Privacy Policy
What we collect, what we deliberately don't, and who else ever sees it.
Last updated September 20, 2026
The short version
We collect your email address and what you bought, because that is how we give you your books and how we prove they're yours.
We never see your card number. We don't use Google Analytics, advertising pixels or any third-party tracker. Our visitor counting is our own, it stores no IP address and no user agent, and it throws the detailed rows away after 90 days.
We don't sell your data. Not to anyone, not ever.
The business responsible for the data on this site is [Legal entity name — to be confirmed], at [Business address — to be confirmed]. Questions go to help@fernbug.com.
What we store when you buy a book
Against your order we keep:
- Your email address — it is the identity the whole purchase hangs on.
- What you bought: the series, the book and the age tier, or the series bundle.
- The money: subtotal, any bundle credit, any discount, the total, the currency, and anything later refunded.
- The discount code you used, if you used one.
- Stripe’s identifiers for the payment and the charge, so we can match a payment back to your order.
- The page you were on when you started checkout, and any utm_ tags that were in the URL, so we know which page or email sent you.
We do not store your card number, expiry, CVC or billing address. The payment form on our checkout page is Stripe's own, embedded in ours; your card details go from your browser to Stripe and never pass through our servers.
We create an account for you automatically when a payment succeeds, using that same email. Your account row holds your email, an optional display name you can set yourself, whether you've opted in to marketing email, and when you last signed in.
What we store when you get in touch
The contact form keeps your name, your email address and your message. If we turn that into a support ticket — or if you open one yourself from your account — we keep the ticket's subject and category, every message on both sides of the conversation, and any files attached to it.
Ticket replies are sent to your email address by us, so a conversation you started in your account continues in your inbox.
What we store when you join the list
If you sign up for the free book or the mailing list, we keep your email address, where you signed up from, which free book you were sent, and when it went out. If you unsubscribe, we keep your address with the unsubscribe recorded against it — that is how we make sure we don't email you again by accident.
How we count visitors
We wanted to know which pages people read without handing our visitors to an advertising company, so we wrote our own counter. When you load a page it records:
- The page path, with identifiers stripped out before it leaves your browser — /account/tickets/T-000042 is stored as /account/tickets/[number].
- The host of the site that linked you here (for example "google.com"), never the full referring URL.
- Whether you are on a phone or a larger screen. That is the whole of the device detail.
- Any utm_ tags in the URL, capped and filtered so the beacon can’t be used to store anything else.
- A session id that lives in your browser’s session storage and expires after 30 minutes of inactivity.
- A long-lived random visitor id, "fb_vid", kept in your browser’s local storage. It is a random number with nothing attached to it, and it exists only so "returning visitor" can be counted at all.
- A one-way hash of your IP address, your browser’s user agent and a secret salt that changes every day. Because the salt rotates daily, the same person hashes to a different value tomorrow — the table cannot be used to follow anyone over time.
Your IP address and your user agent are not stored. They go into that daily hash and are dropped. Neither is your name or email ever attached to a pageview.
The detailed rows are rolled up into daily totals every night and deleted once they are 90 days old. What survives is a single row per day: how many pageviews, how many sessions, the most-read pages and the most common referring sites.
If your browser sends a Do Not Track signal, we send nothing at all. If you block or clear site storage, the counter still works but has no visitor id to send, so you simply look like a new visitor every time. The keys we use in your browser are fb_vid, fb_sid and fb_utm; clearing them removes everything we have put in your browser besides your sign-in session.
Cookies and browser storage
We use no advertising or tracking cookies. The only cookies are the ones that keep you signed in, set by our authentication provider when you sign in and cleared when you sign out. Everything else — the analytics ids above — is browser storage, not cookies, and stays on your device.
IP addresses
Your IP address is used while a request is being handled, to stop one machine from flooding checkout, the contact form or the visitor counter. Those limits are held in a short-lived cache and expire on their own. An IP address is never written into our database.
Email we send you
There are two kinds, and they behave differently.
Transactional email — sign-in links, your delivery email, invoices, replies to your support tickets. It has no open tracking and no click tracking; links in it are the real links, not rewritten ones. You can't unsubscribe from this kind, because it's how you receive what you paid for.
Marketing email — news about new books and the occasional offer. This kind is tracked: we record whether it was delivered, whether it was opened, and which links were clicked, against your email address, and links carry utm_ tags so we can see which email led to a visit or an order.
Two ways to stop marketing email, and both work immediately:
- The unsubscribe link at the bottom of every marketing email. It is signed to your address, so it needs no sign-in and it never expires — an unsubscribe link in a two-year-old email still works.
- The email preference toggle on your account page.
Who else touches your data
We're a small operation and we use a small number of services to run it:
- Supabase — our database, sign-in system and file storage. Your account, orders, entitlements, tickets and invoices live here.
- Stripe — payments. Your card details go to Stripe and only to Stripe. They also hold the payment record and send the card receipt to your email address.
- SendGrid — sends every email we send, transactional and marketing alike.
- Vercel — hosts the site and handles the requests your browser makes to it.
- Upstash — the short-lived cache behind our rate limits, which is where the IP addresses mentioned above briefly live.
We also use AI services to make the books — Anthropic, Together AI and ElevenLabs. They are sent story material, prompts and artwork descriptions. They are not sent your name, your email address, your order or anything else about you.
Beyond that, we share your data only when the law requires it. We do not sell it, and we do not pass it to advertisers or data brokers.
Children
Our books are for children; our store is not. Accounts, purchases and the mailing list are for the grown-up who is buying, and that is the only person we collect anything about. We don't ask for a child's name, age or photograph, and there is nothing in a book for a child to sign up to, comment on or share. Please don't let a child create an account or make a purchase on your behalf.
How long we keep things
- Detailed pageviews: 90 days, then deleted automatically. The daily totals that replace them contain no identifiers at all.
- Orders, invoices and credit notes: kept for as long as we’re required to keep business and tax records. These are the one thing we generally can’t delete on request.
- Your account, entitlements, tickets and mailing list entry: kept while you have them, and until you ask us to remove them.
- Email delivery, open and click records: kept while they’re useful for seeing whether a campaign worked.
Seeing, changing or deleting your data
You can see your orders, your invoices and your books, and change your display name and your email preferences, from your account page, any time.
You can delete your account yourself, from your account page. It shows you exactly what will be removed and what has to stay before you confirm, and it happens immediately — nobody has to read a request first. For a copy of what we hold, or a correction to something that's wrong, ask through the contact page or email help@fernbug.com and a person will do it by hand.
One honest caveat: deleting your account also ends your access to the books you bought, and we have to keep the order and invoice records behind it as accounting records even after the rest is gone.
[Statutory data-protection rights and supervisory authority — to be confirmed for the jurisdictions this business serves].
Keeping it safe
Your data sits behind row-level security in our database: your orders, tickets and invoices are readable by your signed-in account and by nobody else's. Invoice PDFs are kept in private storage and only ever handed out as short-lived signed links. Admin actions are logged with the person who took them. All traffic to the site is encrypted.
No system is perfect. If something ever goes wrong in a way that affects you, we'll tell you rather than hope you don't notice.
Changes to this policy
If what we do changes, this page changes with it and the date at the top moves. If a change is significant, we'll say so in an email rather than quietly editing the page.
Talking to us
Email help@fernbug.com, use the contact form, or open a ticket at your help desk.
This page describes what the site actually does, in plain language. It isn't legal advice, and it doesn't replace advice from a qualified lawyer in your own country.