Privacy Policy
Last updated: November 9, 2025
Introduction
Gifted.Press ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
This policy is designed to comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Information We Collect
Personal Information
- Name and email address (when you create an account)
- Payment information (processed securely through Stripe)
- Profile information (bio, avatar, author details)
- Reading history and preferences
Usage Information
- Reading credits earned and spent
- Books read, reading progress, and time spent
- Comments, highlights, and bookmarks
- Subscription status and tier
Technical Information
- IP address and device information
- Browser type and version
- Cookies and similar tracking technologies
- Analytics data (via Vercel Analytics)
How We Use Your Information
- Provide Services: Process subscriptions, track reading progress, distribute reading credits
- Improve Experience: Personalize recommendations, optimize platform performance
- Communication: Send important updates, notifications, and newsletters (with your consent)
- Financial Operations: Calculate Literary Pool distributions, process author payouts
- Analytics: Understand platform usage, identify trends, improve features
- Legal Compliance: Comply with legal obligations, prevent fraud, enforce our terms
Your GDPR Rights
Under GDPR, you have the following rights:
- Right to Access: Request a copy of all your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Opt out of certain data processing activities
- Right to Withdraw Consent: Revoke consent for data processing at any time
Exercise Your Rights
You can manage your privacy settings and data through your account:
- Export Your Data: GET
/api/gdpr/export-data - Delete Your Account: DELETE
/api/gdpr/delete-account?confirm=true - Privacy Settings: GET/POST
/api/gdpr/privacy-settings
Data Retention
We retain your personal data only as long as necessary to provide our services and comply with legal obligations. Reading history and credits are retained while your account is active. After account deletion, all personal data is permanently removed within 30 days, except as required by law.
Data Security
We implement industry-standard security measures to protect your data:
- Encrypted data transmission (HTTPS/TLS)
- Secure authentication via Clerk
- Payment processing via PCI-compliant Stripe
- Regular security audits and monitoring
- Access controls and audit logging
Third-Party Services
We use the following third-party services:
- Clerk: Authentication and user management
- Stripe: Payment processing and payouts
- Vercel: Hosting and analytics
- Neon: Database hosting
Each service has its own privacy policy and security practices.
Cookies
We use cookies to improve your experience:
- Necessary Cookies: Required for authentication and core functionality
- Analytics Cookies: Help us understand how you use the platform
- Preference Cookies: Remember your settings and preferences
You can manage cookie preferences through the cookie banner or your browser settings.
International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence. We ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements.
Children's Privacy
Our platform is not intended for children under 16. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or platform notification. Continued use of the platform after changes constitutes acceptance of the updated policy.
Contact Us
For privacy-related questions, data requests, or concerns:
Email: privacy@gifted.press
Data Protection Officer: dpo@gifted.press
Response Time: Within 30 days of request
Supervisory Authority
If you believe we have not addressed your privacy concerns adequately, you have the right to lodge a complaint with your local data protection authority.