Animedex logo

Anime tracking & discovery

Privacy Policy

Last updated: 24 May 2026

This Privacy Policy describes how Madalin Simion, operating the Animedex mobile application ("we", "our", or "us"), collects, uses, stores, and protects your personal data. It also explains your rights under the General Data Protection Regulation (GDPR), UK GDPR, and other applicable laws.

This policy applies to the Animedex Android application (package name: com.anime.myapp). Using the App does not itself constitute consent to data processing — where we rely on consent we obtain it separately and explicitly.

Contents

  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Legal Basis for Processing (GDPR)
  5. Automated Decision-Making & Personalisation
  6. Third-Party Services & Firebase
  7. Local Device Storage (ePrivacy)
  8. Data Retention
  9. Data Security
  10. International Data Transfers
  11. Your Rights
  12. Children's Privacy
  13. California Users (CCPA/CPRA)
  14. Changes to This Policy
  15. Contact Us

1. Who We Are

The data controller for Animedex is:

Name: Madalin Simion
Country: Romania, European Union
Email: madalin.simion2000@gmail.com

As our establishment is within the EU, we are directly subject to Regulation (EU) 2016/679 (GDPR) and Romanian Law 190/2018. We have not appointed a Data Protection Officer (DPO) as our processing does not meet the thresholds set out in Article 37 GDPR (we are not a public authority, do not conduct large-scale systematic monitoring, and do not process special-category data at scale).

A Data Processing Agreement (DPA) incorporating the mandatory clauses under Article 28(3) GDPR is in place with Google LLC (Firebase) via Google's standard Firebase Data Processing and Security Terms.

2. Data We Collect

We collect only the data necessary to provide the App's functionality (data minimisation — GDPR Art. 5(1)(c)).

Category Specific data Required? Source
Account credentials Email address; password hash (Firebase manages hashing — we never see plain-text passwords); IP address at login (logged by Firebase) Required to create an account Provided by you
Profile information Username; profile picture (avatar you upload) Optional — the App works without these Provided by you voluntarily
App activity Anime library entries (titles, watch status, episode progress); preferred genre tags; favourite anime selections Core functionality; each entry is optional Provided by you through App use
Device & technical identifiers Firebase installation ID; device OS version (used solely for service reliability) Collected automatically Generated by your device / Firebase SDK

We use Firebase Authentication only — no Firebase Analytics, Firebase Crashlytics, or other Firebase telemetry SDKs are integrated. We do not collect location data, contacts, messages, financial data, health data, Google Advertising ID (GAID), or any data not listed above.

3. How We Use Your Data

We do not sell your data, use it for advertising, or share it for any purpose other than those listed above.

4. Legal Basis for Processing (GDPR Art. 6)

Processing activity Legal basis GDPR article
Account creation and authentication (email, IP at login) Performance of a contract Art. 6(1)(b)
Storing your anime library, watch status, genre preferences Performance of a contract Art. 6(1)(b)
Username and profile picture Your consent (freely given — these fields are optional and the App functions fully without them) Art. 6(1)(a)
Device identifiers for service reliability Legitimate interests (maintaining a stable, secure service) — we have balanced this against your interests and concluded processing is proportionate given the limited data involved and no impact on your fundamental rights Art. 6(1)(f)

Withdrawing consent

Where we rely on consent (username and profile picture), you can withdraw it at any time by deleting the relevant data within the App's profile settings, or by contacting us. Withdrawing consent does not affect the lawfulness of any processing carried out before withdrawal. Upon withdrawal, the relevant data is deleted from our servers within 30 days.

Right to object to legitimate-interests processing

Where we process your data on the basis of legitimate interests (device identifiers for service reliability — Art. 6(1)(f)), you have the right to object at any time under Art. 21(1) GDPR. To exercise this right, contact us at madalin.simion2000@gmail.com. We will cease that specific processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

5. Automated Decision-Making & Personalisation

The App generates anime recommendations for you based on the genre tags and favourite titles you have explicitly saved. This constitutes profiling within the meaning of GDPR Art. 4(4), as it involves automated processing of personal data to evaluate your preferences.

No solely automated decisions with legal or similarly significant effects are made about you — Art. 22 GDPR does not apply. The recommendation feature is purely for your convenience: it only affects which anime titles are surfaced in your feed. You are always free to browse and interact with all content regardless of the recommendations shown.

The logic used: we match your saved genre tags and favourite anime against our content catalogue to surface titles in the same genres or from the same studios. No inferences about your personality, behaviour outside the App, or sensitive characteristics are made.

