Privacy Policy
Last updated: 2026-09-25. Version 1.0.
1. Who is responsible
The controller for the processing described here, within the meaning of Article 4(7) GDPR, is:
Mateu Gili
Spain
contact@novelscraper.com
A postal address is not published. Every right described in section 8 can be exercised by email, which is answered. If a supervisory authority or a court requires an address, it will be provided to them on request.
No data protection officer has been appointed. The processing described here is small in scale, is not systematic monitoring, and involves no special categories of data, so Article 37 GDPR does not require one. This is reassessed if that changes.
2. The short version
NovelScraper is an app that runs on your own device. It keeps your library, your novels and your reading position on that device. You can use all of it without an account and without this service ever seeing anything.
An account does exactly one thing: it copies a small amount of information about your library between your own devices, so they agree on what you are reading and where you are. That is the only reason this service holds any data about you.
We do not sell data, do not show advertisements, use no analytics, and embed no third-party trackers.
3. What is processed, and why
3.1 If you never create an account
Nothing is stored about you, and the app does not phone home: it holds no identifier that would let this service recognise a device.
One request is made without an account, and only if you go looking for one. When you open the registration screen, the app asks this service whether signing up needs an invite code, so it knows which fields to show. That request carries no identifier and nothing is recorded from it beyond what section 3.4 describes.
3.2 Your account
| Data | Why | Legal basis |
|---|---|---|
| Username you choose | To identify your account at sign-in | Art. 6(1)(b) GDPR, performance of a contract |
| Password, stored only as a scrypt hash | To let you sign in. The password itself is never stored and cannot be recovered from the hash | Art. 6(1)(b) |
| Session records: a SHA-256 hash of the session token, creation and expiry time | To keep you signed in. Only the hash is stored, so a copy of the database cannot be replayed as a login | Art. 6(1)(b) |
| Invite code, where one is required and used, and which account used it | To limit who can register during any period when registration is closed, and to stop a code being used twice. While registration is open no invite is asked for and none is recorded | Art. 6(1)(f), legitimate interest in preventing abuse |
No email address, real name, telephone number, date of birth or payment information is requested or stored. If you lose your password it cannot be reset by email, because we have no email address for you.
3.3 What your devices sync
While signed in, your devices exchange small records describing your library. Each record is a key and a value, with a timestamp and a random identifier for the device that wrote it. Taken together they describe:
- which novels are in your library, named by the source extension they are read from and the novel’s address within that source;
- each novel’s title, author and cover address as the source reported them;
- your position in each novel, to the sentence, and which chapters you have read;
- your own ordering, ratings, and the categories you have made;
- which source extensions you have installed, and the address of the repository each came from;
- a random identifier for each of your devices, created by the app, which contains nothing about the device itself.
Legal basis: Art. 6(1)(b) GDPR. This is the service you asked for.
Two things worth being plain about:
- The content of a novel is never sent to this service. No chapter text, no images, no files. The service stores references, not books.
- A book you import from an EPUB file stays on the device you imported it on. It is deliberately excluded from syncing, so neither this service nor your other devices receive it or learn of it.
The server does not interpret the values in these records. It validates that a value is well-formed and within a size limit, and stores it exactly as your device sent it.
3.4 Server logs
Two things write logs, and only one of them can see you.
The application records a line for every request it answers: the time, what was asked for, and the result. The address it records is not yours. Requests reach it through the web server in front, so what it sees and logs is that server’s internal address, the same one for everybody.
The web server records errors, and an error entry can include the real IP address of the request, what was asked for, and the time. Successful requests are not logged there, so in normal use your address is written nowhere.
IP addresses are personal data, and they are processed on the basis of Art. 6(1)(f) GDPR: the legitimate interest in keeping the service available and diagnosing faults and abuse.
4. How long it is kept
| Data | Retention |
|---|---|
| Account, and everything synced under it | Until you delete it, which you can do yourself from Settings at any time. Deletion is immediate and complete: sync records and sessions go with the account |
| Sessions | 30 days, extended while in use. Signing out deletes the session at once |
| Server logs containing IP addresses | Until they are rotated out, which at current volumes is a matter of days, and never more than 30 MB per service. See the note below the table |
| Invites | Until used or expired, and then until an administrator clears them |
| Backups | None are taken. If the server is lost, so is everything on it, which is another reason the library lives on your devices rather than here |
Log rotation here is by size, not by time: each service keeps at most three files of 10 MB, and the oldest is discarded when a new one is needed. There is therefore no fixed number of days, and none is claimed. In practice this service logs only errors, so the volume is small and a line survives days rather than weeks; a burst of errors would shorten that, not lengthen it.
A time-based limit would be a better fit for what the law asks about, and is worth doing if logging ever grows. Until then, an honest description of a size cap is preferred to a number of days that nothing enforces.
5. Who else sees it
The hosting provider. The service runs on a rented server. The provider is established in the European Union and the server is located in Nuremberg, Germany, so your account and everything synced under it stay in the EU. The provider acts as a processor under Art. 28 GDPR and is bound by a written data processing agreement; it does not use the data for its own purposes. Its identity is available on request to anyone with a reason to ask, and to any supervisory authority.
