Privacy Policy
TropeWeaver • tropeweaver.co.uk • UK GDPR + COPPA
For Parents and Guardians — Quick Summary
12 and under can have an account with your permission, but they only see wholesome books (spice 0-1). Anything spicy (spice 2+) is hidden everywhere — Popular, search, trope pages, TBR, Recommendations, shared links and Profile history.
- We collect date of birth, age, and whether they are 13+ / 16+, to enforce this. It is stored privately (only your child and our admins can see it), never shared or sold, and never shown to other users or advertisers.
- We keep it while the account is active and delete it within 30 days of a deletion request. A small cache is kept on your child's device to make the site fast and is cleared on logout.
- You can request review, correction, or deletion of your child's data at any time via our Contact Form — select Child Data Request / Parental Request. Include your child's username or email and your relationship.
- No behavioural advertising to children, no sale of personal data, and no sharing of DOB with Open Library, Google Books, IsbnDB, or affiliate networks.
Full details are in Sections 4, 7 and 8 below. This box is just a plain-language summary.
1. Introduction
TropeWeaver is a UK-built community archive for finding books by tropes, moods, themes and spice level. This Privacy Policy explains what data we collect, why we need it, how long we keep it, and your rights over it. We process personal data in line with UK GDPR and the Data Protection Act 2018. Although we are UK-focused, we also comply with the US Children’s Online Privacy Protection Act (COPPA) because we provide age-gated book discovery and take protection of younger readers seriously.
By creating an account or using TropeWeaver you agree to this policy. If you have questions, use our Contact Form (select "Data / Privacy Request" or "Child Data Request / Parental Request").
2. Who we are — data controller
Data controller: TropeWeaver. Contact: via the Contact form on /about (select "Data / Privacy Request" or "Child Data Request / Parental Request"). Hosting and database infrastructure is provided by Buildy / Superdev (the platform powering TropeWeaver). They act as a data processor on our behalf and only process data to provide hosting, authentication, storage and backups.
3. Data we collect
- Account data: email address, display name or username, authentication tokens and account creation date. Provided when you sign up via our auth provider.
- Age verification data: date of birth in YYYY-MM-DD format you enter in the mandatory AgeGateDialog, plus derived fields we compute and store: age in years, is_13_plus boolean, is_16_plus boolean, and max_allowed_spice (1, 2 or 5). Collected once during onboarding, directly from you. See Section 4 for full handling details.
- Community content: trope tags you add, which trope the tag relates to, book IDs you interact with, TBR list entries, read books and reading history, reading challenges progress, star ratings, spice / burn / pace / point-of-view ratings, written reviews, and community book suggestions. Tags and reviews show your display name publicly, everything else is private to you or aggregated anonymously.
- Technical data: IP address, browser user agent, basic request logs for security and abuse detection, timestamps of actions.
- Cookies and local storage: essential auth cookies to keep you signed in, plus localStorage keys tw_dob, tw_age, tw_is16plus and tw_is13plus for age-gating performance. See Section 13.
4. Age verification data — how we handle it
We collect date of birth because we operate a three-tier content restriction system based on spice level. It is a core safety feature, not an optional preference.
Why we collect it
To comply with our legal obligation to protect children, to enforce the age-appropriate tiers described in Section 7, and to provide an age-appropriate reading experience. Without it we cannot show or hide books correctly.
What exactly is stored
- date_of_birth — string YYYY-MM-DD as you entered it
- age — integer calculated at save time and recalculated on server read
- is_13_plus — boolean (true if age 13 or over)
- is_16_plus — boolean (true if age 16 or over)
- max_allowed_spice — integer: 1 for under 13, 2 for 13-15, 5 for 16+
Where it is stored and who can see it
In the private UserProfile entity in our secure database. This table is protected by Row Level Security: only you can read and update your own row. Site administrators have read access for moderation and support, and that admin access is logged. Your DOB is never public, never shown on your profile page, never shared with other users, never sold, and never sent to book-data providers (Open Library, Google Books, IsbnDB) or affiliate networks (AWIN, Amazon, Bookshop.org).
