Skip to content
The Horror Library

Privacy

Privacy Policy

Last updated 2026-05-04

The Horror Library is operated by Obsidian Codex Press, based in Norway. We take your privacy seriously, and we collect as little data as we possibly can while still providing the service.

This policy explains what we collect, why, how long we keep it, and what rights you have. Questions: [email protected].

Who we are

Obsidian Codex Press, Norway. Email [email protected]. We are the data controller for any personal data processed through horrorlib.com.

What we collect

If you read without an account

If you sign in

Signing in is optional and unlocks cross-device sync, bookmarks, and a saved-stories shelf. When you sign in via Google we receive your email address, name, and profile picture. We do not receive your Google password, contacts, calendar, or any other Google data.

While you have an account, we additionally store:

What we don’t collect

Why we collect what we collect

DataPurposeLegal basis (GDPR)
Umami analyticsUnderstand which stories are read; fix bugsLegitimate interest (Art. 6(1)(f))
Server logsDiagnose and fix bugsLegitimate interest (Art. 6(1)(f))
Account dataProvide the sync servicePerformance of contract (Art. 6(1)(b))
Reading positions / favorites / highlights / notesSync your library across devicesPerformance of contract (Art. 6(1)(b))

How long we keep it

Your rights under GDPR

You have the right to:

To exercise any of these rights, email [email protected]. We respond within 30 days. You can also lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) — datatilsynet.no.

Cookies

We don’t use cookies for analytics, advertising, or tracking. The only data on your device is in localStorage, which is technically distinct from cookies and not transmitted automatically.

If you have an account, signing in creates one session cookie (next-auth.session-token) that keeps you logged in. It is httpOnly, sameSite=lax, and expires after 30 days of inactivity. This cookie is strictly necessary for the sync service to work; GDPR exempts strictly necessary cookies from consent.

Data transfers

We host our database and application on Railway (United States). When you sign in, your account data leaves the EU/EEA and is processed in the US under Standard Contractual Clauses. Umami Cloud is hosted in the EU. Google OAuth involves data transfer to Google (US) for authentication; Google handles its own data per its policy.

Security

All traffic over HTTPS. No passwords on our side (Google OAuth handles authentication). Session tokens are httpOnly and rotated. Database access is restricted to the application. Errors are logged with PII stripped. No system is perfectly secure — if you suspect a vulnerability, write to [email protected]; we take responsible disclosure seriously and don’t pursue legal action against good-faith researchers.

Children

The site is not directed at children under 16. We don’t knowingly collect data from children. If you believe a child has signed up, email us and we’ll delete the account.

Changes to this policy

We will post any changes here with a new “last updated” date. Material changes will trigger a notice on the /settings page for signed-in users at next login.

Contact

[email protected] · Obsidian Codex Press, Norway