IndieFiction

Legal

Privacy Policy

What we collect, why we collect it, and what you can do about it. Analytics only if you accept them, no advertising, and nothing sold, ever.

Last updated: September 6, 2026

Read the Terms & Conditions

1. Who we are

IndieFiction is a book discovery platform for independent authors, operated by Abhishek Aggarwal, a sole trader based in Victoria, Australia. We handle your information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth), and, for authors in the UK or EU, as the data controller under the UK and EU GDPR.

For anything about your data (questions, requests, or complaints), write to hello@indiefiction.com or use our contact form. We aim to respond within 7 days, and always within 30.

2. What we collect

We only collect what the site needs to work. Specifically:

  • Account details: your name and email address. Your password is handled by our authentication provider and stored as a cryptographic hash; we never see it. If you choose Continue with Google instead, Google confirms your identity and passes us your name and email address, and nothing else. There is no password on that account at all. We do not receive your Google password, your contacts, or anything else in your Google account, and we do not post anything to it.
  • Author profile: anything you choose to add (a biography, a photograph, and links to your website or social accounts). All of this is optional, and all of it is public once you publish it.
  • Book submissions: title, description, genre, cover image, the retailer link you provide, and optionally the formats your book comes in and their ISBNs. All of it is public on your book's page.
  • Business accounts: the organisation's name, its logo and website if you add them (all public, on your publisher page), and optionally a contact person, a name and an email address. The contact person is never public, is used only so a person at your organisation can be reached about the account, and is never sent marketing: everything we send goes to the account's login email.
  • Reader accounts: the books you save to your shelf and mark as finished, and the authors and readers you follow. Your shelf is private: shown only to you, and no book page shows who saved it. Following is private with one exception: a reader you follow can see your name on the followers list of their own account page, and nobody else can. Authors are never told who follows them. A reader's public page shows how many people follow it, never who. Following someone means we show you an account notification when they list a new book or story, or publish a review or note; nothing is emailed for it. Your reader profile (your name, photo, the line about what you read and any social links) and the handle you choose are private until you publish a review or a note; from that moment they are public at your page, indiefiction.com/@handle, and so is every post you publish there, which also appears in the site-wide feed at indiefiction.com/reviews. Drafts stay private. A post the spam filter holds is shown only to you and to us until we release it.
  • Messages between readers and authors: what you write, when, and to whom. A conversation is visible to the two people in it and to nobody else, with two exceptions: a message our spam filter holds, and a message one of you reports to us, are read by us so we can decide what to do with them. Either person can switch their inbox off or block the other, and we keep the block so it holds. We never use your messages for marketing or show them to anyone else.
  • Short stories: the text of any story you write or paste in, its title, genre, and whether you marked it as containing adult content. A published story is public, under your name, and readable by anyone. Drafts are private — only you and, where they need to act on a report, we can see them — and we keep them until you delete them or delete your account, because a half-finished story you come back to next month is the point of having drafts. We also record when you published and when you last edited, so we can tell what has changed since we reviewed it.
  • Account notifications: short messages shown on your account page about your own books, stories and subscription, plus occasional site news from us — for example that a book you submitted was approved, with its title and the note we wrote at the time. Only you (and we) can see them, and we record when you last opened the panel so we can show you what is new. If five or more build up unread, we send one email saying how many — not what they are — and not another until you have looked. Because it is about your own account rather than marketing, it goes out whether or not you subscribed to our emails. We also email you whenever your password is changed, every time, so you find out even if it wasn't you who changed it.
  • Messages: anything you send us through the contact form.
  • Ask posts: questions and answers you post in the community are public, including your name and photo if you were signed in. An anonymous question carries only the same random browser id used for likes, so the post itself holds nothing that points back to you. Separately, so that one person cannot flood the page, we store a one-way hash of your IP address with a timestamp: not the address, not attached to your post, and deleted after two days. Neither record lets us name an anonymous asker. Want something you posted taken down? Email us and we will remove it.
  • Story comments: comments you leave on a short story are public, under whatever name you type: no account is involved and we store nothing else with the comment. The same two-day hashed-IP throttle record described for Ask posts applies here, and it is never attached to your comment. Want a comment taken down? Email us and we will remove it.
  • Newsletter address: if you subscribe from the footer or from the Shout-Out archive pages without creating an account, we store just your email address, when you subscribed, and the exact wording you agreed to. Nothing else, and no account is created.
  • Blind Date books by email: at the end of the Blind Date game you can ask us to email you the books you were matched with. We use your address only to send that one email. If you also tick the box to join the reader newsletter, we store your address and the wording you agreed to, the same as any other newsletter signup; if you do not, we do not add your address to any list, though our email provider keeps its own delivery log of the message it sent.
  • Quiz certificates by email: if you pass Level 2 or 3 of the book quiz you can ask us to email you a certificate, with whatever name you type on it. We use the address and the name only to draw and send that one email; neither is stored. If you also tick the box to join the reader newsletter, we store your address and the wording you agreed to, the same as any other newsletter signup. The quiz separately counts, for every question, how often it is answered correctly, runs out of time or uses a hint: those counts are how we edit the questions, and they contain nothing about you, no address, account or IP.
  • ARC reader list: a separate list of people willing to read a book before it is released. Authors join it from their account page; readers join it by ticking the box under the newsletter signup. It is a separate choice from the newsletter, so you can be on one and not the other, and leaving one does not take you off the other. We record the date you agreed and the wording you were shown.
  • Consent records: whether you accepted these terms and whether you opted into the newsletter, with the date and the exact wording shown at the time. We keep this so we can demonstrate what you agreed to.
  • Technical logs: our hosting provider records IP addresses and browser details to serve pages and block abuse. We do not use these to build a profile of you.
  • Story and Upcoming reading statistics: when you read a short story we count the visit and how long the story was open in a visible tab; when you visit an Upcoming book's page or its sample chapters we count the visit. In both cases the author sees only the aggregate— a total view count (and, for stories, an average reading time), never who read it or any one person's time. To keep the counts honest we store a one-way salted hash of your connection details for up to 90 days: not your IP address, not linked to any account, and not readable back into either. No cookie and nothing on your device is involved. Basis: our legitimate interest in showing authors how their work is received.
  • Subscription details: which plan you are on, its status, and when it renews. We never see or store your card number. Card details go directly to Stripe, who processes the payment as merchant of record; we receive only a reference to the subscription.
  • Reader interest list: if you register interest in an upcoming book, we store your email address, your name if you chose to give one, when you registered, and the exact wording you agreed to. This list exists to be given to that book's author. See “Who we share it with” below, because this is the one place on the site where your address goes to another person.

