Skip to main content
HorrorGod

Privacy Policy

Last updated: August 2026

HorrorGod.com is a community forum, not an advertising business. We collect the minimum data needed to run a forum, we do not sell or share it, and we do not use third-party trackers. This policy explains exactly what we store and why.

1. What we store about your account

When you register we store your email address, your chosen username, and a hash of your password. We never store your password itself — only a one-way bcrypt hash that cannot be reversed.

Optionally, you may add a bio, a signature, an avatar color and a preferred language in your settings. These are visible on your public profile (except your preferred language) and you can edit or clear them at any time.

2. Content you publish

Stories, replies and reactions you post are stored and displayed publicly with your username. Private messages between members are stored and are visible only to the sender and the recipient — and to administrators if a message is reported for abuse or we are legally required to review it.

3. Sessions and security data

When you sign in we create a session record that includes your IP address and browser user-agent string. We keep this solely for security: detecting account takeovers, investigating abuse, and letting you sign out of all devices at once.

Sessions expire automatically after 30 days and expired sessions are deleted. Security-relevant actions (bans, role changes, password changes and similar) are recorded in an audit log, which also stores the IP the action came from.

4. Analytics without tracking

Our page-view analytics are aggregate counters: for each day, page and language we store a single number. No visitor identifiers, no IP addresses, no fingerprinting and no cookies are involved in analytics.

We use no third-party analytics services, no advertising networks and no social-media tracking pixels. Nothing on this site reports your visit to anyone else.

5. Cookies

We set exactly one cookie: a session cookie that keeps you signed in. It is HTTP-only and is not readable by scripts. If you never sign in, we set no cookies at all. There are no tracking, preference or advertising cookies.

6. Emails we send

We send email only for account verification and password resets. We do not send newsletters or marketing email, and we will never give your address to anyone else.

7. How long we keep data

Your account data is kept for as long as your account exists. Aggregate page-view counters contain no personal data and are kept indefinitely. Audit log entries are kept while they remain relevant to the security of the site.

8. Deleting your data

You can request deletion of your account at any time by contacting an administrator through the contact link in the footer. We will remove your account, profile, private messages and sessions.

Published stories and replies can either be deleted with the account or anonymized (kept without your username) — tell us which you prefer. We may retain minimal audit records where we have a legitimate security interest or a legal obligation to do so.

9. Your rights

Wherever you live, we honor the core GDPR rights: you may ask what data we hold about you, ask for corrections, ask for a copy of your data in a portable format, and ask for its deletion. Contact an administrator and we will respond within 30 days.

If you believe we have mishandled your data, you also have the right to complain to your local data-protection authority.

10. Changes to this policy

If we ever change what we collect or how we use it, we will update this page and announce the change on the site before it takes effect. The date at the top of this page tells you when it was last revised.