1. Who is responsible
Publifye AS, Solbergliveien 91D, 0683 Oslo, Norway (publifye.org), is the data controller for everything described here. We are a Norwegian company in the EEA, so the GDPR applies to how we handle your personal data.
Our position in one line: we store the minimum needed to give you an account, take your payment and deliver your Bibles. We do not sell your personal data, we run no advertising and no third-party analytics profiling, and we share data only with the providers listed in section 4, purely so the store works.
2. What this store itself stores
tbtm.sale keeps its own data in one Redis database. That is the whole of it:
- Your sign-in session
- When you log in, a session record holding your customer id and email address is stored under
tbtm:reader:<id>and expires on its own. Signing out deletes it. - Contact-form messages
- If you write to us through the contact form, we store your name, email address, message, the time, and the IP address the message came from. The IP is kept as spam/abuse evidence. We keep the message so we can answer it.
- Newsletter subscriptions
- If you subscribe, we store your email address and the date you subscribed — nothing else. Ask us and it is removed.
- Your library ledger (pass holders)
- So a pass can work at all, we record which editions your account has obtained
(
tbtm:lib:owned:<customer>, kept for as long as you hold the account, so re-downloads stay free) and which you obtained today (tbtm:dl:<customer>:<date>, deleted automatically after 48 hours) to count the daily allowance. A short-lived cached copy of your pass status sits alongside them for a couple of minutes at a time. - Reviews
- If a review is recorded for an edition, it is stored with the name and rating given.
That is everything this store holds itself. There is no other database.
3. What is held elsewhere on your behalf
- Your account, your orders and your entitlements
- Held by Lighthouse, Publifye's shared customer platform: your email address, your password (which we never see), your order history and any pass you hold. One account works across Publifye's services.
- Payment
- Handled by Stripe. You enter your card details with Stripe, not with us. We never see or store card numbers. We receive only the fact that an order was paid, so we can deliver what you bought.
- Your files
- The ePub files are served from our S3 object storage through short-lived, single-purpose download links issued to you.
4. Who processes data for us
A short list, each doing only its own job:
- Stripe — payment processing.
- Lighthouse (Publifye AS) — accounts, catalogue, checkout, orders, entitlements.
- pubcontacts (Publifye AS) — our own contact record. Checkout needs a contact id, so when you buy, your email address is looked up there and a record created if there is none.
- pubmail (Publifye AS) — sending you your download and library notices.
- S3 object storage — the ePub files.
- Our own servers — the Redis database in section 2 and the application logs in section 5.
Everything marked Publifye AS is run by us, not by a third party.
5. The chat widget, and logs
The site carries an AI chat widget. What you type into it is sent to our own LLM gateway to be answered, and the conversation is stored in the same Redis database so the thread survives a page reload. If you give the chat your email address it is saved to our contact record so we can follow up. Do not put anything into the chat you would not put in an email to us — it is a message to us, not a private notepad.
We keep ordinary application logs to run the service, keep it secure and debug it; error entries are forwarded to our own central log service. Logs record events and identifiers such as an email address where an action involved one. We do not log passwords, API keys, secrets or request headers.
6. Cookies
We use cookies for one purpose: keeping you signed in and keeping your cart and checkout working across pages. There are no advertising cookies, no cross-site trackers and no third-party analytics profiles. The one third-party request the pages make is to Google Fonts, for the typeface you are reading.
7. How long we keep things
- Sign-in sessions — expire on their own; deleted when you sign out.
- Today's download counter — deleted automatically after 48 hours.
- Your library record — kept while you hold the account, because that is what keeps your re-downloads free.
- Contact messages and newsletter subscriptions — kept until you ask us to remove them.
- Account and order records — kept while your account exists; payment and invoice records are kept as long as Norwegian accounting and tax law requires, which we cannot shorten on request.
8. Your rights
Under the GDPR you may ask us to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, or give you a copy of it. To exercise any of these, write to us and say what you want done.
Deleting your account removes your access to purchases held against it, and we cannot delete records the law requires us to keep. You also have the right to complain to the Norwegian Data Protection Authority (Datatilsynet).
9. Changes, and how to reach us
If what we store changes, this page changes with it — it is written from the running service, not from an intention. The version in force is the one on this page, with its "last updated" date at the top.
Data controller: Publifye AS, Solbergliveien 91D, 0683 Oslo, Norway. Reach us through the contact form.
Publifye AS, Solbergliveien 91D, 0683 Oslo, Norway — trading as TruthBeTold Ministry at tbtm.sale. See also our Terms, Licence and Privacy notices, or write to us.