The short version
- We collect what an account, a library and a comment section actually require, plus a small amount of usage and crash data to keep the app working. You can read without an account.
- Ficverse shows no ads. It does use three measurement services — PostHog (product analytics), Sentry (crash reports) and AppsFlyer (which ad campaign brought you here). Each one has its own switch in Settings › Privacy, and none of them ever receives your stories, comments, searches, username or email.
- The app asks Apple’s tracking permission once, when you open your first story. Saying no changes nothing about how the app works.
- The app asks for no location, camera, microphone or contacts access. Notifications are optional; covers come from Apple’s system photo picker, which gives us only the image you choose.
- Individual reading-history records are deleted automatically after 90 days, and you can remove a story from your history yourself at any time.
- You can delete your account from inside the app, and you choose what happens to your stories.
This summary is for orientation only. The sections below are the policy.
1. Who we are and what this covers
Ficverse (“Ficverse”, “we”, “us”) is a fanfiction reading and
writing application for iPhone and iPad, distributed through the Apple App Store under the
bundle identifier com.secretengineer.Ficverse. This policy explains what personal
data we process when you use the app or visit ficverseapp.com,
why we process it, who else touches it, how long we keep it, and what you can demand from us.
For the purposes of the EU/UK General Data Protection Regulation (GDPR) and the Turkish Law on the Protection of Personal Data No. 6698 (KVKK), Ficverse is the data controller for the data described here. Contact details are in section 17.
This policy does not cover the practices of Apple, Google, or any website you reach by following a link inside the app. Their own policies apply to what they collect.
2. What we collect
2.1 Account and sign-in data
Ficverse has no password of its own. You sign in with Sign in with Apple or Google Sign-In, and we receive only what that provider returns to us:
- a stable user identifier issued by the provider;
- an email address — if you use Apple’s Hide My Email, this is a private relay address and we never see your real one;
- the display name you allow the provider to share, if any.
We never receive, see or store your Apple or Google password.
Browsing without an account. You can open Ficverse and read published stories as a guest. In that case we hold no account, profile or activity data about you: your reading position stays on your device only, and the usage events described in section 2.7 are tied to an anonymous per-install identifier rather than to a person. If you later create an account, the reading positions on that device are moved into it.
2.2 Profile data
- Username (required, public, unique) and display name.
- Bio, avatar and profile banner, if you add them.
- Date of birth — used to confirm you meet the minimum age for an account. We store the date, not a copy of any document, and we do not use it to filter stories.
- Interface language.
2.3 Content you create
- Stories and chapters, both drafts and published versions, including their title, summary, cover image, tags, age rating and content warnings.
- Comments and replies, including the paragraph a comment is attached to.
- Images you upload for covers, avatars and banners.
2.4 Activity data
- Likes, and follows of authors, stories and fandoms.
- Accounts you have blocked.
- Reports you submit about content or users, including the reason and any details you write.
- Reading progress — which chapter you are in and the paragraph you stopped at, so you can resume on another device.
- Reading history events — a record that an account read a chapter. They feed the History tab of your Library and aggregate story statistics such as view counts. These individual records are deleted automatically after 90 days, and you can remove a story from your history at any time by swiping it away, which also deletes your reading position in it.
- Enforcement status — if a moderator restricts your account, we record that it is banned and, for a temporary ban, until when. The app shows you this notice when you sign in.
2.5 Notification data
If you enable notifications we store the delivery token Apple issues for your device, the platform, a device name, and when that token was last used, together with your per-category notification switches (new chapters, comments, follows, likes). The token lets Apple’s push service deliver a notification to your device; it does not identify you to anyone else. We also keep the list of notifications shown inside the app, and whether you have read each one, so the list and the badge look the same on every device you use.
2.6 Technical data
Our hosting, storage and CDN providers process standard connection information — including your IP address, the time of the request and general request metadata — in order to deliver content and to protect the service against abuse. We do not use this data to build a profile of you, and we do not combine it with your reading history for advertising purposes.
2.7 Usage, crash and ad-measurement data
Three kinds of measurement data leave the app. Each is described in full in section 8, together with how to turn it off; in short:
- Usage events — which screens you open and which actions you take: a story was opened, a chapter finished, a comment posted, a search run, a notification tapped. An event carries only identifiers (story, chapter, author IDs), fixed labels and numbers. It never carries the text of a story, comment or search, and never your email or username — a rule enforced by the app’s code, not just by this policy. Events go to PostHog and to our own database. While you are signed in they are linked to your account ID; as a guest, to a random identifier generated for that installation, which is not Apple’s advertising identifier and disappears when you delete the app.