6. Third-Party Services & Firebase

The App uses Firebase Authentication (provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) to create and manage user accounts. When you sign in, Firebase receives and processes your email address, IP address at login, and user-agent string.

If you sign in with Google, Google's OAuth 2.0 service is also involved. Your Google ID token is exchanged for a Firebase session — we receive only the Firebase ID token and do not store your Google account data beyond what Firebase manages.

No other third-party analytics, advertising, crash-reporting, or tracking SDKs are integrated.

Google's data practices are governed by the Google Privacy Policy and the Firebase Privacy and Security documentation.

7. Local Device Storage (ePrivacy)

The App stores the following data locally on your device using Android's standard storage mechanisms. No browser cookies are used.

Data stored locallyPurposeLegal basis
Authentication access token Keeps you logged in between app sessions without re-entering your password Strictly necessary for the service you requested — ePrivacy exemption applies
Firebase installation ID Unique identifier assigned by Firebase to this app installation for service reliability Strictly necessary for the service you requested — ePrivacy exemption applies
Cached user preferences (language, theme) Restores your display settings instantly on launch Strictly necessary for the service you requested — ePrivacy exemption applies

All locally stored data is strictly necessary for the App to function as requested by you. No advertising IDs, cross-app tracking tokens, or third-party tracking data are stored on your device.

8. Data Retention

DataRetention period
Account data (email, username, profile picture, library, preferences) Retained for as long as your account is active. Permanently deleted within 30 days of account deletion.
Firebase installation ID & device OS version Retained for the duration of your account, then deleted alongside account data.
IP address at login (Firebase Authentication logs) Managed by Firebase/Google per their own retention policies (typically 180 days for authentication logs). We have no control over Firebase's internal log retention.
Local device storage (access token, preferences) Cleared automatically upon logout or account deletion.

You can delete your account at any time via Settings → Delete Account within the App. This triggers immediate deletion of all your data from our systems, with permanent removal completed within 30 days.

9. Data Security

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours as required by GDPR Art. 33. Where the breach is likely to result in high risk to you, we will notify you directly without undue delay (GDPR Art. 34).

10. International Data Transfers

Firebase (Google LLC) is a US-based service. When your data is processed by Firebase, it may be transferred to and processed in the United States or other countries outside the European Economic Area (EEA).

These transfers are protected by Standard Contractual Clauses (SCCs) adopted by the European Commission in Decision 2021/914 of 4 June 2021, which Google/Firebase incorporates into its Data Processing Terms. We have conducted a Transfer Impact Assessment (TIA) in accordance with EDPB Recommendations 01/2020 and are satisfied that the SCCs, combined with Google's supplementary security measures, provide adequate protection for your data.

For users in the United Kingdom: transfers to Firebase are covered by International Data Transfer Agreements (IDTAs) or the UK Addendum to the EU SCCs, as adopted by the UK Information Commissioner's Office (ICO), which Google implements as part of its standard processor terms. The EU-UK adequacy decision and Google's UK-specific transfer mechanisms apply to UK users' data.

11. Your Rights

Rights under EU GDPR (all users)

To exercise any right: email madalin.simion2000@gmail.com. We will respond within one month. In complex or multiple cases, we may extend this by a further two months with prior notice (GDPR Art. 12(3)).

EU supervisory authority

You have the right to lodge a complaint with the Romanian data protection authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) .

Rights under UK GDPR (UK users)

If you are based in the United Kingdom, the same rights listed above apply to you under the UK GDPR (as retained in UK law by the EU (Withdrawal) Act 2018). You may lodge a complaint with the UK supervisory authority: Information Commissioner's Office (ICO) .

12. Children's Privacy

The App is a general-audience service and is not directed at children.

This policy is consistent with the U.S. Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal data from US children under 13, and the App is not directed at them. If we become aware that we have received data from a US child under 13 without verifiable parental consent, we will delete it immediately.

13. California Users (CCPA / CPRA)

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), may apply if you are a California resident. As an individual developer, we do not currently meet the revenue or data-volume thresholds that make CCPA mandatory. However, we voluntarily extend the following disclosures:

14. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, the App, or applicable law. When we do, we will update the "Last updated" date at the top. For material changes, we will notify you via an in-app notice or email at least 14 days before the changes take effect. Continued use of the App after the effective date of a material change constitutes acknowledgement of the updated policy. Where a change affects consent-based processing, we will obtain fresh consent.

15. Contact Us

For any questions, data requests, or concerns about this Privacy Policy:

Controller: Madalin Simion
Email: madalin.simion2000@gmail.com
Response time: Within one month (GDPR Art. 12(3))
If you are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority — in Romania, the ANSPDCP; in the UK, the ICO.