IndieFiction

Legal

Privacy Policy

What we collect, why we collect it, and what you can do about it. No tracking, no advertising, and nothing sold — ever.

Last updated: August 1, 2026

Read the Terms & Conditions

1. Who we are

IndieFiction is a book discovery platform for independent authors, operated by Abhishek Aggarwal, a sole trader based in Victoria, Australia. We handle your information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth), and — for authors in the UK or EU — as the data controller under the UK and EU GDPR.

For anything about your data — questions, requests, or complaints — write to hello@indiefiction.com or use our contact form. We aim to respond within 7 days, and always within 30.

2. What we collect

We only collect what the site needs to work. Specifically:

  • Account details — your name and email address. Your password is handled by our authentication provider and stored as a cryptographic hash; we never see it.
  • Author profile — anything you choose to add: a biography, a photograph, and links to your website or social accounts. All of this is optional, and all of it is public once you publish it.
  • Book submissions — title, description, genre, cover image, and the retailer link you provide.
  • Messages — anything you send us through the contact form.
  • Ask posts — questions and answers you post in the community are public, including your name and photo if you were signed in. An anonymous question carries only the same random browser id used for likes, so the post itself holds nothing that points back to you. Separately, so that one person cannot flood the page, we store a one-way hash of your IP address with a timestamp — not the address, not attached to your post, and deleted after two days. Neither record lets us name an anonymous asker. Want something you posted taken down? Email us and we will remove it.
  • Newsletter address — if you subscribe from the footer without creating an account, we store just your email address, when you subscribed, and the exact wording you agreed to. Nothing else, and no account is created.
  • ARC reader list — if you switch on “open to ARC requests” on your account page, we add your address to a separate list of authors willing to read another author's book before it is released. It is kept apart from the newsletter: you can be on one and not the other, and both are switched from the same page.
  • Consent records — whether you accepted these terms and whether you opted into the newsletter, with the date and the exact wording shown at the time. We keep this so we can demonstrate what you agreed to.
  • Technical logs — our hosting provider records IP addresses and browser details to serve pages and block abuse. We do not use these to build a profile of you.

We do not collect payment details, because we do not charge for anything. We do not buy personal data from third parties.

3. Why we use it, and our legal basis

Under the Australian Privacy Principles we may only use your information for the purpose we collected it for, or a directly related purpose you would reasonably expect. Under the GDPR we must additionally have a lawful basis for each use, so we have set those out below.

  • Running your account — to let you log in, submit books, and manage your profile. Basis: performance of a contract with you.
  • Publishing your books and author profile — the entire point of the platform. Basis: performance of a contract, at your request.
  • Newsletter — only if you asked for it, either by ticking the box at signup or by subscribing from the footer. Basis: your consent, which you can withdraw at any time.
  • Running the community (Ask) — publishing the questions and answers you post, and showing your author name and photo on answers you write. Basis: our legitimate interests in running a community, and your act of posting.
  • ARC requests — keeping the list of authors open to receiving advance copies, so those requests can reach people who asked to get them. Basis: your consent, withdrawn by switching it off.
  • Moderating submissions and preventing abuse — keeping the catalogue and the community accurate and the platform safe, including the posting limits described above. Basis: our legitimate interests.
  • Responding to your messages — basis: legitimate interests, or steps taken at your request.
  • Meeting legal obligations — where the law requires us to retain or disclose something. Basis: legal obligation.

We do not sell your personal information, and we never will. We do not share it with advertisers or data brokers.

4. Cookies and tracking

We use only what is strictly necessary to run the site. There is no analytics, no advertising pixels, and no cross-site tracking on IndieFiction.

Strictly necessary:

  • Session cookies (names beginning sb-) — set by our authentication provider to keep you logged in.
  • if_signed_in — a simple yes/no marker so the header can show “My account” without slowing the page down. It contains no identity and no personal data.
  • if_admin — set only for site administrators, so the same header link points to the admin panel instead of an author account. A yes/no marker with no identity in it, and no effect on what anyone is allowed to do.
  • Local storage — remembers your cookie choice, so we do not ask again, and holds a random id used to remember which books and Ask posts you have liked, which answers you found helpful, and which questions you asked from this browser. That id is generated by your browser and is not derived from anything about you: no IP address, no fingerprint, and nothing that identifies you. Clear your browser data and it is gone.

