Back to Home

Privacy Policy

Last updated: July 13, 2026

Your privacy matters. This policy explains what data konsumr collects, how we use it, and your rights regarding your personal information. It applies to the konsumr website, the konsumr iOS and Android apps, and the konsumr browser extension (together, "the Service").

1. Information We Collect

1.1 Information from Sign-In Providers

konsumr is fully passwordless: we never ask for or store a password. You sign in with Discord, Google, Apple (iOS app only), or your email address. Depending on which method you use, we collect different information:

Discord

  • Discord User ID: A unique identifier used to link your account and deliver optional Discord notifications
  • Username: Your Discord username (used as the default for your konsumr username)
  • Email address: Used for account identification
  • Profile picture: Your Discord avatar (used as your default profile image)

Google

  • Google Account ID: A unique identifier used to link your account
  • Name: Your Google profile name (used to generate your konsumr username)
  • Email address: Used for account identification
  • Profile picture: Your Google profile picture (used as your default profile image)

Apple (Sign in with Apple, iOS app)

  • Apple User ID: A stable identifier Apple provides for your account
  • Email address: Used for account identification. If you choose Apple's "Hide My Email", this is a private relay forwarding address, and we store the relay address Apple provides
  • Name: Provided by Apple only on your first sign-in and used once to generate your konsumr username; it is not stored separately
  • Revocation token: A token issued by Apple that we store solely so we can revoke the Sign in with Apple connection when you delete your account

Email

  • Email address: Used for account identification and for sending sign-in emails. On the website we send a magic link; in the mobile apps we send a 6-digit one-time code. Codes are stored only as cryptographic hashes, expire after 10 minutes, are single-use, and are limited to a small number of attempts

You may link multiple sign-in methods to a single account. Accounts with the same verified email address are automatically linked, including across the website and the mobile apps. We store the sign-in tokens issued by these providers in order to operate authentication; they are deleted with your account.

Your initial username is automatically derived from your provider profile (or your email address) and your initial avatar comes from your provider profile picture (or a generated placeholder). You can change both at any time.

1.2 Information You Provide

As you use konsumr, you may provide:

  • Username: A custom username for your profile
  • Profile images: An avatar and banner you upload for your profile
  • Media tracking data: Which shows, movies, and manga you're tracking, your progress, and watch/read status
  • Ratings: Your thumbs up/down ratings on media
  • Notes: Personal notes you add to media items
  • Lists: Curated lists of media you create, including titles, descriptions, and notes on list items. Lists are public by default; you can make any list private
  • Collection photos: Up to 25 photos of your manga collection with optional captions, displayed on your manga collection page if your profile is public
  • Feedback: Feedback you submit to us through the app
  • Content requests: Requests for missing volumes or editions and suggestions for media connections, including any messages you attach (reviewed by our editors)
  • Reports: If you report a user or list, we store the reason and any details you provide. You can also report a data issue on a manga catalog entry (for example a wrong cover, release date, or ISBN); we store the issue types you select, the edition or volumes you flag, and any note you add, and show them to our editors together with your username so they can fix the entry
  • Imported data: If you import your library from AniList, Trakt, Letterboxd, Simkl, MyAnimeList, IMDb, TV Time, or MangaBaka, the watch/read history, ratings, and progress contained in those accounts or export files become part of your konsumr library. Import files are parsed in your browser, but the titles are sent to our server to match against TMDB and AniList

When you set an avatar, banner, or collection photo in the mobile apps, you choose images through the system photo picker. We only receive the photos you explicitly select, and the app does not otherwise access your photo library.

The iOS and Android apps use the camera for one purpose only: the manga barcode scanner, which reads the ISBN barcode on a book's back cover so we can find the matching volume for you. When you scan, only the decoded ISBN digits are sent to our server to look up a catalog match; no photo or camera image is captured, uploaded, or stored, and the camera is never used for any other purpose.

