Legal

Privacy Policy

Last updated: June 18, 2026

1. Who controls your data

ReadRom operates readrom.com and is responsible for the personal information collected through the ReadRom website, reader experience, account features, subscriptions, comments, ratings, and related support channels.

Controller contact: ReadRom, Mumbai, Maharashtra, India. Email: support@readrom.com. Privacy requests: privacy@readrom.com. If a fuller registered business name, business address, local representative, data protection officer, or regional contact becomes legally required, we will update this policy with that information.

2. Scope

This Privacy Policy explains how ReadRom collects, uses, discloses, stores, and protects personal information when you visit readrom.com, create an account, verify age, read books, use interactive features, contact us, use a ReadRom mobile app if available, or buy a subscription.

ReadRom is intended for users aged 18 years or older. By accessing ReadRom or creating an account, you represent that you are at least 18 years old and old enough to access mature romance content in your jurisdiction.

Personal information means information that identifies, relates to, describes, or could reasonably be linked with an identified or identifiable person. This can include direct identifiers such as an email address and indirect identifiers such as a device, account, payment, or pseudonymous browser identifier.

Unlike platforms that allow users to publish their own stories, ReadRom does not currently host user-submitted stories or writer uploads. User-submitted content on ReadRom is limited to features such as comments, ratings, likes, support messages, and similar interactions.

This policy should be read together with our Cookie Policy, Terms of Service, Refund Policy, and Your Privacy Choices page.

3. Information we collect

We collect information you provide directly, information created when you use ReadRom, and limited technical information from your browser or device.

  • Account information: email address, login events, authentication identifiers, account status, and user profile metadata if supplied through authentication providers.
  • Google Sign-In information: if you sign in with Google, we may receive information from Google such as your email address, authentication identifier, profile name, and profile image, depending on your Google settings and the permissions shown during sign-in.
  • Age verification information: date of birth, calculated age eligibility, and age-verification cookies or account metadata used to confirm that users are 18 or older.
  • Reading and interaction information: books and chapters accessed, reading progress, ratings, chapter likes, comments, content preferences, and subscription access state.
  • Payment and subscription information: Razorpay payment identifiers, subscription identifiers, payment status, plan information, billing events, and verification metadata. ReadRom does not store full card, UPI, wallet, or bank account details.
  • Support and communications: messages you send us, contact details used for support, and records of our responses.
  • Device, usage, and analytics information: page views, performance signals, browser/device details, approximate technical location derived from network information, and analytics events when analytics consent is enabled.
  • Cookie and local storage information: consent choices, reading preferences, reading progress, display settings, and random pseudonymous browser IDs used for ratings or chapter likes when functional storage is enabled.
  • Information we do not currently require: ReadRom does not currently ask for gender, mailing address, phone number, government ID, or user-uploaded story manuscripts as part of ordinary reader account creation.
  • If you do not provide information needed for a feature, we may not be able to provide that feature. For example, an email address is needed for account login, payment references are needed for paid subscription access, and functional storage consent is needed for device-based reading preferences.

Personal information categories

CategoryExamplesPrimary purposes
IdentifiersEmail address, account ID, authentication IDs, Google account identifiers if Google Sign-In is used, payment or subscription IDs, pseudonymous browser IDs.Account access, authentication, support, payments, ratings, likes, security.
Age verification informationDate of birth, calculated age eligibility, age-verification cookies, account age-verification status.Confirming 18+ eligibility, enforcing access rules, legal compliance, platform safety.
Commercial informationSubscription plan, payment status, renewal status, refunds, transaction references.Checkout, access control, accounting, tax, fraud prevention, support.
Internet or device activityPages visited, reading activity, device/browser details, analytics events after consent.Service delivery, analytics, performance, security, product improvement.
User contentComments, ratings, likes, support messages, content preferences.Community features, support, moderation, service improvement.
Sensitive informationReadRom does not intentionally collect sensitive personal information except limited payment-related data handled by Razorpay and account-login credentials/session data handled by authentication infrastructure.Payment security, authentication, fraud prevention, legal obligations.

