Legal
Privacy Policy
Last updated: 26 May 2026
1. Who We Are
LustPages (“we”, “us”, “our”) operates the website at lustpages.com. We are the data controller for personal information collected through this site. You can contact us at privacy@lustpages.com.
2. Information We Collect
Account information: When you register, we collect your name, email address, and a hashed password. We never store your password in plain text.
Reading activity: We record which stories you have bookmarked, liked, and your reading progress. This data is used solely to provide the service (e.g. resuming where you left off) and to generate anonymous, aggregated analytics for authors.
Payment information: When payments are enabled, cryptocurrency transactions are processed by NOWPayments. We do not store any card numbers or wallet private keys. We record the transaction ID, amount, and status for accounting purposes.
Communications: If you contact us by email or submit content as an author, we retain that correspondence.
Technical data: We collect standard server logs including IP address, browser type, pages visited, and timestamps. These logs are retained for up to 90 days for security and debugging purposes.
3. Cookies
We use the following cookies:
- Age verification cookie (
lustpages_age_verified) — set for 365 days when you confirm you are 18+. Without this cookie you will be shown the age gate on every visit. - Session cookie (
next-auth.session-token) — set when you log in. Used to keep you authenticated. Expires when you log out or after 30 days of inactivity. - Theme preference — a lightweight localStorage entry storing your dark/light mode preference. Not transmitted to our servers.
We do not use advertising cookies, third-party tracking pixels, or behavioural profiling cookies.
4. How We Use Your Information
- To operate and improve the LustPages platform
- To authenticate your account and keep your session secure
- To deliver transactional emails (welcome, password reset, purchase receipts)
- To provide authors with anonymous aggregated analytics (total views, likes, bookmarks)
- To detect and prevent fraud, abuse, and illegal activity
- To comply with applicable law
We do not use your reading history to serve targeted advertising. We do not sell, rent, or trade your personal data to any third party.
5. Third-Party Services
We use the following sub-processors who may handle your data:
- Supabase — database hosting (EU region). Your account data and reading history are stored here.
- Vercel — application hosting and CDN. Processes request logs.
- Resend — transactional email delivery. Your email address is shared only to deliver emails you have requested.
- NOWPayments — cryptocurrency payment processing. Relevant only when you make a purchase.
- Cloudinary — image hosting for story cover images. No personal data is stored.
Each sub-processor is bound by data processing agreements and is prohibited from using your data for their own purposes.
6. Data Retention
We retain your account data for as long as your account is active. If you request deletion of your account, we will delete or anonymise your personal data within 30 days, except where we are required by law to retain it (e.g. financial transaction records, which are retained for 7 years).
Anonymised, aggregated analytics data (e.g. total story view counts) may be retained indefinitely as it cannot be linked back to any individual.
7. Your Rights
Depending on your jurisdiction you may have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate data
- Erasure — request deletion of your account and associated data
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interests
- Withdrawal of consent — where processing is based on consent, withdraw it at any time
To exercise any of these rights, email us at privacy@lustpages.com. We will respond within 30 days.
8. Children's Privacy
LustPages is strictly for adults aged 18 or over (or the age of majority in your jurisdiction, whichever is higher). We do not knowingly collect personal information from minors. If we discover that a minor has created an account, we will immediately delete all associated data. If you believe a minor has accessed our service, please contact us immediately.
9. Security
We implement industry-standard security measures including TLS encryption in transit, hashed passwords (bcrypt), and access controls limiting who within our team can access user data. However, no system is completely secure and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email to registered users and by a prominent notice on the site. Your continued use of LustPages after the effective date constitutes acceptance of the updated policy.
11. Contact
For privacy-related enquiries: privacy@lustpages.com