Legal
Privacy Policy
1. Controller
Jan Prior
c/o IP-Management #11356Ludwig-Erhard-Str. 1820459 HamburgDeutschlandPrivacy contact: [email protected]
2. Hosting and technical access data
The service is hosted in Germany. When the hosting platform, reverse proxy, or application creates operational logs, those logs may contain the requesting IP address, timestamp, requested route, response status, referrer, and user-agent information. We process this data to deliver the service, diagnose failures, prevent abuse, enforce rate limits, and protect the service. The legal bases are Article 6(1)(b) GDPR where processing is necessary to provide a requested feature and Article 6(1)(f) GDPR for security, abuse prevention, and reliable operation.
3. Anonymous browser storage
Discover works without an account. The browser stores up to 8 recent Discover searchesin local storage on the user's device. This data is not a tracking cookie and is not sent to us merely because it is stored. It can be removed by clearing site data in the browser. Selected parts are sent only when the user actively requests a recommendation.
4. Contact form
If a user submits the contact form, we process the supplied name, reply email address, topic, and message to answer the request. The application sends the message through Proton Mail and does not create a database copy. Mailbox copies are retained only as long as needed to handle the request and meet applicable legal obligations. Per-IP and global submission limits are used to prevent abuse. The legal bases are Article 6(1)(b) GDPR for request-related communication and Article 6(1)(f) GDPR for general enquiries, service security, and abuse prevention.
5. Public AniList and MyAnimeList profiles
If a user enters a public AniList or MyAnimeList username, we send that username to the selected provider and retrieve the public anime list, including public list status, score, progress, and media identifiers. The normalized result is stored in Redis for one hour behind an unguessable capability identifier so it can be used for recommendations. Repeated lookups of the same provider and username may be held in application memory for up to five minutes to reduce provider requests. No provider password, OAuth token, or private list is requested for this anonymous feature. The legal basis is Article 6(1)(b) GDPR for the user-requested lookup and recommendation.
6. Search and recommendation providers
Cloudflare provides DNS and edge delivery; Hetzner hosts the application in Germany; Proton Mail processes operator contact and support email. AniList and MyAnimeList are used for public profile lookup and anime metadata without connected user accounts. Open Library provides book metadata; TMDB provides movie and TV metadata and images. Google sign-in and connected-provider OAuth are disabled for the initial release.
Depending on the selected media type, search terms and provider identifiers may be sent to AniList, MyAnimeList, Open Library, or TMDB. These providers receive requests from our server and process them under their own privacy terms. Do not enter another person's non-public information.
7. Accounts
Account registration, sign-in, provider OAuth connections, list sync, and provider write-back are disabled for the current release. The anonymous public-profile feature does not create an account or store provider session tokens.
8. Recipients, transfers, and retention
Recipients and service providers: Hetzner Online GmbH, Cloudflare, Proton Mail, AniList, MyAnimeList, Open Library, TMDB.
Some providers may process data outside the European Economic Area. Where required, transfers must rely on an applicable adequacy decision or appropriate safeguards such as standard contractual clauses. Before a public launch, the operator must verify the current contracts and transfer safeguards for each processor.
Retention: Public-list contexts expire after one hour and repeated public profile reads may remain in application memory for five minutes. Provider list mirrors are purged after 30 days without refresh and stored provider credentials after 90 days without connection activity; users can disconnect or delete earlier. Browser search history remains until cleared. Expired sessions are purged daily. Encrypted backups use 7 daily, 4 weekly, and 6 monthly snapshots.
9. Rights
Subject to the GDPR's conditions, data subjects may request access, rectification, erasure, restriction, and data portability, and may object to processing based on legitimate interests. Consent, where used, may be withdrawn for the future. Requests can be sent to the privacy contact above. Data subjects also have the right to lodge a complaint with a data-protection supervisory authority, including the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI).
10. Automated decisions and changes
Recommendations do not make decisions that produce legal or similarly significant effects. This notice will be updated before materially different processing, such as enabling analytics, advertising, AI chat, materially changing account features, or adding processors.
Last updated: 2026-08-23
This product uses the TMDB API but is not endorsed or certified by TMDB.