Legal
Privacy Policy
Last updated [DATE] · Draft — pending full legal review before publication
1. Who we are
MBBS ("we," "us," "our") operates an interactive fiction reading app and website (the "Service"). This policy explains what information we collect, why, and what rights you have over it.
Data controller: MBBS Digital Limited, a company incorporated in Nigeria.
Contact: hello@readmbbs.com (general) / support@readmbbs.com (account or data requests)
This policy applies to the MBBS website and mobile app, wherever you access them from.
2. Who can use MBBS
You must be at least 16 years old(or the age of digital consent in your country, if higher) to create an MBBS account. Guest reading (see §3) requires confirming you meet this same minimum age via a one-time prompt shown before your first chapter, stored locally on your device so you're not asked again. This is a self-attested confirmation, not an independently verified check — there's no account at that point to verify age against. We do not knowingly collect personal data from children below this threshold, and if we learn we have, we will delete it.
3. Information we collect
Account information
When you sign up, we collect an email address and generate a username (editable later in account settings). We never see or store your raw password — authentication is handled by our secure authentication provider.
Guest reading
You can read a season's first chapter without an account. Your position is stored locally on your device/session until you either continue as a guest for that session or create an account. If you sign up, that locally-held progress is carried into your new account once, at signup — it isn't retained by us before that point.
Reading progress and choices
Once you have an account, we store where you are in each story and the choices you've made along the way — this is what lets the story respond to your decisions and lets you pick up exactly where you left off, on any device. This information is private to your account. It's never shown to other readers and is only used to determine what content is shown to you as you read.
Purchases
When you buy a season, we store a purchase record: which season, the amount, currency, which payment method was used, and a transaction reference. We only retain confirmation that a purchase happened.
We never store your card or payment details ourselves — that's handled entirely by our payment processors (Flutterwave, Apple, and Google).
Season Reactions
If you've purchased a Season, you can pick from a small, fixed set of reactions to express how it landed for you (e.g. "loved it," "wrecked me") — there's no free text, so there's nothing you write that we'd need to store or moderate. We record which reactions you've picked, tied to your account, so you can see and change your own picks later. What's shown to other readers is an anonymous total only — e.g. "94 readers picked this" — never your identity, never which reactions you personally chose. Aggregate totals are visible even to people who haven't purchased the season yet, since a count reveals nothing personal; only purchasers can add or change a reaction. If you refer another reader, we track whether that referral qualifies, in order to award referral points.
Notifications
If you enable notifications, we store your preferences per notification type (chapter releases, referral points) and per channel (push, email, in-app). We never send re-engagement or "come back" style prompts — only notifications tied to something that actually happened.
Usage analytics
We log basic usage activity (e.g. a chapter was started or completed, a purchase completed, a signup completed) to understand pacing, drop-off, and conversion. We do not use any third-party analytics or advertising tracking tools, and this information is never sold or shared with advertisers.
Location signal
At signup, we ask for your country, which determines regional pricing. If available, we may use IP-based location only as a pre-fill suggestion for that field — never to silently reprice your account later or track your movements. Once set, your pricing country is sticky and only changes if you update it yourself.
4. How we use your information
We use the information above to:
- Operate your account and keep your reading progress in sync across devices.
- Process and verify purchases, and give you access to what you've bought.
- Determine appropriate regional pricing.
- Show anonymous, aggregated reaction totals, and let you see and change your own reaction picks.
- Send you the notifications you've opted into.
- Understand how the product is used, in aggregate, so we can improve pacing, content, and the reading experience.
- Detect and prevent abuse (e.g. spam or fraudulent activity).
- Meet legal obligations (e.g. records needed for tax or dispute-resolution purposes).
We do not sell your personal data, and we do not use it for third-party advertising.
