Website information

Privacy Policy

This policy explains how personal information is collected, used and protected when you visit The Nightspire Legacy website, join the mailing list or get in touch.

Last updated: 29 July 2026

Who operates this website

This website is operated in the United Kingdom by Neil Ault, author and creator of The Nightspire Legacy. For UK data-protection law, Neil Ault is responsible for deciding how personal information collected through this website is used.

Information that may be collected

The website does not keep newsletter or contact-form submissions in its own database. It does provide private, passwordless accounts for the beta-reader programme. It may collect or process:

  • your email address and subscription information when you join the newsletter;
  • your name, email address and message when you use the contact form;
  • your email address, beta-reader application statement, account status, agreement acceptance, sign-in and download history when you use the beta-reader area;
  • emails and other information you choose to provide during correspondence; and
  • technical information such as your IP address, browser and device information, request time and pages requested, where this is recorded in ordinary web-server or service logs.

Please do not send sensitive personal information through the contact form.

Newsletter subscriptions

If you choose to join the mailing list, your email address is used to send updates about The Nightspire Legacy, its books and releases, and closely related author news. Subscribing is optional and is not required to use the website.

MailerLite provides the mailing-list and email-delivery service and processes subscriber information on the site operator's behalf. MailerLite may also record information needed to operate the service, such as subscription status, confirmation, delivery and engagement information.

The lawful basis for sending newsletter emails is your consent. You may withdraw that consent at any time by using the unsubscribe link in a marketing email. Withdrawing consent does not affect processing that took place before withdrawal. A suppression record or other minimal unsubscribe information may be retained where needed to make sure an unsubscribed address is not accidentally added again.

Contact enquiries

When you use the contact form, the name, email address and message you provide are sent to the author through an email service so the enquiry can be read and answered. The website does not store the submission in a database, although copies may remain in the relevant email accounts and service logs.

The contact form uses Cloudflare Turnstile to distinguish genuine enquiries from automated spam. Cloudflare may process technical information associated with the security check, such as your IP address and browser or device signals. Turnstile is an essential anti-abuse control for this form rather than an optional analytics or marketing service.

This information is used only to handle your enquiry, maintain appropriate correspondence records, protect the website from misuse and, where relevant, take steps you request before entering into an agreement. The lawful basis is normally legitimate interests in responding to genuine enquiries and operating the website safely. Contract or legal obligation may apply where the nature of the enquiry requires it.

Beta-reader programme

If you request beta access, the website records your email address, your answers about your motivation, recent genre reading, reading commitment and natural feedback areas, the application question-set version and submission time, account status, the version and time of your confidentiality-agreement acceptance, sign-in activity and successful manuscript downloads. These application answers are used to assess suitability for the beta-reading programme, administer applications, and understand your reading interests and likely feedback strengths. Decisions are made by the programme administrator, not by automated scoring. A shortened or cryptographically hashed representation of your IP address and limited browser information may also be retained to secure access, enforce request limits and investigate misuse.

Passwordless sign-in links are single-use and expire after a short period. The website stores only a cryptographic hash of each link and session token, not the secret sent to you. Programme email is delivered through the configured SMTP provider. Essential account, security, agreement and withdrawal messages are sent where needed to operate or protect the account. Optional operational reading updates are enabled by default and can be disabled or re-enabled from the private dashboard without affecting essential messages.

If you explicitly enable device notifications, the website stores the browser push endpoint and cryptographic subscription keys associated with your beta-reader account. These details are used only to deliver restrained programme updates. Each browser or device must receive notification permission from you separately. You can disable a device or all device reading updates from the dashboard, and permission can also be revoked through your browser or device settings.

Beta-reader feedback is collected through an embedded survey provided by Tally. Tally processes the responses you submit. The survey may receive your opaque public beta-reader ID, personalised copy ID, manuscript version and non-sensitive release identifier so feedback can be matched to the authorised manuscript copy. Your name, email address, database record ID, sign-in token and session token are not intentionally passed in the embedded survey URL.

The Tally form is loaded only on the authenticated feedback page and is essential to the feedback action you explicitly choose to use. It is not used for advertising or general website analytics, and Tally event tracking is not enabled by this website. Survey responses and the permitted identifiers are used to administer and evaluate the beta-reading programme.

This information is used to review applications, administer the programme, provide and protect confidential manuscript access, record the agreement between the reader and the author, communicate about the programme and establish or defend legal rights. Depending on the activity, the lawful basis is taking steps at your request, performance of the beta-reader agreement, legitimate interests in running and securing the programme, or legal obligations.

You can withdraw through your private dashboard or contact [email protected] to request deletion. Access and unnecessary personal data will be removed or pseudonymised where appropriate, but minimum records may be retained where reasonably necessary to evidence the agreement, enforce confidentiality, investigate misuse or meet a legal obligation.

