Privacy Policy
MythFan is committed to transparent data practices. This policy explains what information we collect, how we use it, and the controls available to you as a user.
01.Information We Collect
We collect three categories of information:
(a) Information you provide directly — account registration data (username, email, password hash), discussion posts, wiki contributions, character profile submissions, and voting actions (Oracles, Souls, Devotions).
(b) Information generated automatically — IP address, browser type and version, device fingerprint, pages viewed, referral URL, session timestamps, and interaction logs. This data is collected via server logs and client-side telemetry.
(c) Information from third-party integrations — OAuth profile data (Google, Discord) when you choose to sign in via these providers, limited to your display name and email address.
We do not collect payment data directly; any monetized services route through third-party processors who maintain their own privacy frameworks. We do not collect or store government-issued identification numbers, biometric data, or precise geolocation data.
02.How We Use Your Data
Collected data is used to:
(a) Operate and improve platform services, including authentication, content delivery, and search functionality; (b) Generate aggregated, anonymized community statistics (Oracles, Souls, Devotions) for ranking and display purposes; (c) Enforce community guidelines, detect abuse, and prevent manipulation of voting systems; (d) Send transactional communications such as password resets, account alerts, and policy change notifications; (e) Maintain platform security, including fraud detection and rate limiting.
We do not sell your personal data to third parties. We do not serve behavioral advertising. We do not use your data to train external machine learning models. Aggregated, anonymized data may be used for internal research and platform improvement.
03.Data Sharing & Disclosure
MythFan does not sell, rent, or trade your personal data. We may share information in the following limited circumstances:
(a) With service providers — third-party hosting, CDN, and analytics providers who process data on our behalf under data processing agreements. These providers are restricted from using your data for any other purpose.
(b) For legal compliance — if required by law, court order, or government regulation, we may disclose specific data to the extent necessary. We will challenge overly broad or improper requests where feasible.
(c) To protect rights and safety — where we believe in good faith that disclosure is necessary to protect the safety of users, the public, or the platform from harm, fraud, or illegal activity.
(d) In connection with a business transfer — in the event of a merger, acquisition, or asset sale, user data may be transferred subject to the protections of this policy. You will receive notice of any such transfer.
04.Data Retention
Account data is retained for the duration of your active account plus a 90-day grace period following deletion request, after which it is permanently removed from our primary systems.
Anonymized interaction logs (votes, page views, search queries) may be retained indefinitely in aggregate, non-identifiable form for analytics and ranking algorithm improvement.
Discussion content and wiki contributions you author may remain archived in anonymized or pseudonymized form after account deletion, as these contributions are part of the community knowledge base. A formal erasure request can be submitted to [email protected] if you wish to have your authored content removed.
Server logs (IP addresses, request timestamps) are retained for 90 days for security and debugging purposes, then automatically purged.
05.International Data Transfers
MythFan operates globally and your data may be processed on servers located in different jurisdictions. When data is transferred across borders, we rely on appropriate legal mechanisms such as Standard Contractual Clauses (SCCs), adequacy decisions, or other recognized transfer frameworks.
Users in the European Economic Area, UK, and Switzerland should be aware that their data may be transferred to countries that have different data protection standards. We ensure that such transfers comply with applicable data protection laws and that appropriate safeguards are in place.
06.Third-Party Services
This platform integrates the following categories of third-party services:
(a) Infrastructure providers — cloud hosting and CDN services that store and deliver platform content; (b) Authentication providers — Google and Discord OAuth for optional sign-in; (c) Analytics providers — privacy-respecting analytics tools that process data in aggregate; (d) Communication providers — email delivery services for transactional emails.
Each third party operates under its own data processing agreement and privacy policy. A current list of sub-processors is available upon request by contacting [email protected]. We review our third-party integrations periodically to ensure compliance with our privacy standards.
07.Cookies & Tracking Technologies
We use strictly necessary cookies to maintain session state and user preferences. These include authentication tokens, CSRF protection, and language preference (EN/ES).
Optional analytics cookies may be deployed with your explicit consent. Analytics cookies are disabled by default and activated only upon opt-in. We do not use third-party advertising cookies or cross-site tracking pixels.
A detailed breakdown of cookie categories, specific cookies used, and opt-out mechanisms is available in our Cookie Preferences document.
08.Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
(a) Access — request a copy of the personal data we hold about you; (b) Rectification — request correction of inaccurate or incomplete data; (c) Erasure — request deletion of your personal data ('right to be forgotten'); (d) Restriction — request that we limit processing of your data under certain conditions; (e) Data Portability — request your data in a structured, machine-readable format; (f) Objection — object to processing based on legitimate interests; (g) Withdrawal of Consent — withdraw consent for optional data processing at any time.
Users in the European Economic Area and UK enjoy additional statutory rights under GDPR and UK GDPR. California residents have rights under CCPA/CPRA. Brazilian users are protected under LGPD.
To exercise any of these rights, submit a request through your account settings or via [email protected]. We will respond within 30 days. We do not charge fees for processing rights requests unless they are manifestly unfounded or excessive.
09.Children's Privacy
This platform is not directed at individuals under the age of 18. We do not knowingly collect personal information from minors. Our age requirement is enforced at registration.
If you believe a minor has submitted information to this platform or created an account, contact us immediately at [email protected]. We will promptly delete such information and terminate the account upon verification.
10.Security
We implement industry-standard technical and organisational measures to protect data against unauthorized access, disclosure, alteration, or destruction. These include:
(a) TLS encryption for all data in transit; (b) Bcrypt hashing for all stored passwords; (c) Access-controlled infrastructure with least-privilege principles; (d) Regular security audits and vulnerability assessments; (e) Rate limiting and anomaly detection to prevent automated attacks; (f) Segregated environments for development, staging, and production.
No transmission over the internet or storage system is fully secure. While we strive to protect your data, we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials.
11.Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, MythFan will notify affected users within 72 hours of becoming aware of the breach, where required by applicable law. Notification will include: the nature of the breach, categories of data affected, measures taken to mitigate, and recommended actions for users.
Notifications will be sent via email and, where appropriate, displayed as a platform-wide notice. We will also notify relevant supervisory authorities where legally required.
12.Policy Changes
Material changes to this policy will be announced via a platform notice at least 14 days prior to taking effect. The 'Last updated' date at the top of this document reflects the most recent revision.
Non-material changes (clarifications, formatting updates, or administrative edits) may be made without prior notice but will be reflected in the updated date. Your continued use following the effective date constitutes acceptance of the revised policy.
13.Contact Us
Questions, concerns, or rights requests regarding this Privacy Policy may be directed to [email protected]. Please include 'Privacy Request' in the subject line for expedited handling.