Skip to content

Privacy Policy

Effective 23 August 2026

This policy says what Illarin collects, why, who else sees it, and what you can do about it. Illarin is a personal project that makes no money, sells nothing, and has no reason to collect anything it does not need.

1. What we collect

1.1 Your account

If you sign up with an email address, we store the address and a hash of your password. We never store the password itself. If you sign in with Discord, we store your Discord user ID, and we receive the username and avatar Discord exposes. We also receive the email address on your Discord account when Discord says it is verified, and we use it to fill in your Illarin address only if you have none.

Every account also has the handle you chose, and the date it was created.

1.2 What you upload

The file you uploaded, kept exactly as you uploaded it. The name, blurb, tags, and adult content answer you attached. The images you added. Anything written inside the work itself.

1.3 Your settings

Whether you want to see adult content, and whether your adult work appears on your public profile.

1.4 Applications you connect

For each application you link: the name and version it reported, the permissions you granted it, when you linked it, and when it last used its access. Its access tokens are stored only as hashes.

1.5 Server logs

Our web server records the usual line for each request: the IP address it came from, the time, the address requested, the response status, and the browser’s user agent string. One-time link codes are stripped out of that line before it is written.

2. What we do not collect

  • We do not record who downloads what. Illarin counts downloads for a creator’s benefit. The record holds the asset, the format, the time, and whether the download came from a signed-in reader, the creator, a linked application, or nobody signed in at all. It holds no account, no IP address, and nothing else that could point back to a person.
  • There is no analytics product on the site, no advertising, no advertising or cross-site tracking cookies, and no third-party script watching you read.
  • Nothing you upload is scanned by a machine learning model. Illarin runs no content classifiers, and it does not use your work as training data.

3. Cookies and what your browser stores

Illarin sets a cookie holding your session when you sign in, and two short-lived cookies during a Discord sign-in so that it can bring you back to the page you started from. All three are strictly necessary to sign you in.

Your browser also keeps two things locally, which never reach us: your light or dark appearance choice, and, for the length of the tab, whether you asked to see adult content.

4. Why we use it

  • To run Illarin: signing you in, showing your work, search, downloads, and exports.
  • To hand your library to the applications you have linked, within what you granted.
  • To send you the emails the account needs, which are address verification and password resets.
  • To act on reports and enforce the Acceptable Use Policy.
  • To keep Illarin working and to see what broke when it does not.

6. Who else sees it

We do not sell your personal data, and we have no interest in doing so. It reaches:

  • Our hosting provider, whose servers hold the database, the uploaded files, and the logs.
  • Our email provider, which receives your address and the message when Illarin sends a verification or password-reset email.
  • Our monitoring provider, which receives the server logs described above so that we can see errors and outages.
  • Discord, if you choose to sign in or link with it.
  • Applications you link, which receive the work they are allowed to fetch.
  • Anyone, for work you publish and for your profile. That is the point of publishing.
  • Authorities, where the law, a court order, or a genuine safety risk requires it.

7. How long we keep it

Account data lasts as long as your account. Work you publish lasts until you delete it or it is removed. Deleted work sits in a 30 day recovery window while you can still restore it, and is destroyed after that. Sign-in sessions, email verification links, password reset links, and application linking codes all expire on their own. Server logs are kept for a short rolling window.

8. Your rights

You can see and change most of your data in your account settings, including your email address, your password, your handle, your linked applications, and your content preferences. Deleting an asset or your account is a normal control, not a request you have to file.

For anything else — a copy of your data, a correction you cannot make yourself, an objection, or withdrawing consent — write to team@illarin.xyz. If you are in California you have further rights under the CCPA and CPRA. If you are in the EEA or UK you have further rights under the GDPR and UK GDPR, including the right to complain to your data protection authority.

9. Children

Illarin is not for children under 13, and we do not knowingly collect anything from them. If you believe a child has given us personal data, write to team@illarin.xyz and we will delete it.

10. Where your data goes

Illarin’s servers, and the email, monitoring, and sign-in services it depends on, operate across several countries including the United States. Using Illarin means your data travels to those places. Where the law requires safeguards for that transfer, we rely on the ones our providers put in place, such as Standard Contractual Clauses.

11. Security

Passwords are hashed, never stored in readable form. Session tokens, password reset links, email verification links, and application tokens are stored as hashes too, so a copy of the database does not hand someone your account. Traffic to Illarin is encrypted in transit.

None of that makes a system perfectly secure. Use a password you use nowhere else, keep your Discord account secure, and write to team@illarin.xyz if you think someone has got into your account.

12. Changes

We may update this policy. The effective date at the top says when the current wording took effect, and for a change that matters we will say something through Illarin itself.

13. Contact

Privacy questions and requests go to team@illarin.xyz.

Next: Acceptable Use, the next documentBack to the top