Privacy Notice

STORIES · 18+

YOUR CONTACT DETAILS STAY PRIVATE.

Privacy notice.

Your stories may be public. Your author email is not. Here is how WebbX handles your information.

Effective date: 8 October 2026 · Version 2026-10-08-v2

Private author email Not provided to readers.
Enquiries through WebbX We coordinate with you privately.
You have data rights Contact us to make a request.

1. Who is responsible?

The controller is WebbX — [INSERT LEGAL OPERATOR NAME], organisation number [INSERT ORGANISATION NUMBER], at [INSERT BUSINESS ADDRESS, COUNTRY].

For privacy questions or rights requests, contact [INSERT CONTACT EMAIL].

This notice covers the story submission service. Other functions on the same website may have separate privacy or cookie information.

2. What we collect

  • A required private author email address.
  • An optional public pseudonym, story title, original language and story text.
  • Review results, publication status, submission time and the accepted terms version.
  • Necessary technical information for security and abuse prevention. The story module uses a hashed IP-based rate-limit key. Hosting systems may separately log IP addresses and requests.
  • Messages and relevant evidence when you contact us about rights, complaints, permissions or removal.

No reader account or payment information is collected by this module.

Do not put personal contact information or real-life sensitive personal details into a story. The service is intended for fiction about adults. It does not ask for information about your actual sex life or sexual orientation.

3. Why we use data and our legal bases

Publishing agreement — GDPR Article 6(1)(b): we use your story, selected pseudonym, private email and submission records to review and administer the requested publication, contact you when necessary, coordinate rights requests and deal with removal.

Private email is required to submit. It is not automatically verified.

Legitimate interests — Article 6(1)(f): proportionate security, spam prevention, complaint investigation and protection or defence of rights. Our interests are to operate a reliable service and prevent misuse. You may object to processing based on these interests.

Legal obligation — Article 6(1)(c): where an applicable law requires us to retain or disclose information.

We do not use the author email for newsletters or unrelated advertising under these terms.

A publishing checkbox records acceptance of the agreement, not general consent to all personal-data processing.

Any processing of special-category data needs an applicable additional legal basis. Please do not submit such personal data.

4. What is public and what stays private

Your private email is not part of your public story.

Readers see your chosen pseudonym or “Anonymous”. Author contact and permission requests go through WebbX.

Public information: approved story text, title, selected pseudonym, publication details, summaries and translations where available.

Public information may be indexed by search engines. A pseudonym reused elsewhere may make you identifiable.

Private information: your author email is not displayed in reader pages, story text or this module’s public API responses.

Within the publishing module, viewing private author contact information requires administrator access. We do not supply the email to readers or permission applicants.

Hosting and backup providers process stored website data. Disclosure may also be required by law. We cannot control author contact information independently available elsewhere.

5. Author enquiries go through WebbX

Requests to contact an author, reuse a story, obtain publication permission or propose a collaboration through this service go to WebbX.

We contact the author privately and coordinate a response. We do not disclose the private author email to the requester.

We do not grant rights belonging to the author without the required approval.

If a separate arrangement needs additional data sharing, we will explain it and establish the appropriate legal basis before sharing.

6. Providers and AI processing

Hosting and backups: [INSERT HOSTING/BACKUP PROVIDER, PROCESSING COUNTRIES AND BACKUP RETENTION] .

These providers process stored website data, including private author emails, to host and protect the service.

AI review: OpenAI API receives the story title, declared original language and story text.

The private email field and pseudonym field are not included in the AI review payload. However, information you place inside a story can itself identify you, so keep it out.

OpenAI API data is not used for model training by default unless the API account explicitly opts into sharing.

This module requests store: false, but that does not eliminate all provider retention. OpenAI normally retains abuse-monitoring logs for up to 30 days, with exceptions described in its policies.

Translation: when enabled, necessary story text will be processed by the selected translation provider. We will update this notice before adding a materially different provider or purpose. No translation function is active in the initial submission module.