4. Sources of personal information

We collect personal information from you, from your browser or device, from your use of ReadRom, and from service providers that help us operate the platform.

  • You provide information when you sign in, post comments, contact us, or make requests.
  • Your browser provides technical information and stores choices or preferences when allowed.
  • Supabase provides authentication, database, account, and session infrastructure.
  • Razorpay provides payment, subscription, fraud prevention, and payment-verification information when you start checkout or maintain a subscription.
  • Vercel Analytics, Umami Analytics, and Google Analytics may provide aggregate analytics information after analytics consent, including page views, engagement, traffic sources, performance signals, and aggregate site usage.

5. How we use personal information

We use personal information only for the purposes described in this policy or explained at the time of collection.

  • Provide and maintain ReadRom, including accounts, authentication, reading access, comments, ratings, likes, and reading progress.
  • Process subscriptions, verify payments, prevent payment fraud, manage renewals, and handle refunds or billing support.
  • Personalize the reader experience, including display settings, continue-reading features, and content organization.
  • Respond to support requests, privacy requests, complaints, and operational messages.
  • Improve site performance, content discovery, security, reliability, and product design.
  • Send service-related messages such as login codes, account notices, subscription notices, policy updates, and security alerts.
  • Send optional product or marketing communications only where permitted and with any required consent or opt-out rights.
  • Comply with legal, tax, accounting, dispute-resolution, and regulatory obligations.

6. Legal bases for processing

Where laws such as the GDPR or UK GDPR apply, our legal bases may include the following.

  • Contract performance: to create accounts, provide reading access, process subscriptions, and deliver requested features.
  • Consent: for optional cookies, local storage, analytics, marketing technologies, and optional communications where required.
  • Legitimate interests: to secure ReadRom, prevent abuse, improve functionality, debug errors, understand aggregate usage, and protect legal rights, balanced against user privacy interests.
  • Legal obligations: to keep tax, accounting, payment, fraud-prevention, compliance, and dispute records.
  • Vital interests or public interest: only if needed in unusual circumstances permitted by law.

Processing purposes and legal bases

Processing activityLegal basis where applicable
Create and maintain accountsContract performance; legitimate interests in providing and securing account access.
Verify age and enforce 18+ accessLegal obligations where applicable; legitimate interests in complying with content restrictions and platform safety; contract performance for account access.
Offer Google Sign-InContract performance; legitimate interests in providing secure authentication; consent or user direction through Google’s sign-in flow where applicable.
Deliver books, reading access, ratings, likes, comments, and reader featuresContract performance; legitimate interests in operating ReadRom.
Process subscriptions, refunds, and payment verificationContract performance; legal obligations; legitimate interests in fraud prevention and dispute handling.
Remember reading preferences and device-based reading progressConsent for functional storage where required.
Measure site performance and aggregate usageConsent for analytics technologies where required; legitimate interests for strictly necessary diagnostics.
Send OTP, account, subscription, security, and policy messagesContract performance; legal obligations; legitimate interests in service communications.
Send optional product or marketing communicationsConsent where required; legitimate interests or opt-out consent where permitted by applicable law.
Prevent abuse, spam, fraud, security incidents, and violations of termsLegitimate interests; legal obligations where applicable.
Comply with tax, accounting, legal, regulatory, and law-enforcement obligationsLegal obligations; legitimate interests in establishing, exercising, or defending legal claims.
Future advertising or cross-site marketing tools, if introducedConsent where required; opt-out rights where applicable. Not active today.

7. Cookies and similar technologies

We use essential cookies and similar technologies for sign-in, security, checkout, age verification, and saving privacy choices. With your consent, we use functional local storage for reading preferences and analytics scripts for aggregate site usage.

Unsigned users who confirm they are 18 or older may receive an age-verification cookie that lasts up to 30 days. Signed-in users who complete age verification may have age-verification status stored in account metadata and a long-lived browser cookie, unless they clear cookies or change accounts.