1.3 Automatically Collected Information

We automatically collect:

  • Activity timestamps: When you mark episodes as watched or volumes as read
  • Streak data: Your daily activity streak for the achievement system
  • XP and level: Points earned through tracking activity
  • Achievement unlocks: Which achievements you've earned
  • Social graph: Who you follow, who follows you, and which users you have blocked
  • Streaming region: A country code (for example "US" or "DE") stored on your account so we can show which streaming services offer a title in your country. On the iOS and Android apps we set this once on first launch by reading your device's region/locale setting; you can change it at any time in Settings. It is an approximate country only; we do not collect precise or GPS location
  • Onboarding choices and progress: The interests you pick during first-run onboarding (such as TV, anime, movies, or manga) and which onboarding steps you view, complete, or skip, used to set up your experience and to understand where the sign-up flow can be improved. This is first-party product analytics processed by konsumr and is not sent to a third-party analytics or tracking SDK
  • Signup source and attribution: We record whether an account was created on the website, iOS, or Android. On the website, if you allow the optional signup measurement cookie, we also record the external website hostname that referred you, the path and general type of the first public konsumr page captured for signup attribution, and anyutm_source, utm_medium, andutm_campaign values included in the link. We do not store the full referring URL, unrelated query parameters, or advertising identifiers. Website attribution is linked to your account only if you create one
  • Contextual sign-in journey analytics: On public profiles, lists, manga collections, and media pages, we increment hourly aggregate counters when a contextual sign-in prompt is viewed or selected. These anonymous counters contain only the general page category and intended action. If you select one of these prompts and sign in, we temporarily record whether authentication completed and whether you returned to the intended experience, and whether that journey created a new account. Those later stages are linked to your account and use a random identifier created for that one journey so retries are not counted twice. The anonymous impression endpoint checks the signed journey token transiently to reject unauthenticated writes, but does not copy it into analytics records. Analytics records do not contain the functional sign-in token, public object ID, destination path, username, list slug, media title, IP address, or browser or advertising identifier. Both the aggregate counters and account-linked journey stages are deleted after 90 days
  • Share interaction analytics (website, iOS, and Android): When you open or use a share control, or arrive through a Konsumr share link, we increment an hourly aggregate counter for the general action (such as copied link or opened share sheet) and content category (such as profile, list, or manga collection). A request from the iOS or Android app may be authenticated when you are signed in to prevent abuse, but the resulting counter is not linked to or stored with your account. Konsumr-generated share links add the fixed attribution valuesutm_source=konsumr_share andutm_medium=organic, plus a surface-specificutm_campaign. The rest of the link is the normal public destination path, which may contain a public username, list slug, or media ID. These first-party counters do not include your account ID, username, media title, destination URL, IP address, or a browser or advertising identifier, and are deleted after 90 days
  • Push notification token (iOS and Android): If you enable push notifications in the iOS or Android app, a device push token is registered with your account so we can deliver notifications. It is removed when you sign out or delete your account

We do not collect IP address logs, device fingerprints, precise location data, or advertising identifiers, and the apps contain no third-party analytics or tracking SDKs.

2. How We Use Your Information

We use your information to:

  • Provide and operate the media tracking service
  • Display your tracking progress and statistics
  • Calculate and display achievements, XP, and streaks
  • Send notifications you've enabled: in-app notifications, iOS and Android push notifications, emails (welcome series, weekly release digest, monthly collection recaps, and updates on your requests, feedback, and reports), and Discord direct messages. Notifications can cover upcoming releases, new followers, reactions to your stories, and streak reminders (including when a streak freeze is automatically used). Every notification category can be turned off in your settings
  • Display your public profile to other users (if you opt in; profiles are private by default)
  • Review reports and moderate the Service
  • Improve the Service based on usage patterns
  • Understand which platforms, referral sources, and campaign links lead to new accounts
  • Understand whether aggregate sharing features help people find and start using the Service

We do not sell your personal information or use it for advertising.

