Skip to content
Ficverse
  • Features
  • Safety
  • Privacy
  • Terms
EN TR

Legal

Privacy Policy

Effective: 9 August 2026 Last updated: 9 August 2026 Applies to: the Ficverse iOS/iPadOS app and ficverseapp.com

On this page

  1. Who we are
  2. What we collect
  3. Device permissions
  4. How we use it
  5. Legal bases
  6. What is public
  7. Who we share it with
  8. No ads, no tracking
  9. International transfers
  10. How long we keep it
  11. Your rights
  12. Deleting your account
  13. Children and age limits
  14. Security
  15. Regional notices
  16. Changes to this policy
  17. Contact us

The short version

  • We collect what an account, a library and a comment section actually require — nothing for advertising.
  • Ficverse contains no advertising SDKs, no third-party analytics and no cross-app tracking. The app never shows Apple’s tracking permission prompt because it does not track you.
  • The app asks for no location, camera, microphone or contacts access. Notifications are optional; covers come from Apple’s system photo picker, which gives us only the image you choose.
  • Individual reading-history records are deleted automatically after 90 days.
  • You can delete your account from inside the app, and you choose what happens to your stories.

This summary is for orientation only. The sections below are the policy.

1. Who we are and what this covers

Ficverse (“Ficverse”, “we”, “us”) is a fanfiction reading and writing application for iPhone and iPad, distributed through the Apple App Store under the bundle identifier com.secretengineer.Ficverse. This policy explains what personal data we process when you use the app or visit ficverseapp.com, why we process it, who else touches it, how long we keep it, and what you can demand from us.

For the purposes of the EU/UK General Data Protection Regulation (GDPR) and the Turkish Law on the Protection of Personal Data No. 6698 (KVKK), Ficverse is the data controller for the data described here. Contact details are in section 17.

This policy does not cover the practices of Apple, Google, or any website you reach by following a link inside the app. Their own policies apply to what they collect.

2. What we collect

2.1 Account and sign-in data

Ficverse has no password of its own. You sign in with Sign in with Apple or Google Sign-In, and we receive only what that provider returns to us:

  • a stable user identifier issued by the provider;
  • an email address — if you use Apple’s Hide My Email, this is a private relay address and we never see your real one;
  • the display name you allow the provider to share, if any.

We never receive, see or store your Apple or Google password.

2.2 Profile data

  • Username (required, public, unique) and display name.
  • Bio, avatar and profile banner, if you add them.
  • Date of birth — used to confirm you meet the minimum age and to decide whether mature or explicit stories can be shown to you. We store the date, not a copy of any document.
  • Content preference (general / mature / explicit) and interface language.

2.3 Content you create

  • Stories and chapters, both drafts and published versions, including their title, summary, cover image, tags, age rating and content warnings.
  • Comments and replies, including the paragraph a comment is attached to.
  • Images you upload for covers, avatars and banners.

2.4 Activity data

  • Likes, follows (of authors and of fandoms), bookmarks and reading lists.
  • Accounts you have blocked.
  • Reports you submit about content or users, including the reason and any details you write.
  • Reading progress — which chapter you are in and the paragraph you stopped at, so you can resume on another device.
  • Reading history events — a record that an account read a chapter, used to produce aggregate story statistics such as view counts. These individual records are deleted automatically after 90 days.

2.5 Notification data

If you enable notifications we store the delivery token Apple issues for your device, the platform, a device name, and when that token was last used, together with your per-category notification switches (new chapters, comments, follows). The token lets Apple’s push service deliver a notification to your device; it does not identify you to anyone else.

2.6 Technical data

Our hosting, storage and CDN providers process standard connection information — including your IP address, the time of the request and general request metadata — in order to deliver content and to protect the service against abuse. We do not use this data to build a profile of you, and we do not combine it with your reading history for advertising purposes.

2.7 Correspondence

If you email us for support, a copyright complaint or a privacy request, we keep that message and our reply so we can handle it and show what we did.

We do not collect: precise or coarse location, contacts, calendar, health or fitness data, financial or payment data, browsing history from other apps, or any advertising identifier. Ficverse contains no third-party advertising, attribution or analytics SDKs.

3. Device permissions and what they are used for

PermissionWhen it is requestedWhat it is used forOptional?
Notifications After you sign in, or when you first turn a notification category on Delivering alerts you asked for: new chapters from authors you follow, replies to your comments, new followers Yes — the app works fully without it, and you can revoke it in iOS Settings at any time
Photos Never requested Cover, avatar and banner images are chosen through Apple’s system photo picker. The picker runs outside the app and hands us only the single image you selected, so iOS does not grant Ficverse access to your photo library at all Not applicable — no library access is ever granted
Network access On launch Loading stories, chapter files, images and your library No — the app cannot function offline-only
Sign in with Apple When you choose that sign-in method Creating and authenticating your account Yes — Google Sign-In is an alternative
App Tracking Transparency Never requested Not applicable. Ficverse does not track you across apps or websites owned by other companies —
Location, camera, microphone, contacts, calendar, health, Bluetooth, motion Never requested Not used. The app declares no usage descriptions for these and cannot access them —

Some data also stays only on your device and is never sent to us: unpublished text kept in the local draft cache, downloaded chapter files for offline reading, your reader appearance settings, and your session token, which is stored in the iOS Keychain. Deleting the app removes all of it.

