Sotare

Privacy Policy

Effective date: July 6, 2026
Last updated: July 30, 2026

Who we are

Sotare (sotare.app) is operated by Cleo and Sable House LLC, a limited liability company registered in Wyoming, United States (“we,” “us”). We are the data controller for the personal data described in this policy. Day-to-day operations are conducted by our team working from Israel, a country the European Commission recognizes as providing adequate data protection.

For anything privacy-related, contact us at privacy@sotare.app. This inbox is monitored and is the fastest way to exercise any of the rights described below.

What we collect

We deliberately collect very little. Here is the complete list:

Account data. Your email address, a securely hashed version of your password (we cannot see your actual password), and an optional display name if you choose to set one.

Reading data. Your position in each story you read — which chapter and block you’ve reached — so you can pick up where you left off and so we can enforce which chapters your plan includes.

Subscription data. Whether you have a subscription and which tier. Payment itself is handled entirely by our payment partner (currently Segpay), which acts as the merchant of record: your card number never touches our servers, and we never see or store it. Segpay collects payment data under its own privacy policy and provides us only with your subscription status. Because Segpay is the merchant of record, it is an independent controller of the payment data it collects, and billing records required by tax law are held by Segpay, not by us.

Technical logs. Like nearly every website, our servers automatically log IP addresses, browser type, and requested pages. We keep these logs for 30 days for security and debugging, then they are deleted.

Analytics data. We use Google Analytics to understand in aggregate how Sotare is used — which pages are visited, roughly where visitors come from, and what devices they use — so we can improve the service. Outside the EU and UK this runs by default; in the EU and UK it runs without cookies until you accept them in our cookie banner.

Emails you send us. If you contact support, we keep the correspondence for up to 24 months so we have context if you write again.

That’s it. We do not collect your real name (unless you email it to us), your location beyond what an IP address implies, your contacts, or anything from other apps or sites.

What we don’t do

We do not run advertising trackers. We do not sell your data, and we never have. We do not share your reading history with anyone for marketing. We use Google Analytics to measure aggregate usage so we can improve the service — never to build advertising profiles — and in the EU and UK its cookies are set only if you accept them.

We are also deliberate about one thing specific to Sotare: what you read is your business. Some of our catalog is mature romance, and we treat your reading history with the sensitivity that implies. Story titles from mature imprints never appear in email subject lines. The descriptor on your bank statement is deliberately neutral and never references story or imprint names. Reading-history data is retained only as long as your account exists.

Why we process your data, and on what legal basis

For readers in the EU, UK, and other GDPR-style jurisdictions, the law requires us to name a legal basis for each use of your data:

To provide the service (contract, Art. 6(1)(b)). Your email and password hash let you log in; your reading position lets you resume; your subscription status determines which chapters you can access; transactional emails (receipts, password resets, security notices) keep your account working. Without this data, we cannot provide the service.

To tell you about new releases (consent, Art. 6(1)(a)). If — and only if — you ticked the announcements box at signup or in settings, we’ll email you about new episodes and releases. The box is unticked by default. Every such email contains a one-click unsubscribe, and you can also toggle it in account settings. Withdrawing consent doesn’t affect anything else about your account.

To keep the service secure (legitimate interests, Art. 6(1)(f)). Server logs help us detect abuse, investigate security incidents, and fix bugs. We’ve weighed this against your privacy and limited retention to 30 days. We also keep a record that you gave (or didn’t give) marketing consent, so we can prove it if asked.

To comply with the law (legal obligation, Art. 6(1)(c)). Tax and accounting law requires billing records to be kept for up to 7 years. These are held by our payment partner as merchant of record; we retain only subscription status and transaction references.

Who processes data on our behalf

We use a small number of service providers (“processors”), each bound by a data processing agreement:

ProviderWhat they doWhere
RailwayHosts our API and databaseUnited States
VercelHosts the websiteUnited States (global CDN)
CloudflareServes images and static assetsGlobal CDN
Resend / PostmarkSends our emailsUnited States
Google (Google Analytics)Aggregate website analyticsUnited States (global)

None of these providers may use your data for their own purposes.

Separately, Segpay (US, with EU operations through Segpay EU Ltd, Ireland) processes payments as merchant of record. Unlike the processors above, Segpay is an independent controller of the payment data you give it at checkout, under its own privacy policy at segpay.com. If we change payment partners, we will update this section.

International transfers

We are a US company and our infrastructure is hosted in the United States, so your data is processed there. Our operations team accesses data from Israel, which benefits from an EU adequacy decision. Where our service providers process EU or UK personal data, those transfers are protected by the EU-US Data Privacy Framework and/or Standard Contractual Clauses built into our agreements with them. You can request a copy of the relevant safeguards at privacy@sotare.app.

How long we keep things

Account data and reading progress: for as long as your account exists, then deleted within 30 days of account deletion. Server logs: 30 days. Support emails: 24 months. Billing records: held by our payment partner for up to 7 years because tax law requires it. Marketing consent records: 12 months after account deletion, solely to prove consent was handled lawfully.

When you delete your account, we may retain fully anonymized, aggregated statistics (for example, “60% of readers finish chapter 4”) that cannot be connected back to you in any way.

Your rights

If you’re in the EU, UK, or a similar jurisdiction, you have the right to:

  • Access a copy of the personal data we hold about you
  • Correct inaccurate data
  • Delete your data (see also the in-app deletion flow below)
  • Export your data in a portable, machine-readable format
  • Object to processing based on legitimate interests
  • Withdraw consent for marketing at any time, with no effect on anything else
  • Complain to your local data protection authority, though we’d appreciate the chance to fix things first

How to exercise these rights: email privacy@sotare.app from the address on your account, or use the tools in account settings (deletion and data export are self-service). We respond within 30 days. If a request comes from a different email address, we’ll ask you to verify account ownership first — this protects you from someone else deleting or extracting your data.

Cookies

We use strictly necessary cookies — a session cookie that keeps you logged in and a security token that protects forms against forgery. We also use Google Analytics, which sets analytics cookies (for example, one named _ga). In the EU and UK these are set only if you accept them in our cookie banner; until then, analytics run without cookies. You can change your choice at any time by clearing cookies, and you can block analytics cookies through your browser or Google’s opt-out add-on.

Age requirement

Sotare is for adults. You must be 18 or older to create an account. We do not knowingly collect data from anyone under 18, and if we learn we have, we will delete the account and its data. If you believe a minor has created an account, contact privacy@sotare.app.

California residents

Sotare does not currently meet the thresholds that make the CCPA/CPRA legally applicable to us, but we extend equivalent rights to California residents voluntarily: the right to know what we collect (this policy is the complete inventory), the right to delete, and the right to correct. We do not “sell” or “share” personal information as those terms are defined in the CCPA, and we have not done so in the preceding 12 months, so there is nothing to opt out of. We do not use or disclose sensitive personal information for purposes requiring a right to limit. To exercise these rights, use the mechanisms in the “Your rights” section above; we will not discriminate against you for doing so.

Changes to this policy

If we change this policy in ways that matter — new data collected, new purposes, new providers — we’ll email account holders before the change takes effect and note the date at the top. Minor clarifications may be made without notice. Continued use after the effective date means the updated policy applies.

Contact

Cleo and Sable House LLC
1908 Thomes Ave, Cheyenne, WY 82001
privacy@sotare.app

Privacy Policy | Sotare