5. Who we share information with
We share data only with the service providers needed to operate MBBS, each acting on our instructions and only for the specific purpose listed:
| Provider | Purpose |
|---|---|
| Our database/hosting provider | Secure storage of account and reading data |
| Flutterwave | Payment processing (web) |
| Apple / Google, via our mobile payments provider | Payment processing (in-app purchase on mobile) |
| Our email provider | Transactional email (account, purchase, chapter-release emails) |
| Our application hosting providers | Running the website and backend service |
We do not share your reading progress or in-story choices with anyone beyond what's needed for these providers to perform their specific function.
We may disclose information if required by law, or to protect the rights, safety, or property of MBBS, our readers, or the public.
6. International data transfers
Our infrastructure may store or process data outside your home country. Where this involves transferring personal data out of the EU/EEA or other regions with data-transfer restrictions, we rely on the relevant provider's standard safeguards (e.g. Standard Contractual Clauses).
Open item: confirm specific safeguards once hosting provider(s) and regions are finalized.
7. How long we keep information
- Account data and reading progress: kept for as long as your account is active, so your progress stays available across devices and sessions.
- Purchase records: retained for as long as required for tax, accounting, and dispute-resolution purposes, even after account deletion, to the extent legally required.
- Usage/analytics data: retained in aggregate/operational form; we periodically review whether older, granular data is still needed.
- Reactions: retained for as long as your account is active. On account deletion, your reactions stay as part of the anonymous total (they carry no personal content beyond your account link, which is itself anonymized on deletion — see §9) rather than being removed, since removing them would just make the totals less accurate for no privacy benefit.
Open item: specific retention periods (e.g. "purchase records kept for 7 years") should be set with actual legal/tax guidance before publishing.
8. Your rights
Depending on where you live, you may have rights to:
- Access the personal data we hold about you.
- Correct inaccurate data (most account info is also self-editable in-app).
- Delete your account and associated personal data ("right to erasure").
- Export your data in a portable format ("data portability").
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent (e.g. optional notifications).
EU/EEA readers (GDPR): the legal bases we rely on are performance of a contract (running your account, delivering purchases), legitimate interest (product analytics, abuse prevention), and consent (optional notifications). You also have the right to lodge a complaint with your local data protection authority.
Nigerian readers (NDPR): you have equivalent rights to access, correction, and deletion of your personal data under the Nigeria Data Protection Regulation, and can direct requests to the contact below.
To exercise any of these rights, email support@readmbbs.com. We'll respond within the timeframe required by applicable law (typically 30 days).
9. Account and data deletion
You can request deletion of your account and associated personal data at any time via account settings or by emailing support@readmbbs.com. When you delete your account:
- You'll have a 14-day grace period before deletion actually happens — your account stays fully usable during this time (reading, purchasing, everything works normally), and you can cancel the deletion request at any point before the window closes.
- Once the window closes, your personal reading data (reading progress, choices, notification settings) is deleted, and your email/username are replaced with anonymized values.
- Your reactions stay as part of the anonymous aggregate totals (see §7) — they carry nothing personally identifying once your account itself is anonymized.
- Purchase records are retained only to the extent required by law (see §7), decoupled from your personal profile where possible.
10. Cookies and local storage
MBBS uses local device storage (not third-party ad-tracking cookies) to:
- Hold guest reading progress before you have an account.
- Remember that you've confirmed the minimum age requirement (§2), so guest reading doesn't re-prompt every visit.
- Store device-only reader settings (e.g. text size), which are not synced to our servers.
We do not use third-party advertising cookies or cross-site tracking.
11. Security
We use industry-standard security practices, including HTTPS everywhere and secure authentication, and no payment instrument data touches our own systems — that's handled entirely by our payment processors. Internal access to reader data is restricted to authorized personnel only. No system is perfectly secure, and we can't guarantee absolute security, but we follow standard access-control practices throughout.
12. Changes to this policy
We'll update this policy as the product changes and post the revised version with a new "Last updated" date. Material changes will be flagged more prominently (e.g. in-app notice or email) where appropriate.
13. Contact
Questions or requests about this policy or your data: support@readmbbs.com. See also our Terms of Service and Contact page.