- Crash reports — if the app crashes, hangs or hits an unexpected internal error, Sentry receives the technical trace, your device model, iOS version and app version. Crash reports carry no account ID, no screenshots and no content.
- Ad-measurement data — AppsFlyer receives the fact that the app was installed and opened, a small subset of the usage events above (sign-up, sign-in, story opened, chapter finished, like or follow, story published), a one-way hashed derivative of your account ID that cannot be turned back into it, your IP address and device details including Apple’s vendor identifier (IDFV), and — only if you allowed tracking when asked — the advertising identifier (IDFA). Its sole purpose is to learn which ad campaign, if any, brought you to Ficverse.
2.8 Correspondence
If you email us for support, a copyright complaint or a privacy request, we keep that message and our reply so we can handle it and show what we did.
We do not collect: precise or coarse location, contacts, calendar, health or fitness data, financial or payment data, or browsing history from other apps. The advertising identifier (IDFA) is read only if you allow tracking when the app asks, and only by AppsFlyer. Ficverse contains no advertising SDK and shows no ads.
3. Device permissions and what they are used for
| Permission | When it is requested | What it is used for | Optional? |
|---|---|---|---|
| Notifications | After you sign in, or when you first turn a notification category on | Delivering alerts you asked for: new chapters from authors you follow, replies to your comments, new followers, likes on your stories | Yes — the app works fully without it, and you can revoke it in iOS Settings at any time |
| Photos | Never requested | Cover, avatar and banner images are chosen through Apple’s system photo picker. The picker runs outside the app and hands us only the single image you selected, so iOS does not grant Ficverse access to your photo library at all | Not applicable — no library access is ever granted |
| Network access | On launch | Loading stories, chapter files, images and your library | No — the app cannot function offline-only |
| Sign in with Apple | When you choose that sign-in method | Creating and authenticating your account | Yes — Google Sign-In is an alternative |
| App Tracking Transparency | Once, when you open your first story | Lets AppsFlyer read the advertising identifier (IDFA) so that your install can be attributed to the ad campaign that led to it. Nothing else in the app depends on the answer | Yes — decline and reading, writing, recommendations and notifications work exactly the same. The decision can be changed in iOS Settings › Privacy & Security › Tracking |
| Location, camera, microphone, contacts, calendar, health, Bluetooth, motion | Never requested | Not used. The app declares no usage descriptions for these and cannot access them | — |
Some data also stays only on your device and is never sent to us: unpublished text kept in the local draft cache, downloaded chapter files for offline reading, your reader appearance settings, your reading positions while you browse as a guest, your three privacy switches, and your session token, which is stored in the iOS Keychain. Deleting the app removes all of it.
4. How we use your data
- To run your account — signing you in, showing your profile, keeping your library.
- To deliver stories — serving chapter files, images and covers, and remembering where you stopped so you can continue on another device.
- To show relevant content — Discover is built from the fandoms and authors you follow, the tags you read and what is popular. This is content ranking, not advertising profiling.
- To check the minimum age — your date of birth confirms that you meet the minimum age for an account. It does not hide stories: Adult-rated chapters are shown to anyone who confirms they want to read them.
- To send notifications you turned on, and only those.
- To keep the platform safe — reviewing reports, enforcing the content rules, applying blocks, detecting spam and abuse, hiding content, and suspending or banning accounts that break the rules.
- To produce aggregate statistics — reads, likes and comment counts shown on a story. These are counts, not identified lists of who read what.
- To understand how the app is used and to fix it — which screens and features are used, where readers stop, and which crashes and errors happen, so we can improve the app and repair the failures that lose drafts.
- To measure advertising — to learn which campaign brought a new reader to Ficverse, so we spend on ads that work. This is attribution, not personalised advertising: Ficverse shows no ads and builds no advertising profile of you.
- To answer you when you contact support.
- To meet legal obligations and to establish, exercise or defend legal claims.
We do not use your data to train third-party AI models, and we do not sell it. Ever.
