Privacy Policy
HorrorGod provides a community website and a companion Android app. This policy describes the account, content, payment and device data used to operate these services.
1. What we store about your account
When you register we store your email address, your chosen username, and a hash of your password. We never store your password itself — only a one-way bcrypt hash that cannot be reversed.
Optionally, you may add a bio, a signature, an avatar color and a preferred language in your settings. These are visible on your public profile (except your preferred language) and you can edit or clear them at any time.
Your saved library and online reading progress are associated with your account and can be shared between the website and Android app. The app also keeps local preferences and cached data on your device. Reading position inside an offline download stays on that device and is not synchronized to your online progress.
2. Content you publish
Stories, replies and reactions you post are stored and displayed publicly with your username. Private messages between members are stored and are visible only to the sender and the recipient — and to administrators if a message is reported for abuse or we are legally required to review it.
3. Sessions and security data
Web sign-in creates a session record that can include your IP address and browser user-agent. Android sign-in uses separate, revocable access and refresh credentials tied to your account. The app keeps those credentials in platform secure storage; the server stores token hashes, session state and expiry information.
Sessions expire or can be revoked by sign-out, password changes and account security actions. Expiration prevents access; it does not mean every associated security record is immediately erased. Security-relevant actions, such as bans, role changes and password changes, can be recorded in audit logs with request metadata.
4. Page counts and service providers
Our own page-view statistics are aggregate counters for each day, page and language. They do not use visitor identifiers or cookies. These counters are separate from the request and security logs used to operate the service.
The website uses hosting and Cloudflare delivery and security services; the Android API also uses Railway hosting. These services can process request information such as IP addresses, requested URLs and device or browser metadata. Email delivery and payment providers receive the information needed to deliver messages or process and verify purchases. Their processing is separate from our aggregate page counters.
5. Cookies
The website uses an HTTP-only session cookie to keep you signed in. It can also set a language preference cookie, including when you are not signed in. Cookies and storage used by a payment provider on its own checkout pages are governed by that provider’s policies.
The Android app uses local storage for preferences and cached content, and platform secure storage for sign-in credentials and the key protecting downloaded text.
6. Emails we send
We send account verification and password-reset emails. Depending on your notification preferences, we can also send reply and mention notifications and an optional weekly story digest. You can manage these preferences in your account or use the unsubscribe option in those notification emails. Our email delivery provider processes recipients and message contents to deliver them.
7. How long we keep data
Your account data is kept for as long as your account exists. Aggregate page-view counters contain no personal data and are kept indefinitely. Audit log entries are kept while they remain relevant to the security of the site.
8. Deleting your data
Delete your account directly at /en/account/delete or in the Android app under Account. You must sign in again before confirming deletion. This removes your account, profile, saved library, reading progress, private messages, sessions, and your published contributions. Groups you own and conversations you started are also removed.
Active subscriptions are canceled before deletion. Pending Google Play payments must first be completed or canceled. Deletion does not automatically refund past purchases. Stripe and Google may retain transaction records under their own policies; existing backups expire under the site backup retention schedule. Contact an administrator if you need help or must transfer staff responsibilities.
9. Your rights
Wherever you live, we honor the core GDPR rights: you may ask what data we hold about you, ask for corrections, ask for a copy of your data in a portable format, and ask for its deletion. Contact an administrator and we will respond within 30 days.
If you believe we have mishandled your data, you also have the right to complain to your local data-protection authority.
10. Changes to this policy
If we ever change what we collect or how we use it, we will update this page and announce the change on the site before it takes effect. The date at the top of this page tells you when it was last revised.
11. Membership and payments
Website membership payments are handled by Stripe. Android purchases made through Google Play are handled by Google. HorrorGod stores purchase and subscription identifiers, the account associated with the purchase, status and access-expiry information so the same account can use its membership on the website and app.
For Google Play purchases, the app sends purchase tokens to our server for verification with Google. The server retains encrypted purchase tokens to verify renewals, cancellations and refunds. Payment card information is handled by the payment provider. Each provider can retain transaction records under its own policies.
12. Downloaded Android text
When you explicitly download a story with an active paid membership, the app encrypts the text in app-private storage and binds it to your account. Offline access lasts at most 24 hours and never beyond the membership expiry verified when the download is issued. Downloaded text, its index and its reading position stay on your device; offline downloads do not include audio or images and cannot be exported from the app.
Restarting the app does not extend access. After a device reboot, you must reconnect and download the story again. Signing out, switching accounts, deleting your account in the app or receiving a confirmed access revocation clears downloaded copies. A remote refund, ban or cancellation cannot always be detected while disconnected, so an existing download can remain readable until its access period expires or the app reconnects and confirms revocation.