3. Third-Party Services

konsumr uses the following third-party services:

3.1 Discord

Used for authentication and optional notification delivery. When you enable Discord notifications, we use Discord's API to send you direct messages about upcoming releases. Your Discord ID is stored to enable this feature, and the messages we send through Discord include the names of the releases you track. Receiving Discord notifications requires being a member of the konsumr Discord server.

Discord Privacy Policy

3.2 Google

Used for authentication via Google OAuth. We receive your Google profile information (name, email, profile picture) when you sign in with Google.

Google Privacy Policy

3.3 Apple

Used for Sign in with Apple (iOS app) and for delivering iOS push notifications via the Apple Push Notification service. Apple receives your device push token and the content of notifications we send, which can include the names of titles you track or the username of a new follower.

Apple Privacy Policy

3.4 Google Firebase

Used to deliver Android push notifications via Firebase Cloud Messaging. Firebase receives your device push token and the content of notifications we send, which can include the names of titles you track or the username of a new follower. We use Firebase only for push delivery, not for analytics or advertising.

Firebase Privacy and Security

3.5 Resend

Used to send sign-in emails (magic links on the website, one-time codes in the mobile apps) and the notification emails you have enabled, such as welcome emails, release digests, monthly collection recaps, and updates on your requests, feedback, and reports. Resend processes your email address and the content of these emails, which can include your username and the names of releases you track.

Resend Privacy Policy

3.6 TMDB (The Movie Database)

We fetch TV show and movie information from TMDB, including "where to watch" streaming availability, which TMDB sources from JustWatch. No personal user data is sent to TMDB or JustWatch; we only request media information using their public API. Your streaming region is used solely on our side to choose which country's availability to display.

TMDB Privacy Policy

3.7 AniList

We fetch manga and anime information from AniList's public API. For this, no personal user data is sent to AniList.

Separately, you can optionally connect your AniList account to konsumr. If you do, we store your AniList ID, AniList username, and an AniList access token, we import your AniList library (titles, statuses, ratings, progress, and dates) into konsumr, and, if you use the sync feature, we write your konsumr tracking updates back to your AniList account on your behalf. You can disconnect AniList at any time in your settings, which deletes the stored token.

AniList Terms of Service

3.8 UploadThing

Used to store images you upload (avatars, profile banners, and collection photos). Images are stored on UploadThing's servers and served via their CDN.

UploadThing Privacy Policy

3.9 Vercel

konsumr is hosted on Vercel in the European Union (Frankfurt, Germany). Cookieless Vercel Analytics runs only on our public marketing pages, not inside the app itself. This anonymous, aggregate measurement is separate from the optional signup attribution cookie described in Section 5.

Vercel Privacy Policy

3.10 Railway

Your data is stored in a PostgreSQL database hosted on Railway in the European Union.

Railway Privacy Policy

3.11 Plex

You can optionally connect your Plex account to see which titles you already own in your Plex library. Connecting uses Plex's PIN-based sign-in. If you connect, we store on our servers your Plex account access token, your Plex username and Plex account ID, and the name, machine identifier, address, and per-server access token of the single Plex server you choose. Using these credentials, our servers (not your device) connect to your personal Plex Media Server to scan its libraries and cache which titles you own, matched by TMDB ID; this cache is refreshed roughly once a day and when you trigger a manual sync. We only read your library's title and identifier metadata to build "in your Plex library" markers; we do not read or store your Plex viewing history. You can disconnect Plex at any time in your settings, which deletes the stored connection and all cached library matches and makes a best-effort request to revoke the access token with Plex.

Plex Privacy Policy

4. The konsumr Browser Extension

konsumr offers an optional browser extension ("Konsumr Helper") that helps editors add manga volumes to the catalog. It is not required to use konsumr.

The extension reads publicly displayed volume details, such as the cover image, ISBN, release date, and page count, so an editor can add that volume to konsumr in one click. This product information is not personal data.

