1. Introduction
Welcome to Vertex Reader ("we", "our", or "us"). Vertex Reader is an AI-powered manhwa discovery and reading platform that lets you track, read, and discover titles from community-managed sources.
This Privacy Policy explains what personal information we collect, how we use it, with whom we share it, and the choices you have. By creating an account or using the Service, you agree to the practices described here.
2. Data We Collect
Account Information
When you register, we collect your email address, display name, and a bcrypt-hashed password. If you complete your profile, we also store an optional bio and avatar image URL.
OAuth / Social Login
If you sign in with Google or Discord, we receive and store your provider account ID, access token, and refresh token. We use these solely to authenticate your session and do not use them to access your social account data beyond what you authorise at sign-in.
Session Data
Each session records your IP address, user agent (browser/OS string), and a cryptographically signed session token. Sessions are invalidated when you sign out or after inactivity.
Reading Activity
We store your library — the titles you add, their reading status (e.g. Reading, Completed, On Hold), per-chapter scroll position, timestamps of when chapters were read, ratings, and personal notes. We also maintain aggregate statistics: total chapters read and total time spent reading (in minutes).
Subscription & Billing
Payments are processed by Stripe. We store your Stripe customer ID, subscription ID, subscription tier (Free or Pro), subscription status, billing period start and end dates, and whether you have requested cancellation at period end. We never store raw card numbers or full payment instrument details.
Credits & Transactions
We maintain a credits ledger for each user recording the transaction type (e.g. Purchase, Monthly Grant, Source Creation, Chapter Summary), amount, resulting balance, timestamp, and — where applicable — the associated Stripe payment ID.
Notification Preferences
If you enable Telegram notifications, we store your Telegram bot token and chat ID. If you enable Discord notifications, we store your Discord webhook URL. These credentials are used exclusively to deliver chapter-update notifications you have opted into.
User-Provided LLM API Keys
You may optionally provide your own Anthropic or OpenAI API keys to power AI features on your account. These keys are encrypted at rest using AES-256 and are never exposed in API responses or logs.
3. How We Use Your Data
- Authentication & Account Management — to create, maintain, and secure your account and sessions.
- Reading Experience — to sync your library, track reading progress across devices, and surface personalised recommendations.
- Billing & Subscriptions — to process payments, manage subscription state, and issue credit grants through Stripe.
- Notifications — to send chapter-update alerts via your chosen channels (in-app, Telegram, Discord, or push).
- AI Features — to generate scraping strategies, produce chapter summaries, and power other AI-driven features using the credits system. Your user-provided API keys are used only for your own requests.
- Platform Integrity — to detect abuse, enforce rate limits on community sources, and maintain service reliability.
- Improvement — to understand aggregate usage patterns and improve the platform. We do not sell personal data.
4. Third-Party Services
We integrate with the following third-party providers. Each operates under their own privacy policy and data practices.
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing & subscriptions | Email, name, subscription events |
| Google OAuth | Social sign-in | OAuth tokens (at sign-in) |
| Discord OAuth | Social sign-in | OAuth tokens (at sign-in) |
| Anthropic / Claude | AI strategy generation & summaries | Source HTML excerpts, chapter text |
| OpenAI | Alternative AI provider | Source HTML excerpts, chapter text |
| AWS S3 / MinIO | Cover & chapter image caching | Scraped image files |
| Telegram | Chapter update notifications | Your chat ID (if enabled) |
| Discord | Chapter update notifications | Your webhook URL (if enabled) |
| PostHog (self-hosted) | Product analytics — see §5 below | Account ID, in-app actions |
5. Product Analytics
We use PostHog, a product analytics platform, to understand how the app is used so we can fix bugs and decide what to build next. PostHog runs on our own infrastructure — your analytics data is never sent to PostHog Inc. or any other third party.
We capture a small set of product events tied to your account ID:
- Page / screen views — which routes you visit inside the app.
- Auth events — sign-in / sign-up start, success, failure (and method: email vs. social).
- Library actions — adding a title (search, URL, or external source).
- Reader actions — opening a chapter, completing a chapter (with chapter and title IDs).
- Discover — search queries you submit and the result count.
- Subscription lifecycle — server-side events for your plan starting, renewing, canceling, or failing payment.
- Gamification — Cultivation rank-ups, achievement unlocks, world-firsts.
We do not capture: your chapter image content, your reading history beyond the chapter-completed event, the text you type into chat / recommendations, payment card data, or anything you mark as private. Web session replay (when enabled) masks all input fields and any element marked data-no-replay.
You can disable analytics on a per-device basis at any time: Settings → Privacy → Product analytics. The toggle is honored immediately — no further events are sent from that device until you re-enable it. Analytics data already captured before opting out is retained per the schedule in §6.
6. Data Retention
- Account data — retained until you delete your account. Deleting your account removes your profile, library, reading progress, credits, and notification settings from our active database.
- Sessions — expire automatically after inactivity or upon sign-out. All sessions are invalidated on account deletion.
- Billing records — Stripe retains transaction records per their own data retention policy. We retain Stripe customer IDs for the lifetime of your account to handle disputes.
- Analytics events — 90 days on staging, 13 months on production. Deleting your account also issues a PostHog deletion request that purges your historical events tied to that account ID within 30 days.
- Backups — database backups may retain data for up to 30 days after deletion before being overwritten.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — update inaccurate information via the Profile settings page.
- Deletion — permanently delete your account and associated data from Settings → Delete Account. This is irreversible.
- Portability — request an export of your library and reading data in a structured format.
- Objection — object to certain processing activities by contacting us.
To exercise any of these rights, email us at the address listed in the Contact section. We will respond within 30 days.
8. Security
We take reasonable technical measures to protect your data:
- Passwords are stored as bcrypt hashes — we never store plaintext passwords.
- User-provided LLM API keys are encrypted at rest with AES-256.
- All data in transit is encrypted via HTTPS/TLS.
- Session tokens are cryptographically signed and rotated on privilege changes.
- Database access is restricted to internal services and is not publicly exposed.
No system is perfectly secure. If you believe your account has been compromised, contact us immediately and change your password.
10. Children's Privacy
Vertex Reader is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, please contact us and we will delete the account and associated data promptly.
11. Contact Us
If you have questions about this Privacy Policy, wish to exercise your data rights, or want to report a security concern, please reach out:
Vertex Reader
Email: privacy@vertexreader.site
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after changes constitutes your acceptance of the updated policy.