4. How we use your data

  • To run your account — signing you in, showing your profile, keeping your library.
  • To deliver stories — serving chapter files, images and covers, and remembering where you stopped so you can continue on another device.
  • To show relevant content — Discover is built from the fandoms and authors you follow, the tags you read and what is popular. This is content ranking, not advertising profiling.
  • To operate the age gate — your date of birth and content preference decide which age ratings are visible to you.
  • To send notifications you turned on, and only those.
  • To keep the platform safe — reviewing reports, enforcing the content rules, applying blocks, detecting spam and abuse, and removing content or accounts that break the rules.
  • To produce aggregate statistics — reads, likes and comment counts shown on a story. These are counts, not identified lists of who read what.
  • To answer you when you contact support.
  • To meet legal obligations and to establish, exercise or defend legal claims.

We do not use your data to train third-party AI models, and we do not sell it. Ever.

5. Legal bases for processing

Under GDPR Article 6 and KVKK Articles 5–6, we rely on:

PurposeLegal basis
Account, profile, publishing, reading, library, progress syncPerformance of a contract (our Terms of Use)
Push notificationsYour consent (the iOS permission prompt and the in-app switches)
Mature / explicit content accessYour explicit consent, combined with age verification
Moderation, safety, anti-abuse, service securityLegitimate interests — keeping a user-generated-content platform safe and lawful
Aggregate statistics and service improvementLegitimate interests — understanding what works, using the least identifiable data that answers the question
Responding to legal requests, retaining moderation recordsLegal obligation and legitimate interests

Where we rely on consent, you can withdraw it at any time — this does not affect processing that already happened.

6. What is public, and what is not

Ficverse is a publishing platform, so some data is public by design. Please read this before you publish anything.

DataVisibility
Username, display name, bio, avatar, bannerPublic to anyone using the app
Published stories and chaptersPublic. Chapters are delivered through a worldwide network of servers, and copies may be held there for a time so they load quickly
CommentsPublic, together with your username
Follower and following counts, story countsPublic
Email address, date of birth, content preferencePrivate — never shown to other users
Drafts and unpublished chaptersPrivate to you
Reading progress, reading history, likes, bookmarks, blocksPrivate to you
Reports you fileVisible only to moderators; the reported user is not told who reported them

Once something is published, other people can read, quote or screenshot it. Removing it from Ficverse does not remove copies other people already made.

7. Who we share data with

We do not sell personal data and we do not share it for advertising. We use a small number of infrastructure providers who process data on our instructions:

ProviderRoleWhat it processes
SupabaseDatabase, authentication, file storage and server functionsAccount, profile, content, activity data
CloudflareStorage and worldwide delivery of chapters and cover images, and hosting of this websitePublished chapters, images, connection information such as IP addresses
AppleSign in with Apple, App Store distribution, push notification delivery (APNs)Sign-in identifier, device token, notification payloads
GoogleGoogle Sign-In — only if you choose that methodSign-in identifier and email address
The Movie Database (TMDB)Source of series and film metadataNone of your data. TMDB is queried only by our servers, for titles and cast information. The app never contacts TMDB directly and no user data is sent there

We may also disclose data:

  • to comply with a law, court order or valid request from a public authority;
  • to enforce our Terms of Use, or to investigate suspected fraud, abuse or a threat to anyone’s safety;
  • to a successor entity in a merger, acquisition or asset sale — in which case this policy continues to apply until you are given notice of any change.

8. No advertising, no tracking

To be explicit, because many apps in this category are not:

  • Ficverse contains no advertising, and no advertising, attribution or measurement SDK.
  • It contains no third-party analytics or crash-reporting SDK. In fact the app ships with no third-party runtime dependencies at all.
  • It does not read your Identifier for Advertisers (IDFA) and never presents the App Tracking Transparency prompt, because there is nothing to consent to.
  • It does not track you across apps or websites operated by other companies, and it does not share your data for cross-context behavioural advertising.
  • The website you are reading uses no cookies for advertising or analytics. A small amount of localStorage remembers only your language and light/dark preference; it never leaves your browser.

9. International data transfers

Our providers operate infrastructure in several countries, including within the European Economic Area and the United States. This means your data may be transferred outside the country you live in, including outside Türkiye and the EEA.

Where such a transfer happens, we rely on appropriate safeguards — European Commission Standard Contractual Clauses with our processors, or an adequacy decision where one exists — and, for transfers subject to KVKK, on the transfer mechanisms permitted by Article 9 of that law. You can ask us for details of the safeguards in place using the contact details below.

