Legal
Privacy
What this static book site stores, and what it does not.
Who we are
This site publishes a public reading shell for The Fulcrum: Infinite Structural Equilibrium by Malachai Grant. It is primarily a static site (HTML, CSS, JavaScript) served over HTTPS.
Data we collect
On your device only (default)
- Reading preferences — e.g. Talk persona, context, speaking rate, Listen persona — stored in browser
localStorage. These do not leave your device unless you clear or sync the browser yourself. - Cookie / consent choice — whether you accepted essential-only storage, stored in
localStorage(see Cookies). - Episode unlock credits & access flags — remaining credit count, unlocked episode slugs, whole e-book / Further Studies flags, and per-Sydney-day spend counters (
fulcrum_episode_credits,fulcrum_episode_unlocks,fulcrum_full_access,fulcrum_further_studies,fulcrum_daily_spend). These stay on-device unless you clear site data. - Optional Talk API key — if you paste an xAI key in Talk → Settings for local preview, it is stored only in
localStorageon this device. Prefer the production TTS proxy so no key sits in the browser.
Optional server features
- Text-to-speech (TTS) — if you use Listen / Speak via the same-origin
/api/ttsWorker (or local proxy), the spoken text is sent to that endpoint and then to xAI’s TTS API. Do not send secrets or sensitive personal data in Speak/Listen text. - Stripe Checkout (unlocks) — if you buy an episode unlock pack (1 / 5 / 10), A$20 whole e-book, or A$100 Part 2 — Further Studies collection, you are sent to Stripe’s hosted Checkout (or a Stripe Payment Link in test). Stripe processes payment details under its privacy notice. Our Worker may see Checkout Session metadata (e.g. product, credits, grants, optional return slug) to verify purchase — not your full card number.
- Analytics — none by default. No Google Analytics, no third-party ad trackers. If analytics are ever added, they will be optional, disclosed here and on the Cookies page, and gated behind consent.
What we do not do (default build)
- No accounts, no login, no user database on this static shell (unlocks are device-local in the current scaffolding).
- No sale of personal information.
- No third-party advertising cookies.
- No embedding of secret production API keys in client JavaScript.
Legal bases / Australian context (high level)
For Australian Privacy Principles (APPs) diligence: this shell is designed to minimise collection. Most interaction stays on-device. When TTS is enabled, processing is limited to providing the audio feature you requested. For GDPR-style transparency (EU/UK visitors): we describe categories of data, purposes, and storage location (device vs optional TTS path). This paragraph is descriptive only — not a determination of whether APP or GDPR apply to your deployment.
Retention
Device localStorage persists until you clear site data or use in-page clear controls (e.g. Clear key). Server TTS logs, if any, should be kept minimal and rotated per your Worker/host settings; the stub Worker does not persist request bodies by default.
Children
This book is written for a general adult and serious student audience. It is not directed at children under 13. Part V discusses trauma only as high-level “tilt” framing — not therapy.
Contact
Privacy questions: privacy@malachai.com (placeholder — replace with your monitored address). Security reports: see Security.
Terms · Cookies · Security · AI disclosure · Cover