NovelScraper
← Back to NovelScraper

Privacy Policy

Last updated: 2026-09-25. Version 1.0.

1. Who is responsible

The controller for the processing described here, within the meaning of Article 4(7) GDPR, is:

Mateu Gili
Spain
contact@novelscraper.com

A postal address is not published. Every right described in section 8 can be exercised by email, which is answered. If a supervisory authority or a court requires an address, it will be provided to them on request.

No data protection officer has been appointed. The processing described here is small in scale, is not systematic monitoring, and involves no special categories of data, so Article 37 GDPR does not require one. This is reassessed if that changes.

2. The short version

NovelScraper is an app that runs on your own device. It keeps your library, your novels and your reading position on that device. You can use all of it without an account and without this service ever seeing anything.

An account does exactly one thing: it copies a small amount of information about your library between your own devices, so they agree on what you are reading and where you are. That is the only reason this service holds any data about you.

We do not sell data, do not show advertisements, use no analytics, and embed no third-party trackers.

3. What is processed, and why

3.1 If you never create an account

Nothing is stored about you, and the app does not phone home: it holds no identifier that would let this service recognise a device.

One request is made without an account, and only if you go looking for one. When you open the registration screen, the app asks this service whether signing up needs an invite code, so it knows which fields to show. That request carries no identifier and nothing is recorded from it beyond what section 3.4 describes.

3.2 Your account

Data Why Legal basis
Username you choose To identify your account at sign-in Art. 6(1)(b) GDPR, performance of a contract
Password, stored only as a scrypt hash To let you sign in. The password itself is never stored and cannot be recovered from the hash Art. 6(1)(b)
Session records: a SHA-256 hash of the session token, creation and expiry time To keep you signed in. Only the hash is stored, so a copy of the database cannot be replayed as a login Art. 6(1)(b)
Invite code, where one is required and used, and which account used it To limit who can register during any period when registration is closed, and to stop a code being used twice. While registration is open no invite is asked for and none is recorded Art. 6(1)(f), legitimate interest in preventing abuse

No email address, real name, telephone number, date of birth or payment information is requested or stored. If you lose your password it cannot be reset by email, because we have no email address for you.

3.3 What your devices sync

While signed in, your devices exchange small records describing your library. Each record is a key and a value, with a timestamp and a random identifier for the device that wrote it. Taken together they describe:

Legal basis: Art. 6(1)(b) GDPR. This is the service you asked for.

Two things worth being plain about:

The server does not interpret the values in these records. It validates that a value is well-formed and within a size limit, and stores it exactly as your device sent it.

3.4 Server logs

Two things write logs, and only one of them can see you.

The application records a line for every request it answers: the time, what was asked for, and the result. The address it records is not yours. Requests reach it through the web server in front, so what it sees and logs is that server’s internal address, the same one for everybody.

The web server records errors, and an error entry can include the real IP address of the request, what was asked for, and the time. Successful requests are not logged there, so in normal use your address is written nowhere.

IP addresses are personal data, and they are processed on the basis of Art. 6(1)(f) GDPR: the legitimate interest in keeping the service available and diagnosing faults and abuse.

4. How long it is kept

Data Retention
Account, and everything synced under it Until you delete it, which you can do yourself from Settings at any time. Deletion is immediate and complete: sync records and sessions go with the account
Sessions 30 days, extended while in use. Signing out deletes the session at once
Server logs containing IP addresses Until they are rotated out, which at current volumes is a matter of days, and never more than 30 MB per service. See the note below the table
Invites Until used or expired, and then until an administrator clears them
Backups None are taken. If the server is lost, so is everything on it, which is another reason the library lives on your devices rather than here

Log rotation here is by size, not by time: each service keeps at most three files of 10 MB, and the oldest is discarded when a new one is needed. There is therefore no fixed number of days, and none is claimed. In practice this service logs only errors, so the volume is small and a line survives days rather than weeks; a burst of errors would shorten that, not lengthen it.

A time-based limit would be a better fit for what the law asks about, and is worth doing if logging ever grows. Until then, an honest description of a size cap is preferred to a number of days that nothing enforces.

5. Who else sees it

The hosting provider. The service runs on a rented server. The provider is established in the European Union and the server is located in Nuremberg, Germany, so your account and everything synced under it stay in the EU. The provider acts as a processor under Art. 28 GDPR and is bound by a written data processing agreement; it does not use the data for its own purposes. Its identity is available on request to anyone with a reason to ask, and to any supervisory authority.

