Privacy Policy
Last updated: August 4, 2026
The short version
We collect your email, reading activity, and a bounded acquisition record to run and improve the service. We don't sell your data — never have, never will. Web payments go through Paddle; mobile purchases go through Apple, Google Play, and RevenueCat. We never see your card details. You have full GDPR rights.
1. Who We Are
HSKStory is an online Chinese graded reading platform. Questions about this policy? Email anthony@hskstory.com.
2. What We Collect
Information you provide
- Account: Email address and optional display name. We use passwordless magic links and may offer Google sign-in — no password is ever stored.
- Purchases: Subscription status, entitlement source, and purchase history needed to unlock paid features and support billing issues
Google sign-in (if you choose it)
If you choose to sign in with Google, Google sends us your name, email address, and locale, plus a stable Google account identifier. We use this information only to authenticate you, link the Google identity to your HSKStory account, and fill empty account profile fields.
A profile picture may be included in Google's response, but it is discarded on receipt and never saved. Google access and ID tokens are used only to complete sign-in. Google tokens are not stored, we do not request offline access, and we do not retain a Google refresh token.
The Google identity link is kept while your HSKStory account exists so you can sign in again. When your account is deleted after the 30-day grace period, we remove that identity link with the rest of your account data.
Collected automatically
- Reading activity: Stories read, chapter progress, vocabulary saved, and flashcard reviews
- Acquisition attribution: We keep one first-touch record in first-party localStorage. It is eligible for use for no more than 30 days. While HSKStory remains open, we schedule its deletion at expiry. Because localStorage cannot delete data in the background while the site is closed, expired bytes may remain until you next run HSKStory; we then delete them before the record can be read for attribution, transferred, or replaced. It contains a coarse acquisition channel, sanitized UTM source, medium, and campaign, a registrable referrer domain, and capture time. If you sign in or complete a web purchase, we link it once to your authenticated account. The app-owned acquisition database row is deleted with that account. When a paid conversion is measured, already-sent bounded acquisition event and person properties in PostHog are not deleted by that database cascade; they follow our analytics provider and project retention and data-rights deletion process. You can use the contact in Section 6 to request deletion of provider-held analytics data. We use this record for acquisition and payment conversion measurement. This attribution record contains no anonymous identifier, raw URL or referrer, IP address, user agent, or fingerprint.
- Notifications: Device push tokens if you opt in to mobile reminders
- Diagnostics: Error reports, crash logs, device/app version, and request context used to fix bugs
- Infrastructure logs: Our hosting provider (Cloudflare) and web server log IP addresses and request metadata as part of normal operations. We do not store this data in our application.
3. How We Use It
- Run the service: Deliver stories, audio, and manage your account
- Authenticate: Sign you in, protect your account, and link your chosen sign-in method
- Explorer limits: Track your story count
- Process payments: Via Paddle (our payment processor)
- Support: Respond to questions and resolve issues
- Improve: Analyze usage patterns to improve content and features
We do not sell your personal data to third parties.
4. Third-Party Services
Google — Authentication
If you choose Google sign-in, we use Google as an authentication processor. Google processes the sign-in request and provides the account information described above. Google sign-in does not give HSKStory access to your Google password.
Paddle — Payments
Paddle acts as merchant of record. They process all payments, handle global tax compliance, and issue receipts. We never store or see your card details. Paddle Privacy Policy
RevenueCat — Mobile Purchases & Entitlements
RevenueCat helps us connect App Store, Google Play, and web subscription entitlements to your HSKStory account. They receive account identifiers and purchase status needed to manage access.
Apple App Store and Google Play — In-App Purchases
Apple and Google process mobile in-app purchases, receipts, renewals, refunds, and related billing events. We never receive your full payment card details from them.
Resend — Email
We use Resend to send sign-in links and transactional emails. They receive your email address for delivery purposes only.
If you opt in, Resend also delivers our new-stories newsletter — at most twice a month. You can unsubscribe from any newsletter email or from the Emails section of your account settings. Unsubscribing never affects sign-in links or account emails, which we always send.
Firebase Cloud Messaging — Push Notifications
If you enable mobile reminders, Firebase Cloud Messaging receives a device push token so we can deliver notifications. Push reminders are opt-in.
Cloudflare — Hosting & Audio
Cloudflare proxies our web traffic and serves audio files. They process request data (IP address, headers) as part of normal CDN operations.
Sentry — Error Monitoring
When an error occurs in our web or mobile apps, we send diagnostic data to Sentry to fix bugs. For signed-in users, this may include your user ID to help us identify and resolve the issue; we never send your email to Sentry.
PostHog — Product Analytics
When analytics are enabled, PostHog helps us understand aggregate product usage and improve HSKStory. For signed-in paid-conversion analytics, PostHog receives your numeric HSKStory User ID, not your email. We configure PostHog without advertising cookies or cross-site tracking.
5. Data Storage & Security
Your data is stored on secure servers. We use passwordless or external-provider authentication — no password is ever stored or transmitted. Account deletion has a 30-day grace period so you can cancel an accidental request by signing back in. After deletion, we remove app-owned account data unless a limited billing, security, tax, fraud-prevention, or legal-retention reason requires keeping a record. Data already sent to a provider follows the service-specific retention and data-rights process described above.
6. Your Rights (GDPR)
You have the right to access, correct, delete, or export your data, and to opt out of marketing. Email anthony@hskstory.com to exercise any of these rights, including a request to delete provider-held analytics data.
7. Cookies
We don't use advertising or tracking cookies. We use essential cookies for login and reader preferences (text size, font, voice). That's it.
8. Children's Privacy
Our service is not directed to children under 13. We do not knowingly collect personal data from children under 13.
9. Data Breaches
In the event of a data breach affecting your personal data, we will notify you within 72 hours.
10. Policy Changes
We will notify you of material changes to this policy via email before they take effect.