We do not buy personal data from third parties.

3. Why we use it, and our legal basis

Under the Australian Privacy Principles we may only use your information for the purpose we collected it for, or a directly related purpose you would reasonably expect. Under the GDPR we must additionally have a lawful basis for each use, so we have set those out below.

  • Running your account: to let you log in, submit books, and manage your profile. Basis: performance of a contract with you.
  • Listing your books and publishing your author profile: the entire point of the platform. Basis: performance of a contract, at your request.
  • Newsletter: only if you asked for it, by ticking the box at signup, by subscribing from the footer or the Shout-Out archive, or by turning it on from your account page. Basis: your consent, which you can withdraw at any time.
  • Running the community (Ask and story comments): publishing the questions, answers and comments you post, and showing your author name and photo on answers you write. Basis: our legitimate interests in running a community, and your act of posting.
  • ARC requests: keeping the list of readers and authors open to receiving advance copies, so those requests only ever reach people who asked for them. Basis: your consent, withdrawn by switching it off or telling us.
  • Moderating submissions and preventing abuse: keeping the catalogue and the community accurate and the platform safe, including the posting limits described above. Basis: our legitimate interests.
  • Responding to your messages. Basis: legitimate interests, or steps taken at your request.
  • Managing your subscription: mirroring its status so the site knows what to show, and linking you to Stripe's portal for invoices and card changes. Basis: performance of a contract.
  • The reader interest list: holding your address so the author can receive it and tell you when their book is published. Basis: your consent, given next to the form with the disclosure in front of you.
  • Understanding how the site is used: which pages and books people find, so we can improve discovery. Basis: your consent, given through the cookie banner.
  • Meeting legal obligations: where the law requires us to retain or disclose something. Basis: legal obligation.

We do not sell your personal information, and we never will. We do not share it with advertisers or data brokers.

4. Cookies and tracking

We use two kinds of cookie: those strictly necessary to run the site, and analytics cookies that only load after you accept them. There are no advertising cookies and no cross-site tracking on IndieFiction.

Strictly necessary:

  • Session cookies (names beginning sb-): set by our authentication provider to keep you logged in.
  • if_signed_in: a simple yes/no marker so the header can show “My account” without slowing the page down. It contains no identity and no personal data.
  • if_admin: set only for site administrators, so the same header link points to the admin panel instead of an author account. A yes/no marker with no identity in it, and no effect on what anyone is allowed to do.
  • Local storage: remembers your cookie choice, so we do not ask again, and holds a random id used to remember which books, stories and Ask posts you have liked, which authors you have recommended, which answers you found helpful, and which questions you asked from this browser. That id is generated by your browser and is not derived from anything about you: no IP address, no fingerprint, and nothing that identifies you. Clear your browser data and it is gone.

