Tellura
Legal

Privacy Policy

Last updated: September 9, 2026

1. Introduction

Septem Montes, Inc. ("Septem Montes," "we," "us," or "our") operates the Tellura digital novel platform at tellura.ink, which allows users to read, publish, and discover original stories. Tellura is a brand of Septem Montes, Inc. This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use our website and services (the "Service").

Septem Montes, Inc. is the controller of the personal data described here. Our contact details are in section 14.

Where you are in the European Economic Area or the United Kingdom, the GDPR (and the UK GDPR) applies to our processing of your personal data. Sections 5.2, 6.6, 6.7, 8 and 11.4 are written for those rules in particular, and they apply to you whatever else this policy says.

This policy explains what we do; it is not a contract, and reading it is not you agreeing to anything. Where we need your consent for something, we ask for it separately and you can refuse or withdraw it. Everything else we do rests on one of the legal bases set out in section 5.2.

2. Information We Collect

We collect information that you provide directly to us and information that is collected automatically when you use the Service.

2.1 Account Information

When you create an account, we collect:

  • Email address (required);
  • Password (stored in hashed form using industry-standard cryptographic hashing; we never store your plaintext password);
  • Display name (optional).

2.2 Third-Party Authentication

If you register or log in using a third-party service (Google, Microsoft, Apple, or Facebook), we receive your email address and a unique identifier from that provider. We do not receive or store your password from these providers. The specific information shared depends on your privacy settings with that provider.

2.3 Profile Information

You may optionally provide:

  • A biography;
  • A profile avatar image;
  • Privacy preferences (controlling the visibility of your reviews, comments, followed novels, reading lists, and forum activity);
  • Content preferences (such as adult content filtering and preferred language).

2.4 User-Generated Content

We store content you create on the Service, including:

  • Novels and chapters you publish, and unpublished drafts you have saved;
  • Comments on chapters;
  • Reviews and ratings of novels;
  • Forum threads and posts;
  • Bookmark notes.

2.5 Reading Activity

We collect information about your reading activity, including:

  • Which chapters you have read and your reading progress (scroll position or page number);
  • Your reader preferences (font size, font family, theme, line height, and view mode);
  • Novels and authors you follow;
  • Chapters you have bookmarked.

2.6 Author Monetization Information

If you apply for the author monetization program, we collect additional information including your legal name, date of birth, country of residence, and tax identification number. This information is used to verify your identity, process payouts, and comply with tax reporting obligations.

3. Payment Information

Payment transactions are processed by our third-party payment processor, Stripe, Inc. When you make a purchase, Stripe collects your payment information (such as credit card number and billing address) directly. Tellura does not receive, process, or store your full payment card details.

We do store:

  • An account identifier that links your Tellura account to your payment profile;
  • Transaction records, including purchase amounts and transaction status;
  • Subscription details, including plan type, billing period, and subscription status.

For authors receiving payouts, Stripe handles the collection of bank account or other payout-related financial information directly.

4. Automatically Collected Information

4.1 Analytics Data

When you use the Service, we automatically collect certain information for analytics and service improvement purposes:

  • Chapter view data: which chapters are viewed, reading duration, and completion percentage;
  • Device information: device type (desktop, mobile, tablet);
  • Geographic data: country-level location derived from your IP address (we do not collect precise geolocation);
  • Referrer information: how you arrived at a page (search, browse, direct, external link, or notification);
  • Search queries: search terms you enter on the Service and which results you click on.

4.2 Device Identifiers

For users who are not logged in, we may generate a device identifier for analytics purposes. This identifier helps us understand usage patterns and is not used to identify you personally. When you are logged in, analytics data is associated with your user account instead.

4.3 Security Data

We collect information related to login attempts, including IP addresses, to protect against unauthorized access. This data is retained for a limited period and is used solely for security purposes.

5. How We Use Your Information

5.1 Purposes

We use the information we collect for the following purposes:

  • Providing the Service: operating, maintaining, and improving the reading and publishing platform;
  • Personalization: customizing your reading experience, including reader settings, recommendations, and content preferences;
  • Payment processing: facilitating Coin purchases, subscription billing, and author payouts;
  • Communication: sending account-related notifications (email verification, password resets, novel approval/rejection, new chapter alerts, comment replies), subject to your email preferences;
  • Analytics: understanding how the Service is used to improve features, content discovery, and user experience;
  • Content moderation: reviewing submitted content and enforcing our Terms of Service;
  • Security and fraud prevention: detecting and preventing unauthorized access, abuse, and fraudulent transactions;
  • AI features: running machine translation, the AI co-author, and search indexing on your work when you ask us to. See section 6.6;
  • Legal compliance: fulfilling our legal obligations, including tax reporting for author earnings.

