Privacy
What Sagapic stores, and what it does not.
Draft, for review. This page was written from what the software
actually does, not from a template. It has not been reviewed by a lawyer and it is not
legal advice.
If you never sign in
You can read the free chapters without an account. We set no cookies. Our access log
records the method, path, status, duration and a trace id for each request — not your IP
address and not your browser's user agent.
Your own browser keeps four values and nothing else: your sign-in token, your chosen
edition, your content rating, and whether videos play continuously. Clearing this site's
data removes all four and signs you out.
If you make an account
An account is an email address and a password. The password itself is never stored — what
is stored is an argon2id hash of it, salted per account. We ask for nothing else: no name,
no phone number, no date of birth.
What is stored as you read
- Reading progress
- The highest chapter you have reached in each story, so you can continue on another
device. It only ever moves forward.
- Subscription state
- Whether a subscription is active, which plan, and when the paid period ends. Card
details never reach us; the payment provider holds those.
- Purchases
- Which stories you own outright, with the provider and its order id, so a refund can be
traced and a repeated webhook cannot charge you twice.
- Credits
- A balance and an append-only ledger of every movement, if you ever hold credits.
- Your shelf
- The stories you follow, and which chapters you have downloaded to a device. The
download record is what lets offline access be withdrawn when a subscription lapses.
- Preferences
- An opaque blob of client settings — edition, text size, autoplay, language. Nothing on
the server reads it.
If you report content or block someone
A report stores who filed it, what it points at, the reason you chose, your note if you
wrote one, and how it was resolved. A block stores who blocked whom. A report disclosing
self-harm is escalated ahead of the queue, and the note itself is never copied into our
analytics.
What we measure
Product events, from a fixed list declared in the code — a name that is not on that list
is rejected rather than stored. They carry your account id when you are signed in, and no
id when you are not. What they record:
- the app opening, the catalogue being viewed, a story being opened;
- a chapter opened, completed or abandoned, and which edition you were shown;
- your search terms, and how many results came back;
- the paywall shown and dismissed; checkout started, completed or failed;
- an account created, signed in or deleted; content reported; a user blocked.
Each event is timestamped and carries the trace id of the request that produced it, which
is how a number in a chart can be traced back to a real request. Events are not sold, and
no advertising script runs on this site — the content-security policy does not permit one
to load.
Google Analytics runs on this site. The page loads gtag.js from Google and sends it
the same product events described above — pages viewed, a story opened, a chapter opened
and how far through it you read. Google therefore sees your IP address and sets its own
identifiers. It is the only third-party script the content-security policy permits, and it
receives no email address, no payment detail and nothing you write in a report.
Who else sees anything
- Google Analytics, as described above.
- Typefaces: nobody. The fonts used to be loaded from Google, which meant your
browser contacted Google on every page and Google saw your IP address. They are now
served from this site, so that request no longer happens and the font hosts are not
permitted by the content-security policy at all.
- Payment providers. Whoever takes your money sees what they need to take it,
under their own privacy policy.
Deleting everything
Deleting an account erases the record and cascades to every subsystem holding data against
it. It is not a flag left on a row. It requires your password even though you are already
signed in, so a borrowed phone cannot end an account. The web reader does not yet have a
button for it — write to us and we will run it.
Children
The catalogue stays at Teen until you raise the rating yourself, and adult-rated stories
are left out of the sitemap entirely. Sagapic is not directed at children, and accounts are
not intended for anyone under 13.
Changes and questions
A material change will be dated at the top of this page. Questions go to the address on
the contact page.