Last updated: June 2026
This policy explains what personal data MangaFlow, operated by [Operator legal name & address], collects and how we use it. The data controller is [controller name] ([privacy@yourdomain]).
1. Data we collect
- Account data: email, username, display name, password hash, avatar/banner.
- Content you create: manga, chapters, images, comments, reports, reading progress.
- Usage data: views, likes, bookmarks, follows, and basic technical logs (IP, device/browser) for security and abuse prevention.
2. How & why we use it (legal bases)
- To provide the Service and your account — performance of contract (Art. 6(1)(b) GDPR).
- To keep the platform safe, prevent abuse and moderate content — legitimate interests (Art. 6(1)(f)).
- To comply with legal obligations, e.g. handling copyright notices — Art. 6(1)(c).
- Optional features (e.g. analytics/marketing) — only with your consent (Art. 6(1)(a)).
3. Processors & third parties
We use trusted providers to run the Service:
- Supabase — authentication, database, and metadata hosting.
- Cloudflare R2 — image/media storage and delivery.
- Google — optional “Sign in with Google” (only if you use it).
These act as processors under data-processing agreements. Some may process data outside the EU/EEA under appropriate safeguards (e.g. Standard Contractual Clauses).
4. Retention
We keep account and content data while your account is active. When you delete your account, your profile, content and associated media are removed or anonymised, except where we must retain limited records to comply with the law.
5. Your rights (EEA/UK)
- Access, rectification, erasure, restriction, portability, and objection.
- Withdraw consent at any time (where processing is based on consent).
- Lodge a complaint with your data-protection authority.
You can delete your account in Settings. For other requests, contact [privacy@yourdomain].
6. Cookies
We use essential cookies/local storage to keep you signed in and remember reader preferences. Any non-essential tracking will only run with your consent.
7. Security & children
We apply technical and organisational measures (encryption in transit, row-level access control, scoped storage). The Service is not directed to children under 16.
8. Changes & contact
We will post updates here with a new date. Contact: our contact page or [privacy@yourdomain].
Template only — must be reviewed by legal/DPO and completed with your real controller details and sub-processor list before launch.