Privacy Policy

Last updated: July 1, 2026

1. Information We Collect

When you register, we collect your username, email address, and a hashed password. If you sign in via Google OAuth, we receive your name and email from Google. We do not receive or store your Google password.

As you use the site we record the books you add, reviews you write, and reading-status updates you make. We also collect standard server logs (IP address, browser type, pages visited) for security and performance purposes.

2. How We Use Your Information

  • To operate and personalize your MyFableVault account
  • To display your reviews and reading lists to other users
  • To send transactional emails (password reset, account confirmation)
  • To improve site performance and fix bugs

We do not sell your personal data to third parties.

3. Cookies & Analytics

We use a single auth_token httpOnly cookie to keep you signed in. We do not use advertising or tracking cookies.

We use Google Analytics to understand how the site is used. Google Analytics sets its own cookies (_ga, _ga_*) and collects aggregate, non-personal data such as page views, session duration, and general device and browser information. This data is processed by Google under their Privacy Policy. We do not share personally identifiable information with Google Analytics.

4. Data Sharing

We share data only with the service providers necessary to run the site (database hosting, authentication infrastructure). These providers are contractually bound to protect your data and may not use it for their own purposes.

5. Your Rights

You may request access to, correction of, or deletion of your personal data at any time by contacting us. Account deletion removes your profile and all associated data from our active database within 30 days.

6. Data Retention

We retain account data for as long as your account is active. Server logs are retained for up to 90 days. Backups may retain data for an additional 30 days after deletion.

7. Children

MyFableVault is not directed at children under 13. If we become aware that we have collected data from a child under 13 without parental consent, we will delete that data promptly.

8. Changes to This Policy

We may update this policy from time to time. Material changes will be announced on the site at least 14 days before taking effect.

9. Contact

Questions about this policy? Reach us via the contact page.

Cookie Preferences

We use Google Analytics to understand how the site is used. No advertising or personal data is shared. See our Privacy Policy for details.