Privacy Policy

How we collect, store, and use your personal information.

Last Updated: 2026-09-08 --- ## TL;DR - We collect the **minimum** needed to run the service: your login provider ID, your email address when you use email/password login, IP address, and optional username/display name. - If you create an email/password account, we store your email address for login, email verification, and password reset. If a social login provider sends us an email address, we obfuscate it unless it is needed for your MangaBaka account. - We **do not** sell, share, or disclose your personally identifiable information to third parties. - We may use **aggregated, anonymized data** (trends, stats), but never anything that identifies you. - You can **delete your library and content** at any time, and **delete your account** yourself under Settings → Danger. Deletion is immediate and cannot be undone. Submissions and comments stay in the catalogue with your identity stripped, and library changes stay in an internal audit log. - We use self-hosted [Umami](https://umami.is/) for analytics and [Datadog](https://www.datadoghq.com/) for performance monitoring. No PII is sent to either. _This summary is for convenience only. The full policy below is legally binding._ --- We value your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, store, and use your data. ## 1. Information We Collect We only collect the following information from our users: - Email address for email/password accounts - Social Provider User Identifier (required) from the chosen login provider(s) (Discord, Google, Microsoft, GitHub, GitLab, Naver, Kakao, and Anilist) - Social Provider Access Tokens for import/export integration (Anilist) - IP address (required) for statistics, fraud and abuse tracking. - Username (optional, if provided by you) - Display name (optional, if provided by you) ## 2. How We Use Your Information The Social Provider User Identifier and Social Provider Access Tokens are used to identify you as a user. The data is not used beyond that. For email/password accounts, your email address is used to identify your account, send verification emails, and send password reset emails. We do not use your information for marketing or promotional emails. For social login accounts, we do not request your email address unless needed for account functionality. In cases where a social provider always provides your email, we obfuscate it in our database unless it is needed for your MangaBaka account. We use a self-hosted [Umami](https://umami.is/) instance for website analytics. We use [Datadog](https://www.datadoghq.com/) for application performance monitoring. Datadog may process technical data such as request timing, error traces, and server metrics. No personally identifiable information is sent to Datadog. ## 3. Data Sharing We do not sell, share, or disclose your personally identifiable information to any third parties. Only authorized staff members have access to user information. We may use aggregated, anonymized data (such as reading trends, genre popularity, and library statistics) for research, reporting, or to improve the service. This data cannot be used to identify individual users. ## 4. Data Storage & Security All user information is stored securely in our private database. We take appropriate technical and organizational measures to protect your data. ## 5. User Control & Data Deletion You can delete your library entries, lists, and other user-generated content at any time through the Service. You can also delete your account yourself, under Settings → Danger. Deletion happens the moment you confirm it. There is no grace period and nothing can be restored afterwards. We ask you to empty your library and remove any OAuth applications you own first, so you get a chance to export your library and so the people signed in to your apps are not cut off without warning. What deletion removes: your profile, username and avatar, your connected accounts, sessions and access tokens, your notification settings, recommendations and reading statistics. What it keeps, and why: - **Submissions, reviews and comments stay in the catalogue**, with your name, username and avatar removed from them. They are part of the shared record of how the catalogue was built, and nobody can delete a submission, including us. If you have any of these, your account row survives as an anonymous placeholder so those contributions still have something to point at. It cannot be signed in to and holds nothing personal. - **Internal audit records stay.** Changes to your library (titles, ratings, notes, reading progress) are written to an append-only audit log that we keep and do not delete. It is not visible to other users and is only used to investigate problems. If your account left nothing attributable behind, the account record itself is deleted outright. Deleting your account frees your email address, so you can sign up again with it. That is a new account and has no connection to the old one. ## 6. Changes to This Policy We may update this Privacy Policy as needed. Changes will be indicated by updating the "Last Updated" date at the top of this document. Your continued use of the Service after changes are posted means you accept of the updated policy. ## 7. Contact If you have any questions about this Privacy Policy, please [contact us](/about).