5. Legal bases for processing
Under GDPR Article 6 and KVKK Articles 5–6, we rely on:
| Purpose | Legal basis |
|---|---|
| Account, profile, publishing, reading, library, progress sync | Performance of a contract (our Terms of Use) |
| Push notifications | Your consent (the iOS permission prompt and the in-app switches) |
| Mature / explicit content access | Your explicit consent, combined with age verification |
| Moderation, safety, anti-abuse, service security | Legitimate interests — keeping a user-generated-content platform safe and lawful |
| Aggregate statistics and service improvement | Legitimate interests — understanding what works, using the least identifiable data that answers the question |
| Product analytics (PostHog, our database) and crash reports (Sentry) | Legitimate interests — keeping the app working and improving it, using identifiers rather than content, with an opt-out switch for each in Settings › Privacy |
| Ad measurement (AppsFlyer) | Your consent for the advertising identifier — the App Tracking Transparency prompt; legitimate interests for the identifier-free measurement that remains, with an opt-out switch in Settings › Privacy |
| Responding to legal requests, retaining moderation records | Legal obligation and legitimate interests |
Where we rely on consent, you can withdraw it at any time — this does not affect processing that already happened.
6. What is public, and what is not
Ficverse is a publishing platform, so some data is public by design. Please read this before you publish anything.
| Data | Visibility |
|---|---|
| Username, display name, bio, avatar, banner | Public to anyone using the app |
| Published stories and chapters | Public. Chapters are delivered through a worldwide network of servers, and copies may be held there for a time so they load quickly |
| Comments | Public, together with your username |
| Follower and following counts, story counts | Public |
| Email address, date of birth | Private — never shown to other users |
| Drafts and unpublished chapters | Private to you |
| Reading progress, reading history, likes, blocks | Private to you |
| Reports you file | Visible only to moderators; the reported user is not told who reported them |
| Usage events, crash reports, ad-measurement data | Never shown to other users |
Once something is published, other people can read, quote or screenshot it. Removing it from Ficverse does not remove copies other people already made.
Stories imported from other platforms. A small number of stories on Ficverse are added by our team from other platforms, with attribution to their original author. For those, the author’s public username on the source platform is shown as the author. These authors have no Ficverse account; we hold nothing about them beyond that public username and the source of the story. If you are such an author and want your work or your name removed, write to legal@ficverseapp.com.
7. Who we share data with
We do not sell personal data and we do not share it for personalised advertising. We use a small number of providers who process data on our instructions:
| Provider | Role | What it processes |
|---|---|---|
| Supabase | Database, authentication, file storage and server functions | Account, profile, content, activity data |
| Cloudflare | Storage and worldwide delivery of chapters and cover images, and hosting of this website | Published chapters, images, connection information such as IP addresses |
| Apple | Sign in with Apple, App Store distribution, push notification delivery (APNs) | Sign-in identifier, device token, notification payloads |
| Google Sign-In — only if you choose that method | Sign-in identifier and email address | |
| PostHog | Product analytics (EU-hosted) | Usage events with your account ID, or the anonymous install identifier if you are a guest. Never content, email or username |
| Sentry | Crash and error reporting (EU-hosted) | Crash traces, device model, iOS and app version. No account ID, no content |
| AppsFlyer | Mobile ad attribution | Install and selected in-app events, a hashed account ID, IP address, device identifiers (IDFV; IDFA only with your permission). AppsFlyer reports attribution results to the ad network that served the ad — currently Meta, TikTok, X and Apple Ads — so that campaign can be measured |
| Slack | Our moderators’ workspace | When you file a report, or when something you posted is reported, the report — its reason, the details the reporter wrote, the reporter’s username, an excerpt of the reported content and its author’s username — is posted to a private channel where our moderators review it and record their decision. Slack acts only as a tool for us and does not use this data for its own purposes |
| The Movie Database (TMDB) | Source of series and film metadata | None of your data. TMDB is queried only by our servers, for titles and cast information. The app never contacts TMDB directly and no user data is sent there |
We may also disclose data:
- to comply with a law, court order or valid request from a public authority;
- to enforce our Terms of Use, or to investigate suspected fraud, abuse or a threat to anyone’s safety;
- to a successor entity in a merger, acquisition or asset sale — in which case this policy continues to apply until you are given notice of any change.
