Legal
Last updated: September 2026
Inkrune (“Inkrune”, “we”, “us”, or “our”) is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information. It applies to all users of the Inkrune platform (“Platform”) and reflects our commitment to applicable data-protection laws.
By using the Platform, you consent to the collection and use of your information as described in this Policy. If you do not agree with this Policy, please do not use the Platform.
We serve users globally. Where international data transfers occur, we apply appropriate safeguards to protect your data consistent with applicable law.
Account Information: When you register, we collect your name, email address, and authentication data (OAuth tokens via Google Sign-In). Authors who want to receive payouts additionally provide identity-verification (KYC) details and bank account details for payout configuration.
Reading Data: We record your reading history (which chapters you have read, when, and how long you spent on each) to power your shelf, reading progress, and our recommendation engine. This data is pseudonymised and linked to your account ID.
Payment Information: Reader payments are handled by our third-party payment processors. We never see or store card numbers, only the tokenised payment method references and transaction records the processor returns.
Author Bank Details: Bank details (account holder, bank name, account number, IBAN, routing, SWIFT or local bank codes) are collected only from authors who opt in to payouts, and only for the purpose of paying you. Account numbers, IBANs and routing/SWIFT/bank codes are stored encrypted at rest using application-layer encryption (AES-256-GCM, with a key held separately from the database) and are only ever displayed in masked form (for example “•••• 1234”), to you and to our own staff alike.
Usage Data: We collect standard web analytics data including IP address, browser type, operating system, pages viewed, and referral URLs. This is used in aggregate to improve the Platform.
Content: Authors' submitted stories, chapter text, and profile information are stored as part of the service.
To provide and operate the Platform: authenticating your identity, delivering chapter content, tracking subscription status, and enabling the shelf and reading history features.
To improve the Platform: analysing usage patterns, diagnosing bugs, and developing new features.
To power AI features: your reading history informs personalised recommendations. Chapter content submitted by authors is processed by our AI pipeline to generate recaps, lore codices, and relationship maps. We do not use your personal data to train external AI models.
To process payments and send billing communications: invoices, subscription renewal notices, and payout confirmations.
To communicate with you: important service updates, policy changes, and responses to your support queries. We do not send unsolicited marketing emails without your explicit opt-in.
We do not sell your personal data to third parties.
Payment Processors: We share payment-related data with our payment processors solely for the purpose of processing transactions. Each maintains its own privacy policy and is bound by industry-standard PCI-DSS compliance requirements.
Infrastructure Providers: Your data is hosted on reputable cloud infrastructure. These providers process data only on our instructions and under data processing agreements that comply with applicable law.
AI Model Providers: Chapter content may be processed by third-party large language model APIs (such as OpenAI, Anthropic, and Google) for AI feature generation. Processing is governed by our agreements with these providers. We do not share user account or reading data with AI model providers.
Legal Requirements: We may disclose information if required by law, court order, or government authority, or to protect the rights, property, or safety of Inkrune, our users, or the public.
Account data is retained for as long as your account is active.
When you delete your account, the following is removed immediately, in a single operation: your name, email address, avatar and Google sign-in link are erased from your account record; your profile, reading history and progress, shelves and bookmarks, notifications and notification preferences are deleted; any bank account and identity-verification (KYC) details are deleted; and your account identifier is removed from search logs while both your account identifier and visitor identifier are removed from analytics events. If you have an active paid subscription it is cancelled with the payment provider before deletion proceeds (any remaining paid period is forfeited), and deletion does not go ahead if that cancellation fails. Your previous sign-in can no longer access the account.
Some records are retained after deletion because we are required to keep them: invoices, transactions, subscription records, coin purchases and author payout records are kept for accounting, tax and dispute-resolution purposes (typically 7 years under applicable accounting rules), and moderation and security audit logs are kept so we can enforce our Terms and investigate abuse. These records reference your former account only by an internal identifier and are not used for any other purpose.
Comments, reviews and ratings you posted remain on the Platform but are shown as authored by “Deleted user”. Author-published content (novels and chapters) may remain on the Platform after account deletion if it is subject to active reader subscriptions; in such cases, authorship attribution is removed and the content is anonymised.
Subject to applicable data-protection law, you have the following rights regarding your personal data:
Right of Access: You may request a copy of the personal data we hold about you.
Right to Correction: You may request that we correct inaccurate or incomplete personal data.
Right to Erasure: You may request deletion of your personal data, subject to our legal retention obligations.
To exercise any of these rights, contact us at privacy@inkrune.in. We will respond within 30 days. We may request identity verification before processing your request.
We implement industry-standard security measures including TLS encryption for data in transit, application-layer encryption for author bank details at rest (see Information We Collect), regular security audits, and role-based access controls to limit data access within our team.
We use JWT-based authentication with short-lived access tokens and rotating refresh tokens. Passwords are never stored; we use OAuth-only authentication (Google Sign-In).
No system is completely secure. If you discover a security vulnerability, please report it responsibly to security@inkrune.in before public disclosure.
In the event of a data breach that is likely to result in risk to your rights and freedoms, we will notify affected users and the appropriate data protection authority as required by law.
For any privacy-related questions, data subject requests, or concerns, please contact our Privacy team at privacy@inkrune.in.
For general support, contact support@inkrune.in.