Local cache
For performance we cache tw_dob, tw_age, tw_is16plus and tw_is13plus in your browser localStorage after you complete the AgeGateDialog. This lets us filter content without an extra server call on every page. These keys are cleared when you log out. They are not tracking cookies and are not sent to third parties.
Security
DOB data is encrypted at rest by our hosting platform. Access is limited to you and administrators only. We do not collect government ID, passport, or any other verification documents — it is self-declared DOB only.
Accuracy and corrections
You provide your DOB directly. If you make a typo, contact us via the Contact form (select "Data / Privacy Request") to request correction. Administrators can delete your stored DOB which forces the age gate to re-appear on next login so you can re-enter it. Providing a false DOB to bypass restrictions is a breach of our Terms.
No automated profiling beyond tiering
We do not use DOB for automated decision making, advertising profiling, or behavioural targeting. The only automated logic is mapping age to one of three content tiers and filtering spice ratings accordingly.
5. How we use your data
- To create and manage your account and keep you signed in.
- To enforce the three-tier age filter: deciding which books to show or hide, which spice rating options are enabled, and showing hidden-count banners and age-gating messages.
- To save your TBR, read history, challenge progress and personal recommendations.
- To calculate community average spice ratings per book and apply filtering site-wide: homepage Popular Right Now, search results, trope pages, TBR, Find Your Next Obsession recommendations, shared recommendation links, shared challenge links, and profile history.
- To display trope tags, reviews and ratings with your display name where you chose to contribute publicly.
- To improve discovery, deduplicate tags, and moderate content.
- To answer support requests and send essential service updates.
- To detect spam, abuse, or attempts to bypass age gates.
6. Lawful basis (UK GDPR)
- Contract: processing needed to provide your account, lists, challenges and core features you signed up for.
- Consent: where you voluntarily submit trope tags, reviews, book suggestions, and non-essential cookies if we add them in future.
- Legal obligation: protecting children by enforcing age-appropriate content tiers and complying with COPPA and UK child safety expectations.
- Legitimate interest: securing the service, preventing abuse, understanding aggregated usage without identifying individuals, and improving TropeWeaver. For age data, our legitimate interest is specifically child safety and providing age-appropriate content as required by our Terms.
- COPPA consent and parental permission: we allow users aged 12 and under to have an account provided a parent or guardian has given permission. By allowing a child aged 12 or under to create and use an account, the parent consents to our collection of the minimal data described in this policy (email, display name, DOB, age flags, TBR, read lists, ratings limited to Tier 1). For under-13 users in the US we obtain verifiable parental consent through this permission requirement — the parent must supervise account creation and explicitly allow use. If a parent later withdraws consent, we delete the child’s data within 30 days.
7. Three-tier content restriction system
We filter books based on the community average spice rating (1 to 5). The rating is calculated from all spice_ratings submitted by readers for that book. If a book has no ratings yet, it remains visible until the community rates it.
How filtering works in practice:
- We load your UserProfile, compute community averages for each book in the current view, then hide those over your max_allowed_spice threshold.
- Filtering applies everywhere: Popular Right Now on homepage, search results, trope pages, Your Reading List (TBR), Find Your Next Obsession (Recommendations — both matched books and your saved recommendations), Shared Recommendations links, Shared Challenges links, and Profile History.
- User experience: when books are hidden we show an amber banner stating how many were hidden for age reasons and links to Terms and Privacy. Rating controls for disallowed spice levels are disabled with an explanation. Empty states explain that no books match your current filters within your age tier.
- Shared links respect the viewer’s age, not the sharer’s. If you share a recommendation containing a spice 3 book, a 14-year-old opening it will not see that book — they see the age-appropriate version.
- We make a best-effort to filter correctly but spice averages rely on community submissions. We do not guarantee perfect filtering and encourage reporting mis-rated books.
8. Children’s data and COPPA compliance
TropeWeaver allows readers aged 12 and under to have an account with parent or guardian permission, and we comply with the US Children’s Online Privacy Protection Act (COPPA) and UK GDPR provisions for children.