8. Analytics, crash reports and ad measurement — and how to turn them off
Ficverse shows no advertising and contains no advertising SDK. It does measure three things, through three separate services, and each has its own switch in Profile › Settings › Privacy. Turning a switch off takes effect immediately; events waiting to be sent are discarded rather than flushed.
| Switch | Service | What it receives | What it never receives |
|---|---|---|---|
| Share usage data | PostHog (EU) and our own database | Event names such as story_opened or comment_created, the IDs of the story, chapter or author involved, fixed labels (which tab, which sign-in method) and counts; your account ID while signed in, an anonymous install identifier otherwise; app version |
Story or chapter text, comment text, search queries, report details, email, username, display name |
| Send crash reports | Sentry (EU) | Crash and hang traces, unexpected internal errors, device model, iOS version, app version | Your account ID, screenshots, the contents of any screen, any personal data |
| Ad measurement | AppsFlyer | Install and app-open events; sign-up, sign-in, story opened, chapter finished, like/follow and story published events with their IDs; a hashed, irreversible derivative of your account ID; IP address; vendor identifier (IDFV); the advertising identifier (IDFA) only if you allowed tracking | Screen views, searches, comments, reports, blocks, any text, your raw account ID, email or username |
The tracking prompt
Apple requires an app to ask before it reads the advertising identifier for attribution. Ficverse asks once, when you open your first story, so that you see what the app is before deciding. If you decline, AppsFlyer still receives the identifier-free events above and Apple’s privacy-preserving SKAdNetwork / AdAttributionKit reports, which tell an ad network only that an install happened, not who you are. Declining disables nothing. You can review the current status in Settings › Privacy and change it in iOS Settings › Privacy & Security › Tracking.
What we do not do
- We do not show ads, sell ad space, or build a profile of your interests for advertising.
- We do not use usage or attribution data to decide what stories you see; Discover is ranked from your follows and what is popular, exactly as described in section 4.
- We do not send any of this data to social networks or data brokers ourselves. The only party that receives attribution results is the network that served the ad you tapped, through AppsFlyer, and only for the purpose of measuring that campaign.
- The anonymous install identifier used for guests is generated by the app, is not Apple’s advertising identifier, and is never shared with AppsFlyer or any ad network.
- The website you are reading uses no cookies for advertising or analytics. A small amount of localStorage remembers only your language and light/dark preference; it never leaves your browser.
9. International data transfers
Our providers operate infrastructure in several countries. Supabase, Cloudflare, PostHog and Sentry process Ficverse data in the European Economic Area (Cloudflare also caches published chapters and images worldwide so they load quickly); AppsFlyer and Slack process data in the EEA and the United States. This means your data may be transferred outside the country you live in, including outside Türkiye and the EEA.
Where such a transfer happens, we rely on appropriate safeguards — European Commission Standard Contractual Clauses with our processors, or an adequacy decision where one exists — and, for transfers subject to KVKK, on the transfer mechanisms permitted by Article 9 of that law. You can ask us for details of the safeguards in place using the contact details below.
10. How long we keep data
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account |
| Drafts and unpublished chapters | Until you delete them or delete your account |
| Published stories and chapters | Until you unpublish or delete them. On account deletion, you choose whether they are deleted or remain published without an author |
| Comments | Until you delete them. On account deletion they are anonymised rather than deleted, so other people’s reply threads stay readable |
| Reading progress, likes, follows, blocks | Until you remove them or delete your account |
| Individual reading-history events | Automatically deleted after 90 days, or earlier if you remove the story from your history. Only aggregate counts survive |
| Push notification tokens | Until you disable notifications, sign out, or delete your account |
| In-app notification list | Until you delete your account |
| Usage events (PostHog and our database) | Up to 24 months. On account deletion the account ID is detached from events in our database |
| Crash reports (Sentry) | 90 days |
| Ad-measurement data (AppsFlyer) | Up to 24 months |
| Reports and moderation records, including ban records and the Slack messages about a case | Up to 24 months after the case is closed, so repeat offenders can be identified and decisions can be justified. A permanent ban is kept for as long as it is in force |
| Support and legal correspondence | Up to 3 years, or longer where a legal claim requires it |
| Encrypted backups | Deleted data disappears from live systems immediately and ages out of backups within 30 days |
11. Your rights
Depending on where you live, you have the right to:
- Access the personal data we hold about you, and get a copy of it;
- Correct data that is wrong or incomplete — most of it you can edit yourself in the app;
- Delete your data — see section 12;
- Restrict or object to processing based on our legitimate interests;
- Port your data — receive it in a structured, machine-readable format;
- Withdraw consent you previously gave, such as for notifications, mature content or tracking — and turn off usage data, crash reports and ad measurement at any time in Settings › Privacy;
- Not be subject to a decision based solely on automated processing that produces legal effects. We do not make such decisions; enforcement actions against an account are reviewed by a person.