The email provider. Mail sent to the address in this policy is handled by Proton AG, which operates in Switzerland. Anything you write to us is therefore processed there: your address, what you asked, and whatever you chose to include. Proton acts as a processor for that correspondence.

Switzerland sits outside the EEA, but the European Commission has decided it offers an adequate level of protection, so no further safeguard is needed for this. Nothing else about the service touches it: the sync data never leaves the EU, and an email you never send is an email nobody handles.

Nobody else. No data is sold, shared, or disclosed to advertisers or analytics providers. Data is disclosed to public authorities only where a legal obligation requires it.

5a. If you donate

Donations are not solicited or accepted on this site. There is no donation button, form or widget here, and nothing on these pages is loaded from a payment platform.

If you choose to donate, it happens on GitHub Sponsors or Ko-fi, reached from the project’s source repository, entirely outside this site. No payment ever passes through this service, and no card number, bank detail or billing address is seen by it or stored here.

The platform is a separate controller for what it collects from you, under its own privacy policy and its own terms, which you should read before donating. It then passes on a limited amount: typically the name or alias you donated under, the amount, the date, and any message you chose to attach. That information is received in order to acknowledge the donation and to keep the accounting records that tax law requires.

Legal basis: Art. 6(1)(b) GDPR for handling the donation itself, and Art. 6(1)(c) for keeping the records the law obliges. Those records are kept for four years, the general limitation period for tax matters in Spain, which is longer than anything else described here.

Donating is not connected to your account in any way. It buys nothing, grants no access, unlocks no feature, and is not recorded against any username. If you donate and also hold a sync account, the two are not linked.

6. What the app contacts on your device

These are connections your own device makes. They do not pass through this service, and it does not learn of them. They are described here so you know what the app does.

7. Cookies

The service itself sets one cookie, ns_session. It holds an opaque session token, is marked HttpOnly and Secure, and exists only to keep you signed in. It is strictly necessary to provide a service you have asked for, so under Article 22.2 of Law 34/2002 (LSSI-CE) it needs no consent.

That is the only one. No advertising, analytics, profiling or tracking cookies. No pixels, no fingerprinting, no cross-site identifiers. No third-party code of any kind runs on these pages, which is a deliberate choice: nothing here is embedded from anywhere else, so nothing else can set a cookie or see that you visited.

That is also why you are not asked to agree to anything. A consent banner exists to obtain permission for cookies that are not strictly necessary, and there are none to ask about.

8. Your rights

Under Articles 15 to 22 GDPR you may ask for:

Write to contact@novelscraper.com. You will receive an answer within one month, extendable by two further months for complex requests, in which case you will be told why. Exercising these rights is free unless a request is manifestly unfounded or excessive.

Deleting your account. Settings, under Server account, has a Delete account button. It asks for your password again, because a session left open somewhere should not be enough to destroy an account, and then deletes the account together with every sync record and session held under it, at once and for good. You can also ask at contact@novelscraper.com if you would rather.

Nothing on your own devices is touched: your library stays where it is and goes on working without an account. Your other devices keep what they already have and stop syncing.

Complaints. Under Art. 77 GDPR you may complain to a data protection supervisory authority, in particular the one where you live, where you work, or where you believe the infringement happened. It is your location that decides this, not where the service or its server is.

The authority for the controller is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es. You may complain there whatever country you are in.

If you would rather complain in your own country, the European Data Protection Board publishes the list of national authorities at edpb.europa.eu.

9. Security

Passwords are hashed with scrypt, from the Python standard library, never stored in plain text and never recoverable. Session tokens are random and stored only as SHA-256 hashes. All traffic is served over HTTPS; certificates renew automatically. The session cookie is HttpOnly and Secure. The database is reachable only from the application, never from the internet.

This is a small service run by an individual. It is not certified to any security standard, and no service can promise it will never be breached. If a breach occurs that is likely to result in a risk to your rights and freedoms, the supervisory authority will be notified within 72 hours under Art. 33 GDPR and you will be told directly where Art. 34 requires it.

10. Children

The service is not directed at children and no account is knowingly created for a child under 14. Because no age or identifying information is collected, age cannot be verified. If you believe a child’s data is held here, write to contact@novelscraper.com and it will be deleted.

11. Changes

Material changes will be announced on this page and in the application’s release notes before they take effect, and the version and date at the top will change. Continuing to use an account after a change takes effect indicates acceptance of the updated policy; if you do not accept it, ask for your account to be deleted.