Privacy Policy

Effective date: [TBD — set on real launch]
Draft — not yet reviewed by a lawyer
This is a working draft written to describe what HLS actually collects and does today. It has not been reviewed by a legal professional and should not be treated as final. Get it reviewed before real users rely on it, and before assuming it satisfies GDPR/CCPA or similar requirements in whatever regions your users are in.

1. Who we are

HLS ("we", "us") is operated by Paulo Henrique Nunes Sabatino, trading as El Plebo, of [registered/correspondence address — TBD, not a home address], who is the data controller for the personal information described below. Contact: [contact email — TBD, not yet set up].

2. Information we collect

  • Account info: when you sign in with Discord, we receive your Discord user ID and the profile info Discord shares with us (username, avatar, email).
  • Profile info you provide: your handle, display name, bio, and avatar.
  • Content you create: books, chapters, character art, and other content you upload as a creator.
  • Transaction data: your wallet balances, purchase and earning history, and which chapters you own. Full payment card details are handled entirely by Stripe — we never receive or store them.
  • Reading data: your progress and choices within books you read, so you can resume where you left off.
  • Error/diagnostic data: when something breaks, our error-tracking tool (Sentry) may capture the page you were on, browser/device info, your IP address, and technical details about the error.
  • Product usage & session activity: during our beta, our analytics tool (PostHog) records which features you use and how you move through key flows, and captures session recordings of your interactions to help us find and fix problems. Recordings mask text you type into form fields (including payment and access-code fields). We identify this data by your account ID and handle only. No advertising or cross-site tracking.
  • Support messages: if you contact us through the in-app support widget, the messages you send and our replies are stored by PostHog and linked to your account so we can follow up.
  • Cookies & local storage: functional storage used to keep you signed in, plus analytics storage used by PostHog to recognise your browser between visits during the beta. No advertising cookies.

3. How we use this information

To provide the Service (your account, library, and reading progress), process purchases, prevent fraud and abuse, diagnose and fix bugs, understand how the Service is used so we can improve it, and communicate with you about your account when necessary. We don't use your data for advertising, and we don't sell personal information.

4. Who we share it with

We use a small set of service providers to run HLS, each of which processes data on our behalf under their own privacy terms:

  • Supabase — database, authentication, and file storage.
  • Stripe — payment processing for Gem purchases.
  • Discord — sign-in (OAuth identity provider).
  • Sentry — error tracking.
  • PostHog — product analytics, session replay, and in-app support messaging (EU-hosted), used during the beta to understand feature usage, diagnose problems, and respond to your feedback.
  • Vercel — hosting.
  • Anthropic — powers creator-facing AI-assist features (for example, dialogue polish). Only content you explicitly submit to one of these features — a line of dialogue and a few lines of surrounding context, never a whole chapter — is sent, and only when you trigger the action.

We don't share your personal information with anyone else except where required by law, to protect our legal rights, or with your explicit consent.

5. Data retention

We keep your data while your account is active. If you request account deletion, we'll delete your profile and any content that hasn't been purchased by a reader. A book or chapter that readers have already bought is archived instead of deleted, so their access isn't taken away — see Terms of Service §4. We may also retain transaction records for as long as needed for financial recordkeeping, fraud prevention, or legal compliance.

6. Your rights

You can request a copy of your data, ask us to correct it, or ask us to delete your account by contacting [contact email — TBD]. Depending on where you live, you may have additional rights under laws like the GDPR or CCPA — this section needs real legal tailoring based on where our users actually are, not a generic placeholder.

7. Children's privacy

The Service isn't directed at children under 16, and creating an account requires confirming you're at least 16 (we don't collect a birthdate). If we learn we've collected personal information from a child under that age without appropriate consent, we'll delete it.

8. Security

We use reasonable technical and organizational measures to protect your data, but no method of storage or transmission is 100% secure, and we can't guarantee absolute security.

9. International data

Our service providers may process and store data in countries other than your own. By using the Service, you understand your information may be transferred internationally.

10. Changes to this policy

We may update this policy from time to time. If we make material changes, we'll post the updated policy here with a new effective date.

11. Contact

Questions about this policy, or a data request: [contact email — TBD].