey answers, and whether and when you accepted the Confidentiality Agreement.
- Reader reliability: the outcome of each reading project (for example completed, completed on time, verified, or left early), worked out from the reading activity above.
- Profiles you choose to fill in: avatar, bio, gender, age range, favourite genres, strengths, the languages you read in, the audiences and manuscript types you enjoy, your availability, whether you’re open to paid or volunteer reads and your reading preferences for beta readers; pen name, bio, location, genres and website or social links for authors and publishers.
- Notes kept by authors and publishers about the readers they work with (a private note, and optionally gender and age).
- Messages you exchange with authors, publishers or team members.
- Reading Room activity: the Reading Opportunities authors and publishers list (the manuscript details they choose to show, what they ask of readers and any reward), and the applications readers send: which listing, the optional message, and whether it was accepted, declined or withdrawn.
- Bug reports you send: what you describe, up to five optional screenshots, and, only if you choose to include them, technical details (page, browser, device, screen size, app version).
- Billing status for paying organisations (plan, renewal date). Stripe processes and stores the payment details; we never see or store full card numbers.
Why we use it
We use account, manuscript, reading and messaging data to provide the service you or your publisher signed up for: showing manuscripts to the right people, saving your place, passing feedback to the author, and sending the emails the service depends on. Those are sign-in and verification links, password resets, invitations, payment problems and reading-deadline reminders (you can turn reminders and some notifications off in Settings).
We use security records to keep accounts and manuscripts safe from abuse, and bug reports to fix problems. Reading Room profiles are shown only because you choose to show them. We do not use your data for advertising, we do not sell it, and we do not run analytics or advertising trackers.
Who can see it
- The author or publisher who invited a beta reader, and the team members they give access to, see that reader’s progress, reading time, feedback, survey answers and reliability outcomes for their own manuscripts, never for another organisation’s.
- A beta reader’s highlights and notes are never shown to other readers. The notes authors keep about readers are never shown to the reader.
- Other signed-in BetaReadIt users, if you show your profile in the Reading Room: a beta reader profile shows your display name, avatar, bio, gender, age range, genres, strengths, the Reading Room details you added and your reliability status (“New Reader” or “Verified Reader” with counts). An author profile shows your pen name, bio, location, genres, links and open Reading Opportunities. A shown author profile also has a public page anyone can open (without the Reading Opportunities, only how many are open). Your email and manuscripts are never shown.
- The author or publisher you apply to sees your Beta Reader profile and your message, even if your profile isn’t shown in the Reading Room.
- While reading, a watermark shows a partly masked version of your email and the time, to discourage screenshots.
Service providers and where data is stored
The BetaReadIt app’s servers and database are in Australia. We use a small number of providers, and share with each only what it needs:
- Cloudflare: secure delivery of the app, and routing of emails sent to our support address.
- Hostinger: hosting of this website.
- Stripe: payments for paid plans.
- Resend: sending the service’s emails.
- Google: sign-in with Google, if you choose it; the inbox where support emails are read; storage of our encrypted database backups; and the fonts this website uses.
- GitHub: sign-in with GitHub, if you choose it.
These providers may process data outside Australia, including in the United States. We choose providers that protect personal information to a standard comparable to the Australian Privacy Principles and, for users in Europe, the GDPR.
How long we keep it
- Account, reading and profile data is kept while your account is active.
- When you delete your account (Settings → Delete account), it stays recoverable for 30 days. After that it is anonymised automatically: your name, email, password, avatar, bio, gender and age are removed, linked Google or GitHub sign-ins are unlinked, and every note an organisation kept about you and every Reading Room application you sent are deleted. Feedback you already gave an author (highlights, notes, ratings, survey answers) stays with them, shown as from “Deleted user”.
- Bug reports and their screenshots are deleted after 12 months. Screenshots that were forwarded to our support inbox are removed from the app after 30 days.
- Security logs are deleted after 24 months.
- If an author deletes a manuscript, the anonymous outcome of your reading project for it is kept, so your reliability counts stay accurate.
- Encrypted database backups are kept on a rolling schedule of 7 daily, 4 weekly and 12 monthly copies, so deleted data can remain in a backup for up to 12 months before it is overwritten.
Cookies and storage on your device
In the app we set only strictly necessary cookies: a session cookie that keeps you signed in, a matching security token that protects your account from cross-site request forgery, and a cookie that remembers which organisation you are working in. Your browser also stores a few display choices (such as the manuscript view or message sounds) on your own device.
This website sets no cookies for visitors. It loads its fonts from Google Fonts, so your browser connects to Google’s servers to fetch them and Google receives your IP address as part of that request.
There are no analytics, advertising or tracking cookies, so no consent banner is needed.
Your choices and rights
- Correct your details and profiles at any time in the app.
- Hide a profile by turning off “Show my profile in the Reading Room”, and withdraw an application that hasn’t been answered.
- Turn off reading reminders and some notification emails in Settings.
- Delete your account yourself in Settings → Delete account.
- Download a copy of your data yourself in Settings → Your data, as one file (JSON). It leaves out other people’s messages and, for a manuscript you can no longer open, the passages your highlights quoted.
- Ask for anything else about your data by writing to support@betareadit.com. Beta readers can also ask the author or publisher who invited them. We reply within 30 days.
If you are unhappy with how we handled your request, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au). If you live in the European Economic Area or the UK, you have the rights given by the GDPR, including access, correction, deletion, restriction, objection and data portability, and you can also contact your local data protection authority.
Children
BetaReadIt is not for children under 13, and we don’t knowingly collect their data. Readers aged 13 to 17 may use it only with a parent or guardian’s permission, and Reading Room profiles are for adults only. If you believe a child under 13 has an account, tell us and we will delete it.
Your data and the manuscript
Manuscripts are provided for reading only: they can’t be downloaded by readers, and copying, printing and the right-click menu are disabled while reading. These are deterrents and access controls, not absolute copy protection, so please don’t share screenshots or the text.
Security
Connections to BetaReadIt are encrypted, passwords are stored only as secure hashes, database backups are encrypted before they leave our server, and access to each manuscript is limited to the people its author or publisher chose.
Changes to this policy
If we make a material change to this policy, we’ll update the date above and let account holders know by email or in the app.