Controller and contact
Danger All In One is the official franchise website operated by author and screenwriter Saša Slavić in Croatia. Saša Slavić is the controller for information collected directly through this site. Privacy requests may be sent to sashaslavic@dangerallinone.com.
Your privacy choices
Visitors can separately choose whether to allow the site's anonymous, first-party visit measurement. It starts only after that explicit choice or, where available, after Google's certified IAB TCF consent interface reports consent for storage and content measurement. Google's certified IAB TCF message remains the control for advertising choices in the European Economic Area, United Kingdom, and Switzerland. External video or social embeds are click-to-load.
Open privacy and cookie settings
You may change or withdraw a prior choice at any time. Rejecting optional processing does not block access to the books, screenplays, music, or other public content. Browser controls can also remove cookies and local storage, although signed-in or saved-preference features may stop working.
Information and purposes
When you request a page, hosting and security providers necessarily receive the IP address, requested URL, date and time, browser or device information, and limited request headers. This is used to deliver the site, prevent abuse, diagnose failures, and protect the service. Fastly provides edge hosting and security.
Information you voluntarily submit may include an email address, display name, account profile, newsletter choice, contact message, community contribution, feedback, or AI question. It is used to provide the requested feature, respond to you, maintain the service, and prevent abuse. Do not submit passwords, payment-card information, private manuscripts, or sensitive personal information through public forms or AI chat.
After valid analytics consent, the site may record a pseudonymous visitor and session identifier, page path, broad interaction type, media play, and duration. The visitor identifier lets the site distinguish returning consented visitors without using an email address. Search or question text is not sent to the site's analytics endpoint. Private analytics and administration data are access-restricted.
Cookies and local storage
| Name or group | Provider | Purpose | Category and duration |
|---|---|---|---|
daio_access | Danger All In One / Supabase authentication | Maintains a signed-in account session. | Strictly necessary; normally up to about 1 hour. |
daio_refresh, daio_remember | Danger All In One / Supabase authentication | Refreshes a signed-in session and remembers the user's explicit sign-in choice. | Strictly necessary for the requested account feature; session-only or up to 30 days when “remember me” is chosen. |
Google CMP and TCF consent record, including identifiers such as FCCDCF where used | Stores and demonstrates privacy choices and makes them available to participating vendors. | Necessary consent record; duration and vendor details are shown in the certified consent interface. | |
daioAnalyticsConsent | Danger All In One | Remembers the visitor's explicit first-party analytics choice. | Consent preference; local storage; expires after up to 400 days unless changed or cleared. |
daioAnalyticsSession | Danger All In One | Groups consented, pseudonymous site-usage events during a browser session. | Analytics; session storage; created only after analytics consent. |
daioAnalyticsVisitor | Danger All In One | Distinguishes a returning consented visitor without storing an email address or account identity. | Analytics; local storage; created only after analytics consent and expires after up to 400 days unless cleared or consent is withdrawn. |
| Reading, spoiler, soundtrack, profile, chat, and interface preference keys | Danger All In One | Remembers a feature or preference the visitor actively uses on this device. | Functional storage; session or persistent until cleared, depending on the feature. |
| Advertising cookies, local storage, and consent strings | Google AdSense and consented ad-technology vendors | Ad delivery, measurement, fraud prevention, frequency controls, and—only when consented—personalization. | Advertising; names and durations vary and are listed by purpose and vendor in the certified consent interface. |
| YouTube or TikTok storage | Google/YouTube or TikTok | Loads an external video or social post requested by the visitor. | External media; activated only after a deliberate click. Provider-set duration. |
Google advertising and the August 2026 IP update
This website may use Google AdSense. Subject to consent and account settings, Google and other third-party vendors may receive cookies or local-storage identifiers, the page and referrer, ad interactions, browser or device information, and an IP address. Google states that its August 2026 EEA, UK, and Swiss rollout may use IP addresses for advertising measurement, device identification, approximate location, and personalization where consent permits.
See how Google uses data from partner sites, Google's business data responsibility information, and Google Ads Settings. Consent Mode signals cover advertising storage, analytics storage, advertising user data, and ad personalization. Consent Mode does not replace the certified consent platform.
Providers and international transfers
Providers used for specific features may include Fastly for hosting and security; Supabase for accounts, community data, and consented analytics storage; Brevo for requested newsletter email; OpenAI for AI features a visitor chooses to use; Google for AdSense, consent management, and YouTube; and TikTok for explicitly loaded social embeds. Retailer and social links open third-party sites governed by their own notices.
Some providers may process information outside Croatia or the European Economic Area. Where GDPR applies, transfers should rely on an applicable adequacy decision, Standard Contractual Clauses, or another lawful safeguard offered by the provider. Information is not sold by the author as a standalone product.
Legal bases and retention
Consent is used for optional advertising personalization, optional analytics, external media, and marketing email. Contract or steps requested by you support account and service features. Legitimate interests support proportionate security, fraud prevention, service reliability, and responding to ordinary communications, subject to your rights.
Account cookies follow the periods in the table. Consent records are retained for the period needed to demonstrate and honor the choice. Newsletter records remain until withdrawal or operational deletion; account, community, contact, and security records are kept only as long as needed for the requested service, abuse prevention, disputes, or legal duties. Provider retention may also apply as described in the provider's notice.
Your data-protection rights
Where GDPR applies, you may request access, correction, deletion, restriction, objection, and portability where applicable, and may withdraw consent without affecting processing that was lawful before withdrawal. Email the controller above; identity may need to be verified. You may also complain to the Croatian Personal Data Protection Agency, AZOP, or another competent supervisory authority.
You may unsubscribe from marketing email using the unsubscribe route provided with a message or by contacting the website. Advertising choices may also be reviewed through the privacy settings control above and Google Ads Settings.
Children, security, and changes
The website is a general-audience entertainment and publishing site and is not directed to children under 13. Reasonable technical and organizational safeguards are used, but no Internet service can guarantee absolute security.
This notice may be updated when website features, providers, or legal requirements change. Material changes will be reflected in the revision date shown above.