10. How long we keep data

DataRetention
Account and profileUntil you delete your account
Drafts and unpublished chaptersUntil you delete them or delete your account
Published stories and chaptersUntil you unpublish or delete them. On account deletion, you choose whether they are deleted or remain published without an author
CommentsUntil you delete them. On account deletion they are anonymised rather than deleted, so other people’s reply threads stay readable
Reading progress, likes, follows, bookmarks, blocksUntil you remove them or delete your account
Individual reading-history eventsAutomatically deleted after 90 days. Only aggregate counts survive
Push notification tokensUntil you disable notifications, sign out, or delete your account
Reports and moderation recordsUp to 24 months after the case is closed, so repeat offenders can be identified and decisions can be justified
Support and legal correspondenceUp to 3 years, or longer where a legal claim requires it
Encrypted backupsDeleted data disappears from live systems immediately and ages out of backups within 30 days

11. Your rights

Depending on where you live, you have the right to:

  • Access the personal data we hold about you, and get a copy of it;
  • Correct data that is wrong or incomplete — most of it you can edit yourself in the app;
  • Delete your data — see section 12;
  • Restrict or object to processing based on our legitimate interests;
  • Port your data — receive it in a structured, machine-readable format;
  • Withdraw consent you previously gave, such as for notifications or mature content;
  • Not be subject to a decision based solely on automated processing that produces legal effects. We do not make such decisions; enforcement actions against an account are reviewed by a person.
  • Complain to a supervisory authority — in Türkiye the Personal Data Protection Authority (KVKK), or in the EEA/UK your local data protection authority.

To exercise any of these, email privacy@ficverseapp.com from the address linked to your account, or tell us your username. We answer within 30 days and will tell you if we need longer. We may need to verify your identity first — we will not ask for more data than is necessary to do so, and we never ask for a copy of an identity document by email.

12. Deleting your account

You can delete your account entirely from inside the app — no email, no support ticket:

  1. Open Profile, then Settings.
  2. Choose Delete account.
  3. Confirm by typing your username, and choose what should happen to your stories.

What happens then:

  • Your account, profile, drafts, reading progress, likes, follows, bookmarks, blocks and push tokens are deleted.
  • Your stories: if you chose to delete them, they and their chapter files and covers are removed. If you chose to keep them published, they remain readable with no author attached and can no longer be edited.
  • Your comments are anonymised, not deleted, so replies written by other people remain intelligible.
  • Moderation records relating to reports about you may be retained for the period in section 10, as is necessary to keep the platform safe.

Deletion is permanent and cannot be undone. Deleting the app alone does not delete your account.

13. Children and age limits

Ficverse is not intended for children. You must be at least 13 years old to create an account — or older where your country sets a higher minimum age for consenting to online services (16 in several EEA countries).

  • Everyone starts with access to General and Teen rated stories only.
  • Mature and Explicit stories are shown only to users whose stored date of birth makes them 18 or over and who have deliberately enabled that content preference.
  • Sexual content involving minors is forbidden without exception and is removed immediately, with the account permanently banned and, where required, reported to the competent authorities.

We do not knowingly collect data from children under 13. If you believe a child under that age has created an account, write to privacy@ficverseapp.com and we will delete the account and its data.

14. How we protect data

  • Everything the app sends to us and receives from us travels over an encrypted connection. Unencrypted connections are blocked outright.
  • Your sign-in is held in the iPhone’s own secure storage (the Keychain), not in ordinary app files.
  • The database itself decides who is allowed to read what, so one account cannot reach another account’s private information even if someone tampers with the app.
  • Administrative keys exist only on our servers. The app never carries a key that could unlock anything beyond your own account.
  • We never handle your Apple or Google password, so there is no password of yours for us to lose.

No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the competent supervisory authority as required by law (within 72 hours under GDPR).

15. Regional notices

Türkiye (KVKK)

Your data is processed under Articles 5 and 6 of Law No. 6698 on the grounds set out in section 5. Under Article 11 you may learn whether your data is processed, request information about it, learn its purpose, know the third parties it is transferred to, request correction or erasure, object to a result produced solely by automated analysis, and claim compensation for damage caused by unlawful processing. Requests go to privacy@ficverseapp.com.

European Economic Area and United Kingdom (GDPR)

The rights listed in section 11 apply in full, and you may lodge a complaint with your national data protection authority.

California (CCPA/CPRA)

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by California law. We do not offer financial incentives in exchange for personal information, and we do not discriminate against anyone who exercises their privacy rights.

16. Changes to this policy

We may update this policy as the app changes. The “last updated” date at the top always reflects the current version. If a change materially affects how we use your data, we will give notice in the app before it takes effect, and where the law requires it we will ask for your consent again. Continuing to use Ficverse after a change takes effect means you accept the updated policy.

17. Contact us

If you have a question about this policy, or you want to exercise a right described in it, get in touch. We would rather answer a question than have you guess.

  • Data controller Ficverse — Türkiye
  • Privacy requests privacy@ficverseapp.com
  • General support support@ficverseapp.com
  • Copyright / legal legal@ficverseapp.com
  • Website ficverseapp.com

This policy is published in English and Turkish. Both versions describe the same practices; if a difference in wording creates a conflict, the Turkish version prevails for users resident in Türkiye and the English version prevails elsewhere.

© 2026 Ficverse · Home · Terms of Use · Türkçe This product uses the TMDB API but is not endorsed or certified by TMDB.