Privacy
Privacy Policy
Last updated 2026-05-04
The Horror Library is operated by Obsidian Codex Press, based in Norway. We take your privacy seriously, and we collect as little data as we possibly can while still providing the service.
This policy explains what we collect, why, how long we keep it, and what rights you have. Questions: [email protected].
Who we are
Obsidian Codex Press, Norway. Email [email protected]. We are the data controller for any personal data processed through horrorlib.com.
What we collect
If you read without an account
- Anonymous analytics via Umami — page views, country (derived from IP, then discarded), screen size, referring site, OS family, browser. No cookies, no fingerprinting, no cross-site tracking. Your IP is processed momentarily to derive country, then discarded — never stored.
- Local browser storage (localStorage) — your reading progress, theme preference, font choice, and a flag for whether you’ve dismissed the sign-in prompt. This data lives only on your device. Clear your browser storage and it’s gone.
- Server logs — when something breaks, we keep the stack trace and request URL in our hosting provider’s logs so we can fix it. No cookies, no request bodies, no personal data.
If you sign in
Signing in is optional and unlocks cross-device sync, bookmarks, and a saved-stories shelf. When you sign in via Google we receive your email address, name, and profile picture. We do not receive your Google password, contacts, calendar, or any other Google data.
While you have an account, we additionally store:
- Reading positions — scroll position and percentage for each story you’ve started, so you can resume on any device.
- Saved stories — your shelf.
- Highlights and notes — passages you’ve marked, plus any notes you attach.
- Custom collections — your private reading lists.
What we don’t collect
- We do not sell or share your data with third parties.
- No third-party analytics (no Google Analytics, no Facebook Pixel).
- No third-party advertising. Ads on horrorlib.com promote Obsidian Codex Press only — they don’t track you, drop cookies, or share your behaviour with any ad network.
- We have no newsletter and don’t collect email addresses for marketing.
Why we collect what we collect
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Umami analytics | Understand which stories are read; fix bugs | Legitimate interest (Art. 6(1)(f)) |
| Server logs | Diagnose and fix bugs | Legitimate interest (Art. 6(1)(f)) |
| Account data | Provide the sync service | Performance of contract (Art. 6(1)(b)) |
| Reading positions / favorites / highlights / notes | Sync your library across devices | Performance of contract (Art. 6(1)(b)) |
How long we keep it
- Umami analytics: 12 months, then deleted automatically.
- Server logs: rotated and deleted automatically by our hosting provider, typically within 30 days.
- Account data: until you delete your account. Deletion is permanent and removes all data within 30 days, including from backups.
- Session cookies: auto-expire after 30 days of inactivity.
- localStorage on your device: lives until you clear it.
Your rights under GDPR
You have the right to:
- Access — see what we hold about you. The /settings page has an “Export my data” button that downloads a full JSON.
- Rectification — correct inaccurate data. Email us, or update via your Google profile if you signed in with Google.
- Erasure — delete your account from /settings. Permanent and removes all data within 30 days.
- Data portability — export your data as JSON from /settings.
- Restriction of processing — pause use of your data. Email us.
- Objection — object to our use of your data. Email us.
To exercise any of these rights, email [email protected]. We respond within 30 days. You can also lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) — datatilsynet.no.
Cookies
We don’t use cookies for analytics, advertising, or tracking. The only data on your device is in localStorage, which is technically distinct from cookies and not transmitted automatically.
If you have an account, signing in creates one session cookie (next-auth.session-token) that keeps you logged in. It is httpOnly, sameSite=lax, and expires after 30 days of inactivity. This cookie is strictly necessary for the sync service to work; GDPR exempts strictly necessary cookies from consent.
Data transfers
We host our database and application on Railway (United States). When you sign in, your account data leaves the EU/EEA and is processed in the US under Standard Contractual Clauses. Umami Cloud is hosted in the EU. Google OAuth involves data transfer to Google (US) for authentication; Google handles its own data per its policy.
Security
All traffic over HTTPS. No passwords on our side (Google OAuth handles authentication). Session tokens are httpOnly and rotated. Database access is restricted to the application. Errors are logged with PII stripped. No system is perfectly secure — if you suspect a vulnerability, write to [email protected]; we take responsible disclosure seriously and don’t pursue legal action against good-faith researchers.
Children
The site is not directed at children under 16. We don’t knowingly collect data from children. If you believe a child has signed up, email us and we’ll delete the account.
Changes to this policy
We will post any changes here with a new “last updated” date. Material changes will trigger a notice on the /settings page for signed-in users at next login.
Contact
[email protected] · Obsidian Codex Press, Norway