- Complain to a supervisory authority — in Türkiye the Personal Data Protection Authority (KVKK), or in the EEA/UK your local data protection authority.
To exercise any of these, email privacy@ficverseapp.com from the address linked to your account, or tell us your username. We answer within 30 days and will tell you if we need longer. We may need to verify your identity first — we will not ask for more data than is necessary to do so, and we never ask for a copy of an identity document by email.
12. Deleting your account
You can delete your account entirely from inside the app — no email, no support ticket:
- Open Profile, then Settings.
- Choose Delete account.
- Confirm by typing your username, and choose what should happen to your stories.
What happens then:
- Your account, profile, drafts, reading progress, reading history, likes, follows, blocks, notifications and push tokens are deleted.
- Your stories: if you chose to delete them, they and their chapter files and covers are removed. If you chose to keep them published, they remain readable with no author attached and can no longer be edited.
- Your comments are anonymised, not deleted, so replies written by other people remain intelligible.
- Usage events already stored in our database are detached from your account ID. PostHog and AppsFlyer stop receiving anything the moment the account is gone; if you also want the events they already hold erased, ask us at privacy@ficverseapp.com and we will pass the request on.
- Moderation records relating to reports about you may be retained for the period in section 10, as is necessary to keep the platform safe.
Deletion is permanent and cannot be undone. Deleting the app alone does not delete your account.
13. Children and age limits
Ficverse is not intended for children. You must be at least 13 years old to create an account — or older where your country sets a higher minimum age for consenting to online services (16 in several EEA countries).
- Every story and chapter carries a General, 13+ or Adult label, shown before you start reading.
- An Adult-rated chapter opens only after the reader explicitly confirms it. This is a confirmation, not an age check: we do not verify anyone’s age, and a stored date of birth does not hide any story.
- Sexual content involving minors is forbidden without exception and is removed immediately, with the account permanently banned and, where required, reported to the competent authorities.
We do not knowingly collect data from children under 13. If you believe a child under that age has created an account, write to privacy@ficverseapp.com and we will delete the account and its data.
14. How we protect data
- Everything the app sends to us and receives from us travels over an encrypted connection. Unencrypted connections are blocked outright.
- Your sign-in is held in the iPhone’s own secure storage (the Keychain), not in ordinary app files.
- The database itself decides who is allowed to read what, so one account cannot reach another account’s private information even if someone tampers with the app.
- Administrative keys exist only on our servers. The app never carries a key that could unlock anything beyond your own account.
- We never handle your Apple or Google password, so there is no password of yours for us to lose.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the competent supervisory authority as required by law (within 72 hours under GDPR).
15. Regional notices
Türkiye (KVKK)
Your data is processed under Articles 5 and 6 of Law No. 6698 on the grounds set out in section 5. Under Article 11 you may learn whether your data is processed, request information about it, learn its purpose, know the third parties it is transferred to, request correction or erasure, object to a result produced solely by automated analysis, and claim compensation for damage caused by unlawful processing. Requests go to privacy@ficverseapp.com.
European Economic Area and United Kingdom (GDPR)
The rights listed in section 11 apply in full, and you may lodge a complaint with your national data protection authority.
California (CCPA/CPRA)
We do not sell personal information. Passing install and in-app events to AppsFlyer and, through it, to the ad network that served an ad may count as “sharing” under California law. You can opt out at any time by declining the tracking prompt and turning off Ad measurement in Settings › Privacy; we honour that choice without asking you to create an account. We do not offer financial incentives in exchange for personal information, and we do not discriminate against anyone who exercises their privacy rights.
16. Changes to this policy
We may update this policy as the app changes. The “last updated” date at the top always reflects the current version. If a change materially affects how we use your data, we will give notice in the app before it takes effect, and where the law requires it we will ask for your consent again. Continuing to use Ficverse after a change takes effect means you accept the updated policy.
17. Contact us
If you have a question about this policy, or you want to exercise a right described in it, get in touch. We would rather answer a question than have you guess.
- Data controller Ficverse — Türkiye
- Privacy requests privacy@ficverseapp.com
- General support support@ficverseapp.com
- Copyright / legal legal@ficverseapp.com
- Website ficverseapp.com
This policy is published in English and Turkish. Both versions describe the same practices; if a difference in wording creates a conflict, the Turkish version prevails for users resident in Türkiye and the English version prevails elsewhere.