Your data
Privacy policy
Version 2026-08-06 — your account records the version you accepted.
Who is responsible for your data
This site is operated by Lamp, who is the data controller for the personal data described below. For anything privacy-related — questions, requests, complaints — contact owner@lantern.cz.
What we store, and why
Lantern stores only what the service needs to work. Nothing is sold, shared for advertising, or used for profiling beyond the reading recommendations described below.
Your account — email address, display name, a one-way encrypted password (bcrypt hash; we cannot read your password), account role, and sign-up date. Legal basis: performance of a contract (Art. 6(1)(b) GDPR) — we can’t run an account without it.
Your reading — your library and its folders (including which saved novels you follow for new-chapter notifications), reading progress per novel (the latest chapter and your place inside it, so “Continue” works — you can remove single novels or clear this history yourself on the History page), star ratings, and which novels you’ve opened (each account counts once in a novel’s public view counter — nothing more than “this account has seen this novel” is stored). Legal basis: performance of a contract; these are the features you use.
What you write — comments, replies, announcement comments, and reviews, shown publicly under your display name (never your email), plus any error reports you file, which only the staff sees along with their reply to you. Legal basis: performance of a contract. You can delete your own comments and reviews at any time.
Recommendations — the “For you” shelf is computed from the genres and tags of novels already in your library and history. It runs inside the site, creates no extra stored data, and is never shared. Legal basis: legitimate interest (Art. 6(1)(f)) in making the catalog useful; if the operator has switched the shelf off, no such computation happens.
Notifications — in-app notes when someone replies to your comment, when the staff answers an error report you filed, and when a novel you follow gets new chapters, each with a short preview. The reply and follow notifications can be switched off in Settings (that’s your right to object in one click).
The security log — events that concern your account (sign-up, failed sign-in attempts against your email address, coin adjustments, data exports, erasures, and any admin action taken on your account) are recorded in an audit trail that only administrators can see. Legal basis: legitimate interest (Art. 6(1)(f)) in keeping the site secure and its records provable. Entries are purged after one year.
Cookies
This site sets no advertising or tracking cookies. It uses six functional ones, each created only when you use the matching feature:
lantern_session — keeps you signed in (HTTP-only, 30 days). adult_content_filter — remembers your 18+ visibility choice; with no saved choice it starts at Normal while guest testing access is active. reader_preferences — your reading font, colors, and text size. novel_list_view — whether listings show as a cover grid or a list. site_theme — the dark or light look you picked for the whole site. announcements_seen — the date of the newest announcement you’ve opened, so the header knows when to show its “fresh news” dot. All six only store a choice you made, which is why no consent banner interrupts you.
One more marker, lantern_seen, holds only today’s date — the same value for every visitor, gone within 48 hours — so the day’s visitors can be counted once each in the site’s aggregate statistics. It contains no identifier and cannot recognize you across days or link your visits together.
How long we keep things
Account data lives until you delete your account, at which point everything attached to it is removed with it — library, history, comments, reviews, ratings, and notifications. Read notifications are purged on a schedule even sooner. Two things outlive the account: entries in the security log — including the record of the deletion itself, which keeps your account id and email so the erasure stays provable — expire after one year; and routine database backups rotate out on the operator’s schedule, taking deleted data with them as they do. Emails you send the operator are kept as ordinary correspondence for as long as the matter they concern stays open.
Your rights
Under the GDPR you can access, correct, export, delete, restrict, and object to the processing of your data, and you can complain to your local supervisory authority. Lantern builds the main rights straight into Settings:
Download my data — exports the data connected to your account as one JSON file: profile (including your recorded policy and terms acceptance and any restriction status), library, reading history, viewed novels, unlocks, purchases, comments, reviews, ratings, notifications, announcement comments, error reports, and any novels you are assigned to as a contributor (access & portability, Art. 15 & 20). Two stores stay outside that file: the security log, and — if you write for this site — the publishing history (which version of a chapter’s text you saved or published, kept with the chapter for accountability). Ask the operator if you need either.
Delete my account — erases you permanently (erasure, Art. 17).
Display name, password, and notification preferences — editable in Settings at any time (rectification, Art. 16).
For anything else — including correcting your email address or restricting processing (Art. 18: your data stays stored but your public writing is hidden and activity is paused while, say, a dispute is resolved) — contact the operator above; requests are answered within one month.
Age
You must be at least 16 years old to create an account. On this testing installation, a fresh browser starts in Normal mode, so regular and 18+ novels are shown without an account or confirmation. Visitors can still choose Hide 18+ or Only 18+; no adult-confirmation timestamp is stored for signed-out visitors.
Where the data lives
Everything is stored in this site’s own database on the operator’s server — there is no third-party analytics, advertising, or tracking service behind it, and the site makes zero third-party requests (even the fonts are served from this site). If the operator has enabled password-reset email, those messages travel through the mail server the operator configured (that provider sees the message and your address); nothing else emails you. If the operator hosts outside the EU, transfers rely on the safeguards the operator publishes (such as EU standard contractual clauses).
Changes
If this policy changes in a way that matters, the date above changes with it and significant changes are announced on the site before they take effect.