SYNward
PRIVACY / PUBLICIn force

Privacy policy

What SYNward collects, why it collects it, and what you can make us do about it.

SYNward is operated by Lupus Rex Enterprises LLC (“we”, “us”). This policy explains what personal information we collect when you use the site, why we hold it, who else sees it, and how you can get at it or have it removed. It applies to the site and nothing else.

1. What we collect

Only what the site needs to work, and it arrives in three ways.

You give it to us.

  • Your email address, when you open an account. It is the account: we do not ask for a name, a password or a phone number.
  • Your marketing choice — whether you want occasional email about new releases. We ask once and record the answer.
  • Anything you write to us, if you get in touch.

It comes from Google, if you choose Google sign-in. Google tells us your email address, your name and your profile picture. We use the email address to identify your account and ignore the rest. We never receive your Google password, and we cannot see anything else in your Google account.

The site records it as you read.

  • Reading activity — how far through an edition you are, what you have bookmarked, and what you have marked to come back to. This is what lets you pick up where you left off on another device.
  • Your holdings — the balance of slivers on your account and the ledger of how it changed, plus which editions you have unlocked.
  • Ordinary technical records — IP address, browser and device type, and timestamps of requests, logged by our hosting and database providers. These are kept for security and debugging, not to build a profile of you.

We do not run advertising, we do not use third-party analytics or tracking pixels, and we do not buy information about you from anyone.

2. Cookies and local storage

We use cookies for signing in, and for nothing else. There is no advertising or cross-site tracking cookie on this site, which is why you are not asked to dismiss a consent banner.

  • Sign-in cookies. When you sign in, we store a session token in a cookie so the site knows it is you on the next page. It lasts up to 400 days and is refreshed as you browse. Signing out deletes it.
  • Short-lived sign-in cookies. Requesting a link or using Google sign-in sets one or two cookies that exist only to complete that sign-in safely, and are discarded once it finishes.
  • Preference cookies. Where you were headed before you were asked to sign in, and whether you last used a code or a link, so the next visit does not make you choose again. They identify no one.
  • Local storage. Your terminal settings — audio, motion and reader typography — and a local copy of your reading position are kept in your browser and never sent to us. Clearing your browser data removes them.

3. Why we hold it

  • To run your account and the site — signing you in, keeping your place, tracking what you hold. Without this the site cannot function, so we rely on the necessity of performing our agreement with you.
  • To keep the site working and secure — logs, abuse prevention, debugging. This is our legitimate interest in operating a service that stays up and is not abused.
  • To email you about new releases — only if you asked us to, and only until you tell us to stop. That is consent, and you can withdraw it at any time from your hideout without giving a reason.
  • To take payment, if and when you buy something, and to keep the records tax and accounting rules require us to keep.

4. Who else sees it

We do not sell your information, rent it, or share it for anyone else’s marketing. We do use service providers to run the site, and they only handle your information on our instructions:

  • Supabase — our database, authentication and the delivery of sign-in emails.
  • Vercel — hosting and delivery of the site itself.
  • Google — only if you choose Google sign-in, and only for that.
  • A payment processor, once payments are live. See below.

We may also disclose information where the law requires it, or where it is necessary to establish or defend a legal claim. If the business is ever sold or merged, account information may transfer with it; if that happens you will be told before anything about this policy changes for you.

5. Payments

SYNward does not take payments yet. When it does, they will be handled by a third-party payment processor. Your card number and security code go directly to that processor and never reach our servers — we do not see them and cannot store them. We will hold a record of what you bought, when, and how much you paid, because we have to.

This policy will be updated with the processor’s name before the first payment is taken.

6. How long we keep it

Account information is kept for as long as your account exists. Delete your account and we delete your email address, your reading activity, your bookmarks and your marketing preference. Two things survive that, and only these: records we are legally required to keep, such as transaction records for tax purposes, and security logs, which age out on their own within a few months.

7. What you can make us do

Whatever your jurisdiction, we will honour all of these for anyone who asks:

  • See it — get a copy of what we hold about you.
  • Correct it — have anything inaccurate fixed.
  • Delete it — have your account and its contents removed.
  • Take it elsewhere — receive it in a portable format.
  • Stop the email — turn marketing off from your hideout or through the unsubscribe link on any message. This never affects sign-in emails, which are not marketing and cannot be turned off while your account is open.
  • Object or restrict — ask us to stop or limit a particular use.

Write to info@synward.net and we will answer within 30 days. We will never charge you for asking, and we will never make the site worse for you because you did. If you are in the UK or EU and you think we have handled this badly, you can complain to your local data protection authority.

8. Where it is held

Our providers store and process information in the United States and potentially other countries. If you are reading from outside the US, using the site means your information is transferred there. Where the law requires a safeguard for that transfer, we rely on our providers’ standard contractual clauses.

9. Security

Access to the database is restricted at the row level, so one reader’s account cannot read another’s. Traffic is encrypted in transit. There are no passwords on this site to be stolen — sign-in is by one-time code, one-time link, or Google. No system is perfectly secure, and we do not claim otherwise; if a breach ever affects you, we will tell you and the relevant regulator as quickly as the law requires.

10. Children

SYNward is not intended for anyone under 16, and we do not knowingly collect information from them. If you believe a child has given us their information, write to us and we will delete it.

11. Changes

If we change this policy we will update the effective date above. Where a change materially affects what we do with information we already hold, we will tell account holders by email before it takes effect rather than relying on you to notice.

12. Contact

Lupus Rex Enterprises LLC, operator of SYNward — reach us at info@synward.net. The terms of service govern your use of the site alongside this policy.

Privacy policy — SYNward