5.2 Our Legal Bases (EEA and UK)

Under the GDPR we must have a legal basis for each purpose. Ours are:

  • Performance of a contract (Article 6(1)(b)): providing the Service, your account, reading progress and preferences, publishing your work, processing payments and paying authors, sending service messages you need in order to use your account, and running an AI feature you have asked for;
  • Legitimate interests (Article 6(1)(f)): analytics and service improvement, recommendations and discovery, content moderation, security and fraud prevention, and defending legal claims. Our interest is in operating a working, safe platform; we have weighed that against your interests and you may object at any time under section 11.4;
  • Legal obligation (Article 6(1)(c)): tax reporting and record-keeping, responding to lawful requests from authorities, and honouring your data protection rights;
  • Consent (Article 6(1)(a)): optional analytics and marketing cookies, optional marketing email, and — separately and specifically — sending your text to an AI provider outside the EEA under section 6.7. You may withdraw any of these at any time, and withdrawing costs you nothing except the feature it relates to.

We do not make decisions about you by automated means alone that produce legal effects or similarly significantly affect you. Recommendations and content ranking are automated, but they only change what we show you.

6. Information Sharing and Disclosure

We do not sell your personal information. We share your information only in the following circumstances:

6.1 Service Providers

We share information with third-party service providers who perform services on our behalf, including:

  • Payment processing and author payouts (Stripe);
  • Content delivery, hosting, storage and bot protection (Cloudflare);
  • Database hosting (Supabase, in the European Union);
  • Application hosting for our translation and AI services (Hetzner, in Germany);
  • Transactional email delivery (Resend);
  • Authentication services, when you sign in via Google, Microsoft, Apple, or Facebook;
  • Website analytics (Google Analytics) and web fonts (Google Fonts), which receive your IP address and the pages you view;
  • Operational error alerting (Discord), which may receive your account id inside a technical log entry when something fails;
  • Search-engine URL submission (IndexNow, operated by Microsoft), which receives the addresses of published pages;
  • Where you use the importer, the site you are importing from;
  • AI providers, which are covered separately in section 6.6.

Where we have a data processing agreement with a provider, that provider may use your personal information only to perform the service for us, on our instructions, and not for its own purposes. We have such an agreement with each provider named above.

One exception: we do not have a data processing agreement with DeepSeek, the provider behind the AI features described in section 6.6. What that means for you is set out there and in section 6.7. It is why those features are switched off until you turn them on.

6.2 Public Information

Certain information is publicly visible on the Service by design, including your display name, published novels and chapters, comments, reviews, and author profile. You can control additional visibility through your profile privacy settings.

6.3 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government agency).

6.4 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.

6.5 Aggregated and Anonymized Data

We may share aggregated or anonymized information that cannot reasonably be used to identify you, such as platform-wide reading statistics or genre popularity data.

6.6 AI Providers

Three features send the text of your work to an AI provider: machine translation, the AI co-author, and search indexing. Each is off until you give permission for it, and we ask separately for each of the three.

Be clear about what that permission covers, because it is broader than a single work: it applies to that feature across your account, including works you add later. And once you have enabled a feature for a work, related processing continues automatically as you edit it -- re-indexing a novel after you change a chapter, or refreshing a translated title after you edit it. Withdrawing permission stops all of it.

Two providers are involved, and they receive different things:

  • DeepSeek receives the text itself — the chapters or drafts the feature is working on, including unpublished text if that is what you asked it to work on. DeepSeek processes and stores it in the People's Republic of China. We have no data processing agreement with DeepSeek, and its published terms permit it to use data it receives to train and improve its own models. We cannot promise, on DeepSeek's behalf, that it will not.
  • Google also receives the text itself, in the United States, and returns the numerical representations (embeddings) we store to make search and context retrieval work. The difference from DeepSeek is not what is sent but what may be done with it: we use a paid tier under a data processing agreement, so Google acts on our instructions only and may not use your writing for its own purposes.

Tellura does not use your work to train generative AI models, and will not license or sell it to anyone for that purpose. That is a promise about us. Section 6.7 explains what we can and cannot promise about DeepSeek, and how you control it.

