Privacy Policy
[COMPANY LEGAL NAME] ([REGISTERED ADDRESS]) is the data controller for アニメ日本語 (anime nihongo). This describes what we collect, why we are allowed to, who else sees it, and what you can make us do about it.
1. What we collect
- Account data — name, email address, hashed password, and the provider id if you sign in with GitHub or Google. We never see your password in plain text or your OAuth provider password at all.
- Your study data — decks, titles, JLPT levels, and the cover art you upload.
- Subscription data — which plan you are on, its status, and the renewal date. We never receive or store your card details; those go directly to Dodo Payments.
- Support messages — what you send through the contact form: your name, email, and the message itself.
- Technical data — server logs, and a salted hash of your IP address on contact-form submissions. We keep the hash rather than the address so we can spot one script filing fifty tickets without holding data that identifies you.
- Security data — a device signature worked out from your browser and device settings, plus your IP address, checked on every sign-in attempt. This is how we tell you from someone working through a list of stolen passwords, and it is collected for anyone who loads the site, not only while you are signed in.
- Usage data — which pages you open, what you click, the site or search that brought you here, and your device, browser and approximate location worked out from your IP address. This is collected by PostHog and Google Analytics on our behalf, and it is how we tell a feature nobody can find from a feature nobody wants.
We do not run advertising trackers, we do not build advertising profiles, and we do not sell what the analytics collect. The cookie that keeps you signed in is strictly necessary for the service to work. The analytics cookies are not, and Google Analytics also passes data to Google in the United States — if you would rather not be counted, any content or cookie blocker will stop both, and the site works exactly the same without them. The security check above is not in that category: it protects your account, so it runs regardless.
2. Why we are allowed to use it
- Performing our contract with you — running your account, storing your decks, taking payment, sending service email such as password resets and receipts.
- Legitimate interests — keeping the service secure, preventing abuse, answering your support messages, and measuring how the service is found and used so we can improve it. We have considered your rights and think these are unsurprising uses.
- Legal obligation — keeping transaction records for tax and accounting.
We do not sell your data, and we do not use it to train machine-learning models.
3. Who else processes it
These are our sub-processors. Each is bound to protect your data and use it only on our instructions.
- Cloudflare — Hosting, CDN, and object storage for uploaded cover art. Receives: IP address, request metadata, uploaded files.
- Supabase — Managed Postgres database. Receives: Account details, decks, support messages, subscription state.
- Dodo Payments — Merchant of record — takes the payment and issues the invoice. Receives: Name, email, billing address, card details (we never see the card).
- Resend — Transactional email delivery. Receives: Email address, message content.
- Better Auth (Infra) — Account security — spotting bots, credential stuffing and sign-ins from impossible locations, and the dashboard we manage accounts from. Receives: IP address, device and browser characteristics, sign-in and session events.
- PostHog — Product analytics — which features get used, and where people get stuck. Receives: Page views, clicks, device and browser, approximate location from IP, and your account id once you sign in.
- Google (Analytics) — Audience and acquisition measurement — how people find the site. Receives: Page views, referring site or search, device and browser, approximate location from IP.
We also disclose data where we are legally required to, and to a buyer if the business is ever sold — in which case we will tell you first.
4. International transfers
Our providers operate globally, so your data may be processed outside your country. Where that involves a transfer out of the UK, EEA or another region with transfer rules, it is covered by Standard Contractual Clauses or an equivalent safeguard.
5. How long we keep it
- While your account is open — for as long as you keep using the service.
- After you delete your account — your decks, uploads and account record are removed within 90 days. Backups age out on their own schedule shortly afterwards.
- Support messages — kept for two years, so we have the history if you come back about the same issue.
- Invoices and transaction records — kept as long as tax law requires, typically six to seven years. This is the one thing deleting your account does not erase.
6. Your rights
Depending on where you live you can ask us to: give you a copy of your data; correct it; delete it; restrict or object to how we use it; or hand it over in a portable format. You can also withdraw consent where we relied on it, and complain to your local data protection authority.
Deleting your account from account settings does most of this immediately. For anything else, email [LEGAL EMAIL] or use the contact form — we answer within 30 days and will not charge you for it.
7. Security
Passwords are hashed with scrypt. Traffic is encrypted in transit. Database access runs through a service role reachable only by server code that has already authorised the caller, and every table denies access to the public keys that reach browsers. Uploads go straight to object storage on short-lived signed URLs scoped to your account. No system is perfectly secure, but we will tell you and the relevant regulator without undue delay if a breach affects you.
8. Children
The service is not for under-16s, and we do not knowingly collect their data. If you believe a child has given us data, email [LEGAL EMAIL] and we will delete it.
9. Changes
We will post any update here and change the date below. If a change materially affects how we use your data, we will email you before it takes effect.
10. Contact
[COMPANY LEGAL NAME], [REGISTERED ADDRESS]. Email [LEGAL EMAIL] for anything privacy-related, including data-subject requests.