Privacy Policy

Last updated: 18 June 2026

Who we are

Hanko (hanko.live) is operated from the United Kingdom, and UK data protection law (UK GDPR and the Data Protection Act 2018) applies to how we handle your data. We are the “controller” of the personal data described here. Contact us about privacy at privacy@hanko.live or through the support page.

What we collect

Your email and authentication details, your library — statuses, episode or chapter progress, ratings, and notes — comments you post, your subscription state, and technical data needed to keep the service secure (such as IP-based rate-limit counters). If you sign up with a social account, the basic profile fields your provider returns (display name, avatar URL) are imported so your account works on day one. Usage analytics are collected only if you opt in.

How we use it & our legal bases

PurposeLegal basis
Running your tracker, stats, and accountContract
Billing the Supporter planContract
Generating recommendations from your libraryContract
Security, rate-limiting, and abuse preventionLegitimate interests
Optional usage analyticsConsent (the banner — withdraw any time)
Responding to legal obligations (e.g. takedown records)Legal obligation

AI features

For supporter AI recommendations, a summary of your library (titles, ratings, statuses, notes) is sent to our AI provider at the moment recommendations are generated. It is not used to train models and is not retained beyond the request. We don't make any decisions about you with legal or similarly significant effects by automated means.

Service providers & sharing

We rely on a small set of third-party services to run the app. They only receive the minimum data they need to do their job, and we pick providers with strong privacy and security posture. We never sell your personal data, and we don't share it for advertising — there are no ads on Hanko. We may disclose data where the law requires it (for example a court order) or where necessary to protect the service or its users from fraud or abuse.

ProviderPurposeData
Authentication serviceSign-in and account stateEmail, password hash, optional OAuth profile fields, session tokens
Database hostingStores your library, ratings, notes, and subscription stateEverything in your account, isolated per user by row-level security
Payment processorBills supporters and keeps your subscription state in syncCard details (never reach our servers), billing email, subscription id
AI providerGenerates personalised recommendations for supportersA summary of your library (titles, ratings, statuses, notes) is sent at the moment recommendations are generated. Not used for training, not retained.
Analytics serviceAggregate usage and performance metrics — only if you opt inPage views and performance timings; loads only after you accept the consent banner
Rate-limit servicePrevents abuse of AI recommendationsAnonymous usage counter, no personal fields

Cookies & analytics

We use first-party cookies only — strictly to keep you signed in and to remember your preferences, including your analytics choice. No advertising cookies, no third-party tracking. Analytics load only after you accept the consent banner, and you can withdraw that consent at any time by clearing the site's cookies. Because we don't track or sell data, browser signals like Global Privacy Control are honoured by default.

Payments

Payments are handled by our payment processor. We never see or store your card details — only your subscription state and the customer reference that links the two systems.

Where your data lives

Our database is hosted in Europe. Some providers (for example hosting, payments, and the AI provider) process data in the United States or other countries; where they do, the transfer is safeguarded by the UK Extension to the EU–US Data Privacy Framework or the UK International Data Transfer Agreement/Addendum, as applicable.

How long we keep it

Your account data is kept while your account exists. When you delete your account, your profile, library, comments, and cached recommendations are removed from live systems immediately and leave backups within 30 days. Billing records are kept as long as tax law requires. We may retain minimal records (such as a ban reason or takedown correspondence) where necessary for security, to prevent abuse or ban evasion, or to establish or defend legal claims.

Security

Your data is encrypted in transit, isolated per user by row-level security in our database, and accessible only through the service's own code paths. No system is perfectly secure, but if a breach ever puts your rights at risk we will handle it as UK GDPR requires, including notifying the ICO within 72 hours where applicable.

Your rights

You can export a copy of your data and delete your account at any time from Settings — no email needed (step-by-step guide: deleting your data). Under UK GDPR you also have the right to access, correct, or erase your data; to object to or restrict processing (including processing based on legitimate interests); to data portability; and to withdraw consent (for example, analytics) at any time. Contact us for anything the self-service tools don't cover and we'll respond within a month. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).

Children

Hanko is not for children under 13, and we don't knowingly collect their data. If we learn an account belongs to someone under 13, we delete the account and its data.

Changes

If we make material changes, we'll announce them in the app before they take effect. Continued use after the effective date means you accept the updated policy.