Track manga, manhwa & anime across sources

Open Library

Privacy Policy

How Tsuiseki handles your data

Tsuiseki collects the information needed to run your account, save your private tracking data, process optional support, connect services and imports you request, protect the Service, and answer reports. Guest tracking stays in your browser until you choose to sign in or migrate it. Tsuiseki does not sell personal data.

1. Who controls the data

Tsuiseki is operated by Keith Panlaqui, trading under the Tsuiseki name, from the Philippines. That operator is responsible for the personal data described in this Policy. “Tsuiseki,” “we,” and “our” refer to the individually operated Service.

Contact: Tsuiseki Privacy

Email: privacy@tsuiseki.xyz

Location and notices: Philippines — formal notices are accepted through the email address above.

2. Data Tsuiseki processes

  • Guest data: locally stored Library items, progress, status, filters, and preferences before account migration.
  • Account and identity data: user ID, name, email, profile image, and identity-provider account records supplied through enabled GitHub, Google, Discord, or X sign-in.
  • Tracking data: titles, media identifiers, progress, status, ratings, notes, schedule preferences, time zone, and private organization settings.
  • Season-continuity data: account-synced Season Stack preference, per-chain stacked or separate presentation overrides, retained continuity-history seen or dismissed state, and the tracker identity used to determine whether a shared continuity event is relevant to your Library. Shared catalogue and chain facts are not private user records.
  • Connected-service data: when you connect MyAnimeList, Tsuiseki retains the MAL account ID and username, encrypted access and refresh credentials, token expiry, and granted scopes while the connection remains stored. The MAL connection is separate from Tsuiseki sign-in.
  • MAL review and import data: an explicitly requested review temporarily retains approved fields such as stable MAL media identity, anime or manga classification, title, allowlisted catalogue artwork, mapped list status, episode or chapter progress, useful totals, and a bounded provider update timestamp. An explicit import may save those approved tracking fields as Tsuiseki Library records. Private MAL notes, comments, scores, tags, priority, reread or rewatch fields, visibility, social data, arbitrary URLs, credentials, roles, entitlements, and billing fields are not imported.
  • Profile data: display name, selected cosmetics, and optional avatar submissions and moderation outcomes.
  • Supporter data: entitlement source, billing status, provider customer/subscription identifiers, payment period dates, webhook records, cancellation or resumption state, fraud/security signals, and retained Supporter presentation or automation settings. Tsuiseki does not receive full card details.
  • Reports and communications: source-report details, affected title and provider, destination URL, requested action, copyright authority details where supplied, and incorrect-grouping reports. For an incorrect-grouping report, the server records the selected reason and resolves the affected chain, media membership, ordinals, evidence references, and stack state from your owned tracker context rather than accepting arbitrary replacement relationships from the client.
  • Security and operations data: bounded rate-limit state, audit events, request identifiers, session-security records, short-lived hashed OAuth state, encrypted PKCE verifier material, and hashed or reduced network/device signals where implemented.
  • Usage analytics: aggregated page-view information supplied through Vercel Web Analytics. Tsuiseki’s analytics contract excludes authenticated user IDs, title names, provider identities, and chapter or episode numbers from custom payloads.

3. Why the data is used

  • provide accounts, tracking, Calendar, explicit imports, exports, recommendations, settings, connected services, continuity presentation, and Supporter features;
  • determine which shared continuity changes are relevant to titles already in your Library and retain your explicit seen, dismissed, stacked, or separate presentation choices;
  • complete a user-requested MyAnimeList connection, retrieve an explicitly requested bounded library snapshot, show a non-mutating preview, and add only server-approved missing titles after a separate import action;
  • preserve existing Tsuiseki Library records, progress, and status when imported data matches or disagrees;
  • resolve and classify external destinations without hosting the underlying media;
  • process billing confirmations and subscription actions;
  • moderate optional avatars and respond to incorrect-link, incorrect-grouping, copyright, privacy, and security reports;
  • prevent abuse, enforce limits, investigate failures, and maintain append-only administrative accountability;
  • understand aggregated product usage and improve reliability;
  • comply with legal obligations and establish, exercise, or defend legal claims.

Processing is limited to purposes needed to provide the requested Service, pursue legitimate operational and security interests allowed by law, comply with obligations, or act on consent where consent is required.

