← Back to the catalog

Privacy Policy

Last updated: 18 September 2026

Grimdark Archive is an independent fan project. We try to collect as little as possible, keep it first-party, and tell you plainly what happens. This page is a plain-language summary, not legal advice.

What we collect, and why

Anonymous usage analytics. To understand how the catalog is used and how fast it loads, we record first-party engagement (such as which books are opened, searches, clicks on the buy button and which format and retailer they went to, and the steps of a sign-in: whether the button was shown, clicked and completed, never who), page-performance measurements (Core Web Vitals), and a new-versus-returning flag. For each visit we also record which kind of page it began on, the site or link it arrived from if your browser sent one (the site's address only, never the page), any campaign tags in the address you followed (ref and utm), whether you are on a phone, tablet or desktop, and the family of your browser and operating system (never the full browser identifier or a version). Within a visit these are tied to a short-lived session id kept in your browser's sessionStorage that is discarded when you close the tab. It is not a cross-visit identifier and it is never joined to an account. To count how many different people visit in a day, we compute a hash from your network address and browser identifier keyed by a random value that is replaced every 24 hours and deleted the following day, and keep only the hash. It cannot be reversed, it cannot recognise you tomorrow, and the address and identifier it was computed from are not stored. We also record an approximate country from Cloudflare's edge network. Known crawlers are not counted, and to keep your own visits out of these first-party counts on a device, open the catalog or any book, series or author page with ?notrack=1 added to the address (?notrack=0 turns counting back on); this page and the legal pages run no first-party engagement script, so the switch does not work from here. We run no advertising. Cloudflare, which hosts the site, also collects cookieless page-view and page-speed statistics for us (Cloudflare Web Analytics): referrers, browser and device type, and country. It sets no cookies, keeps no cross-site identifier, and its script loads only after the page has finished loading; the opt-out above does not apply to it.

Reports you send. If you report a missing book, an inaccuracy or anything else about the catalog, we store your message and which book it was about. If you send any of those reports while signed in, it also carries your account, for one purpose: so the site can tell you, on a later visit, that the report has been addressed. The form says so before you send. That link is removed when you delete your account; the report itself stays, without it. If you report a bug, we store your message, an optional email (only if you choose to give one), and technical context attached at the moment you submit: your browser and operating system, viewport size, language, the page you were on, recent in-page actions, and any recent JavaScript errors. This is collected only when you submit a report, to help us reproduce and fix the problem. Bug reports are never linked to an account.

Your collection, without an account. The books you mark as owned or read are stored in your browser (localStorage). Unless you sign in, they are never sent to us. You can download them as a file at any time from the "Download my collection" control.

Accounts (optional)

Signing in is optional and exists to keep your collection in sync across your devices; the only other thing it is used for is the report notice described above. Everything above works without it. When sign-in is available and you choose to use it:

What an account stores. Your Google account identifier (an opaque number, not your name), your email address and whether Google marks it as verified, the times you created the account, last used it and first changed your collection, the set of books you have marked, a random per-browser id used to keep your devices in step, and, as described under Reports above, any report about the catalog you sent while signed in, until you delete the account. We do not store your name, your profile picture, or anything else Google offers.

What Google receives. When sign-in is available, a visit while signed out shows Google's own Continue with Google button, served by Google from accounts.google.com, so Google learns that your browser opened a page carrying its button. If you sign in, Google learns that you signed in to this site. Both are under Google's own policy, as an independent controller. See how Google uses information from sites that use its services (opens in a new tab).

Sign-in outcomes. We count how many sign-ins succeed, how many create a new account, and how many are refused and why, as daily totals with no identifier and no session id. These totals are kept on the server and are not affected by the opt-out above.

Who else processes it. Cloudflare hosts the site, the database that holds accounts and collections, and the cookieless page statistics described above. We do not sell or share your personal information, and accounts are never joined to the analytics above.

How long we keep it. A sign-in session lasts 90 days. An account is kept until you delete it. Deleting an account removes its sessions immediately and its remaining data shortly after, during periodic clean-up rather than on a fixed schedule. When you remove a book from a synced collection, a small deletion marker for that book is kept for 180 days so that your other devices learn about the removal, then it is cleaned up too. Expired sessions and other housekeeping data are removed the same way. There is no automatic deletion for inactivity.

Why we are allowed to. Because you asked for it: providing the sync you signed up for, and telling you about a report you sent while signed in, is the legal basis. There is no profiling and no marketing.

Your rights. You can see what we hold (your collection is the account; a report you sent while signed in is the message you typed, and the site shows you when it was addressed), download the collection as a file, sign out, and delete the account yourself from the account menu, which asks you to type your email address to confirm. Deleting the account ends every session on every device. For anything else, email us at the address below.

Cookies and local storage

We set no cookies on an ordinary visit. If you sign in, we set one strictly necessary first-party session cookie (__Host-bl_session, 90 days) that keeps you signed in. It is not used for tracking or advertising, so no consent banner is required. Google's sign-in button is Google's own and is covered by Google's policy. We use your browser's localStorage and sessionStorage for the purposes above. Clearing this site's data in your browser removes all of it.

Third parties

Buy links take you to Bookshop.org or Amazon, which apply their own tracking under their own policies. Those links carry our affiliate id, so the retailer can credit a purchase or sign-up to this site and pay us a commission (see the affiliate disclosure); review links to Goodreads and Audible carry nothing of ours. Retailers report purchases to us only in aggregate; we never receive anything that identifies you. Book cover images are loaded from Amazon and Open Library. The site is hosted on Cloudflare. We do not sell or share your personal information.

Retention

Raw analytics rows (the per-visit and per-event records described above) are kept for 13 months and then deleted; the daily totals computed from them are kept indefinitely and contain no identifiers. The random value that keys the daily visitor hash is deleted the day after its creation. Reports are kept for as long as they are useful for running and debugging the site, and a bug-report email is kept only to follow up on that report. Account retention is described above.

Your choices

Leave the email field blank if you do not want a reply. You can clear this site's data at any time from your browser. You never need an account to use the catalog or to keep a collection on one device. If a content blocker removes the Cloudflare analytics script, the site works exactly the same.

Contact

Questions, or want something removed? Email brian@desired-path.com.

Changes

We may update this policy. The "last updated" date above reflects the current version.