CtrlK

Privacy Policy

How we collect, store, and use your personal information.

Last Updated: 2026-03-24

---

## TL;DR

- We collect the **minimum** needed to run the service: your login provider ID, IP address, and optional username/display name.
- We **do not** store your email address. If a provider sends it, we obfuscate it.
- We **do not** sell, share, or disclose your personally identifiable information to third parties.
- We may use **aggregated, anonymized data** (trends, stats), but never anything that identifies you.
- You can **delete your library and content** at any time. Full account deletion is available on request.
- We use self-hosted [Umami](https://umami.is/) for analytics and [Datadog](https://www.datadoghq.com/) for performance monitoring. No PII is sent to either.

_This summary is for convenience only. The full policy below is legally binding._

---

We value your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, store, and use your data.

## 1. Information We Collect

We only collect the following information from our users:

- Social Provider User Identifier (required) from the chosen login provider(s) (Discord, Google, Microsoft, GitHub, GitLab, Naver, Kakao, and Anilist)
- Social Provider Access Tokens for import/export integration (Anilist)
- IP address (required) for statistics, fraud and abuse tracking.
- Username (optional, if provided by you)
- Display name (optional, if provided by you)

## 2. How We Use Your Information

The Social Provider User Identifier and Social Provider Access Tokens are used to identify you as a user. The data is not used beyond that.

We do not use your information for marketing or promotional emails.

We do not request or store your e-mail address. In cases where a Social Provider always provide your e-mail, we obfuscate it in our database and discard the data.

We use a self-hosted [Umami](https://umami.is/) instance for website analytics.

We use [Datadog](https://www.datadoghq.com/) for application performance monitoring. Datadog may process technical data such as request timing, error traces, and server metrics. No personally identifiable information is sent to Datadog.

## 3. Data Sharing

We do not sell, share, or disclose your personally identifiable information to any third parties. Only authorized staff members have access to user information.

We may use aggregated, anonymized data (such as reading trends, genre popularity, and library statistics) for research, reporting, or to improve the service. This data cannot be used to identify individual users.

## 4. Data Storage & Security

All user information is stored securely in our private database. We take appropriate technical and organizational measures to protect your data.

## 5. User Control & Data Deletion

You can delete your library entries, lists, and other user-generated content at any time through the Service.

<!-- TODO: Implement full account deletion. Until then, users can contact us to request manual deletion. -->

Full account deletion is not yet available as a self-service feature. If you wish to delete your account and all associated data, please contact us and we will process the request manually.

## 6. Changes to This Policy

We may update this Privacy Policy as needed. Changes will be indicated by updating the "Last Updated" date at the top of this document. Your continued use of the Service after changes are posted means you accept of the updated policy.

## 7. Contact

If you have any questions about this Privacy Policy, please [contact us](/about).