Cookies and similar technologies

With your consent, this website uses Google Analytics to understand aggregate website use, such as pages visited, approximate location, device and browser information, and how visitors arrived at the site. Google Analytics is not used for advertising on this website. It is not loaded unless you accept optional services, and Google may use cookies or similar technologies and receive technical information including your IP address.

The website stores your optional-service choice in your browser's local storage so it can remember whether you accepted or rejected those services. This preference is necessary to respect your choice and can be removed through your browser settings.

The newsletter form uses MailerLite for subscription management and Google reCAPTCHA for spam protection. These services are treated as optional and are not loaded unless you accept optional services. If you accept, those providers may use cookies or similar technologies and receive technical information such as your IP address, browser and device information. reCAPTCHA is used to distinguish genuine subscriptions from automated submissions.

Cloudflare Turnstile on the contact form is separate from these optional newsletter services. It is loaded only on the contact page and is required to protect that form from automated misuse.

You can accept or reject optional services with equal prominence when the choice is shown. You can also review or change the choice at any time using the control in the footer. Rejecting optional services does not prevent you from reading the website, but the protected newsletter form cannot operate without its anti-abuse and mailing-list services.

Third-party services and links

Personal information may be shared only where reasonably necessary with providers supporting the website, including the website host, email and SMTP providers, Cloudflare for website delivery and Turnstile anti-abuse checks, MailerLite, Tally for beta-reader feedback, and Google for Analytics, reCAPTCHA and remotely hosted fonts. These providers may receive technical request information when their services are used. They process information under their own terms and, where acting for the site operator, under appropriate service arrangements.

The website also links to social media and other external websites. Following a link takes you to a service controlled by another organisation. Its own privacy information will apply, and this policy does not cover how that organisation uses your information.

Why information is used

Personal information is used to understand website use where you consent to analytics, provide the newsletter you request, respond to enquiries, administer secure beta-reader access, deliver and secure the website, prevent spam and misuse, diagnose technical problems, meet legal obligations and establish or defend legal rights. Information is not sold.

Where legitimate interests are relied upon, those interests are operating a secure and useful author website, communicating with people who make enquiries and keeping proportionate records. Those interests are considered against your rights and expectations.

International transfers

Some service providers or their sub-processors may process information outside the United Kingdom. This can include locations in the European Economic Area and the United States. Where UK data-protection law requires safeguards for a transfer, the relevant provider arrangements may use an adequacy regulation, approved contractual protections or another lawful transfer mechanism. MailerLite publishes further information about its processing arrangements in its privacy policy.

How long information is kept

Newsletter information is kept while you remain subscribed and afterwards only where reasonably necessary to manage the mailing list, honour an unsubscribe request, resolve a complaint or meet a legal obligation. Contact correspondence is kept only as long as reasonably necessary to deal with the enquiry and any related legal or administrative need. Beta-reader account and access records are kept for the programme and afterwards only to the extent reasonably necessary to evidence agreement acceptance, administer withdrawal, protect the unpublished work, investigate misuse or meet legal obligations. Technical logs are retained according to the relevant host or service provider's operational and security practices.

Data security

Reasonable technical and organisational measures are used to protect personal information, including encrypted web connections where the website is served over HTTPS, access controls provided by relevant services, anti-spam controls and limiting the information collected. No internet or email service can be guaranteed to be completely secure.

Your data-protection rights

Depending on the circumstances, UK data-protection law may give you rights to:

  • ask whether your personal information is being used and obtain a copy;
  • ask for inaccurate or incomplete information to be corrected;
  • ask for information to be deleted or its use restricted;
  • object to processing based on legitimate interests or for direct marketing;
  • receive certain information you provided in a portable format; and
  • withdraw consent where consent is the lawful basis.

These rights are not all absolute. To make a request, email [email protected]. Information may be requested to confirm your identity before a request is completed.

Complaints

If you have a concern about how your information has been handled, please contact the site operator first so it can be investigated. You also have the right to complain to the UK Information Commissioner's Office. Guidance and the ICO's complaint service are available at ico.org.uk.

Children's privacy

The website is about a fantasy book series and may be read by a general audience, but its newsletter and contact form are not designed to collect personal information from children. If you believe a child has provided personal information without appropriate permission, please get in touch so the situation can be reviewed and the information deleted where appropriate.

Changes to this policy

This policy may be updated when the website, its providers or legal requirements change. The date at the top of the page will show when it was last updated. Material changes affecting newsletter subscribers may also be communicated through an appropriate channel.

Privacy contact

For questions, requests or complaints about privacy on The Nightspire Legacy website, email Neil Ault at [email protected].