- 12 and under can have an account with parent permission. If you are 12 or under you may create and use an account only if your parent or guardian has given permission and supervises your use. By allowing you to use TropeWeaver they consent to our collection of the minimal data needed to run your account: email, display name, date of birth, age, is_13_plus / is_16_plus flags, max_allowed_spice, TBR, read history, challenge progress and Tier 1 ratings and tags.
- What 12 and under can see and do: Tier 1 — spice 0-1 only. Every book averaging spice 2 or higher is hidden everywhere: Popular Right Now, search, trope pages, TBR, Recommendations, shared links, profile history. They cannot see anything spicy, cannot submit spice 2+ ratings, and cannot submit tags describing romantic or sexual content beyond wholesome patterns.
- How we obtain parental consent under COPPA: during sign-up and in the mandatory AgeGateDialog we explain the age tiers and that 12 and under need parent permission. We rely on the parent actively permitting account creation and entry of DOB as consent. For US users under 13, this permission serves as verifiable parental consent to collect the limited data described above for the purpose of providing an age-filtered reading experience only. We do not collect more than is necessary, and we do not require ID documents.
- Minimal data and no behavioural ads: for 12 and under we collect only what we need to provide Tier 1 filtering and your lists. We do not show personalised ads to any user, including children. We do not sell personal data. Children’s DOB is never used for advertising, never shared with Open Library, Google Books, IsbnDB, AWIN, Amazon or Bookshop.org, and never used for cross-site tracking.
- 13 to 15 year olds: may hold an account without additional parental consent under UK GDPR (13 is the age of consent for information society services) but are restricted to Tier 2 — spice 0-2 only, 3+ hidden, cannot submit spice 3+ ratings. Same minimal collection as adults.
- Parental rights under COPPA: a parent or guardian can submit a request via our Contact Form — select Child Data Request / Parental Request — at any time to review what personal information we have collected from their child, direct us to delete it, and refuse to allow further collection or use. We will verify you are the parent or legal guardian before acting and will complete deletion within 30 days. You can also request we reset DOB so the age gate re-appears.
- No third-party tracking of children’s age data: book-data APIs receive only book IDs and search terms, not DOB. Affiliate networks only receive a click after you actively choose to buy, and Buy links are not shown in a way that encourages children to make purchases.
- If parental consent is withdrawn or not given: if we learn a child aged 12 or under is using TropeWeaver without parent permission, we will restrict the account to Tier 1 and contact the email on file where possible, and delete the account and all personal data including DOB within 30 days if consent is not confirmed or is withdrawn.
- Contact for parents: use our Contact Form and select Child Data Request / Parental Request. We aim to respond within 7 working days for child-related requests.
For FTC information about COPPA, see ftc.gov/legal-library/browse/federal-register-notices/childrens-online-privacy-protection-act-coppa . For UK ICO children’s guidance, see ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/children/ .
9. Retention and deletion
- Account data and age data: kept while your account is active. DOB, age, is_13_plus, is_16_plus, max_allowed_spice are part of your UserProfile and deleted when you delete your account or request erasure. For 12 and under, this includes data collected with parental consent, deleted within 30 days of consent withdrawal.
- Deletion timeline: upon account deletion or erasure request, we delete or anonymise personal identifiers including DOB, email, display name association, TBR, read books, challenges, and community content attribution within 30 days where technically feasible. Aggregated counts (e.g. how many users rated a trope) may remain but contain no DOB or identifiable info.
- Backups: backups rotate on a 30 to 90 day cycle. DOB may persist in encrypted backups until rotation overwrites them.
- Child data: if parental consent is withdrawn for a child 12 or under, or we learn a child is using TropeWeaver without parent permission, we delete the child’s account and personal data including DOB within 30 days as described in Section 8, in line with COPPA retention limits.
- Local cache: tw_dob, tw_age, tw_is16plus, tw_is13plus are removed from browser storage on logout. You can also clear them manually via browser settings.