Email correspondence provider: [INSERT PROVIDER AND PROCESSING COUNTRIES] .

The initial module does not automatically send emails. Correspondence is handled by the administrator.

We may use professional advisers or disclose information to authorities when legally necessary. We do not sell private author email addresses.

7. International transfers

Some providers, including OpenAI, may process data outside the EU/EEA.

Where required, transfers must rely on an applicable adequacy decision or appropriate safeguards such as Standard Contractual Clauses, together with any necessary additional measures.

[INSERT THE ACTUAL TRANSFER LOCATIONS AND SAFEGUARDS APPLICABLE TO YOUR PROVIDER CONTRACTS, AND HOW AUTHORS CAN REQUEST A COPY.]

Contact us for information about the safeguards applicable to your data. We do not promise that all processing takes place in Sweden or the EU.

8. Retention and deletion

  • Published stories and private contact records: retained while the story remains published and the information is needed to administer it. On a verified removal request, public access is removed and unneeded contact records are deleted or anonymised without undue delay.
  • New pending or unpublished submissions with private emails: normally removed after 90 days from submission. Rejected submissions are normally removed after 30 days.
  • Scheduled cleanup: the module schedules daily cleanup, which depends on WordPress scheduled tasks running. Older submissions without the private-email field are handled manually.
  • Rights disputes, complaints and legal holds: relevant records may be retained only as long as needed to meet an applicable obligation or establish, exercise or defend legal claims. A legal hold pauses automatic cleanup for the relevant submission.
  • Rate-limit keys: normally expire after one hour of inactivity. Aggregate hourly rate counters expire after two hours. Repeated attempts can extend the individual key’s expiry.
  • Hosting logs, backups and correspondence: [INSERT ACTUAL RETENTION PERIODS FOR HOSTING LOGS, BACKUPS AND CONTACT MESSAGES] . Deleted records may remain temporarily in backups until the relevant rotation completes.

Technical hashes used to prevent duplicate submissions are deleted when the corresponding story is permanently deleted.

AI-provider retention follows the applicable provider settings and policies described above.

9. Your rights

Depending on the circumstances, you may request access, correction, erasure, restriction or portability of your personal data, and object to processing based on legitimate interests.

Where a processing activity actually relies on consent, you may withdraw that consent without affecting the lawfulness of earlier processing.

Send requests to [INSERT CONTACT EMAIL], preferably from the email used to submit.

We may request proportionate additional information to verify your authority. We normally respond within one month. Lawful extensions may apply, and we will inform you if one is necessary.

You may complain to the Swedish Authority for Privacy Protection, IMY, or the competent supervisory authority in your country.

10. Automated review and human review

AI may approve a story for automatic publication, flag it or leave it for manual review. This assesses submitted text against publishing rules, not your identity, character or legal ownership.

AI can make mistakes. You may request human review through WebbX and provide your explanation.

The service is free and does not use review decisions to determine payments, employment or credit eligibility.

11. Security, cookies and other site tools

Private author emails are stored in protected WordPress metadata with this module’s public REST exposure disabled.

Administrator-only controls are used for access within the module. Security also depends on hosting, administrator accounts, backups and other installed plugins. No system can promise absolute security.

The story module does not add advertising or analytics trackers and does not store form drafts in your browser.

WordPress sessions, hosting tools or other plugins on the same site may separately use cookies, analytics or other processing.

[INSERT LINK TO THE ACTUAL SITE COOKIE NOTICE AND IDENTIFY ANY ACTIVE ANALYTICS/TRACKING PROVIDERS, OR CONFIRM NONE ARE USED.]

Where consent is required, optional tracking must remain disabled until valid consent is obtained.

12. Adults only and updates

Only adults aged 18 or over may submit stories. If you believe a child has submitted personal information, contact us so we can investigate and remove it where appropriate.

An age declaration is not a guarantee of verified age.

We will update this notice when the service or its processing changes. The current effective date and version appear above.

New purposes requiring a new legal basis will not be introduced merely by changing this page.

Your story can travel. Your private email stays private.