Separately from the features above, we keep an operational archive of co-author sessions and of superseded chapter revisions so that work is not lost when something is deleted or overwritten. That archive is storage, not training material: nothing reads it to build a model. Its retention period is in section 8.

6.7 International Transfers

We are a United States company, and our providers are in several countries. Where personal data leaves the EEA or the UK, we rely on the following:

  • Within the EEA: our primary database (Supabase, EU) and our translation and AI application servers (Hetzner, Germany) are located in the European Union. No transfer mechanism is needed for these.
  • United States providers (Stripe, Cloudflare, Resend, Google, and the authentication providers): transfers are made under the data processing terms we have with each provider, which incorporate the European Commission's Standard Contractual Clauses, that provider's certification under the EU-US Data Privacy Framework, or both. We will tell you which applies to a given provider if you ask.
  • DeepSeek, in the People's Republic of China: read this before switching on any of the features in section 6.6.

China is not covered by a European Commission adequacy decision, and we do not have Standard Contractual Clauses or any other Article 46 safeguard in place with DeepSeek. This means we cannot rely on the usual mechanisms, and it has four consequences we want you to see plainly:

  • Providers there can be required by national security and intelligence law to give the authorities access to data they hold, including your text, without notice to you and without a route of appeal that a court in the EEA or the UK would recognise. We would not know if it happened, and we could not tell you;
  • Your text will not have the legal protection there that it has in the EEA or the UK;
  • Enforcing your rights over it — including asking for it to be deleted — may be difficult or impossible in practice;
  • DeepSeek's own published terms permit it to use data it receives to train and improve its models.

So we ask for your explicit consent before any of it happens, under Article 49(1)(a) of the GDPR. We ask separately for each of the three features, at the point you first try to use it, and we tell you the above before you decide. If you say no, nothing is sent and you lose only that feature.

You can withdraw that consent at any time in your profile settings, with a single click, and withdrawing is as easy as giving it. Withdrawal stops anything further being sent. It does not, and cannot, recall text that has already been sent — which is the honest reason we ask you before the first send rather than after.

7. Cookies and Tracking Technologies

7.1 Cookies We Use

We use cookies and similar technologies to operate and secure the Service:

  • Authentication cookies (necessary): We use secure cookies to manage your login session. These cookies are essential for the Service to function and cannot be disabled.
  • Analytics cookies (optional): With your consent, we use cookies to collect usage data that helps us improve the Service.
  • Marketing cookies (optional): With your consent, we may use cookies for promotional purposes.

7.2 Local Storage

We use browser local storage to store your preferences, such as cookie consent choices and reader display settings (font, theme, etc.), so they persist between visits.

7.3 Cookie Consent

When you first visit the Service, we present a cookie consent banner that allows you to accept or reject optional cookies (analytics and marketing). You can manage your cookie preferences at any time through the cookie settings accessible from the banner. Necessary cookies (authentication) cannot be disabled as they are required for the Service to function.

8. Data Retention

We keep personal data only as long as we need it. Where we can give you a period, we have; where the period depends on something we cannot predict, we have said what determines it.

  • Account data: kept while your account exists. When you ask us to delete your account we close it immediately, and 30 days later we scrub the personal data from it. The 30 days exist so that readers who have paid for chapters can finish reading them and subscriptions can end cleanly; ask us and we will do it sooner;
  • User-generated content: kept while your account exists. Comments, reviews and forum posts you leave behind are detached from you and shown as "[Deleted]" rather than removed, so other people's conversations do not collapse;
  • Co-author sessions: deleted sessions are held for a 30-day grace period, then purged;
  • Operational archive (superseded chapter revisions and purged co-author sessions, per section 6.6): 365 days, then deleted automatically. Your copy of it is deleted when you delete your account;
  • Proof of consent and of agreement to our terms: kept for as long as we may need to show that you agreed and what you agreed to, including after your account closes. We remove the IP address from these records when we scrub your account;
  • Reading progress and preferences: kept while your account exists;
  • Analytics data: chapter views, analytics events and search queries are kept in our live database for 7 days and aggregated into summaries that no longer identify anyone. The raw events are then moved to a compressed archive rather than destroyed;
  • Security logs: kept in our live database for 90 days and used solely for fraud prevention and security, then moved to the same compressed archive;
  • Payment and tax records: kept as long as tax and financial law requires, which is generally seven years, and reviewed for deletion after that.

