Privacy policy
Ta strona jest dostępna po angielsku i norwesku.
Last updated 9 October 2026. This policy explains how Stories in Norwegian handles personal data.
Who is responsible
The controller is Martin Mastermo Jenssen, a private individual operating Stories in Norwegian:
Martin Mastermo Jenssen
Valheimveien 25, 4020 Stavanger, Norge
Email: martinkontakter@gmail.com
Phone: +47 41752356
Reading without an account
You can read free stories without an account. We don't set advertising or analytics cookies. Your browser stores a few settings locally (theme, text size). If you finish a story without being signed in, your browser also keeps a small local note of it (story and quiz answers, for up to 7 days); if you then sign in on that browser, it is saved to your account. We also collect the limited website statistics described below; reports about word explanations are optional (see below). Like any website, our hosting and media providers process your IP address and basic request data to deliver pages and audio and to keep the service secure.
Website statistics
We use Vercel Web Analytics to understand visits to public pages and improve the website. It gives us aggregate page-view and visitor counts, referring websites, approximate location, and browser/device information. It uses no analytics cookies and does not track you across websites; its request-derived visitor identifier expires after 24 hours. We remove query strings and URL fragments and exclude sign-in, account, saved-word, checkout and administration pages. We do not send account IDs, email addresses, story text, selected words or quiz answers to analytics, and we do not record sessions. Vercel processes these statistics for us. The native apps do not use this website analytics service.
With an account
When you sign in, we process:
- Account data — your email address, and the name and profile image your sign-in provider shares if you use Apple or Google (Clerk copies these into your account). Managed by our authentication provider, Clerk.
- Session and security data — for each signed-in session, Clerk records technical data such as the device/browser (client) and an approximate location (city and country) derived from your IP address. It is used to keep sessions working and secure, not for advertising.
- Learning data — reading position, finished stories and quiz scores, the days you were active (for your streak), saved words, your chosen level, interests and language, and any star ratings or written feedback you give. Stored with our database provider, Convex, linked to an internal user ID.
- Purchase data — whether you have bought the full library, on which platform, and the purchase records our payment partners keep. See Purchases below.
We use this to provide your account, sync your progress between devices, give access to what you bought, and answer support requests (legal basis: performance of our contract with you, GDPR Art. 6(1)(b)). We use limited technical data to prevent abuse, for example rate limits on word explanations and on reports (legitimate interest, Art. 6(1)(f)).
Word explanations (AI)
When you tap a word, we may ask OpenAI to write a translation and a short explanation. We send only the word, the sentence it appears in, the story's level and the language for the explanation. We never send your name, email or user ID. We ask OpenAI not to store the response for later use, but OpenAI may still keep API requests for a limited time under its own policies (for example, for abuse monitoring). Answers are stored by us and shared with all readers of the same story, so the same word isn't looked up twice. Explanations are generated automatically and can contain mistakes.
Reporting an explanation
You can report a word explanation with the Report button next to it. This is optional and works with or without an account. A report contains the reason you pick from a fixed list (there is no free-text field), the story, word and language, and a copy of the explanation as you saw it, so we can review it even if it changes later. If you are signed in, the report is linked to your internal user ID. If not, it is linked to a random report ID that your browser or app creates the first time you report and keeps locally; it is not linked to your account or used for anything else. We use these IDs only to ignore repeated reports and to limit abuse. Reports are stored with Convex, are reviewed by us, and are never sent to OpenAI. We keep reports while we need them to review explanations; when you delete your account, we remove the link between your reports and your account.
Purchases
Purchases in the iPhone and Android apps are made through Apple (App Store) or Google (Google Play), which process the payment under their own terms. Purchases on the website are made through Lemon Squeezy, which acts as the merchant of record (the reseller) for web purchases: it handles checkout, payment, taxes, receipts and billing contact, and processes your name, email address, billing details and payment information under its own privacy policy (lemonsqueezy.com/privacy). For a web purchase we store a randomly generated checkout ID and Lemon Squeezy's order number, linked to your account; the order's status, amount, currency and refund status; which version of our web refund terms applied at checkout (older checkouts may instead retain when you consented to immediate access and which version of that text you saw); and the related timestamps. We never see your full card details. For purchases in the apps, RevenueCat keeps the record of which account owns the library, identified by our internal user ID, and uses the purchase records to provide us with purchase reporting (for example, how many purchases and refunds there have been). This is used to run the service, not for advertising or tracking across other apps.
Service providers
- Clerk — sign-in and account management.
- Convex — database and backend.
- Cloudflare (R2) — delivery of images and audio.
- Vercel — website hosting and aggregate website statistics.
- RevenueCat — record of which account owns the library, and purchase reporting.
- Apple, Google — purchases in the apps.
- Lemon Squeezy — purchases on the website (merchant of record).
- OpenAI — word explanations (story text only, no personal data).
Some of these providers are based in, or process data in, the United States. Where personal data is transferred outside the EEA, this happens under the transfer safeguards the provider offers under the GDPR, such as the EU Standard Contractual Clauses.
How long we keep data
We keep your account and learning data until you delete your account. When you delete it, we delete your learning data, saved words, feedback and account at our providers, and ask RevenueCat to delete your customer record. We keep a minimal deletion record — your internal user ID, when deletion was requested and completed, and which cleanup steps succeeded — so we can finish and prove the deletion and so a delayed message from a payment partner can't recreate your account. It contains no email, name or learning data and is kept for as long as the service runs. Technical records of purchase notifications (notification ID, type and time) are kept without your user ID. Records we must keep by law, such as accounting records for purchases, are kept for the period the law requires. Payment providers (Apple, Google and, for web purchases, Lemon Squeezy) keep their own financial records under their own legal obligations; we cannot delete those. If you sign in with Apple in our iPhone app, we store a token from Apple only so that we can revoke the app's access to your Apple ID when you delete your account. Shared word explanations contain no personal data and are kept. Reports you made about word explanations (reason and copy of the explanation) are kept for review without any link to your account; your story ratings and written feedback are deleted.
Your rights
You have the right to access, correct and delete your data, to restrict or object to processing, and to data portability. You can delete your account yourself (see Delete your account) or contact us. You can also complain to the Norwegian Data Protection Authority (Datatilsynet), datatilsynet.no.
Children
Stories in Norwegian is made for adults and is not directed at children under 16.
Changes
If we change how we use personal data, we'll update this page and, for important changes, tell signed-in users in the app.