  • It does not track or collect the websites you visit or your browsing history.
  • It keeps a local cache of your konsumr editor data, such as the series and editions available to you, in your browser's storage so it can match volumes without re-fetching. This stays in your browser and is cleared when you remove the extension.
  • When you add a volume, it sends those volume details to your konsumr account, exactly as if you had entered them on konsumr directly.
  • The "Copy for konsumr" button writes the detected details to your clipboard at your request.
  • The extension contains no analytics or tracking and does not sell or share data with third parties.

5. Cookies, Local Storage, and On-Device Data

On the website, konsumr uses:

  • Session cookies: To keep you logged in (managed by NextAuth.js, backed by server-side sessions)
  • Security cookies: Short-lived cookies (5 minutes) used during account linking to prevent unauthorized access
  • Deferred sign-in journey cookies: If you select a contextual sign-in prompt on a public page, an HTTP-only cookie named konsumr-deferred-intent-init keeps up to four timestamped, one-way token fingerprints and expires 30 minutes after the most recent prompt selection. Only a fingerprint created within the preceding 30 minutes is accepted. This confirms that an OAuth return originated from an action in your browser without storing the public object identifier. The signed value, or an email-bound signed variant for a magic link, is carried in the sign-in return URL so Discord, Google, and email sign-in can return you to the requested experience. Email binding also supports a magic link opened in another browser. After successful authentication, if setup remains incomplete, we keep a small number of signed, HTTP-only, account-and-journey-specific cookies whose names begin konsumr-deferred-intent-armed-. Each stores the requested action, a random journey identifier, the stable public object identifier, its issue and expiry times, and a one-way account binding for up to 24 hours. The account binding prevents setup from carrying into another person's session on the same browser. Older setup journeys are pruned as new ones are added. When a journey is completed or abandoned, a matching cookie whose name begins konsumr-deferred-intent-consumed- may retain that same signed, account-bound journey until its original expiry. This completion marker makes late or duplicate tabs ignore the journey instead of reopening it. Older browser sessions may temporarily retain the former konsumr-deferred-intentcookie until its existing 24-hour expiry. For a setup journey, the opaque journey identifier is also kept in that tab's session storage until completion, abandonment, or the tab closes, preventing another tab from opening the setup dialog. These values are used for functional routing, not advertising, and expire within the periods described above. Completing or abandoning a journey makes it inactive immediately, although a completion marker may remain until expiry. The object identifier and signed token are never copied into analytics records
  • Signup measurement preference cookie: After you choose whether to allow signup measurement, a first-party cookie named konsumr-signup-attribution-consentremembers that choice for up to 180 days. This prevents us from repeatedly asking and does not contain referral or campaign information
  • Optional signup attribution cookie: If you choose Allow before sign-in, a first-party, server-protected cookie named konsumr-signup-attributionstores the limited first-touch information described in Section 1.3 for up to 30 days while you complete sign-in. It is sent only to konsumr and is not available to advertising partners. If you choose Don't allow, we do not set it and remove any existing copy
  • Browser storage: The current tab's session storage holds temporary email sign-in context until the check-inbox page reads it, then removes it. Local storage holds interface preferences such as your preferred view mode

In the iOS and Android apps:

  • Session token: Stored securely on your device, in the iOS Keychain or, on Android, the system's encrypted storage. App sessions last up to 90 days and are revoked when you sign out
  • Widget data (iOS and Android): A snapshot of your upcoming releases and streak is stored on your device (in a shared container on iOS, and in local widget storage on Android) so home-screen widgets can display it. It is cleared when you sign out and is never transmitted anywhere by the widgets

Some interface preferences, such as your default library sort, your saved calendar filters and presets, and your calendar layout, are saved to your account and synced across your devices. These are your own settings; they are not visible to other users and are not shared with any third party.

