Last updated: 1 August 2026
This Privacy Policy explains how Nimu collects, uses, shares and protects your personal data, and the rights you have over it under the EU General Data Protection Regulation (Regulation (EU) 2016/679, the GDPR) and the ePrivacy rules on cookies and similar technologies. It applies to the Nimu website and, where available, the Android application, which share a single account and backend.
Nimu is a fan-made anime release tracker: a calendar, episode information, a personal watchlist, and optional notifications. The controller responsible for the personal data described in this Policy is Nimu (we, us, our), meaning the party that decides why and how that data is processed. You can contact us about anything in this Policy, including to exercise your rights, at privacy@nimu.app. Full corporate details are available on request.
We are a small, independent service and are not required to appoint a Data Protection Officer under Article 37 of the GDPR. Your point of contact for every data protection matter is privacy@nimu.app.
This Policy covers the personal data we process as controller when you visit or use the Service. It does not cover third-party websites or streaming platforms we may link to, each of which has its own privacy policy, or the anime catalog sources described in our Terms and Conditions, which supply reference information about titles rather than information about you.
We collect only what the Service needs. Where we rely on your consent you may withdraw it at any time, and where we rely on our legitimate interests you may object, both as explained in section 10. We never sell your personal data and we never use your activity to build advertising profiles.
Your email address, a password (kept only as a secure cryptographic hash by our authentication provider, never in readable form and never visible to us), an internal account identifier, and, if you choose to add them, a display name and profile picture. Lawful basis: performance of our contract with you, Article 6(1)(b).
Your year of birth and your country, collected at sign-up. We store the year only, not a full date of birth. We use these to confirm that you meet the minimum age for the Service and to apply the correct age of digital consent for your country. Lawful basis: compliance with a legal obligation, Article 6(1)(c) read with Article 8, together with performance of our contract with you, Article 6(1)(b).
The titles you add to your watchlist, their status (for example, watching or completed), your favourites, and the episodes you mark as watched. This is the core of what the Service does for you. Lawful basis: performance of our contract with you, Article 6(1)(b).
Whether you have turned on episode notifications for titles you follow, and, separately, whether you have opted in to optional product or promotional messages. Each choice is stored with the date you made it and can be switched off independently in Settings at any time. If you enable browser push, we store an anonymous push subscription so your device can receive alerts. Lawful basis: performance of our contract for the episode notifications you asked for, Article 6(1)(b); your consent for promotional messages and for web push delivery, Article 6(1)(a).
Technical information generated when you use the Service, such as your IP address, browser or device type, and the timestamps of your requests. We use it to keep the Service secure and available, prevent fraud and abuse, and diagnose faults. Lawful basis: our legitimate interests in operating a secure and reliable service, Article 6(1)(f).
On the account forms — sign-up, sign-in, password recovery and resending a confirmation email — we use Cloudflare Turnstile to tell real people apart from automated bots. Turnstile is a privacy-preserving alternative to a traditional CAPTCHA and does not use advertising tracking cookies. Lawful basis: our legitimate interests in preventing automated abuse and protecting accounts, Article 6(1)(f).
A small number of first-party cookies and items of browser local storage, described in full in our Cookie Policy. Strictly necessary items do not require consent; anything else stays off until you turn it on.
If you email us for support or to exercise a right, we process the content of your message and your contact details to answer you and to keep a record of the request. Lawful basis: our legitimate interests in responding to you, Article 6(1)(f), or performance of the contract where your request concerns your account.
The table below summarises the main categories of personal data we process, the purpose, and the lawful basis under Article 6 of the GDPR. It is a summary; the sections above and below give the full detail.
| Personal data | Purpose | Lawful basis |
|---|---|---|
| Email address, hashed password, account identifier | Create, secure and operate your account and sign you in | Contract, Article 6(1)(b) |
| Optional display name and profile picture | Personalise your profile | Contract, Article 6(1)(b) |
| Year of birth and country | Confirm you meet the minimum age and apply the correct age of digital consent | Legal obligation, Article 6(1)(c) with Article 8; and contract, Article 6(1)(b) |
| Watchlist, favourites and viewing progress | Provide the tracker and watchlist features | Contract, Article 6(1)(b) |
| Episode notification settings and web-push subscription | Send the episode alerts you turned on and deliver them to your device | Contract, Article 6(1)(b); web push on consent, Article 6(1)(a) |
| Promotional message opt-in | Send optional product news you asked for | Consent, Article 6(1)(a) |
| IP address, device and browser data, timestamps, logs | Keep the Service secure, prevent abuse and diagnose faults | Legitimate interests, Article 6(1)(f) |
| Anti-bot verification signals (Cloudflare Turnstile) | Prevent automated sign-up and abuse | Legitimate interests, Article 6(1)(f) |
| Analytics and advertising cookies (only if and when active) | Measure usage and show advertising | Consent, Article 6(1)(a) |
| Support messages you send us | Answer your query and record your request | Legitimate interests, Article 6(1)(f), or contract where it concerns your account |
We use a small number of cookies and items of local storage, listed in full in our Cookie Policy. Under the ePrivacy rules, strictly necessary items are used without consent because the Service cannot work without them. Analytics and advertising technologies, which are not in use today, would run only after you opt in through the cookie banner or the Cookie preferences link in the footer of every page.
