Plain-language summary
The library is designed to collect as little reader data as practical. Reading preferences, bookmarks, and anonymous reading position stay on your device unless you deliberately use an account-based feature.
Data we may process
- Account identifiers and verified email when you sign in, follow a topic or series, or comment.
- Comment text, moderation state, a one-way email hash, and one-hour-scoped one-way network hashes for abuse prevention.
- An encrypted email delivery address only when a commenter explicitly requests approved-reply notifications.
- Newsletter and notification choices, verification, and unsubscribe records.
- Consent choices and privacy-respecting aggregate performance measurements.
Comments
Pending and unverified comments are private, excluded from search and page HTML, and visible only to authorized moderators and—where supported—the submitter. Verification links expire after 24 hours. Email addresses are never shown with public comments, and the optional reply-notification address is encrypted with a separate server secret.
Advertising and analytics
Advertising and nonessential analytics remain off until the required configuration and consent are present. Declining nonessential cookies does not prevent access to library content.
Retention and rights
Verification links expire after 24 hours. Rate-limit hashes rotate each hour and are cleared from older comment records during comment processing. Moderation and spam retention periods, the responsible entity, and a reader request channel must be configured before public launch.
International use
Before production launch, the administrator must complete a jurisdiction-specific legal review, name the responsible entity, publish contact details, and document processors and retention periods.