Not allowing signup measurement does not affect your access to the Service. That preference controls optional website referral and campaign attribution; it does not disable the functional deferred sign-in journey cookie when you request one, the anonymous aggregate contextual-prompt counters, or the cookieless Vercel Analytics described in Section 3.9. We do not use third-party analytics cookies, cross-site advertising cookies, or advertising identifiers.

6. Data Sharing

We share your data only in these circumstances:

  • Public profiles: Profiles are private by default. If you enable public profile visibility, anyone with your profile link can see your username, avatar, banner, join date, level and XP, streaks, library statistics (titles tracked, episodes watched, watch time), follower and following lists, unlocked achievements, public lists, your tracked titles with ratings and favorites, your manga collection page including collection photos, and share images generated from this data
  • Stories and activity: If your profile is public, your recent tracking activity (episodes watched, movies seen, manga volumes read and collected, titles finished, achievements unlocked, and lists created) can appear in a stories rail and on your public activity timeline. This is shown to people who follow you and to other members who are suggested your profile based on shared library taste. Activity sharing is controlled by a "Show my activity" setting that is on by default; you can turn it off at any time to keep your activity out of stories entirely, or choose which activity categories are included. Activity is never shown if your profile is private. We store which stories you have viewed and which stories you have reacted to
  • Story reactions: When you react to someone's story, the story owner can see that you reacted, your username and avatar, and the emoji you used, and receives an in-app notification and (if enabled) a push notification. Reaction notifications are aggregated per person per day and respect the owner's notification settings
  • People discovery: To suggest members you might want to follow, we compare public libraries and show a count of titles you have in common; when you view another member's library you can also filter by titles you both track. These comparisons use only library data that is already public under each member's profile visibility settings
  • Public lists: Lists are public by default and visible to anyone with the list link, and may be indexed by search engines. Lists you set to private are only visible to you
  • Share images: Publicly accessible share images (for example profile cards and monthly recaps) are generated only from data that is already public under your visibility settings; private content renders a placeholder instead
  • Share destinations: When you select a third-party app or service in a browser or device share sheet, the selected share image, text, and public link are sent to that destination. Konsumr sends this content only after you choose a destination. The third party's terms and privacy policy apply to how it handles the shared content
  • Moderation and editors: When you submit feedback, a report, or a content request, the konsumr team reviews it together with your username and avatar. For reports, the team also sees the reported account or list and the details you submitted
  • Service providers: With the third-party services listed above, only as necessary to operate the Service
  • Legal requirements: If required by law or to protect our rights

We do not sell, rent, or trade your personal information to third parties.

7. Data Retention and Deletion

Deferred sign-in setup and completion-marker cookies expire within 24 hours; completing or abandoning a journey makes it inactive immediately even if its marker remains until expiry. The initiation cookie expires within 30 minutes. Contextual prompt counters and account-linked authentication, new-account, and return stages are deleted after 90 days. The signup measurement preference cookie lasts for up to 180 days. The optional signup attribution cookie lasts for up to 30 days and is removed sooner if you do not allow it or complete sign-in. If you create an account, the signup platform and permitted attribution are retained with the account. Changing the choice to Don't allow while signed in removes stored website referral, landing page, and campaign details. The signup platform remains until the account is deleted.

We retain your data for as long as your account is active. You can delete your account at any time in the iOS or Android app under Settings > General > Delete Account, or by contacting us by email. Deletion is permanent and removes:

  • Your profile information and sign-in connections
  • All tracking data and progress, notes, ratings, and achievements
  • All lists you created
  • Uploaded images (avatar, banner, and collection photos), including removal from our storage provider
  • Follows, blocks, and reports involving your account
  • Notifications, push tokens, and all active sessions
  • Stored provider tokens, including your AniList and Plex access tokens (deleting your account also disconnects Plex and removes cached Plex library matches)
  • Your stories and activity records, including story views and reactions
  • Issue reports you filed and your stored streaming region
  • Your signup platform and any associated attribution details
  • Your account-linked contextual acquisition journey events

If you signed in with Apple, we also revoke the Sign in with Apple connection with Apple. A small number of records may be retained in anonymized form with your identity removed, for example moderation records and notifications you triggered for other users. Some data may persist in backups for a limited time before being purged.