Analytics (only with your consent):

  • Google Analytics 4 (cookies named _ga and _ga_*): tells us which pages and books people find, and roughly where visitors come from. Google uses your IP address to work out an approximate location and does not store it. We also count three things as they happen — creating an account, starting checkout and completing a subscription— so we can see which pages lead people to sign up. These are counts and nothing more: your name, your email address and your payment details are never sent to Google, which is both our rule and theirs.

These load only after you accept in the cookie banner. Decline and the script is never requested at all — not loaded and switched off, not present. The site works exactly the same.

You can change your mind at any time.“Cookie settings” at the bottom of any page brings the banner back, and declining there stops analytics from loading again from that moment on.

We have not asked for, and do not set, advertising cookies. If that ever changes, the banner will ask you separately — accepting analytics is not accepting advertising.

Google is an additional recipient of this data and may process it outside your country under its own safeguards.

5. Who we share it with

We use a small number of service providers to run the platform. They process data on our instructions only, and cannot use it for their own purposes.

  • Supabase: database, login, and image storage. Our project is hosted in the United States (North Virginia).
  • Vercel: website hosting and content delivery. Pages are served from servers worldwide.
  • Brevo: sends our emails, including confirmations, password resets, and the newsletter. Brevo is based in the European Union.
  • Google: verifies who you are, and only if you choose to sign in with Google. Google tells us your name and email address. We send nothing about you to Google beyond the fact that a sign-in was requested, and choosing this is entirely optional. Google is based in the United States.
  • Google Analytics: measures how the site is used, and only if you accepted analytics cookies.
  • Stripe: processes subscription payments as merchant of record. The purchase is made from Stripe, on Stripe's checkout, and they receive your card details directly; we do not.

One disclosure on this site goes to a person rather than a service provider: the reader interest list. Register interest in an upcoming book and your email address (and name, if you gave one) exists so that the author can download it and email you when the book is out. The wording beside the form says exactly this before you submit.

Be clear about what that means: once an author has downloaded the list, they hold their own copy and we cannot take it back: deleting our copy does not undo the disclosure. Authors agree, as a condition of their subscription, to use the list only to announce that book, never to sell or share it, and to honour opt-outs. If an author misuses your address, tell us. We can and do end subscriptions over it.

We may also disclose information if the law requires it, or to establish or defend a legal claim.

6. Where your data goes

IndieFiction is operated from Australia, and our providers store data in the United States and the European Union. Wherever you live, this means your personal data is held outside your country, including if you are in Australia.

Australian Privacy Principle 8 requires us to take reasonable steps to ensure overseas recipients handle your data consistently with the APPs, and we rely on our providers' contractual commitments to do so. For UK and EU authors, those transfers rest principally on Standard Contractual Clauses approved by the European Commission, together with the technical protections described below. You can ask us for details of the safeguards that apply.