You can change choices at any time from the persistent Privacy choices widget, the Cookie preferences button, or the footer. ReadRom treats Global Privacy Control signals as a request to reject analytics and marketing technologies unless you later choose otherwise.

8. Mobile apps, device permissions, and app stores

If ReadRom is offered through Android or iOS apps, this policy also applies to app use. App stores, mobile operating systems, and device manufacturers may independently collect information under their own privacy policies and account settings.

Push notifications: if offered, we may use push notifications for service updates, reading reminders, subscription notices, or optional product updates. You can disable push notifications in your device settings or in-app settings where available.

Device permissions: ReadRom does not currently need camera, microphone, contacts, precise location, photo library, or file-storage permissions for ordinary reading. If a future feature requests a permission, we will ask through the operating system prompt and explain the feature purpose.

Mobile analytics and diagnostics: mobile apps may use app analytics, performance monitoring, and crash diagnostics such as Firebase Analytics, Firebase Crashlytics, Google Play services, Apple diagnostics, or similar tools. Where consent is required, analytics will be enabled only after consent.

Biometric login: if Face ID, Touch ID, fingerprint, or similar biometric unlock is offered, biometric templates are handled by the device operating system. ReadRom does not receive or store your biometric template.

9. Payments

Paid subscription checkout is handled by Razorpay. Razorpay may collect and process payment details, device information, fraud-prevention signals, and transaction information according to its own policies and legal obligations.

ReadRom receives the payment and subscription identifiers needed to verify payment, grant access, prevent duplicate processing, respond to billing issues, and maintain financial records. ReadRom does not directly store full card, UPI, wallet, or bank account details.

Service providers

ProviderRolePolicy
SupabaseAuthentication, database, account sessions, comments, ratings, subscription access checks.https://supabase.com/privacy
GoogleGoogle Sign-In if you choose to authenticate with Google; Google Analytics after analytics consent where configured; Google Play services or mobile app services if used in a ReadRom app.https://policies.google.com/privacy
RazorpayPayment checkout, payment verification, subscription billing, fraud prevention, payment security.https://razorpay.com/privacy/
VercelHosting, deployment infrastructure, performance, and analytics where enabled.https://vercel.com/legal/privacy-policy
Umami AnalyticsAnalytics enabled after analytics consent.https://umami.is/privacy
AppleApple App Store, iOS platform services, diagnostics, push notifications, or Sign in with Apple if introduced.https://www.apple.com/legal/privacy/

10. Sharing and disclosure

We do not sell personal information. We disclose personal information only as needed to operate ReadRom, comply with law, protect rights, or with your direction.

Where required, we use contracts or data-processing terms with service providers that process personal information for us. Users may contact support@readrom.com to ask for more information about processor safeguards or available data-processing terms, subject to confidentiality and legal limits.

  • Service providers and processors: hosting, authentication, database, analytics, payment processing, security, and support providers.
  • Payment partners: Razorpay and its payment ecosystem when you initiate or maintain a subscription.
  • Legal and safety recipients: regulators, courts, law enforcement, advisors, or counterparties if required by law or needed to protect rights, safety, security, or prevent abuse.
  • Business transfers: if ReadRom is involved in a merger, acquisition, financing, reorganization, or asset transfer, personal information may be transferred subject to appropriate protections.
  • Public areas and other users: comments, display names, ratings, likes, or other public interactions may be visible to other users depending on the feature. ReadRom does not display your email address, payment details, private reading progress, or support messages to other users.

11. Sale, sharing, and targeted advertising

ReadRom does not currently sell personal information and does not currently share personal information for cross-context behavioral advertising. We do not currently load third-party advertising pixels or behavioral ad networks.

We do not currently serve ads. If we introduce advertising, behavioral advertising, or cross-site marketing tools in the future, we will update this policy before launch and seek any required consent or provide required opt-out choices.

12. Data retention

We keep personal information only for as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or permitted by law.

