1. Who We Are
Fictify (“we”, “us”, “our”) operates the Fictify mobile application and website (fictify.app). We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. What Data We Collect
We collect the following categories of personal data:
- Account data: email address, display name, age group, date of birth
- Reading data: stories read, reading progress, reactions, followed series and creators
- Subscription data: plan type, payment status, trial dates
- Creator data: pen name, bio, genre specialities, earnings (for creator accounts)
- Analytics data: app usage events (only with your explicit consent)
- Technical data: device type, app version, push notification tokens
3. How We Use Your Data
- Provide and personalise the reading experience (story recommendations, progress saving)
- Process subscriptions and creator payouts
- Send notifications about new stories and series updates (with your consent)
- Moderate content for safety and community guidelines
- Improve our product through anonymised analytics (with your explicit consent)
4. Legal Basis for Processing
- Contract: providing the service you signed up for
- Consent: analytics tracking, marketing communications
- Legitimate interest: fraud prevention, content moderation, service improvement
- Legal obligation: age verification, COPPA compliance
5. Analytics & Cookies
We use PostHog for analytics, which is GDPR-compliant. Analytics data is only collected after you give explicit consent. You can withdraw consent at any time via your Privacy & Data settings. We use essential cookies for authentication and session management. Non-essential analytics cookies require your consent.
6. Children's Privacy (COPPA)
We take children's privacy seriously. Users who indicate they are under 13 will never have analytics enabled, regardless of consent settings. Content is filtered based on age group to ensure age-appropriate material. We do not knowingly collect more data than necessary from users under 13.
7. Data Sharing
We do not sell your personal data. We share data only with:
- Supabase: database and authentication hosting (EU region)
- Stripe: payment processing for subscriptions and creator payouts
- PostHog: analytics (EU hosting, only with consent)
- Apple/Google: in-app purchase processing
8. Your Rights
Under UK GDPR, you have the right to:
- Access: request a copy of your personal data (via Export My Data)
- Rectification: correct inaccurate data via your profile settings
- Erasure: request deletion of your account and data
- Restriction: limit how we process your data
- Portability: receive your data in a structured, machine-readable format
- Withdraw consent: for analytics and marketing at any time
9. Data Retention
We retain your data for as long as your account is active. If you request deletion, we anonymise your data within 30 days and permanently remove it within 90 days. Creator content and associated earnings records may be retained longer for legal and tax purposes.
10. Contact Us
For privacy enquiries or to exercise your rights, contact us at privacy@fictify.app.