7. How long we keep it

  • Account and profile: for as long as your account exists. Delete your account and we remove your profile, biography, and photograph.
  • Published books: until you remove them, or you ask us to. On a business account, deleting the account deletes its listings with it.
  • Business contact person: for as long as the account exists, or until you blank the fields on your publisher profile.
  • Lapsed business accounts: a business account whose plan has lapsed, or that remains suspended, may be deleted after two years, together with everything it holds. We do not keep an organisation's data indefinitely with nothing to show for it.
  • Short stories: until you delete them. Deleting your account deletes your stories with it, drafts included — unlike an Ask question, nothing is kept and re-labelled, because a story is the whole of what you wrote rather than one side of a conversation someone else is still having. If we had already quoted an extract in a newsletter or a social post before you deleted it, that copy stays where it is: a newsletter that has been sent cannot be recalled. We publish no new extracts after you remove a story.
  • Ask posts: your questions and answers stay public until you or we remove them; email us and we will take yours down. If you delete your account, your answers are deleted with it, while your questions remain but are shown as Anonymous, detached from your name, so the thread still makes sense to the next reader.
  • Story comments: public until you or we remove them; email us and we will take yours down. A comment is deleted for good when the story it sits on is deleted.
  • Story and Upcoming reading statistics: the hashed connection records behind view counts are deleted after 90 days. The aggregate totals — a story's view count and average reading time, an Upcoming book's view count — are part of the work's record and stay with it.
  • Your shelf and the authors you follow: until you remove them, and deleted with your account. A book that leaves the site leaves every shelf it was on. Reviews and notes: until you delete them, and deleted with your account, photos included. A post we take down is kept invisible rather than erased, so a contested removal can be reviewed against the real text.
  • Messages: a conversation is kept until either person deletes their account, when the whole conversation is deleted for both of you. A message we remove is kept invisible rather than erased, for the same reason as a removed post. Blocks are kept until you lift them.
  • Message tokens: a record of each conversation you open and which allowance it used, and of each pack you buy (how many tokens, the amount, and Stripe's reference for the payment; never your card details, which Stripe holds), kept for the life of your account and deleted with it. If you open a conversation with a paid token, we email the other person to say that you did, with a link to reply; the email never carries the message itself.
  • Account notifications: deleted after 180 days, deleted immediately when you dismiss one yourself, and deleted with your account. Longer than the 90 days we hold reading statistics on purpose: these are your own record of decisions about your work, and a review note from five months ago is still the thing you may want to refer back to.
  • Newsletter records: until you unsubscribe. We keep a record of the unsubscribe itself so we can prove we honoured it, and so we do not email you again by mistake. Ask us to erase the address outright and we will, from our list and from our email provider, though then nothing is left to stop a later import adding you back.
  • Removed author profiles: if we take a profile down for breaking these terms, such as claiming to be someone else, we keep a copy of what was published and the reason it went. A contested removal has to be reviewable against the real text rather than our description of it. Delete the account and that copy goes with it.
  • Closed accounts: when an account is deleted we keep a one-way hash of the email address, the reason, and how many books and answers were affected. The hash cannot be turned back into your address; it exists so a deletion can still be accounted for afterwards. Everything else goes.
  • Messages: up to 2 years, so we have context if you write again.
  • Technical logs: short-lived, and retained by our hosting provider under their own schedule.
  • Analytics: only collected if you accepted it. Google holds the visit-level data for up to 14 months and then deletes it; the aggregate counts we actually look at (how many people read a page) are kept indefinitely, and identify nobody. Declining, or withdrawing later through “Cookie settings”, stops new data being collected — it does not reach into what Google already holds, which ages out on that schedule.
  • Reader interest lists: while the author's subscription is active, and for 30 days after it lapses so an expired card doesn't instantly destroy their list; then our copy is deleted. It is also deleted when the author removes the book. Each download an author makes is logged (who, which book, how many addresses, when) so “when did my address leave your system?” always has an answer. Remember that deletion of our copy does not reach copies an author already downloaded.
  • Subscription records: the mirror of your plan's status, kept while your account exists. Invoices and payment records are held by Stripe as the seller, under their own retention obligations.

8. Your rights

Wherever you live, you can ask us to show you what we hold, correct it, or delete it. If you are in the UK or EU, the GDPR additionally gives you the right to:

  • receive a copy of your data in a portable format;
  • object to processing based on our legitimate interests;
  • ask us to restrict processing while a dispute is resolved;
  • withdraw consent at any time (this does not affect anything we did before you withdrew it).

If you are in Australia, the Australian Privacy Principles give you the right to access the personal information we hold about you and to ask us to correct anything inaccurate, out of date, or misleading. You can also ask us to stop using your information for direct marketing at any time.

The quickest routes: change your details on your account page, switch the newsletter off with the toggle there, or click unsubscribe in any email. Erasure is self-service too: the same page will delete your account outright, after showing you what that removes. For anything else, email hello@indiefiction.com. We do not charge for this.

If you think we have handled your data badly, please tell us first: we would rather fix it, and we will respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner. Authors in the UK can complain to the Information Commissioner's Office, and those in the EU to their national supervisory authority.

9. How we protect it

The site is served over HTTPS. Passwords are hashed by our authentication provider and are never visible to us. Access to the database is restricted at row level, so one author's account cannot read another's private data. Uploaded images are validated by their actual file contents rather than their filename, and stored under generated names.

No system is perfectly secure. If a breach ever affects your personal data, we will notify you and the relevant authority as the law requires.

10. Age requirement

IndieFiction is for adults. You must be 18 or older to create an account. We do not knowingly collect personal data from children. If you believe a child has created an account, tell us and we will remove it.

11. Changes to this policy

We will update this page as the platform grows. The date at the top always reflects the latest version. If a change materially affects your rights, we will tell you, by email if you have an account with us.

Questions about this page? Get in touch. We answer every message.