This page explains what data animux collects, why, and what you can do about it. If something is unclear, write to privacy@animux.app.
Who runs animux
animux is operated by Jairo Caro Accino as a sole proprietor based in Almería, Spain. For privacy questions, account deletion, or data requests: privacy@animux.app.
What we collect
From your Google account (when you sign in)
Email address — used as your account identifier.
Name and profile picture — shown in the app for personalization.
We never see your Google password. Sign-in is verified via Google's ID token.
From your use of the app
Tracking list: which anime you marked as watching, completed, plan-to-watch, paused, dropped, or not interested, plus your episode count and score.
Taste signals: swipes during onboarding (yes / no / love / want) and other interaction events used to improve your recommendations.
Push token (when push notifications are enabled): a Firebase Cloud Messaging token tied to your device, used only to deliver episode reminders for shows on your watching list.
Server logs: standard request logs (timestamp, IP, user agent, endpoint, response code) retained up to 30 days for debugging and abuse detection.
What we do not collect
No advertising identifiers, no third-party trackers, no analytics SDKs.
No location data, contacts, or media library access.
Why we collect it
To run the service (legal basis: performance of contract): your tracking list and taste signals exist so the app can sync across your devices and tailor recommendations.
To send episode reminders (legal basis: consent): only when you opt in to push notifications. You can revoke at any time from your OS settings or in-app.
To prevent abuse (legal basis: legitimate interest): server logs and rate-limit data.
Who we share it with
We use a small number of processors to run the service. None of them receive your data for marketing.
Google — verifies your sign-in token. Subject to Google's privacy policy.
Fly.io (Paris region) — hosts the backend and the database. Acts as a data processor under DPA.
Tigris — object storage for poster images. Stores public assets only; no user data.
xAI (Grok) — powers the daily anime news feed and moderates user-submitted reviews. No email, name, or account identifier is sent.
Firebase Cloud Messaging (Google) — delivers push notifications when you opt in. Receives the device token and the message payload only.
AniList — we fetch the public anime catalog from AniList. We do not send them any of your data.
We do not sell your data. We do not run advertising. There are no affiliate trackers in the app.
Where it lives
Backend and database run on Fly.io in the Paris (CDG) region. Backups are stored in Tigris (also EU). All data stays within the European Economic Area unless an external processor (e.g. Google for SSO verification, xAI for the news feed and review moderation) requires a brief transfer for the specific request.
How long we keep it
While your account is active: we keep your tracking list, taste signals and account record.
If you delete your account: the account is marked deleted immediately and you are signed out. After a 30-day grace period (during which you can sign back in to restore everything), all your personal data — tracking list, taste events, push tokens, account row — is permanently erased.
Server logs: up to 30 days, then rotated out.
If you want immediate erasure without waiting the 30 days, email privacy@animux.app from your account address and we'll honour it.
Your rights (GDPR)
Because we are based in the EU, the General Data Protection Regulation gives you the right to:
access the data we hold about you;
correct it if it's wrong;
delete it (see "How long we keep it" above);
export it in a machine-readable format;
object to a particular use;
withdraw consent for push notifications at any time.
Email privacy@animux.app from your account email and we'll respond within 30 days. If you think we mishandled your data, you can also complain to the Spanish Data Protection Authority (AEPD): aepd.es.
Cookies
The web landing page (animux.app) does not use cookies. The mobile app stores a session JWT and your sign-in details in the device's secure storage so you stay logged in. That's the only persistent client-side identifier.
Children
animux is not directed at children under 14. If you are under 14, please do not create an account. If you are between 14 and 16 in the EU, sign-up is allowed under Spanish law (LOPDGDD article 7), but you should ask a parent or guardian first.
Changes to this policy
If we change this policy in a way that materially affects how your data is used, we will notify signed-in users by email at least 14 days before the change takes effect. Past versions are kept in the project's git history (github.com/kidandcat/anime).