Legal
Privacy policy
Last updated 19 July 2026
1.Who is responsible for your data
The Huld is operated by [legal entity name], [company registration number], [registered address]. We are the data controller for the personal data described in this policy.
For any question about your data, or to exercise the rights in section 8, contact us at [privacy@ contact address].
2.What we collect if you don't have an account
Browsing the catalogue requires no account and no personal data. We do not run analytics, we do not fingerprint your browser, and we do not embed advertising or social media trackers.
Two things are stored locally in your browser and are never transmitted to our servers:
- Your chosen theme. Stored so the site doesn’t flash the wrong colours on your next visit.
- Your reading position for character pages. This is what powers the spoiler gate — it stays on your device so we never need to know how far into a book you are.
You can clear both at any time through your browser’s site data settings.
3.What we collect if you vote
If you rate a book’s spice level or agree with a trope tag without being signed in, we set a cookie called hvid containing a random identifier. We never store that identifier itself — we store a keyed hash of it, so a vote can be tied to the same browser without being tied to you.
Its purpose is integrity: without it, a single person could vote the same book a thousand times. It is not used for profiling, and it is not shared with anyone.
4.What we collect if you create an account
Accounts are optional. If you create one, we process:
- Your email address. Used to sign you in — we send a single-use link rather than asking you to invent another password.
- Your reading activity. The shelf status you set on a book (want to read, reading, read, did not finish) and any rating you give it.
- A record of changes to that activity, so features that depend on history rather than current state can work correctly.
Reviewer and administrator accounts additionally have a password, stored only as a bcrypt hash. We never store passwords in a readable form.
5.Cookies and local storage in full
- hvid — voting integrity
- Set only when you cast a vote, never on an ordinary page view. Contains a random value; we store only a keyed hash of it. Expires after 400 days. HttpOnly.
- huld_session — signed-in session
- Set only when you sign in. Contains a signed token identifying your account and role. Expires after 12 hours. HttpOnly.
- huld-theme — local storage
- Your chosen colour theme. Stays in your browser; never sent to us.
- huld-read:… — local storage
- Your reading position per character, powering the spoiler gate. Stays in your browser; never sent to us.
There are no other cookies. We use no analytics, advertising, or third-party tracking cookies of any kind. Because everything above is either strictly necessary for a function you actively requested or stored only on your own device, we do not show a consent banner — but we do tell you plainly what happens, which is what this section is for.
6.Why we're allowed to process it
Under the GDPR, our legal bases are:
- Performance of a contract (Article 6(1)(b)) — for your email address and reading activity. You asked us to keep a shelf; we cannot do that without storing it.
- Legitimate interests (Article 6(1)(f)) — for the voting identifier. Our interest is keeping community ratings honest, and the impact on you is minimal because the identifier is random and hashed.
7.Who else sees your data
We do not sell your data, and we do not share it for advertising.
Your data is processed on our behalf by:
- Amazon Web Services — hosts our database and application servers in the EU (Ireland), and sends your sign-in email. Your email address is the only personal data that leaves our systems.
- Vercel — serves the website itself.
One thing worth stating plainly, because it isn’t obvious: book cover images are loaded directly from Hardcover, our bibliographic data source. That means your browser contacts their servers when a cover appears on screen, and your IP address and browser type are visible to them in the process — as with any image loaded from another site. We do not send them anything about you beyond that.
8.How long we keep it
- Sign-in links are deleted the moment they are used. Unused ones stop working after 15 minutes and are cleared shortly afterwards, so an email address never lingers in a link that no longer works.
- Account data and reading activity are kept until you delete your account. Deletion is immediate and complete — your email address, shelf, ratings, and the record of changes to them are all removed in one go, not flagged as hidden.
- Voting records are kept as long as the rating remains meaningful. They are not linked to your identity, and any that were tied to your account are removed with it.
9.Your rights
If you are in the EU or EEA, you have the right to access, correct, delete, export, or restrict our use of your personal data, and to object to processing based on legitimate interests. Where processing relies on your consent, you may withdraw it at any time.
To exercise any of them, write to [privacy@ contact address] and we will respond within one month. Deletion, when you ask for it, is immediate and complete rather than a flag that hides your data — see section 8.
If you believe we have handled your data improperly, you may complain to your national supervisory authority — in Sweden, that is Integritetsskyddsmyndigheten (IMY).
10.Transfers outside the EU
Our database and application servers are in the EU (Ireland). Our hosting provider operates a global network, which can mean data is processed outside the EU in the course of serving pages. [confirm transfer mechanism — standard contractual clauses with Vercel and AWS]
11.Changes to this policy
If we change how we handle your data, we will update this page and its date. If the change is significant and we have your email address, we will tell you directly rather than relying on you to notice.