Privacy Policy
A plain-language draft of how this magazine handles reader information. Replace the placeholders and have counsel review it for every region you serve.
Who this applies to
This draft describes StoryVault, a reading magazine on the web. It does not name a registered company, a street address, or a registration number because those details have not been supplied. Add the legal entity that operates the site before you treat this as a finished policy.
What we collect today
In this prototype, information falls into a short list:
- Pages you request. The host that serves the site may keep ordinary server logs (such as IP address, user agent, and the URL requested) for security and reliability. Those logs are controlled by the hosting operator you choose, not by this repository. Document the actual host and retention period before launch.
- Newsletter address. If you submit the mailing-list form and check the consent box, we store the email address you typed, when you consented, and a short note of the form you used. We do not add you without that checkbox. We do not sell the list.
- Desk accounts. Staff who sign in to
/adminhave an email, display name, role, and a password hash. Passwords are not stored in the clear. - Continue reading. A first-party cookie remembers story slugs you opened on this browser so the homepage can offer them again. It is not a view-count and is not used for advertising.
- Sign-in session. After a successful desk login, Auth.js sets a session cookie so you stay signed in for a limited time.
- Cookie preferences. If you allow or decline analytics or advertising, that choice is stored in a first-party cookie so the site can honor it on later visits.
- Appearance. Light or dark theme is stored in your browser (local storage), not as an advertising cookie.
Optional analytics and advertising
The site includes dormant hooks for measurement and ads. They do not run unless an operator configures them and, by default, you allow that category on the cookie policy.
This deployment has an analytics provider configured. The measurement script loads only after analytics consent is granted, unless an operator has turned that requirement off after their own legal review. When it does run, the magazine sends page path, page kind, story or category slugs, search usage without the typed query, and reading milestones. It does not send email addresses, names, or desk credentials.
Google AdSense is a dormant framework. Until a publisher ID and slot IDs are configured, this site does not load the AdSense script and does not show advertising units.
Naming Google, or any other vendor, in this draft is not a completed processor list. Add each vendor, the data they receive, the location of processing, and the lawful basis that applies to your readers before you enable those tools.
What we do not do in this prototype
- We do not take payments or store card numbers.
- We do not sell mailing lists or reader profiles.
- We do not run a public account sign-up for readers.
- We do not show test advertisements or invented earnings figures.
How long we keep information
Retention periods must be filled in for the live service. As a starting description of this prototype: newsletter rows remain until you ask to be removed or the operator deletes the list; desk sessions expire after the configured session lifetime (eight hours unless changed); the continue-reading cookie lasts thirty days; cookie preferences last up to one year.
Your choices
You can allow or decline optional analytics and advertising on the cookie preferences panel. Declining does not hide stories. Essential cookies for desk sign-in and continue-reading stay on.
To ask about the newsletter, a desk account, or a copy or deletion request, use the privacy mailbox on the contact page. Those addresses are placeholders until a real inbox is connected.
Jurisdictions and compliance
Privacy rules differ by location. A single policy and a pair of on/off controls do not automatically satisfy GDPR, UK GDPR, CCPA/CPRA, or any other regime. The operator of this site must identify where readers are, what the lawful bases are, whether a representative or DPO is required, and whether a certified consent platform is needed. This page does not claim that work is done.
Contact
Privacy questions (placeholder): privacy@storyvault.example
General (placeholder): hello@storyvault.example