4. Service providers and disclosures

Tsuiseki uses service providers only for defined operational purposes. Depending on enabled features, these may include:

  • Vercel: hosting, deployment, firewall, Web Analytics, image optimization, and moderated avatar Blob storage.
  • Neon: PostgreSQL account, tracking, settings, connected-service, import-result, continuity preference/history, billing-state, report, and administrative records.
  • Identity providers: GitHub, Google, Discord, and X when enabled, for authentication.
  • MyAnimeList: an independent connected service used only when you choose to authorize Tsuiseki and request review or import. MAL controls its own account, API availability, and privacy practices. Connecting MAL does not make it a Tsuiseki sign-in provider or create continuing synchronization.
  • Lemon Squeezy: hosted checkout, payment processing, subscription administration, and signed billing events when Supporter billing is enabled.
  • OpenAI: automated safety classification of normalized avatar submissions only when custom-avatar moderation is enabled.
  • Metadata and destination providers: bounded title, release, artwork, identifier, continuity, and external-link requests described in the External Sources Policy. Public Library continuity views use Tsuiseki’s local normalized registry rather than sending each user’s Library to continuity providers.

Data may also be disclosed where reasonably necessary to comply with law, protect users or the Service, investigate abuse, or complete a business transfer permitted by law. Tsuiseki does not provide advertisers with access to your private Library or conversations.

5. International processing

Tsuiseki is operated from the Philippines, while service providers may process data in other countries. Those countries may have different privacy laws. Tsuiseki selects bounded service integrations and uses contractual and technical safeguards appropriate to the service and data involved.

6. Retention and deletion

Guest data remains in your browser until you migrate it, clear it, or remove it. Account data is retained while your account is active and for as long as reasonably needed to provide the Service, maintain security and audit integrity, resolve disputes, meet billing or legal requirements, and enforce these policies.

MyAnimeList authorization attempts expire within ten minutes and are deleted when used. Connected MAL credentials remain encrypted while the connection exists. Disconnecting deletes Tsuiseki’s stored MAL connection and pending attempts; it does not delete your MAL account or Tsuiseki Library records already created through a completed import.

An uncommitted MAL review is short-lived and expires within thirty minutes. After a successful import, Tsuiseki deletes the title-level normalized preview rows and retains only the resulting Library records plus a bounded import summary containing counts, capacity, revision, and timestamps. Imported Library records remain independently editable and deletable even after MAL is disconnected.

Continuity-history seen or dismissed state is retained for the reviewed ninety-day window, subject to the approved Supporter grace behavior. Per-chain presentation overrides may remain with your account while the referenced chain and account are valid. Downgrade or a disabled continuity rollout hides paid history and grouped presentation but does not change your Library records.

Raw continuity import staging and diagnostics are bounded and scheduled for purge within seven days after apply or reject. Shared normalized catalogue facts may remain while referenced by tracker identities, active chains, evidence, reports, overlays, events, or audit. Incorrect-grouping reports and immutable administrative events may remain while required for correction, abuse prevention, security, dispute resolution, or legal obligations.

Library exports are generated on demand. Rejected or replaced avatar files are removed where the implemented moderation flow requires it; moderation and audit outcomes may remain where needed for abuse prevention. Provider reports and administrative events may be retained as bounded legal and operational records.

Tsuiseki does not promise a fixed retention period where the product does not yet enforce one. A verified request may result in deletion, blocking, correction, or lawful retention of particular records depending on the request and applicable obligations.

7. Your choices and rights

  • export your private Library from Settings;
  • connect, reconnect, review, import from, or disconnect MyAnimeList from Settings when the feature is enabled;
  • correct your display name, time zone, progress, status, continuity presentation preference, and other editable account data;
  • mark continuity-history items seen or dismiss them while that feature and your access are enabled;
  • delete imported Library records without reconnecting MAL;
  • stop future Supporter renewals where a managed subscription is active;
  • sign out and clear guest browser storage;
  • request access, correction, objection, erasure or blocking, portability, or other rights available under applicable law;
  • file a complaint with the Philippine National Privacy Commission or another competent authority.

Tsuiseki may need to verify your identity before acting on a request and may decline or limit a request where permitted by law, including to protect another person’s data, preserve security, or comply with legal obligations.

8. Cookies, local storage, and analytics

Auth.js uses essential cookies to maintain sign-in and security state. Tsuiseki uses browser storage for guest tracking and product preferences. Vercel Web Analytics is configured as a production analytics service and is described by Vercel as cookie-free and based on anonymized, short-lived visitor identification.

See the Cookie Policy for the current inventory and controls.

9. Security, children, and changes

Tsuiseki uses access controls, bounded inputs, authenticated encryption for stored external credentials, short-lived OAuth and preview state, server-owned import and continuity decisions, same-origin mutation controls, encryption in transit, provider allowlists, rate limits, append-only audit records, and other reasonable safeguards. No online system can guarantee absolute security.

Tsuiseki is not designed to collect sensitive personal information from children. A parent or guardian should contact Tsuiseki if they believe a child provided personal data without required permission.

Material changes will be published with a new effective date. Where required, Tsuiseki will provide a more direct notice or request consent.