Privacy Policy

1. Who We Are

The Service is operated by us ("we", "us", "our"), and for the purposes of the personal data covered by this policy we are the data user / controller.

This policy applies to the Shansu Fiction website (books.shansu.com) and the Shansu Fiction app.

2. What We Collect

2.1 Account data

Collected when you register and sign in: email address, password (stored as a hash — we do not keep plaintext passwords) and nickname. You may optionally add an avatar and gender. Verification codes for registration and password recovery are sent to your email address.

2.2 Reading and usage data

Bookshelf entries, reading history, reading progress (the chapter you are on and your position within it), and records of the books you browse and click. This data is used to show you "continue reading", to sync progress across devices, and to compile popularity statistics.

2.3 App bookshelf sync data

If you sign in to the app and use bookshelf sync, we upload your bookshelf entries to the server, including: book title, author, cover information, chapter title, chapter number and in-chapter reading position, and update time.

Please note the following about local TXT files: for a local file you open in the app, the text itself always stays on your device and is never uploaded to our servers. However, if you add that local file to a bookshelf that syncs, the entry’s title, author and reading progress will be uploaded along with the bookshelf so that your reading position can be restored on your other devices. If you would rather that information did not leave your device, do not add the book to a syncing bookshelf, or turn off bookshelf sync in settings.

2.4 Device and log data

When you use the Service, our servers automatically record: IP address, browser and operating system information (User-Agent), time of access, and the address of the page accessed. App requests also carry a device identifier, the client platform and the client version. This data is used to keep the Service secure, to diagnose faults and to prevent abuse.

2.5 Content you submit

Comments, feedback messages and works submitted through the author area. When you post a comment, we record and display the location inferred from your IP address (to province or country level), which helps reduce impersonation and spam.

2.6 Transaction data

Top-up and spending records, and virtual currency balance. We do not collect or store your card numbers, payment passwords or other payment credentials — those are handled directly by third-party payment channels.

3. Content Watermarking

To deter bulk scraping and unauthorised republication, we embed a marker that is invisible to the eye in the chapter text shown to you. The marker encodes your account identifier (or, if you are not signed in, a random client identifier held in your browser) together with the time of access to the minute.

About this technique, we want to be explicit:

  • its only purpose is to trace the source of a leak when content is found to have been republished at scale;
  • it is not used for advertising, profiling or any form of behavioural analysis;
  • it does not affect normal reading, copying, in-page search or screen readers;
  • pages crawled by search engines do not carry the marker.

4. How We Use This Data

  • to provide account registration, sign-in and authentication;
  • to provide core features such as reading, bookshelves and progress sync;
  • to process top-ups and the unlocking of paid chapters;
  • to display and moderate the comments and submissions you post;
  • to keep the Service secure: detecting abnormal access, applying rate limits, and preventing scraping and account theft;
  • to compile statistics on the popularity of works and on overall usage, in order to improve the product;
  • to reach you where necessary about changes to the Service, security incidents or enquiries you have raised;
  • to meet obligations under applicable law.

5. Third-Party Services and Sharing

We do not sell your personal data. It is processed by third parties only in the following cases:

  • Google Analytics (Google LLC): used to measure website traffic. It collects information such as pages viewed, time spent, approximate location and device type through cookies. You can install Google’s browser add-on to opt out, or refuse the relevant cookies in your browser.
  • Email providers: used to send you registration and password-recovery codes, and therefore see your email address.
  • Third-party payment channels: used to process top-ups, and therefore see the transaction information required.
  • AI service providers: we call external AI services when generating assets such as book covers. That process involves book information only, not your personal data.
  • Disclosure required by law: we may disclose data where the law requires it, where a judicial or administrative authority requests it through due process, or where it is necessary to protect the vital interests of others.

6. Cookies and Local Storage

We use the following cookies and browser local storage:

  • Sign-in credentials: to keep you signed in;
  • Client identifier: a random string used to distinguish visitors and compile statistics;
  • Access verification identifier: used to recognise genuine browser traffic and resist automated scraping;
  • Reading preferences: theme, font size, line spacing, page width and reading position — held only in your browser and never uploaded;
  • Analytics cookies: set by Google Analytics.

You can clear or refuse cookies in your browser, but doing so may break features such as staying signed in and remembering reading preferences.

7. Storage and Cross-Border Transfers

Your data is held on servers operated by us and by our cloud providers. Because our users are spread across many countries and regions, your data may be transferred to, and processed and stored in, a region other than the one you are in. We take reasonable steps to ensure such transfers receive protection equivalent to that described in this policy.

8. Retention

  • Account data: kept until you close your account. After closure we delete or anonymise your personal data, except where the law requires us to retain it.
  • Reading records and bookshelves: kept until you delete the relevant records or close your account.
  • Comments and submissions: no longer displayed once deleted; copies in system backups are overwritten within the backup rotation cycle.
  • Access logs: generally kept for no more than 6 months, for security investigation.
  • Transaction records: kept for the statutory period required to meet financial and legal obligations.

9. Your Rights

To the extent permitted by applicable law, you may exercise the rights below. Please raise a request through the feedback function on the site; we will respond within a reasonable period after verifying your identity.

  • Access and correction: you may access the personal data we hold about you and ask us to correct anything inaccurate. Some of it can be changed directly in your account settings.
  • Deletion and closure: you may ask us to delete your personal data or close your account.
  • Withdrawing consent: you may withdraw consent previously given at any time. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before it was withdrawn.

If you are in the European Economic Area or the United Kingdom, you also have the rights conferred by the General Data Protection Regulation (GDPR), including restriction of processing, objection to processing, data portability, and the right to lodge a complaint with your local data protection authority.

If you are a California resident, you also have the rights conferred by the California Consumer Privacy Act (CCPA / CPRA), including the right to know the categories and purposes of the data collected, the right to request deletion, and the right not to be discriminated against for exercising your rights. We do not sell or "share" your personal data.

If you are in the Hong Kong Special Administrative Region, you may exercise the rights of access and correction under the Personal Data (Privacy) Ordinance.

10. Minors

The Service is intended only for users aged 18 or over, and we do not knowingly collect personal data from anyone under 18. If we find that data has been submitted by a minor, we will delete it as soon as possible. If you are a guardian and discover that someone in your care has used the Service, please let us know through the feedback function on the site.

11. Security

We take reasonable technical and organisational measures to protect your data, including: HTTPS encryption across the site, storing passwords as hashes rather than plaintext, rate limiting on our interfaces, and access control on administrative entry points.

Please understand, however, that no method of transmission or storage over the internet is completely secure. We keep improving our safeguards, and if a data breach occurs that may affect your rights, we will notify you and the relevant regulators as applicable law requires.

12. Changes to This Policy

We may update this policy from time to time. The updated version will be published on this page with a revised date. Significant changes affecting your rights will be announced on the site or through in-app notices.

For the rules governing use of the Service, please see the Terms of Service.