Information submitted through the project form
The regular project form can collect your name, email address, project type, manuscript stage, estimated page count, a project-files link, an optional author-visible referral code, the details you choose to write, and your permission to receive a reply. If you arrive through a labeled marketing, referral, or advertising link, the site can temporarily keep a sanitized referral code, source, medium, campaign, term, content label, and advertising click identifier (GCLID, GBRAID, WBRAID, or MSCLKID) in browser session storage so it remains available if you navigate to the contact form in that tab. This is pending same-tab attribution, not a final referral record, and it does not store manuscript text.
Before an inquiry is submitted or a code is otherwise confirmed, a newer valid explicit ref= value on another approved referral link in the same tab can replace an older pending code. A page opened without an explicit code can use the current pending value. An active associate page keeps its offer, process, selected portfolio/style studies, and project-start navigation on that page; its built-in form binds the displayed partner’s exact permanent affiliate ID on the server. The regular main-site contact form can display a pending code in a visible, editable field when that separate route is used. We use submitted labels, codes, and identifiers to understand which outreach led to an inquiry, connect a later project outcome when appropriate, administer referral eligibility, and manage a project if the author proceeds.
Referral attribution does not require a tracked link, tracking cookie, contact list, or one-to-one introduction. An eligible author may confirm one valid active code through the visible regular form field, email, text, written chat, a documented phone call, an author-confirmed partner introduction, or the form on an associate page that visibly identifies the partner. The associate-page form securely binds that displayed partner’s permanent affiliate ID on the server and does not show a code-entry field. Once the author submits or otherwise confirms one valid active code and we create a private project referral record, the first author-confirmed code locks to that project. A later browsing link or pending session value cannot replace the record; only a clear documented clerical correction allowed by the terms can change it. Attribution alone does not establish the new-lead test, qualifying offer, project or payment milestone, commission eligibility, or payout. Email messages and any files or links you provide become part of that correspondence.
Self-service referral partner accounts and records
Referral signup uses MyBookIllustrator’s same-origin portal and collects only a full name, email address, U.S. and adult confirmations, acceptance of the current program terms, and promises to disclose the commission and promote fairly. It does not ask for a website, referral plan, contact list, introduction, password, payout destination, bank or card information, tax identifier, payment-account login, or client-confidential information.
The portal emails a single-use verification link that expires after 48 hours. Opening the link only displays a confirmation page; choosing Continue submits the confirmation, consumes the token, and automatically activates the account, permanent affiliate ID/referral code, and default public associate page. This two-step design limits accidental activation by automated email scanners. Verification confirms control of the email address only; it does not prove identity or endorsement.
Partners sign in without a password. The portal sends a single-use magic link that expires after 15 minutes; opening it displays a Continue step before the token is consumed. A successful sign-in creates a secure, HTTP-only, same-site session that ends after two hours of inactivity or 12 hours at the latest. Public signup, author-request, and page-report forms also use the same essential same-site security session to hold short-lived anti-forgery and single-use form tokens; it is not used for advertising or cross-site referral tracking and expires under the same session limits. Do not forward or publish verification or sign-in links. MyBookIllustrator stores token hashes rather than the private token text, keeps portal files and account records outside the public web root, and uses limited rate and security records to prevent abuse.
An activated account can store the permanent affiliate ID/referral code, verified email, full name, consent version and timestamps, assigned commission-plan identifier, any private-plan acceptance version and time, account status, login timestamps, approved palette, hero-art, layout, offer focus, call-to-action, portfolio-study selections, section order/visibility, optional-form settings, public display name, headline, short introduction, current vanity address, historical vanity mappings, and the version and time of any website-embed representation-policy acceptance. The public associate page shows the affiliate ID and permitted profile selections plus MyBookIllustrator-controlled offer, process, artist-directed AI-assisted portfolio/style-study disclosure, referral disclosure, and author-form content. It does not publish the partner’s private email, legal name unless chosen as the display name, tokens, session data, payout destination, or internal records.
An authenticated active partner may optionally upload one profile image and one header image after confirming ownership or permission. The portal accepts only tightly limited JPEG, PNG, or still WebP input, verifies MIME and dimensions, decodes and resizes it, strips original metadata by re-encoding it as WebP, discards the original bytes during the request, and stores only the current processed file and technical metadata outside the public web root. The public page receives the current processed file through a fixed same-origin media route. Replacing or removing an image removes the superseded current file; paused or closed accounts are not served media. Rate/security records may be kept for their enforcement window, while current processed images are kept until replacement, removal, or account closure unless a specific abuse, rights, dispute, or legal preservation need requires limited retention.