We use your personal data to:
We will not use your personal data for a new purpose that is incompatible with those above without informing you first and, where the law requires it, obtaining your consent.
We share personal data only with service providers that process it on our behalf, under a written data processing agreement and on our instructions, and only where the law requires disclosure. We do not sell your personal data, and we never share it so that another company can carry out its own marketing.
We use Supabase to run the Nimu backend. Our contracting entity is Supabase Pte Ltd (Singapore); Supabase Inc. (United States) is an affiliated company that provides platform operation and support. We have configured our project to store data in a European Union or European Economic Area region. Because the contracting entity is outside the EEA, transfers to Supabase are protected by the EU Standard Contractual Clauses in its Data Processing Agreement (see section 8).
The Nimu website is built on Next.js and hosted by Vercel Inc. (United States), which serves the application and delivers it through a global edge network. In doing so it processes technical connection data such as your IP address. Transfers are protected by the EU Standard Contractual Clauses (see section 8).
Cloudflare, Inc. (United States) provides the Turnstile anti-bot check used on the account forms. Transfers are protected by the EU Standard Contractual Clauses (see section 8).
To send account emails, such as address confirmation and password reset, we use, or plan to use, a specialist email delivery provider acting as our processor. We will keep this Policy current as that arrangement is finalised.
If you turn on browser push notifications, the alerts are delivered through the push service built into your browser or operating system. We send only the message and an anonymous device endpoint; we do not share your account details with those services.
We plan to show a limited amount of advertising, potentially through Google AdMob and Google Ads (provided in the EEA by Google Ireland Limited), to help cover running costs. This is not active at the time of writing. When it goes live it will run only for users who have consented through our cookie tool, it will not be shown to accounts registered as under the applicable age of digital consent, and we will update this Policy first.
We may disclose personal data where we are required to by law, court order or a valid request from a competent authority, or where it is necessary to establish, exercise or defend legal claims, or to protect the rights, safety or property of our users, the public or us.
We do not sell your personal data, to anyone, at any time.
Some of our processors are established outside the EEA, in particular Supabase Pte Ltd (Singapore), with support functions in the United States, and our United States providers Vercel and Cloudflare. Using the Service therefore involves transferring your personal data outside the EEA. For each such transfer we rely on the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914, Modules Two and Three as applicable), incorporated into the data processing agreement of each provider, together with the technical and organisational safeguards described in section 12. Where a United States provider is additionally self-certified under the EU-US Data Privacy Framework, that adequacy decision may also apply. You may ask us for more information about these safeguards using the details in section 17.
Subject to the conditions and exceptions in the GDPR, you have the right to:
To exercise a right, use the relevant control in Settings where one exists (Export my data, the editable profile fields, or Delete account), or contact us at privacy@nimu.app. We will respond without undue delay and within one month of your request, as required by Article 12(3); for complex or numerous requests we may extend this by two further months and will tell you if we do. We do not charge for handling a request unless it is manifestly unfounded or excessive.
If you consider that we have not handled your personal data lawfully, you have the right to lodge a complaint with a supervisory authority (Article 77). You may complain to the authority in the EU or EEA country where you live or work, or where the alleged infringement took place. In Portugal this is the Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt; a directory of all national authorities is published by the European Data Protection Board at edpb.europa.eu. We would appreciate the chance to address your concern directly first.
We apply technical and organisational measures appropriate to the risk, including: database access rules that restrict every table to its owner (row-level security); encryption of data in transit and at rest; a policy of not embedding long-lived administrative credentials in client-side code; anti-bot protection at sign-up; and an internal process for detecting and responding to personal data breaches, including notifying the competent authority and affected users where the law requires. No online service can be completely secure, so we also encourage you to use a strong, unique password and to keep it confidential.
The Service is intended for users aged 13 and over, and you must also meet any higher age of digital consent that applies in your country, as set out in our Terms and Conditions. The Service is not directed at children under 13, and we do not knowingly collect their personal data. Push notifications and personalised advertising are off by default for every account, and we do not enable personalised advertising for accounts registered as under the applicable age of digital consent. If you believe a child has created an account without the required consent, contact us at privacy@nimu.app and we will act promptly, including by deleting the account.
Nimu does not show advertising today. If advertising is introduced, it will be provided through partners such as Google AdMob and Google Ads, it will run only for users who have consented through our cookie tool, it will be non-personalised by default, and it will never be personalised for accounts registered as under the applicable age of digital consent. We will update this Policy and our Cookie Policy with the specific partners and their roles before any advertising goes live.
We do not take decisions that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing (Article 22). Any personalisation, such as suggested titles, is a convenience feature that you can turn off in Settings, and it never determines anything that affects your legal rights.
We may update this Policy from time to time, for example when we add a feature or a new recipient. We will change the Last updated date above, and where a change is material we will make reasonable efforts to notify existing account holders, for example with a notice in the app. The current version always governs how we process your data.
For any question, request or complaint about your personal data, contact us at privacy@nimu.app. Full corporate details are available on request.