  • Account records: kept while your account is active. After account closure, we generally deactivate the account for up to 6 months, then permanently delete or anonymize account records unless a longer retention period is required for legal, tax, accounting, security, fraud-prevention, dispute, or backup purposes.
  • Subscription and payment records: kept for up to 8 years where needed for billing, tax, accounting, refund, fraud-prevention, chargeback, and legal obligations, unless applicable law requires a different period.
  • Comments, ratings, likes, and reading activity: kept while the feature or account remains active. After account closure or a valid deletion request, we delete or anonymize these records within 6 months unless retention is legally required.
  • Support records: kept for up to 3 years after the issue is resolved unless a longer period is needed for disputes, legal obligations, or security investigations.
  • Consent and age-verification records: kept as needed to demonstrate privacy choices, age eligibility, and re-consent requirements. Stored cookie choices are treated as valid for 180 days from the date of consent unless changed or cleared earlier. Anonymous age-verification cookies last up to 30 days; signed-in age verification may remain in account metadata until the account is deleted or corrected.
  • Functional local storage: remains on your device until you clear browser storage, revoke consent, replace the stored values, or the relevant feature removes it.

13. Security

We use reasonable technical and organizational measures designed to protect personal information, including HTTPS/TLS for data in transit and reliance on established infrastructure providers for authentication, hosting, database, and payment processing.

No online service can guarantee perfect security. You are responsible for keeping access to your email account and devices secure, because ReadRom login may rely on email OTP or OAuth authentication.

14. International transfers

ReadRom may use service providers that process or store information in countries other than where you live. Those countries may have data-protection laws different from your own.

Where required, we rely on appropriate safeguards such as contractual protections, service-provider security commitments, adequacy mechanisms, consent, or other lawful transfer bases.

15. Your privacy rights

Depending on where you live, you may have rights to access, know, correct, delete, export, restrict, object to processing, withdraw consent, opt out of certain sharing or targeted advertising, or appeal a decision about your request.

To make a request, email support@readrom.com and include the email address associated with your ReadRom account. We may need to verify your identity before acting on a request. We will not discriminate against you for exercising privacy rights.

16. Account deletion

You may request deletion of your ReadRom account by emailing support@readrom.com from the email address associated with your account, or by providing enough information for us to verify the account.

After a verified deletion request or account closure, we will delete or anonymize personal information according to the retention periods in this policy, except where we need to retain information for legal, tax, accounting, payment, fraud-prevention, security, dispute-resolution, or enforcement purposes.

Deleting an account may remove access to reading history, comments, ratings, subscription state, and other account-linked features. Some public interactions may be removed, anonymized, or retained where legally necessary or technically required for platform integrity.

17. GDPR, UK GDPR, and EEA/UK rights

If you are in the EEA, UK, or another region with similar rights, you may have rights to access personal data, correct inaccurate data, delete data, restrict or object to processing, receive a portable copy, withdraw consent, and lodge a complaint with a supervisory authority.

Withdrawal of consent does not affect processing that happened before withdrawal, and some information may still be processed where another lawful basis applies.

ReadRom is operated outside the EEA and UK. Because our processing of European data is occasional, low-risk, and does not involve special categories of data on a large scale, we do not designate an EU or UK representative under Article 27 of the GDPR. You may exercise your rights or contact us directly at privacy@readrom.com.

18. How to complain

You may contact us at privacy@readrom.com if you have a privacy concern, complaint, appeal, or unresolved rights request.

If GDPR, UK GDPR, or similar law applies, you may also lodge a complaint with a supervisory authority. Examples include the UK Information Commissioner’s Office (ICO), France’s CNIL, Ireland’s Data Protection Commission (DPC), Germany’s state data protection authorities, or the authority in the EEA country where you live or work.

You may also contact us first so we can try to resolve the issue directly.

19. California privacy rights

California residents may have rights to know/access, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, and not be discriminated against for exercising CCPA rights.

ReadRom does not currently sell personal information or share personal information for cross-context behavioral advertising. Visit Your Privacy Choices to manage cookie, analytics, and opt-out choices. We also honor Global Privacy Control signals for analytics and marketing choices.