When an author submits the form on an associate page, the portal binds the permanent affiliate ID on the server; the author does not type a code. The form can collect the author’s name, email, optional project title, free-sample or project-start choice, project details, and adult/contact confirmations. It creates a private per-project referral record and a limited status event for the partner, sends a project notice to MyBookIllustrator, and sends the author a receipt. The partner does not receive the author’s email, message, manuscript, or payment details through the dashboard. A submission records attribution but does not automatically approve project fit, commission eligibility, or a payout.
A public “Report this page” form is tied to the exact affiliate ID and can collect a fixed report reason, a 10- to 1,000-character description, an optional reply email, security/rate information, and the report time. Reports are stored privately and emailed to MyBookIllustrator for manual review; they are not shown to the partner. Do not include sensitive credentials or payment information. Report records are kept only as reasonably needed to investigate the concern, enforce the program, document a decision, or satisfy a legal preservation need.
For an active partner, MyBookIllustrator may also keep the first valid code confirmed by the author, confirmation channel and time, documented clerical corrections, the 180-day new-lead check, a separate per-project referral record ID, the commission plan and stage amounts in force when that referral was recorded, qualifying project, cleared/non-pending payment dates, 24-hour failure/reversal waits, delivery status, refunds, reversals, proportional adjustments, future-commission offsets, eligible amounts, manual review decisions, and payout dates. The affiliate ID/referral code identifies the partner; the referral record ID identifies one author/project. Referral attribution does not require partners to provide author contact lists, and MyBookIllustrator does not require a referral tracking cookie. These records are used to decide eligibility, provide a status or ledger, correct errors, prevent duplicate or fraudulent credit, protect the portal, and maintain ordinary payment and tax records.
Pending signup information is kept only long enough to complete or troubleshoot email verification and is removed under the portal cleanup schedule after the 48-hour link expires. Active account and public-profile settings are kept while the account operates. Security and rate-limit records are kept only as long as reasonably needed for their enforcement window or an abuse investigation. Referral, commission, payout, dispute, consent, and tax-related operational records are generally retained for four years, or longer when reasonably required for a legal preservation obligation. Closing or suspending an account removes or disables public access as appropriate but does not require deletion of records that must be retained for payment, fraud prevention, dispute, tax, or legal purposes.
Partners may ask MyBookIllustrator for their referral ledger, request correction of an account, attribution, milestone, refund, offset, or payout record, or request account closure by emailing tobymikle@gmail.com. MyBookIllustrator is operated by Toby Mikle. Customer privacy limits the project details that can be disclosed to a partner.
Author Showcase submissions
The Author Showcase form collects a private contact name and email address plus an author or pen name, book title, publication status, intended reader age, story summary, author introduction, optional story notes, a required book-cover image, an optional adult author photo, and public book or author links you choose to provide. It also collects confirmations about age, rights, accuracy, image and likeness permission, automatic posting, photographs of minors, child privacy, and the Showcase terms.
Image uploads first enter the host’s temporary upload area. The server checks the file type, byte size, and pixel dimensions; decodes, resizes, and re-encodes a new JPEG display copy; and removes embedded metadata such as EXIF and location data when present. Original upload bytes are not published or retained after processing. Metadata removal cannot hide a private address, school, location, or other information visibly pictured in the image, so submitters must inspect the visible background before uploading.
The public listing is limited to the author or pen name, book title, author-provided publication status, intended reader age, story summary, author introduction, optional story note, sanitized book-cover image, optional sanitized adult-author image, and at most one recognized public book, retailer, library, or author link allowed by the server’s link rules. The private record contains the contact name, email address, any submitted link that is withheld, the consent record and timestamps, technical image descriptors, marketing attribution and advertising click identifiers, verification and management token hashes, and the keyed rate-limit HMAC. None of those private fields is included in the public listing or feed.
After server-side validation and submitter email verification, the public fields and sanitized images are posted automatically as an author-submitted, not independently verified community listing. MyBookIllustrator does not independently verify the submitter’s identity, authorship, image ownership, a pictured adult’s consent, publication status, claims, or external links and does not endorse the listing. Community submissions are kept out of search-result snippets with data-nosnippet. Public external links are marked as user-generated and nofollow links.
The website sends the submitter a verification email containing a token-bearing verification link and a separate private management link. It does not send the submission to Toby by email. Verification confirms control of the submitted email address only; it does not prove authorship, ownership, accuracy, or endorsement. The submitter can use the private management link from that email to remove the listing. Token-bearing verification, confirmation, and management pages do not load the Google Ads or Microsoft Advertising measurement tags.
