Noveletta Privacy Policy

Effective Date: December 23, 2025 Last Updated: December 23, 2025

This Privacy Policy explains how Guildling LLC ("Guildling," "we," "us," or "our") collects, uses, discloses, and protects information when you use Noveletta (the "Service"), including our websites, applications, and related services.

If you do not agree with this Privacy Policy, do not use the Service.

1. Who We Are

Controller (GDPR) / Business (U.S.): Guildling LLC Address: 365 S 43rd St, Boulder, Colorado 80305, USA Contact: legal@noveletta.com)

If you are located in the EEA/UK, the "controller" of your personal data is Guildling LLC.

2. Scope

This Privacy Policy applies to personal data we process when you:

  • visit our website(s),
  • create an account,
  • use Noveletta features,
  • publish or interact with public contributions, and/or
  • contact us for support.

3. What We Collect

We collect information in three main ways: (a) information you provide, (b) information collected automatically, and (c) information from third parties.

3.1 Information You Provide

You may provide:

  • Account information: email address, username/display name, authentication details (e.g., tokens), and account settings.
  • Profile information: optional bio, avatar, preferences (including spoiler/chapter settings if offered).
  • Public contributions (User Content): content you post, submit, edit, or otherwise contribute (such as notes, tags, comments, entity edits, feedback, lists, or other material). By default, contributions are public (see Section 6).
  • Communications: messages to support, feedback, survey responses, or other communications.
  • Payment information (if/when paid features exist): subscription status and transaction metadata. We do not intend to store full payment card numbers; payment processing will be handled by a third-party processor (TBD).

3.2 Information Collected Automatically

When you use the Service, we may collect:

  • Device and usage data: IP address, device/browser type, operating system, app version, pages/screens viewed, interactions, time spent, referrer URLs, and diagnostic logs.
  • Cookies and similar technologies: cookies, local storage, and similar tools to support login/session, preferences, security, and basic analytics.

3.3 Information From Third Parties

We may receive:

  • Authentication provider info (e.g., Google/Apple sign-in if enabled): stable identifiers, email address, and basic profile details depending on your provider settings.
  • Service provider data (e.g., uptime/monitoring logs) in connection with operating the Service.

4. How We Use Information

We use personal data to:

  • Provide and operate the Service (create accounts, authenticate users, maintain preferences, display content).
  • Publish and display public contributions (consistent with your settings and defaults).
  • Maintain safety and integrity (prevent abuse, spam, fraud; secure accounts; enforce rules).
  • Communicate with you (support responses, critical notices, policy updates, service messages).
  • Improve the Service (debugging, performance monitoring, product development, and analytics).
  • Process payments (if/when paid features exist, via a third-party processor).
  • Comply with legal obligations and enforce our agreements.

5. Legal Bases for Processing (GDPR)

If you are in the EEA/UK, we rely on the following legal bases:

  • Performance of a contract (Article 6(1)(b)): to provide the Service you request (account creation, features, settings).
  • Legitimate interests (Article 6(1)(f)): to secure and improve the Service, prevent abuse, and understand usage in a privacy-respecting way. We balance these interests against your rights.
  • Consent (Article 6(1)(a)): where required (e.g., certain cookies or optional features). You can withdraw consent at any time.
  • Legal obligation (Article 6(1)(c)): where we must comply with law.

6. Public by Default Contributions

Noveletta is designed as a knowledge base where contributions are public by default.

That means:

  • Your User Content may be visible to other users and the public (depending on product design).
  • Certain profile information (such as your display name and avatar) may appear alongside your contributions.
  • Even if you delete content, copies may persist temporarily in caches, backups, logs, or where other users have quoted or referenced it.
  • You may have tools to edit, remove, or control visibility of certain content. Availability of controls may vary by feature and maturity of the Service.

7. How We Share Information

We may share information as follows:

7.1 Service Providers (Processors)

We use vendors to run the Service. These vendors process personal data on our behalf under contractual obligations.

Current core providers include:

  • Supabase (database, authentication, storage, related infrastructure services)
  • Vercel (hosting, web delivery, and related infrastructure)

We may also use additional vendors for:

  • Email delivery (TBD)
  • Payment processing (TBD)
  • Monitoring / error logging (TBD)

7.2 Legal, Safety, and Enforcement

We may disclose information if we believe it is reasonably necessary to:

  • comply with law, regulation, legal process, or governmental request,
  • protect the rights, property, and safety of Guildling, our users, or others,
  • investigate or prevent abuse, fraud, security, or technical issues,
  • enforce our terms and policies.

7.3 Business Transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal data may be transferred as part of that transaction.

7.4 With Your Direction

We share information when you instruct us to (for example, sharing content publicly, integrating third-party services, or authorizing disclosures).

8. Cookies and Similar Technologies

We use cookies and similar technologies for:

  • Essential functionality (login/session, security, preferences)
  • Basic analytics and performance (to understand how the Service is used and improve it)

Where required by law (including in the EEA/UK), we will provide a cookie banner and consent mechanism for non-essential cookies, and you may withdraw consent at any time through available controls.

You can also control cookies through your browser settings. Disabling cookies may break certain features.

9. No Targeted Advertising / No Sale of Data

We do not currently plan to run ads and we do not sell personal data in the traditional sense.

If we ever introduce advertising or tracking practices that change these statements (including "sharing" for cross-context behavioral advertising under certain U.S. state laws), we will update this policy and provide required choices and controls.

10. Data Retention

We retain personal data for as long as reasonably necessary to:

  • provide the Service,
  • maintain security and prevent abuse,
  • comply with legal obligations,
  • resolve disputes, and
  • enforce agreements.

Retention depends on the type of data. We may retain aggregated or de-identified data longer.

Backups and logs may persist for a limited period even after deletion requests, consistent with reasonable operational needs.

11. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal data. However, no system can be guaranteed 100% secure.

12. International Transfers

We are based in the United States and may process/store data in the U.S. and other countries where we or our service providers operate.

For EEA/UK users, when personal data is transferred outside the EEA/UK, we rely on appropriate safeguards (such as Standard Contractual Clauses and/or other lawful transfer mechanisms) as required by applicable law.

13. Your Rights and Choices

13.1 GDPR Rights (EEA/UK)

You may have the right to:

  • access your personal data,
  • correct inaccurate data,
  • delete your data,
  • restrict processing,
  • object to processing,
  • data portability,
  • withdraw consent (where processing is based on consent), and
  • lodge a complaint with a supervisory authority.

13.2 U.S. State Privacy Rights

Depending on your state, you may have rights to access, delete, correct, and opt out of certain processing. Even though we do not plan ads/sale, we will honor applicable requests.

13.3 How to Exercise Rights

Email privacy@noveletta.com with your request. We may need to verify your identity before responding.

14. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal data from children under 13. If we learn we have collected such data, we will delete it.

15. Third-Party Links

The Service may link to third-party sites/services. Their privacy practices are governed by their own policies, not ours.

16. Automated Processing

We may use automated systems to help operate, protect, and improve the Service (for example, to organize content, detect abuse, maintain quality, and support features). These systems may process information you submit and information generated through your use of the Service.

We do not make decisions that produce legal or similarly significant effects about you solely through automated processing.

17. Changes to This Policy

We may update this Privacy Policy from time to time. If changes are material, we will provide notice by posting the updated policy and updating the Effective Date (and where appropriate, via email or in-product notice).

18. Contact Us

Email: privacy@noveletta.com Mail: Guildling LLC, 365 S 43rd St, Boulder, Colorado 80305, USA

Feedback