erhalerBeta
DiscoverSign in

Contents

  1. 1. Introduction
  2. 2. Who we are (controller)
  3. 3. What information we collect
  4. 4. How and why we use it
  5. 5. Who we share it with (sub-processors)
  6. 6. Where your data is stored and transferred
  7. 7. How long we keep your information
  8. 8. Your rights
  9. 9. Children
  10. 10. Cookies and similar technologies
  11. 11. AI and your content
  12. 12. Automated decision-making
  13. 13. Security
  14. 14. Changes to this Policy
  15. 15. Contact and supervisory authority

Privacy Policy

Effective: 15 August 2026 · Version 2.3

This Privacy Policy explains what personal information Verhaler collects when you use our service, how we use it, who we share it with, and the rights you have under EU and Dutch data-protection law. It applies to the Verhaler website at verhaler.com and any related applications, and is part of our Terms of Service.

Contents

  1. 1. Introduction
  2. 2. Who we are (controller)
  3. 3. What information we collect
  4. 4. How and why we use it
  5. 5. Who we share it with (sub-processors)
  6. 6. Where your data is stored and transferred
  7. 7. How long we keep your information
  8. 8. Your rights
  9. 9. Children
  10. 10. Cookies and similar technologies
  11. 11. AI and your content
  12. 12. Automated decision-making
  13. 13. Security
  14. 14. Changes to this Policy
  15. 15. Contact and supervisory authority

1.Introduction

Verhaler is a marketplace for interactive, branching digital stories. To run that marketplace we have to collect and process some information about the people who use it - both Readers and Writers. This Policy is our explanation of what we collect, why, who we share it with, and what you can do about it.

We have written this Policy to satisfy our obligations under the EU General Data Protection Regulation (GDPR), the Dutch Uitvoeringswet AVG (UAVG), and the ePrivacy Directive. Where this Policy uses defined terms ("Reader," "Writer," "Book," "Service," etc.) without explaining them, those terms have the meanings given in our Terms of Service.

The information here is intended to be readable. If anything is unclear, or if you want more detail about something specific, please write to us at [email protected].

2.Who we are (controller)

Verhaler Interactive is the controller of personal data processed through the Service. We are registered with the Dutch Chamber of Commerce (KvK):

Verhaler Interactive
Keizersgracht 452, 1016 GD Amsterdam, the Netherlands
KvK: 42059039
General contact: [email protected]
Privacy contact: [email protected]

Data Protection Officer

We have not appointed a Data Protection Officer because we are not required to under article 37 GDPR. We keep this assessment under review and will appoint one if our processing changes in a way that triggers the obligation.

3.What information we collect

The categories of personal information we collect depend on how you use the Service. Some categories apply only to Writers (people who publish or sell Books).

Account information

When you create an account, we collect: your email address, a hashed version of your password (we never store passwords in readable form), your chosen display name, the date you created the account, and the country of residence you select. If you sign in using Google, we receive your email address and Google account identifier from Google in place of a password.

Profile and content

We store the Books, characters, scenes, choices, media files, and other content you create on the Service. Your profile may include an author byline, biography, and avatar if you choose to add them.

Reading and usage data

When you read a Book, we record your progress through the story (which chapter, which choices you have taken, where you stopped) so that the Service can resume where you left off. We record which Books and Expansions you have purchased, and when.

Reviews and competitions

When you review a Book, we store the review itself, whether you recommend the Book, and the network address (IP address) the review was posted from. The network address is used only to keep review counts honest (see section 4) and to investigate suspected review abuse; it is never shown to anyone, on any page or interface.

If you enter a writing competition, we additionally record the country of residence you declare when entering, your acceptance of the competition rules, and the times of these actions. If your entry is evaluated, we record the evaluation panel's category scores for your entry.

Payment information

Book purchases are processed by our payment partner, Stripe (see section 5). Card details are entered directly on Stripe's hosted, PCI-DSS Level 1 certified checkout pages; Verhaler never receives them. We do not see or store your full card number, CVV, or bank account number. Stripe sends us a small amount of data about each transaction: a Stripe customer identifier, the last four digits of the card, the card brand and country, the billing postal code, and the outcome of the charge. Refunds and chargebacks generate related records.

Writers using payouts: if you choose to receive payouts, the full set of information needed to verify your identity and pay you out (legal name, address, date of birth, government ID, tax-residence country, tax identification number, bank account details, and, for some countries, a copy of an identity document or proof of address) is collected and stored by Stripe under the Stripe Connected Account Agreement. We see only confirmation of whether the verification has succeeded or what is outstanding, plus the high-level country and capability state. See the Stripe Privacy Policy at stripe.com/privacy for the full description.

Communications you send us

If you email us, send us a report, or contact our support, we keep those messages and your reply history so we can answer you and keep a record of what was decided.

Newsletter subscription

If you subscribe to our newsletter - which you can do with or without a Verhaler account - we store the email address you enter, the time and the page you subscribed from, and an unsubscribe token. If you unsubscribe, we keep the address on a suppression list so that we do not email it again.

Technical and security information

Our servers automatically record technical information about requests to the Service: your IP address, the time of the request, the URL, the response status, the user-agent string of your browser or application, and similar diagnostic information. This is used to operate the Service, prevent abuse, and investigate security incidents. See section 7 for retention.

Information we do not collect

We do not collect special-category personal data (data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data, health data, or data about sex life or sexual orientation) as a regular matter. If such information appears in Book content you write, that is your choice as the author; the content is treated as user-generated content under our Terms, not as a profile of you.

We do not use advertising trackers or cross-site tracking technologies (for example, Google Analytics, Facebook Pixel, or similar), and we do not sell or rent your personal information to anyone. For aggregate traffic measurement we use a single privacy-friendly, cookieless analytics tool (Plausible) that does not profile you, sets no cookies, and does not track you across other websites - see sections 5 and 10.

4.How and why we use it

We process personal information for the purposes below, on the following lawful bases under article 6 GDPR. We never use one lawful basis as a fallback for another - each purpose is tied to the specific basis we rely on.

Operating the Service (art. 6(1)(b) - contract)

Creating and managing your account, saving the Books you write, saving your reading progress, processing the purchases you make, sending you transactional emails about your account (sign-in confirmations, password resets, receipts, purchase confirmations), and providing customer support.

Payments, payouts, and tax (art. 6(1)(b) and art. 6(1)(c) - contract and legal obligation)

Charging you, paying out Writer earnings, calculating and remitting VAT, issuing invoices (including self-billed invoices in a Writer's name where the Writer has agreed under Terms §9), and retaining accounting and tax records for the period required by Dutch law (currently seven years under article 52 of the Algemene wet inzake rijksbelastingen).

Security and abuse prevention (art. 6(1)(f) - legitimate interest)

Detecting and blocking suspicious sign-in attempts, rate-limiting abusive requests, investigating fraud and chargebacks, investigating reports of content that violates our Acceptable Use Policy, and protecting the integrity of the Service. Our legitimate interest in keeping the Service safe and reliable is balanced against your interests; we have assessed that this processing is proportionate.

Writing competitions and review integrity (art. 6(1)(f) - legitimate interest)

When we run a writing competition, we process entry details to check eligibility and administer the competition under its published rules. We count positive reviews toward competition standings with a cap, so that positive reviews from the same network count at most three times toward an entry's standing; this is why review network addresses are recorded. When results are published, we publish the winners' display names, their countries of residence, and the evaluation panel's scores for the winning entries, as the competition rules state in advance. Scores for entries that did not win are not published; any entrant may request their own scores from us at any time. Our legitimate interest is running a fair, fraud-resistant and transparent competition; we have carried out a legitimate-interests assessment for this processing and can provide it on request. You can object to this processing at any time (see section 8); in particular, a winner may ask us to announce the result without naming them.

Content moderation and platform safety (art. 6(1)(b), art. 6(1)(c), and art. 6(1)(f))

Screening uploaded media for prohibited material, acting on user reports of illegal content as required by the Digital Services Act (Regulation (EU) 2022/2065), and removing content or accounts where required. See Terms §12 for how the moderation system works and section 12 of this Policy for how automated decisions interact with your rights.

Improving the Service (art. 6(1)(f) - legitimate interest)

Understanding how the Service is used in aggregate (for example, which features are most used, where errors occur) so that we can improve it. We do not profile individual users for this purpose. For website-traffic measurement we use Plausible, a cookieless, privacy-friendly analytics tool that produces only aggregate statistics and does not build a profile of you or track you across other sites (see sections 5 and 10). Because the tool is cookieless and does not identify you, the impact of this processing on your privacy is minimal.

Marketing communications (art. 6(1)(a) - consent)

If you subscribe to the newsletter, we use your email address to send you occasional news about Verhaler - new features, new Books, announcements. We send these only to addresses that subscribed, and every issue contains a one-click unsubscribe link. Unsubscribing stops the emails and does not affect anything else about your account. Transactional emails about your account are separate and are covered under "Operating the Service" above.

Compliance with legal obligations (art. 6(1)(c))

Responding to lawful requests from authorities, complying with tax-reporting rules (including, where applicable, DAC7 reporting of platform earnings to the Dutch tax authority), retaining records required by law, and complying with court orders.

5.Who we share it with (sub-processors)

We share personal information with third parties only where necessary to operate the Service, only for the purposes listed below, and only under written terms (a Data Processing Agreement, or "DPA") that require the third party to process the data on our instructions and to apply appropriate security and confidentiality measures, in accordance with article 28 GDPR.

The categories of sub-processors we use are described below. Material additions (a sub-processor in a new category) are announced 30 days in advance as described in section 14.

Payment and payout infrastructure

Stripe (Stripe Payments Europe Ltd. and its affiliates) processes all Book purchases, holds Writer Connect accounts, and handles payouts. Stripe is an independent controller for some of its own purposes (fraud prevention, regulatory compliance); see the Stripe Privacy Policy at stripe.com/privacy.

Cloud hosting and storage

Our application servers, database, and media storage are operated by an EU-based cloud-hosting provider. Personal information stored at rest in our database and our media bucket stays in the EU.

Content delivery and network security

Cloudflare sits at the network edge in front of the Service: it provides our authoritative DNS, secures (terminates the TLS connection for) traffic between your browser and us, and screens requests for denial-of-service attacks and abuse before they reach our servers. Because every request to the Service passes through Cloudflare, it processes connection metadata - including your IP address, the pages you request, and your browser's user-agent - on our behalf under a data-processing agreement. Cloudflare also powers the anti-bot check (Turnstile) on our sign-in, registration, and password-reset forms. See cloudflare.com/privacypolicy.

Automated moderation provider

Google (Gemini API) powers our automated content moderation: to screen uploaded media for prohibited material, including child sexual abuse material, we send that media to the Gemini API on a request-by-request basis. Google is engaged under its paid, business-tier terms, which contractually prohibit it from using the content to train, develop, or improve its own models. We do not send the text of Books to this provider. See section 11 for more detail.

Accounting and invoicing

An EU-based accounting platform is our system of record for the invoices we issue: our own sales invoices (the gross price of each Book sale, where Verhaler is the seller) and the monthly self-billed royalty invoices and credit notes we raise in a Writer's name. Readers receive a receipt from Stripe, our payment processor - not an invoice. Relevant invoice metadata is sent to the accounting platform; payment card data is not.

Analytics

Plausible Analytics (operated in the European Union) provides aggregate, privacy-friendly website analytics - for example, how many people visit a page, which pages are popular, and which country traffic comes from. Plausible is cookieless and stores no identifier on your device. It counts unique visits using a temporary, daily-rotating hash that is never stored and cannot be used to identify or re-identify you across days or websites. We receive only aggregate statistics, never a profile of an individual visitor. Plausible processes a small amount of technical data (including your IP address and user-agent, transiently, to derive that hash) on our behalf under a data-processing agreement, and not for advertising. See plausible.io/data-policy. You can opt out of this aggregate measurement at any time by blocking plausible.io with any content or ad blocker; the Service works identically with analytics disabled.

Professional advisers and authorities

We may share information with our lawyers, accountants, tax advisers, or auditors where necessary for them to advise us, and with public authorities (courts, tax authority, supervisory authorities, law enforcement) where we are legally required to do so or to defend our legal rights.

Successors

If Verhaler is acquired, merged, or transfers a part of its business to a third party, your information may be transferred as part of that transaction, subject to the same protections set out in this Policy. We will tell you in advance if this happens and give you a reasonable opportunity to exercise your rights.

6.Where your data is stored and transferred

Our database, server backups, and media storage are located in the European Union. Day-to-day, your personal information stays in the EU.

Some of our sub-processors operate from outside the European Economic Area (EEA), in particular the United States. Where personal information is transferred to a country outside the EEA, we rely on one or more of the following safeguards under chapter V GDPR:

  • The EU-US Data Privacy Framework adequacy decision, for transfers to US recipients certified under that framework.
  • The European Commission's Standard Contractual Clauses, for transfers where DPF certification does not apply or where we want a back-up safeguard.

You can request a copy of the safeguards we rely on for a specific transfer by writing to [email protected].

7.How long we keep your information

We keep personal information only as long as we need it for the purpose we collected it for, or for as long as the law requires us to. The main retention periods are:

Account information

Kept while your account is open. When you close your account (see Terms §17), personal information is scrubbed within 30 days, subject to the specific exceptions below.

Books you have published to paying Readers

Books that have been purchased by other users remain available to those Readers after you close your account, with your author byline replaced by a generic placeholder ("Deleted account"). This is necessary to honour the contracts we have with the Readers who paid for those Books; it is permitted under article 17(3) GDPR (the right to erasure does not apply where processing is necessary for the performance of a contract).

Reading progress and purchase history

Kept while your account is open. Deleted within 30 days of account closure, except for aggregated, non-identifying analytics.

Payment, invoice, and tax records

Retained for seven years from the end of the financial year in which the transaction occurred, as required by article 52 of the Algemene wet inzake rijksbelastingen (AWR). The lawful basis is article 6(1)(c) GDPR (compliance with a legal obligation).

Server logs and security records

Application logs are retained for up to 90 days. Records of confirmed security or abuse incidents may be retained for longer (up to two years) where necessary to defend or establish legal claims.

Review network addresses

The network address stored with a review (section 3) is deleted by a daily automated sweep one year after the review is posted, and immediately when you delete your account.

Competition records

If you enter a writing competition, the evaluation panel's category scores and your entry details are kept as part of that competition's permanent record. Competition correspondence and the panel's written evaluation notes are deleted 60 days after the results are announced. Records of prize payments are kept for seven years, as Dutch tax law requires.

Backups

Encrypted database backups are retained for up to 30 days on a rolling basis. When you delete information, it persists in backups until the relevant backup ages out, and is not used for any other purpose in the meantime.

Support correspondence and reports

Kept for as long as needed to handle the matter, and for up to two years after the matter is closed, so that we can answer follow-up questions and demonstrate how we handled a particular report.

Newsletter subscriptions

Kept until you unsubscribe. After you unsubscribe, the address stays on a suppression list - keeping it is what lets us honour the opt-out, and processing it for any other purpose stops.

8.Your rights

Under the GDPR and the Uitvoeringswet AVG, you have the following rights in relation to the personal information we hold about you:

  • Right of access (art. 15) - to ask us for a copy of the personal information we hold about you and information about how we use it.
  • Right to rectification (art. 16) - to ask us to correct information that is inaccurate or incomplete.
  • Right to erasure (art. 17) - to ask us to delete your information. This right is not absolute; it does not apply where we are required to keep the information by law (for example, tax records) or where keeping it is necessary to honour a contract with someone else (for example, a Book a Reader has bought from you - see section 7).
  • Right to restriction (art. 18) - to ask us to limit how we use your information in certain circumstances.
  • Right to data portability (art. 20) - to receive your account and content data in a machine-readable format and to transmit it to another service.
  • Right to object (art. 21) - to object to processing based on legitimate interests. Where you object, we will stop the processing unless we can show compelling legitimate grounds that override your interests, or the processing is needed to establish, exercise, or defend legal claims.
  • Right to withdraw consent (art. 7(3)) - where we rely on your consent for a specific processing activity, you can withdraw it at any time. (We rely on consent only sparingly; most of our processing is on contract or legitimate-interest bases.)
  • Right not to be subject to automated decisions (art. 22) - see section 12.
  • Right to lodge a complaint with a supervisory authority - see section 15.

You can handle the most common requests yourself. When you are signed in, the Settings page lets you download a copy of your account data, export your books as Markdown files, and delete your account.

For anything not covered there, or if you would rather ask us directly, write to [email protected]. We will respond within one month of receiving your request, in line with article 12(3) GDPR. We may extend this period by up to two further months where the request is particularly complex or where we have received a large number of requests; if we do, we will tell you within the first month and explain why.

We may need to verify your identity before we act on a request, to make sure we are not disclosing your information to someone else. We will not charge a fee unless the request is manifestly unfounded or excessive.

9.Children

The Service is not directed at children. You must be at least 16 years old to use Verhaler, in line with article 8 GDPR and the Dutch implementation in article 5 UAVG.

We do not knowingly collect personal information from people under 16. If we become aware that we have collected personal information from someone under 16 without the verifiable consent of a parent or guardian where required, we will delete that information and close the account. If you believe we hold information about a child, please contact us at [email protected].

10.Cookies and similar technologies

We use only strictly necessary cookies, in the sense of article 5(3) of the ePrivacy Directive - that is, cookies that are essential for the Service to function and that you have implicitly requested by signing in or making a purchase. These do not require a consent banner.

Our cookies authenticate you and keep you signed in. The longest continuous session is 90 days, after which you will be asked to sign in again.

We do not use advertising cookies, pixels, fingerprinting, or cross-site tracking. For aggregate analytics we use Plausible, which is cookieless: it stores nothing on your device and reads no information from it, so it falls outside the consent requirement of article 5(3) of the ePrivacy Directive and needs no consent banner (see section 5). If we ever add a technology that stores or reads information on your device for analytics or advertising, we will introduce a consent mechanism before doing so and update this Policy.

Stripe Checkout is hosted on Stripe's own domain, not ours, and any cookies set during that flow are set by Stripe under Stripe's own privacy policy.

11.AI and your content

Verhaler does not offer AI writing tools, AI media generation, or AI chat features. We do not offer AI prose-writing assistance, and fully AI-generated Books are not permitted (see the AUP). The one place we rely on a third-party automated service is content moderation, as described in Terms §12.

How automated moderation processes your content

When you upload media, it may be sent to our moderation provider (listed in section 5) over a secure connection to be screened for prohibited material. The provider returns a classification, which we use to decide whether the content is allowed. We do not send the text of your Books to this provider.

No training on your content

Verhaler does not use your content - Book text, characters, media, or anything else - to train AI models. The moderation provider we use is also contractually prohibited from using the content we send it to train, develop, or improve its own models. This is written into the paid, business-tier API terms we have accepted:

  • Gemini API Additional Terms - Paid Services ("Google doesn't use your prompts ... or responses to improve our products").

Safety and abuse monitoring at the provider

The provider may retain the content we send it for a short period solely to detect and prevent misuse of its services (for example, to enforce its prohibited-use policies). The exact retention is set by the provider. These short retentions are not training, and the content is not used to develop the provider's models.

Legal basis

Moderation processing is necessary to keep the Service safe and to meet our obligations under the Digital Services Act, and rests on article 6(1)(f) GDPR (our legitimate interest in a safe platform) and article 6(1)(c) GDPR (compliance with a legal obligation), rather than on your consent.

12.Automated decision-making

We use automated screening of uploaded media for our strict-rule prohibitions in the AUP. For most flags the outcome is a referral for human review, and an account ban or the permanent removal of your content is confirmed by a human reviewer before it takes effect. The exception is suspected child sexual abuse material: so that it is never served, the classifier automatically hides the media as soon as it is detected, pending human review and any report to the authorities. That automatic step is reversible if it turns out to be a false positive.

Under article 22 GDPR you have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you. Enforcement decisions that significantly affect you - an account ban or the permanent removal of your content - are made by a human reviewer, not by automated processing alone; the automatic child-safety quarantine described above is an interim, reversible measure. You can ask us to review any moderation decision that affected you - see Terms §12 for how appeals work.

We do not use automated decision-making for credit decisions, pricing, or any other commercial decision that affects you.

13.Security

We take appropriate technical and organisational measures to protect personal information against unauthorised access, disclosure, alteration, and destruction, as required by article 32 GDPR. These measures include encryption in transit and at rest, secure password storage, short-lived authentication tokens, access controls, rate limiting, and routine reviews of our security posture and of our sub-processors. We do not publish more granular implementation detail because doing so would help attackers more than it would help our users.

No system is perfectly secure, and we will tell you about a personal-data breach affecting you when the GDPR requires us to - in particular when a breach is likely to result in a high risk to your rights and freedoms (article 34), and we will notify the Autoriteit Persoonsgegevens within 72 hours where article 33 applies.

14.Changes to this Policy

We may update this Policy from time to time. Material changes (for example, a new category of processing, a new sub-processor in a new category, or a change to the legal basis we rely on) will be announced by email to the address associated with your account or by a prominent notice in the Service, and will take effect no earlier than 30 days after notice. Minor changes (clarifying wording, fixing typos, updating contact information) will be made by updating the "Effective" date at the top of the page.

We keep an internal version history and can tell you what changed in any previous version on request.

15.Contact and supervisory authority

For any question about this Policy or about how we handle your personal information, write to:

Verhaler Interactive
Keizersgracht 452, 1016 GD Amsterdam, the Netherlands
KvK: 42059039
Privacy: [email protected]
General: [email protected]

If you are not satisfied with how we have handled your information, you have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens:

Autoriteit Persoonsgegevens
Postbus 93374, 2509 AJ Den Haag, the Netherlands
Telephone: +31 (0)88 1805 250
Web: autoriteitpersoonsgegevens.nl/en

If you live in another EU or EEA country, you can also lodge a complaint with the supervisory authority of that country.

Verhaler Interactive
Keizersgracht 452, 1016 GD
Amsterdam, the Netherlands
Follow us on Instagram!
Contact
[email protected]
[email protected] · reports & takedowns
More on contact & business details →
Verhaler updates

Occasional email about what we are building. No noise.

Read

Discover

Writers

Get paidDocsCommunity

Legal

TermsAcceptable UsePrivacyRefunds & Cancellations
© 2026 Verhaler Interactive. Verhaler is Dutch for storyteller.