The email provider. Mail sent to the address in this policy is handled by Proton AG, which operates in Switzerland. Anything you write to us is therefore processed there: your address, what you asked, and whatever you chose to include. Proton acts as a processor for that correspondence.
Switzerland sits outside the EEA, but the European Commission has decided it offers an adequate level of protection, so no further safeguard is needed for this. Nothing else about the service touches it: the sync data never leaves the EU, and an email you never send is an email nobody handles.
Nobody else. No data is sold, shared, or disclosed to advertisers or analytics providers. Data is disclosed to public authorities only where a legal obligation requires it.
5a. If you donate
Donations are not solicited or accepted on this site. There is no donation button, form or widget here, and nothing on these pages is loaded from a payment platform.
If you choose to donate, it happens on GitHub Sponsors or Ko-fi, reached from the project’s source repository, entirely outside this site. No payment ever passes through this service, and no card number, bank detail or billing address is seen by it or stored here.
The platform is a separate controller for what it collects from you, under its own privacy policy and its own terms, which you should read before donating. It then passes on a limited amount: typically the name or alias you donated under, the amount, the date, and any message you chose to attach. That information is received in order to acknowledge the donation and to keep the accounting records that tax law requires.
Legal basis: Art. 6(1)(b) GDPR for handling the donation itself, and Art. 6(1)(c) for keeping the records the law obliges. Those records are kept for four years, the general limitation period for tax matters in Spain, which is longer than anything else described here.
Donating is not connected to your account in any way. It buys nothing, grants no access, unlocks no feature, and is not recorded against any username. If you donate and also hold a sync account, the two are not linked.
6. What the app contacts on your device
These are connections your own device makes. They do not pass through this service, and it does not learn of them. They are described here so you know what the app does.
- Update checks. The app asks GitHub whether a newer version has been released, and downloads releases from GitHub. This discloses your IP address to GitHub, Inc. (United States) and its content delivery network. You can avoid this by not using the in-app update check.
- Voice downloads. Narration voices are downloaded from GitHub in the same way, once, when you choose to install one. Narration itself then runs on your device; no text is sent anywhere to be spoken.
- Source extensions and the sites they read. The app ships with no sources and no repositories. If you add a repository and install a source, your device fetches from the address you gave it, and then connects directly to the novel’s website to read it. Those sites see your IP address and set their own cookies, and their own privacy policies apply. This service is not involved in those connections and receives nothing from them.
7. Cookies
The service itself sets one cookie, ns_session. It holds an opaque session
token, is marked HttpOnly and Secure, and exists only to keep you signed in.
It is strictly necessary to provide a service you have asked for, so under
Article 22.2 of Law 34/2002 (LSSI-CE) it needs no consent.
That is the only one. No advertising, analytics, profiling or tracking cookies. No pixels, no fingerprinting, no cross-site identifiers. No third-party code of any kind runs on these pages, which is a deliberate choice: nothing here is embedded from anywhere else, so nothing else can set a cookie or see that you visited.
That is also why you are not asked to agree to anything. A consent banner exists to obtain permission for cookies that are not strictly necessary, and there are none to ask about.
8. Your rights
Under Articles 15 to 22 GDPR you may ask for:
- access to the data held about you, and a copy of it;
- rectification of anything inaccurate;
- erasure, which for an account is immediate and total;
- restriction of processing;
- portability, in a structured, commonly used, machine-readable form;
- objection to processing based on legitimate interests (Art. 21).
Write to contact@novelscraper.com. You will receive an answer within one month, extendable by two further months for complex requests, in which case you will be told why. Exercising these rights is free unless a request is manifestly unfounded or excessive.
Deleting your account. Settings, under Server account, has a Delete account button. It asks for your password again, because a session left open somewhere should not be enough to destroy an account, and then deletes the account together with every sync record and session held under it, at once and for good. You can also ask at contact@novelscraper.com if you would rather.
Nothing on your own devices is touched: your library stays where it is and goes on working without an account. Your other devices keep what they already have and stop syncing.
Complaints. Under Art. 77 GDPR you may complain to a data protection supervisory authority, in particular the one where you live, where you work, or where you believe the infringement happened. It is your location that decides this, not where the service or its server is.
The authority for the controller is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es. You may complain there whatever country you are in.
If you would rather complain in your own country, the European Data Protection Board publishes the list of national authorities at edpb.europa.eu.
9. Security
Passwords are hashed with scrypt, from the Python standard library, never stored
in plain text and never recoverable. Session tokens are random and stored only as
SHA-256 hashes. All traffic is served over HTTPS; certificates renew
automatically. The session cookie is HttpOnly and Secure. The database is
reachable only from the application, never from the internet.
This is a small service run by an individual. It is not certified to any security standard, and no service can promise it will never be breached. If a breach occurs that is likely to result in a risk to your rights and freedoms, the supervisory authority will be notified within 72 hours under Art. 33 GDPR and you will be told directly where Art. 34 requires it.
10. Children
The service is not directed at children and no account is knowingly created for a child under 14. Because no age or identifying information is collected, age cannot be verified. If you believe a child’s data is held here, write to contact@novelscraper.com and it will be deleted.
11. Changes
Material changes will be announced on this page and in the application’s release notes before they take effect, and the version and date at the top will change. Continuing to use an account after a change takes effect indicates acceptance of the updated policy; if you do not accept it, ask for your account to be deleted.