Privacy & data we collect
Manga Vault is built with privacy in mind. Here’s a high-level overview of what we collect, why, and what we don’t do with your data. For the legally-binding details, see our Privacy Policy.
What we collect
Account info
- Email address — For sign-in, password recovery, and important transactional emails (e.g., deletion confirmation).
- Password — Stored as an encrypted hash; we can never see your actual password.
- Optional profile data — Display name, username, bio, avatar, cover image, favorite genres.
Collection data
- Every volume you add (Owned or Wishlist), with associated metadata (condition, quantity, custom value, reading progress, etc.).
- Shelf assignments.
- Lending records.
Activity data
- Achievements you’ve unlocked.
- XP earned.
- Reading streaks.
- Last-active timestamp (for the activity-status feature).
Subscription info
- Whether you have an active PRO subscription (received from Apple/Google).
- We don’t store your payment method or billing details.
Catalog requests
- ISBNs you’ve requested be added to our catalog.
What we don’t collect
- Payment info — Apple and Google handle subscriptions; we never see card details.
- Photos beyond what you upload — We don’t access your camera roll except when you choose a photo.
- Location — We don’t use GPS or track your location.
- Browsing data — We don’t track what you browse outside Manga Vault.
- Behavioral analytics for ad networks — We don’t share data with advertising platforms.
Where data is stored
We use AWS (Amazon Web Services) for infrastructure:
- Cognito — Account authentication.
- DynamoDB — Your account data (collection, profile, friends).
- S3 + CloudFront — Cover images, profile photos, catalog data.
- Lambda — Backend processing.
All data is encrypted in transit (HTTPS) and at rest (DynamoDB encryption).
Who can see your data
- You — Always.
- Friends — Only what you’ve made visible via privacy toggles. See Privacy toggles.
- Manga Vault employees — Only when investigating support cases (and only with your explicit permission), or when legally required (e.g., subpoena).
We don’t:
- Sell your data.
- Share it with advertisers.
- Use it for behavioral targeting.
Cookies and tracking
The app uses minimal local-storage equivalents (e.g., cached auth tokens). We don’t use third-party tracking pixels or analytics SDKs that share data with marketing platforms.
We may use anonymous, aggregate analytics (e.g., “how many users opened the app today”) to monitor service health, but these don’t include personal identifiers.
Catalog data is public
Our catalog (series, volumes, ISBNs, cover art) is not personal data — it’s publicly available bibliographic information. Anyone can see it.
Your specific collection (which volumes you own from the catalog) is the personal part.
Data retention
- Active accounts — We retain your data as long as your account is active.
- Deleted accounts — Data is purged within 30 days of permanent deletion.
- Audit logs — We retain anonymized audit logs for up to 7 years for legal/compliance purposes.
Your rights
You have rights to:
- Access your data — Use the Export My Data feature.
- Delete your data — See Deleting your account.
- Correct errors — Edit your profile / collection any time.
- Object to processing — Contact us if you have specific concerns.
These rights are designed to comply with GDPR (EU), CCPA (California), and similar privacy regulations.
Reporting concerns
If you have privacy concerns, contact support. We take privacy seriously and will respond promptly.
The full Privacy Policy
For the complete legal document, visit mangavault.app/privacy.html.
Updates
We update our Privacy Policy occasionally. Material changes are announced in-app or via email before taking effect.