Under California's 'Shine the Light' law (Civil Code Section 1798.83), residents are entitled to ask whether a business has disclosed personal information to third parties for direct marketing. ReadRom does not disclose personal information to third parties for direct marketing purposes.

20. India DPDP-style rights

Where India’s digital personal-data framework applies, you may have rights to access information about processing, correct or erase personal data, withdraw consent, seek grievance redressal, and nominate another person where legally available.

You can contact support@readrom.com or privacy@readrom.com to exercise these rights. We will process requests according to applicable law and any identity-verification requirements.

To submit a grievance or query regarding your personal data under the DPDP Act 2023, you can contact our designated Grievance Officer (Data Privacy Grievance Officer) at privacy@readrom.com. We will acknowledge and address your grievance within the statutory timelines. If you are not satisfied with the Grievance Officer's response, you have the right to lodge a complaint with the Data Protection Board of India (DPBI) once established.

21. Children and teens

ReadRom is an adults-only service for users who are 18 or older. Users under 18 are not permitted to access ReadRom, create an account, read mature content, or buy subscriptions.

We use an age-verification gate to ask for date of birth or age eligibility before access. Unsigned users who verify age may receive a 30-day age-verification cookie. Signed-in users may have age verification stored in account metadata. If a user indicates they are under 18, access is blocked.

Because ReadRom is not available to users under 18, we do not offer a parental-consent onboarding path for 13–17 year olds. Parents or guardians may contact support@readrom.com about privacy concerns, suspected underage access, or deletion requests.

We do not knowingly collect personal information from children under 13. If we discover that an under-13 child has provided personal information, we will delete or anonymize it as soon as reasonably possible unless legal retention is required. We do not knowingly sell or share children’s personal information.

22. AI-assisted content disclosure

Some stories, cover art, character images, supporting visuals, summaries, metadata, or editorial support material available on ReadRom may be generated, edited, or assisted using artificial intelligence tools and human editorial processes.

ReadRom remains responsible for the final publication, presentation, and operation of content on the service. AI-assisted content disclosure does not mean that user personal information is used to train public AI models.

ReadRom may use internal or third-party AI tools for editorial support, content organization, moderation support, recommendations, customer support, or operational workflows. When personal information is involved, it is handled according to this Privacy Policy and applicable law.

23. Automated decision-making and profiling

ReadRom does not currently make decisions that produce legal or similarly significant effects using solely automated processing.

We may use basic product logic, such as subscription access checks, reading progress, sorting, recommendations, or fraud-prevention checks, to operate and secure the service.

24. Communications

We may send transactional messages such as OTP codes, subscription notices, payment notices, security alerts, and policy updates. These are part of the service.

If we send optional marketing or product updates, you can opt out using the instructions in the message or by contacting support@readrom.com. You may still receive transactional messages after opting out of optional marketing.

25. Data breach and security incidents

If we become aware of a security incident involving personal information, we will investigate and take steps required by applicable law, which may include notifying affected users, regulators, service providers, or payment partners where required.

Where GDPR or UK GDPR applies and a breach is notifiable to a regulator, we will aim to notify the relevant supervisory authority within 72 hours after becoming aware of the breach, unless the law provides otherwise. Where user notification is required, we will notify affected users without undue delay. In the United States and other regions, we will notify users or regulators without unreasonable delay or within the timeframe required by applicable law.

26. Languages

ReadRom currently provides its legal documents in English. If the service is offered in additional languages, we will aim to make core legal notices available in those languages where required or reasonably practical.

27. Changes to this policy

We may update this policy from time to time. If changes are material, we will provide notice through the site, email, renewed cookie consent, or another legally appropriate method.

The Last updated date at the top of this page shows when this policy was most recently revised.

28. Contact

For privacy questions, cookie choices, rights requests, complaints, or account deletion requests, contact support@readrom.com.

Cookie Policy · Your Privacy Choices · Terms of Service · Refund Policy · Contact us