9. Data Security

We implement industry-standard security measures to protect your personal information:

  • Password protection: passwords are cryptographically hashed before storage. We never store plaintext passwords;
  • Encryption in transit: all data transmitted between your browser and our servers is encrypted using HTTPS;
  • Infrastructure security: we use reputable cloud infrastructure providers with built-in protections against common attacks;
  • Access controls: access to user data is restricted to authorized personnel on a need-to-know basis;
  • Abuse prevention: we employ measures to prevent brute-force attacks and unauthorized access to accounts.

While we strive to protect your personal information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

10. Children's Privacy

You must be at least 16 to use Tellura, and the Service is not directed to anyone younger. We do not knowingly collect personal information from children under 16.

If we learn that we have collected personal information from a child under 16, we will take steps to delete it promptly. If you believe a child has provided us with personal information, please contact us at legal@tellura.ink.

Sixteen is the age our registration enforces, and it matches Article 8 of the GDPR, which sets 16 as the age at which a person can consent for themselves to a service like ours in most of the EEA. Where a child under 13 is concerned, this is also our compliance with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. Sections 6501-6506.

11. Your Privacy Rights

11.1 California Residents (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: you have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the sources of that information, the business purposes for collecting it, and the categories of third parties with whom we share it;
  • Right to Delete: you have the right to request that we delete the personal information we have collected from you, subject to certain exceptions (such as legal obligations or completing a transaction);
  • Right to Correct: you have the right to request that we correct inaccurate personal information;
  • Right to Opt-Out of Sale: we do not sell personal information. If we change this practice in the future, we will provide you with the right to opt out;
  • Right to Non-Discrimination: we will not discriminate against you for exercising any of your privacy rights.

11.2 Exercising Your Rights

To exercise any of these rights, please contact us at legal@tellura.ink. We will respond to verifiable consumer requests within 45 days. We may need to verify your identity before processing your request.

11.3 All Users

Regardless of your location, you may:

  • Access and update your account information through your profile settings;
  • Control the visibility of your profile and activity through privacy settings;
  • Manage your email notification preferences;
  • Manage your cookie preferences through the cookie consent banner;
  • Manage your permissions for the AI features described in section 6.6, in your profile settings;
  • Delete your account from your profile settings, or by contacting us at legal@tellura.ink.

11.4 EEA and UK Residents (GDPR)

If you are in the European Economic Area or the United Kingdom, you have the following rights over your personal data. They are free to exercise, and we will answer within one month.

  • Access (Article 15): a copy of the personal data we hold about you, and confirmation of how and why we use it;
  • Rectification (Article 16): correction of anything inaccurate or incomplete;
  • Erasure (Article 17): deletion of your personal data. You can do this yourself from your profile settings. Some records survive, and section 8 says which and why — chiefly tax records we are required to keep and proof that you agreed to our terms;
  • Restriction (Article 18): to have us pause processing while a dispute about accuracy or legitimate interests is resolved;
  • Portability (Article 20): a machine-readable copy of the data you gave us, or transmission of it to another controller where technically feasible;
  • Objection (Article 21): to object to processing we base on legitimate interests, including profiling for recommendations. You may object to direct marketing at any time and we will stop;
  • Withdraw consent (Article 7(3)): at any time, for cookies, for marketing, and for the AI transfers in section 6.7. Withdrawal is as easy as giving consent and does not affect processing already carried out.

Right to complain. You may lodge a complaint with the data protection authority in the country where you live or work, or where you think something has gone wrong. We would rather you told us first at legal@tellura.ink, but that is a preference, not a condition, and nothing here requires you to come to us before going to a regulator.

To exercise any of these rights, write to legal@tellura.ink. We may need to verify your identity first, and we will explain what we need if so.

12. Do Not Track

Some web browsers transmit "Do Not Track" (DNT) signals to websites. Because there is no universally accepted standard for how to respond to DNT signals, we do not currently respond to DNT signals. We will continue to monitor developments around DNT browser technology and update our practices accordingly.

13. Changes to This Privacy Policy

This is a versioned, dated document with a public changelog. We do not edit it silently.

For material changes we will tell you plainly what changed, and give you notice before the new version takes effect. Where a change requires your consent, we will ask for it separately rather than treating your continued use of the Service as agreement.

Earlier versions remain available so you can see what applied when.

14. Contact Us

If you have any questions about this Privacy Policy, our data practices, or your privacy rights, please contact us at: