Skip to content
РRusLit
CatalogueClubs
Log inSign up

Privacy Policy

Version of September 16, 2026

This policy explains what personal data the RusLit service processes, why and on what legal basis, who can see it, how long it is kept and what rights you have. We collect only what the service needs to work and never use your data for advertising.

Details in square brackets will be filled in before the service launches.

  1. 1. Who is responsible for your data
  2. 2. What data we process
  3. 3. Why and on what legal basis
  4. 4. What other users can see
  5. 5. Moderation
  6. 6. Cookies and browser storage
  7. 7. Who receives your data
  8. 8. How long we keep data
  9. 9. Your rights
  10. 10. Age
  11. 11. Data security
  12. 12. Changes to this policy
  13. 13. Contact

1. Who is responsible for your data

Data controller: [CONTROLLER NAME], [CONTROLLER ADDRESS].

For any questions about personal data, write to [DATA PROTECTION CONTACT EMAIL]. [DATA PROTECTION OFFICER CONTACT DETAILS, IF APPOINTED].

2. What data we process

  • Account: email address, password (stored only as an irreversible hash), display name, native language, registration date, roles, date and version of the accepted Terms of Use.
  • Your content: words in your personal vocabulary with translations and context sentences, chapter notes (private and public), clubs you created, club memberships and applications, club notes, club bookmarks, reports you submitted.
  • Reading: your reading position in works and reader settings (font size and theme) - in your profile if you are signed in, or in your browser if you allowed functional cookies.
  • Moderation: reports about your content together with the text at the time of the report, moderators' decisions, date and reason of a block, hiding of your display name.
  • Technical data: IP addresses and request details are used to limit request rates and prevent abuse, and they appear in server logs.

3. Why and on what legal basis

  • Your account and the service features (reader, vocabulary, notes, clubs) - performance of the Terms of Use (Art. 6(1)(b) GDPR).
  • Emails confirming your address, resetting or changing your password and confirming account deletion - performance of the Terms of Use (Art. 6(1)(b) GDPR).
  • Security, protection against spam and abuse, content moderation, request rate limits - legitimate interest in running the service safely and fairly (Art. 6(1)(f) GDPR).
  • Functional cookies and browser storage - your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
  • Compliance with the law - the controller's legal obligation (Art. 6(1)(c) GDPR) [LIST OF APPLICABLE REQUIREMENTS].

No decisions about you are made automatically: reports are reviewed, and decisions to hide content or block accounts are made, by human moderators. Automatic limits (on the number of notes, clubs and requests) are the same for everyone and do not assess individuals.

4. What other users can see

  • Your display name is shown next to your public chapter notes - to any visitor of the site, including visitors who are not signed in. If you do not want to show your name, keep your notes private or choose a neutral display name in your profile.
  • A club's name, description and creator's name are visible to all visitors.
  • Club members can see your name, bookmark colour, the chapter you are reading and your club notes. A club's creator can see the names of applicants.
  • Private notes, your vocabulary, reading position and email address are not shown to other users. Only the service administrators can see email addresses.
  • If a moderator has hidden your display name, other users see an anonymous label instead.

5. Moderation

Users can report a public note, a club note or a club. A report keeps the text as it was when the report was submitted, so a moderator can see what was reported even if the text was changed later. A moderator can hide content - in response to a report or on their own if they notice a violation - hide a display name and block an account. All of these measures can be reversed, and decisions on content are kept in the moderation history.

A blocked user can see the reason for the block and sign in in restricted mode to download their data and delete their account. A block restricts behaviour on the service, not the rights to your own data.

6. Cookies and browser storage

Strictly necessary cookies are set without consent - signing in and account protection do not work without them:

  • ruslit.auth - keeps you signed in; up to 14 days, extended while you use the service (or until you close the browser if you did not choose "Remember me").
  • ruslit.antiforgery and XSRF-TOKEN - protection against request forgery; until you close the browser.
  • cookie_consent - your cookie choice; 6 months.

Functional cookies and browser storage are used only with your consent:

  • lang - the interface language you chose; 1 year.
  • reader_prefs - reader theme and font size, so pages open in your chosen style straight away; 1 year.
  • Browser storage (localStorage) - reading position and reader settings when you read without signing in; until deleted. When you sign in, this data is moved to your profile.

Without consent, the language and reader settings apply only in the open tab, and your reading position is not saved when you are not signed in. There are no analytics or advertising cookies. You can change your choice using the "Cookie settings" link at the bottom of every page; if you decline, functional cookies and browser data are deleted.

7. Who receives your data

We do not sell data or share it for advertising. Data is processed only by contractors the service cannot work without, under data processing agreements:

  • Hosting: [PROVIDER NAME, COUNTRY OF HOSTING].
  • Email delivery: [EMAIL SERVICE NAME, COUNTRY].
  • Traffic protection and delivery: [SERVICE NAME, COUNTRY - ONCE CONNECTED].

Transfers outside the European Economic Area: [STATE WHETHER THERE ARE ANY AND THEIR SAFEGUARDS - FOR EXAMPLE, STANDARD CONTRACTUAL CLAUSES].

Data may be disclosed to public authorities only in the cases and in the manner required by law.

8. How long we keep data

  • Your account and content are kept as long as the account exists. When you delete your account, they are deleted immediately.
  • When you delete your account, moderation records are kept in anonymised form: reports you submitted and moderators' decisions no longer link to you (the target, reason, comment and decision are kept), and in reports about your content the text is erased as well. These records are kept for [MODERATION RECORD RETENTION PERIOD].
  • Server logs are kept for [LOG RETENTION PERIOD].
  • Database backups are kept for [BACKUP RETENTION PERIOD], after which deleted data disappears from them as well.

9. Your rights

  • Access and portability: you can download all your data as a single JSON file in your profile.
  • Rectification: you can change your name and native language in your profile; to change your email address, write to [DATA PROTECTION CONTACT EMAIL].
  • Erasure: you can delete your account with all its data in your profile. This is also available while your account is blocked.
  • Withdrawing consent: use the "Cookie settings" link at the bottom of every page.
  • Restriction of processing and objection to processing based on legitimate interest: write to [DATA PROTECTION CONTACT EMAIL].
  • Complaint to a supervisory authority: [SUPERVISORY AUTHORITY OF THE CONTROLLER'S LOCATION] or the data protection authority of your country.

We respond to requests within one month. To protect your data, we may ask you to confirm that the request comes from the account owner.

10. Age

The service is intended for users aged 16 and over. Some EU countries set a lower age from which people can use online services on their own (13 to 15), but the service applies a single threshold of 16 for everyone. If we learn that an account was created by someone under 16, the account will be deleted.

11. Data security

Passwords are stored only as hashes, access to data is limited by roles, requests are protected against forgery, and the rate of sign-in attempts and other sensitive actions is limited. The connection to the site is encrypted [HTTPS - AFTER LAUNCH].

12. Changes to this policy

The version date is shown at the top of this document. We will notify you in advance about significant changes [NOTIFICATION METHOD - FOR EXAMPLE, BY EMAIL OR ON THE SITE].

13. Contact

[CONTROLLER NAME], [CONTROLLER ADDRESS], [DATA PROTECTION CONTACT EMAIL].

Terms of UsePrivacy Policy

Cookies on this site

Strictly necessary cookies keep you signed in and protect against request forgery - they are always set. With your consent, the site will also remember your interface language, the reader's theme and font size, and your reading position when you are not signed in. There are no analytics or ads.

Learn more in the Privacy Policy