8. Your Rights

8.1 For All Users

You have the right to:

  • Access your data (view your profile and tracking history)
  • Correct your data (edit your profile and notes)
  • Delete your data (delete your account in the iOS or Android app or by contacting us)
  • Export your data (download your library, lists, and achievements as JSON from the Import & Export section of your profile on the website)
  • Control visibility (toggle public/private profile settings and per-list visibility)
  • Opt out of notifications (each category of email, push, in-app, and Discord notifications can be disabled in your settings). Marketing and digest emails also include a one-click unsubscribe link that lets you opt out of that email type without signing in; the link only updates your own email preferences
  • Change your optional signup measurement choice at any time through Cookie preferences

8.2 European Union Residents (GDPR)

If you are located in the European Union, you have additional rights under the General Data Protection Regulation:

  • Right to access: Request a copy of your personal data
  • Right to rectification: Request correction of inaccurate data
  • Right to erasure: Request deletion of your data ("right to be forgotten")
  • Right to data portability: Request your data in a machine-readable format (see the self-serve JSON export above)
  • Right to object: Object to processing of your data
  • Right to withdraw consent: Withdraw consent at any time through Cookie preferences for optional website signup measurement, through the relevant setting for other optional features, or by contacting us

Legal basis for processing: We process data as needed to provide the Service and take steps you request when creating an account. The deferred sign-in journey cookie is used to carry out the contextual return you request. We rely on your consent for the optional signup attribution cookie and its referral and campaign details. We rely on our legitimate interests for security, moderation, improving the Service, recording the platform where an account was created, and aggregate cookieless website analytics, anonymous aggregate share and contextual-prompt measurement, and short-lived measurement of completed contextual sign-in journeys, while respecting your rights. We process data where necessary to meet legal obligations. Your data is stored in the European Union.

8.3 California Residents (CCPA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act:

  • Right to know: Request information about what personal data we collect and how it's used
  • Right to delete: Request deletion of your personal data
  • Right to opt-out: We do not sell personal information, so this right does not apply
  • Right to non-discrimination: We will not discriminate against you for exercising your privacy rights

9. Data Security

We implement reasonable security measures to protect your data, including:

  • Encrypted connections (HTTPS) for all data transmission
  • Passwordless authentication: we never store passwords. OAuth sign-ins (Discord, Google, Apple) are verified server-side, and email sign-in codes are stored only as hashes, expire after 10 minutes, are single-use, and are protected against brute-force attempts
  • Server-side sessions that can be revoked at any time; signing out immediately invalidates the session
  • Secure on-device storage in the apps (session token in the iOS Keychain or, on Android, the system's encrypted storage)
  • Database encryption at rest
  • Limited access to personal data

However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

10. Children's Privacy

konsumr is not directed at children under 13. We do not knowingly collect personal information from children under 13. Users must be at least 13 years old (or the minimum age in their country) to use konsumr. Users who sign in with Discord, Google, or Apple must also comply with those services' age requirements. Adult (18+) content is hidden by default and only available behind an explicit opt-in setting restricted to adults, as described in our Terms of Service.

11. International Data Transfers

Your data is primarily stored and processed in the European Union. Some of the service providers listed above (such as Discord, Google, Apple, Firebase, Resend, and UploadThing) may process data in the United States or other countries. By using konsumr, you consent to these transfers.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the "Last updated" date at the top of this page. If a change requires a new consent choice, we will ask you again.

13. Contact Us

If you have questions about this Privacy Policy or want to exercise your data rights, please contact us at:

aldodumitrescu@gmail.com

For GDPR-related inquiries, you may also contact your local data protection authority.