THE GREMMOIRE · EFFECTIVE
Privacy Policy
Version 2026-07-19.2
Effective 2026-07-19
This Policy explains how The Gremmoire handles information when you visit, create an account, use community features, or make contact.
ValentineDesigns operates the Site. Privacy contact: [email protected].
1. Scope and hosting roles
This Policy covers The Gremmoire website, community, account, profile, messaging, and reader-related services. It does not replace the policies of external websites.
OpenAI hosts the published Site and processes hosted data for ValentineDesigns under the ChatGPT Sites Data Processing Addendum. ValentineDesigns decides why and how Site information is handled. OpenAI does not endorse The Gremmoire.
2. Information you provide
- Account information: private login username, public @handle, display name, password-derived security record, and role.
- Optional contact information: an email address and its verification status.
- Security information: passkey public credentials and device metadata, encrypted authenticator secrets, one-time backup-code digests, recovery requests, and security-event records. Device biometrics never reach the Site.
- Optional profile information: About Me, status, avatar, birthday, name, location, gender, profession, and their visibility choices.
- Community content: Lounge messages, forum threads and replies, board posts and replies, status comments, friend relationships, notifications, Private Messages, and Instant Messages.
- Support or rights requests and the information you include in them.
3. Information collected automatically
- Session, anti-abuse, and guest identifiers stored in cookies or similar browser storage.
- Presence heartbeats and coarse online status controlled by your visibility setting.
- Basic request and security data such as timestamps, requested paths, error records, and network address signals used for rate limiting and abuse prevention.
- Device-local preferences such as theme, text size, first-visit dismissal, installed-app state, reader progress, bookmarks, and local reader entries.
4. Local reader files
Book and story files imported into the reader are designed to be processed locally in your browser. Their contents are not intentionally uploaded. Reader progress and local-library details stay on your device unless a future feature clearly asks you to sync them.
5. How information is used
- Create and secure accounts, authenticate members, provide recovery, and maintain sessions.
- Operate profiles, friends, messages, notifications, community spaces, moderation, and owned-story bookshelves.
- Apply your visibility choices for optional profile and presence information.
- Prevent spam, fraud, abuse, compromise, and technical attacks; investigate incidents; and enforce the Terms.
- Maintain, troubleshoot, understand, and improve the Site; communicate important account, policy, security, maintenance, and service updates; and comply with law.
6. Legal bases where required
Where law requires a legal basis, information is processed as needed to perform this agreement, for legitimate interests in operating and securing the community, to comply with legal obligations, and with consent where required. Optional profile fields are supplied and shared at your choice.
Acknowledging this Policy is not blanket consent to every possible use. Optional processing that legally requires consent will be presented separately.
7. When information is shared
The Site does not sell personal information or use third-party behavioral advertising.
- With other members or the public according to the feature and visibility setting you choose.
- With OpenAI and infrastructure providers acting as service providers or processors for hosting, storage, delivery, security, and support.
- With an email-delivery or media provider only when enabled and needed to provide the feature.
- With advisers, authorities, or other parties when reasonably necessary for law, rights, safety, or abuse response.
8. Visibility and member choices
Public fields may be visible to anyone. Friends-only fields are returned only to accepted friends and you. Hidden fields are returned only to you for editing. Empty optional field labels are omitted.
Birthday sharing separately controls who can see it and whether the full date, month and day, month only, or nothing is shown. New personal-information fields default to hidden.
Online presence may be shown to everyone, friends only, or nobody. Private Messages and Instant Messages are limited to their participants. A report makes only the submitted message and bounded surrounding context available for authorized safety review, subject to the narrow legal and infrastructure exceptions in the Terms.
9. Cookies and browser storage
An essential HTTP-only session cookie keeps members signed in; an essential guest token supports temporary Lounge participation. Device preferences and reader data may use local or session storage and IndexedDB.
The Site does not use advertising cookies. If non-essential analytics or advertising storage is added, this Policy and any legally required consent control will be updated first.
10. Retention
- Ordinary signed-in sessions expire after 30 days unless ended sooner.
- Online presence is current only for a short rolling window.
- One-time verification, authentication, and recovery challenges expire quickly and become unusable after use.
- Account, profile, social, and community information remains while active, then is deleted, de-identified, or retained only as reasonably needed for backups, disputes, safety, legal duties, and enforcement. Message-report snapshots may be retained separately from the live participant thread while a safety review or related recordkeeping need remains.
- Device-local reader data remains until you remove it or clear Site storage.
11. Security
The Site uses measures designed for its risk, including salted password hashing with a server-side secret, HTTP-only sessions, same-origin mutation checks, rate limits, encrypted authenticator secrets, one-time recovery material, and public-key passkey verification. No system can guarantee absolute security.
Report suspected compromise or a privacy incident to [email protected].
12. International processing
The Site and its providers may process information in countries other than where you live. Where required, appropriate contractual or other lawful transfer safeguards apply.
13. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, withdraw consent, complain to an authority, or appeal certain decisions. Contact [email protected]; account verification may be required.
14. Children and age information
The Site is not targeted or designed for children. You must be at least 13, or any higher minimum age required where you live. Birthday is optional profile information and is not currently an identity-verification tool.
15. Sensitive information
Do not submit protected health information, payment-card data, government identifiers, precise home addresses, or other information the Site does not need. Optional gender and birthday fields may be sensitive in some places; they remain hidden by default.
16. Policy updates and contact
Material changes receive an in-site notice. Account holders will be asked to open and acknowledge the current version before continuing to protected features. Acceptance records document which version applied.
Privacy questions or requests: [email protected]. Operator: ValentineDesigns.