10. Data security
We take security seriously. DOB and other personal data are encrypted at rest by our hosting provider. UserProfile rows are protected by Row Level Security so only you can read your own data; administrators have read access for moderation only. Admin actions are logged. We enforce HTTPS, secure auth tokens, and regular dependency updates. No method is 100% secure, but we review access controls regularly and limit who can see age data to what is strictly necessary.
11. Third parties and data sharing
We do not sell your personal data. We share only what is needed to run TropeWeaver:
- Hosting / infrastructure: Buildy / Superdev host our database, auth and file storage. They may process DOB and account data solely to provide hosting.
- Book data providers: Open Library, Google Books API, IsbnDB — we send only book identifiers, ISBNs or search terms. No DOB, email or age flags are sent to them.
- Email delivery: if we send transactional email (verification, support reply), we share only email address and message content with the provider.
- Affiliate partners: AWIN (Waterstones), Bookshop.org UK, Amazon UK — they receive no personal data from us. Only after you click a Buy link do they set their own cookies to attribute a sale. Your DOB is never shared with them.
- Legal: we may disclose data if required by UK law, court order, or to protect children’s safety.
12. Affiliate tracking
TropeWeaver is reader-supported. Some outbound Buy links are affiliate links: Waterstones via AWIN (Publisher 2990225 / Advertiser 3787), Bookshop.org UK (ID 17793) and Amazon UK (Associates ID tropeweaver0c-21). When you click a Buy link we may earn commission at no extra cost to you. AWIN, Amazon and Bookshop.org may set their own cookies only after you click, to attribute the purchase back to us. Those cookies are controlled by the retailer or network — see their privacy notices. We disclose the affiliate relationship in the site footer and on any page with affiliate links, in line with UK ASA and CMA guidance. Affiliate cookies are never set before a click, and age data is never included in affiliate attribution.
13. Cookies
- Essential auth cookies: set by our auth provider to keep you signed in. Strictly necessary under PECR, no consent needed.
- Age-gating localStorage: tw_dob, tw_age, tw_is16plus, tw_is13plus — stored locally in your browser for performance (so we can filter without repeated server calls). Not cookies in the HTTP sense, but similar. Cleared on logout. No tracking purpose.
- Affiliate cookies after click: set by AWIN, Amazon or Bookshop.org only after you actively click a Buy link. They attribute any purchase within their window back to TropeWeaver. Controlled by the retailer.
- No analytics or ad cookies today: we set no non-essential analytics, advertising or social tracking cookies ourselves. If we add them in future we will ask for consent first and update this policy.
14. International transfers
Our hosting provider and some book-data providers may process data outside the UK, including in the US. Where transfers outside the UK occur we rely on UK adequacy regulations or Standard Contractual Clauses as a safeguard. Your DOB is not transferred to book-data providers or affiliate networks; the only cross-border processing of DOB is within our hosting platform’s encrypted database as needed to run the service.
15. Your rights
Under UK GDPR you have:
- Access: request a copy of personal data we hold about you, including your stored DOB, age flags, TBR, read history and ratings.
- Rectification: request correction of inaccurate DOB or other data. You can also ask us to reset DOB so you can re-enter via the age gate.
- Erasure: request deletion of your account and associated personal data including DOB within 30 days.
- Restriction and objection: object to certain processing where we rely on legitimate interest, including processing for child safety tiering — note that objecting to age tiering will require us to limit or delete your account as we cannot provide an ungated experience to protect children.
- Portability: request your data in a portable format.
- Complain: lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk. If you are in the US and believe COPPA has been breached, you can complain to the US Federal Trade Commission (FTC) at ftc.gov.
To exercise rights use our Contact Form and select "Data / Privacy Request" or "Child Data Request / Parental Request". We respond within one month, faster for child-related requests.
16. Changes to this policy
We may update this policy as TropeWeaver evolves, for example if we add new age-gating features, change retention periods, or add analytics with consent. The last updated date below will change. If changes are significant we will highlight them on the site or via email where you have provided one.
17. Contact
For parental COPPA requests, use Contact Form and select "Child Data Request / Parental Request". For deletion or any privacy question, select "Data / Privacy Request". We aim to respond within 30 days.
