Trajan’s Forum

Privacy notice

A plain-language description of how this private application handles authentication and owner-provided information.

Effective August 24, 2026

What the application handles

Trajan’s Forum is a private, single-owner reading and history application. Google or GitHub provides basic account information during sign-in so the application can confirm that the account belongs to the approved owner. The application does not provide public profiles or social features.

The owner may add private library records, reading notes, shelves, tags, historical relationships, and related evidence. This information is available only behind the owner-authentication boundary.

How information is used

Account information is used only to authenticate the owner and maintain the signed-in session. Library and historical information is used to provide the features the owner requests, including organization, recommendations, and historical tutoring.

When the owner deliberately uses an AI feature, the application sends only the bounded context needed for that request. The application does not sell personal information, use it for advertising, or make it public.

When the owner uses camera-assisted book intake, the phone browser removes photo metadata before upload. The prepared book or shelf image is sent to OpenAI for OCR with provider storage disabled, and Trajan’s Forum does not retain the source photograph. Recognized metadata may be checked with Open Library before the owner reviews it.

Where information is processed

Vercel hosts the application, Supabase provides the private PostgreSQL database, Google and GitHub provide sign-in, and OpenAI processes requests for optional AI features. Each provider may process limited technical information under its own terms and privacy policy.

Trajan’s Forum does not maintain a separate public user directory. Authentication state is held in a protected session cookie, and OAuth credentials remain server-side.

Retention and control

The owner controls the application data and can export the private library. OAuth access can be revoked through the relevant Google or GitHub account settings. Application data can be corrected or removed by the owner through the private application or its administrative maintenance process.

Questions about this notice can be sent to the support address displayed on the Google sign-in consent screen.