Showcase records and sanitized images awaiting verification are stored in a private directory outside the public web root and cannot be served publicly. After verification, sanitized display images are delivered only through a same-origin media endpoint, and their URLs may appear in the public feed. Unverified pending submissions and their images expire after 7 days. Rate-limit records are kept for 7 days. Removing a listing makes its media endpoint refuse the images immediately; short-lived technical backups may persist under the stated retention and legal-preservation rules. Published listings otherwise remain until the submitter removes them, MyBookIllustrator removes them for safety or policy reasons, or a longer period is reasonably necessary to handle a legal request or dispute. For abuse prevention, the Showcase keeps a keyed HMAC derived from the request address rather than storing the raw IP address in the Showcase record. The hosting service may separately keep ordinary access or security logs, such as an IP address, request time, requested path, and browser information, under its server settings.
Free browser tools keep working files on your device
Interactive tools such as MyBook and the One Ancestor Story Lab save your working project in private browser storage on that device so it remains available when you return. MyBook creates its project backup and print PDFs inside your browser; your manuscript, artwork, and exported book are not uploaded to MyBookIllustrator for those actions. Use MyBook’s Save button to keep a separate .mybook backup because clearing browser data, using a private window, or losing the device can remove the browser copy.
MyBook requests typefaces from Google Fonts, so Google can receive ordinary technical request information such as your IP address, browser, and the requested font files. That request does not include your manuscript, artwork, or saved project.
FormSubmit processes the regular project inquiry
The regular project-inquiry form posts to FormSubmit, a third-party form-processing provider, which forwards the submitted information to tobymikle@gmail.com. FormSubmit processes each submission on its own systems under its own terms and privacy practices. The referral portal, its associate-page author form, and the Author Showcase use MyBookIllustrator’s same-origin systems instead of FormSubmit. If you do not want to use FormSubmit, you may email Toby directly.
Referral signup, public profile fields, and the associate-page author form do not request payout details. Only after a commission stage is manually confirmed as eligible is a partner asked privately for the destination required by their choice of PayPal, Zelle, Venmo, Cash App, or mailed business check. A check requires the legal payee name and U.S. mailing address. Do not enter bank or card details, passwords, account logins, tax identifiers, a payout email or handle, or a mailing address in signup, a profile field, or an author form.
PayPal processes deposits
The deposit page sends a fixed payment request to PayPal with the MyBookIllustrator PayPal email, currency, amount, item name, return addresses, and an optional plain-text project reference. PayPal—not this website—collects and processes your PayPal login, card, bank, billing, and transaction information under PayPal’s own terms and privacy practices.
MyBookIllustrator receives the payment information and payer details that PayPal normally provides to a seller for the transaction. Do not email payment-card numbers or account credentials.
Google Ads and Microsoft Advertising measurement
The site loads the Google Ads tag identified as AW-1069544796 and the Microsoft Advertising UET tag identified as 343263550. These tags can send visit, device, browser, and interaction information to Google and Microsoft and may use cookies or similar technologies to measure whether advertising leads to a site visit or inquiry. MyBookIllustrator does not use this information to read the contents of your manuscript or project message.
Google and Microsoft handle that information under their own privacy practices. You can limit cookies through your browser settings. The contact form and PayPal remain separate services with their own technologies when you interact with them.
Project and submission records
Project correspondence, delivered-file records, and payment records may be kept as needed to manage the work, answer questions, and meet ordinary business recordkeeping obligations. Author Showcase retention is described separately above. MyBookIllustrator does not sell project-inquiry or Author Showcase information or use it for third-party advertising.
Private referral records may include the partner’s affiliate ID/referral code and contact information, separate per-project referral record IDs and status, an author-confirmed attribution, manual eligibility and payout approvals, commission amounts, payout method, electronic payout email, mobile number, or handle when applicable, legal check payee name and U.S. mailing address when applicable, payout or mailing date, and transaction or check reference. Payout destinations are kept out of signup, public profile fields, author forms, and public pages and are used only to administer the program, make payments, resolve record questions, and meet ordinary business or legal obligations. MyBookIllustrator does not request or use a partner’s password, payment-app login, card number, or bank login for a referral payout.
Correction or deletion requests
An Author Showcase submitter can use the private management link issued after verification to remove the public listing without emailing Toby. For other corrections, to ask what project information Toby has, or to request deletion when the management link is unavailable, email tobymikle@gmail.com. Some transaction or business records may need to be kept when required for payment, dispute, tax, or legal recordkeeping; any limitation will be explained in the reply.
Questions
Privacy questions can be sent to tobymikle@gmail.com.