This legal document is provided in English only.

Privacy notice

First-party usage analytics

HackerBoost uses first-party analytics to understand which books, parts, and chapters are useful, where readers stop, and which pages lead to subscriptions.

We record random visitor and visit identifiers, page paths, content identifiers, language, reading progress, active reading time, internal navigation, the hostname of an external referrer, and campaign parameters when supplied. For subscription reporting we record Stripe transaction identifiers, currency, amounts, refunds, and the content or landing page associated with checkout.

We do not store IP addresses, full user-agent strings, or complete external referrer URLs in analytics. Administrators and recognized automated crawlers are excluded. A browser Do Not Track signal is respected for readership analytics.

These records are used only to operate and improve HackerBoost, understand subscription performance, and reconcile sales. They are not sold or used for third-party advertising.

Weekly publication-news email

HackerBoost may offer optional weekly publication-news email about newly published books, parts, and chapters. The preference is independent from sign-in, subscription, billing, beta-program, support, security, and other operational email.

Preference records contain the current enabled state, language, timestamps, immutable change events, and private management-token hashes. Management and unsubscribe tokens are random and stored only as keyed HMAC hashes. Email identities used for suppression, delivery, and provider correlation are also stored as keyed HMAC hashes where possible.

Active suppressions from hard bounces, invalid addresses, blocked or dropped mail, spam reports, provider or global unsubscribes, and manual or legal suppression override an enabled preference. RFC 8058 one-click unsubscribe is supported by POST and is idempotent; opening a management or unsubscribe link with GET does not unsubscribe the account.

SendGrid event processing for this weekly flow stores only sanitized campaign, delivery, event type, reason, status code, and same-origin path facts. It does not store raw provider payloads, webhook signatures, request headers, IP addresses, user-agent strings, raw private tokens, or recipient email addresses in weekly engagement records.