Because none of these are used for tracking or advertising, they do not require consent — but we tell you about them anyway. If we add analytics later, we will ask for your consent before anything loads, and update this page.

5. Who we share it with

We use a small number of service providers to run the platform. They process data on our instructions only, and cannot use it for their own purposes.

  • Supabase — database, login, and image storage. Our project is hosted in the United States (North Virginia).
  • Vercel — website hosting and content delivery. Pages are served from servers worldwide.
  • Brevo — sends our emails, including confirmations, password resets, and the newsletter. Brevo is based in the European Union.

We may also disclose information if the law requires it, or to establish or defend a legal claim.

6. Where your data goes

IndieFiction is operated from Australia, and our providers store data in the United States and the European Union. Wherever you live, this means your personal data is held outside your country — including if you are in Australia.

Australian Privacy Principle 8 requires us to take reasonable steps to ensure overseas recipients handle your data consistently with the APPs, and we rely on our providers' contractual commitments to do so. For UK and EU authors, those transfers rest principally on Standard Contractual Clauses approved by the European Commission, together with the technical protections described below. You can ask us for details of the safeguards that apply.

7. How long we keep it

  • Account and profile — for as long as your account exists. Delete your account and we remove your profile, biography, and photograph.
  • Published books — until you remove them, or you ask us to.
  • Ask posts — your questions and answers stay public until you or we remove them; email us and we will take yours down. If you delete your account, your answers are deleted with it, while your questions remain but are shown as Anonymous — detached from your name — so the thread still makes sense to the next reader.
  • Newsletter records — until you unsubscribe. We keep a record of the unsubscribe itself so we can prove we honoured it, and so we do not email you again by mistake. Ask us to erase the address outright and we will, from our list and from our email provider — though then nothing is left to stop a later import adding you back.
  • Removed author profiles — if we take a profile down for breaking these terms, such as claiming to be someone else, we keep a copy of what was published and the reason it went. A contested removal has to be reviewable against the real text rather than our description of it. Delete the account and that copy goes with it.
  • Closed accounts — when an account is deleted we keep a one-way hash of the email address, the reason, and how many books and answers were affected. The hash cannot be turned back into your address; it exists so a deletion can still be accounted for afterwards. Everything else goes.
  • Messages — up to 2 years, so we have context if you write again.
  • Technical logs — short-lived, and retained by our hosting provider under their own schedule.

8. Your rights

Wherever you live, you can ask us to show you what we hold, correct it, or delete it. If you are in the UK or EU, the GDPR additionally gives you the right to:

  • receive a copy of your data in a portable format;
  • object to processing based on our legitimate interests;
  • ask us to restrict processing while a dispute is resolved;
  • withdraw consent at any time — this does not affect anything we did before you withdrew it.

If you are in Australia, the Australian Privacy Principles give you the right to access the personal information we hold about you and to ask us to correct anything inaccurate, out of date, or misleading. You can also ask us to stop using your information for direct marketing at any time.

The quickest routes: change your details on your account page, switch the newsletter off with the toggle there, or click unsubscribe in any email. For anything else, email hello@indiefiction.com. We do not charge for this.

If you think we have handled your data badly, please tell us first — we would rather fix it, and we will respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner. Authors in the UK can complain to the Information Commissioner's Office, and those in the EU to their national supervisory authority.

9. How we protect it

The site is served over HTTPS. Passwords are hashed by our authentication provider and are never visible to us. Access to the database is restricted at row level, so one author's account cannot read another's private data. Uploaded images are validated by their actual file contents rather than their filename, and stored under generated names.

No system is perfectly secure. If a breach ever affects your personal data, we will notify you and the relevant authority as the law requires.

10. Age requirement

IndieFiction is for adults. You must be 18 or older to create an account. We do not knowingly collect personal data from children. If you believe a child has created an account, tell us and we will remove it.

11. Changes to this policy

We will update this page as the platform grows. The date at the top always reflects the latest version. If a change materially affects your rights, we will tell you — by email if you have an account with us.

Questions about this page? Get in touch — we answer every message.