Security
How BookSway handles accounts and Amazon credentials.
How BookSway authenticates users, separates Author and Creator data, and stores Amazon Ads credentials.
Accounts and access
BookSway uses Supabase for authentication and its application database. Users sign in with email and password or Google. Each account has one role: author or creator. That role is stored on the BookSway profile and is not taken from editable browser metadata when authorizing access.
Role separation
Author library, campaign management, and Amazon connection settings are available to authors. Campaign discovery and joining are available to creators. Creators cannot access an author’s Amazon connection. Authors do not receive a creator private workspace.
Amazon credentials
Authors can securely connect their Amazon Ads account. For eligible connected profiles, BookSway sets up creator Attribution destinations automatically. Creators share one BookSway link and never receive Amazon credentials or raw Attribution URLs.
When an author chooses to connect Amazon Ads, BookSway stores the author's advertising-profile metadata and an encrypted refresh credential so that author can manage the connection inside BookSway. BookSway may retrieve Amazon Attribution reports for that author. It does not share Amazon credentials with creators or browsers.
Amazon access happens after the author starts Connect from BookSway and completes Amazon authorization. Authors can disconnect the Amazon Ads connection inside BookSway, which makes the stored refresh credential unusable. Disconnect does not by itself prove that Amazon revoked access on the Amazon side.
Refresh credentials are encrypted at rest with AES-256-GCM before storage. Access tokens are short-lived and are not stored as a long-lived database secret. Amazon secrets are not sent to browsers or to creator accounts.
Private data
BookSway uses account, book, campaign, membership, and Amazon connection data to operate the BookSway product those records belong to. It does not sell Amazon advertising data. When the scheduled Attribution reporting job runs, BookSway may retrieve report pages for that author. Authors do not trigger Attribution retrieve from product UI. Creators do not receive the author Amazon dataset. Authors pay Creators for recorded Creator rewards through Stripe. BookSway calculates those rewards from qualifying Amazon-attributed activity using frozen campaign terms. Settled is not paid.
Storage and access control
Application data lives in PostgreSQL with row-level security. Private cover and avatar images are stored in restricted buckets. Eligible marketplace images — open-campaign covers and spotlight or public-campaign author avatars — are served through BookSway app routes that check eligibility, not as a public bucket listing. Author dashboards may still use short-lived signed URLs for owned files. BookSway does not claim SOC 2, ISO, GDPR certification, “bank-level” security, or Amazon approval. Encryption and access controls described here are the current implementation, not a substitute for a third-party audit.
Reporting a problem
Security concerns and suspected vulnerabilities can be reported to security@booksway.app. BookSway investigates reported issues, contains affected systems where appropriate, preserves relevant evidence, remediates confirmed issues, and notifies affected providers or parties where required. Do not send passwords, access tokens, or other secrets.
Security incidents involving Amazon information will be escalated and reported to Amazon through the required security reporting channel.