Privacy Policy

Draft — pending legal review. This page is not final legal advice; it describes current data handling in plain language.

What we collect

When you connect AniList, MyAnimeList, or Google, we store the OAuth identity and access tokens for that connection (httpOnly, never exposed to client-side JavaScript), plus the app data you generate: your watchlist, thumbs up/down feedback, recommendation history, digest snapshots, and any share/invite links you create. Google sign-in only stores your name, email, and profile picture as an identity — it does not feed recommendations unless you also connect AniList.

Third parties

We send data to: OpenAI (to generate embeddings and re-rank recommendations), AniList and MyAnimeList (to read your history and add titles to your lists), Google (identity sign-in), MongoDB Atlas (where your data is stored), and Sentry (error tracking — error details only, not your anime data).

Cookies

We use httpOnly session cookies to keep you signed in to each connection. We don't use advertising or third-party tracking cookies.

Retention & deletion

You can export or permanently delete everything we store for each connection at any time from your Account settings. Deleting a connection removes its data immediately and revokes its session.

Contact

Questions about this policy can be sent to the project maintainer.