Privacy Policy
Last updated: 10 September 2026
Tsumihon is a personal library manager for doujinshi and manga. We designed it to keep almost everything on your device. This page explains what data Tsumihon handles, where it goes, and the choices you have.
If you have questions, write to support@tsumihon.app.
What Tsumihon is
Tsumihon is a collection and reading app you install on your mobile or tablet device. It catalogs books you own or have added, fetches metadata and cover art from public sources, and shows them in a built-in reader. We do not sell, distribute, or host any of the books or images themselves.
Tsumihon is intended for adults. Some content surfaced through external catalog sources is not appropriate for minors.
Your account
Using Tsumihon requires a Tsumihon account. The account is what powers cross-device sync, lets you restore your library on a new device, and ties your in-app purchases to a persistent identity.
When you create an account we collect:
- An email address.
- An authentication credential (for example, a hashed password or an identity-provider token, depending on how you sign in).
We use this information to authenticate you, deliver service-related messages, and let you recover your account.
You can delete your account from the app’s settings — see Delete your account for the exact steps and for what is removed. Deletion removes your synced library and account record from our backend, and the app clears its local copy on the device at the same time. Backup files you exported yourself are left alone.
Data stored on your device
When you use Tsumihon without cloud sync, the following data lives on your device only:
- Your library: book titles, authors, tags, ratings, reading progress, notes.
- Cover thumbnails and any downloaded files you cache for offline reading.
- Settings: theme, reading direction, source preferences, app-lock state.
- Session credentials you add yourself for external catalog sources you choose to log into.
You can clear any of this from the app’s settings at any time.
Cloud sync
Your library metadata and settings sync to our backend so they appear on your other devices when you sign in. The synced record contains:
- Library metadata (titles, tags, progress, notes, etc.).
- App settings.
- Your account email and authentication state.
- A list of your own devices — a device name, platform, app version, last-seen time and push token — so a sync can be sent to them.
- Cover images you have chosen yourself, in a private bucket only your account can read.
- Your source logins and any AI provider key you enter, encrypted — see below.
We do not sync your downloaded book files, the covers the app fetched for itself, or analytics data.
Your source logins and API keys
These are encrypted on your device before they leave it, with a random key your phone keeps for you. We hold only the ciphertext and we cannot read it: the key is stored in Apple’s or Google’s own keystore, which they move between your devices end-to-end and cannot read either. We do not proxy your requests to a source, and we never use an AI key you enter.
This exists so that signing in to a source once works on every device you own, rather than being re-entered on each. Turning cloud sync off keeps them on the device that has them.
Our backend runs on Supabase (database, authentication, file storage) and Cloudflare (support-log storage, the website, and the anti-spam check on the contact form). Purchases are handled by RevenueCat together with Apple or Google. Crash reports and, if you turn them on, usage analytics go to Google Firebase. Each is a processor acting on our instructions under a data-processing agreement. Support-log storage is in the Asia-Pacific region; the rest follow the provider’s own regions. We may change providers as the service evolves and will continue to apply equivalent protections.
Share links
Sharing a book is the only feature that makes any part of your library readable by people who are not signed in to your account. It is always something you start deliberately, per book, and it is off until you do.
When you create a share link:
- We publish a snapshot of that one book to a page at
tsumihon.app/s/…. The page is reachable by anyone who has the address. There is no password and no sign-in on it. The address is unguessable rather than access-controlled, so it is not discoverable — but whoever you send it to can pass it on. - The snapshot contains bibliographic fields only: titles, artist, circle, parody, characters, cosplayers, tags, conventions, type, format, page count, release date, publisher, magazine, series and volume, ISBN, description, the cover image, and the source links stored on the book.
- It does not contain your price, notes, physical location or condition, shelf assignment, download state, ratings, categories, or your account identifier. These are excluded by an allowlist, so fields added to Tsumihon in future are not published unless they are deliberately added to it.
- We record how many times the page has been opened, so you can see whether a link has been used before deciding to cancel it. We do not record who opened it, and we do not store visitors’ IP addresses for this purpose.
- Cover images are served through our own infrastructure rather than linked from the original source. As a result, the source site does not learn who viewed the page.
Every link expires seven days after you create it, and is deleted from our systems shortly after that. You can cancel any link at any time from Settings → Privacy → Active share links; cancelling takes effect immediately, and the cover stops being served within an hour. Deleting a book, wiping your library, or deleting your account also cancels its links.
Share pages are excluded from search-engine indexing and are not listed anywhere on our site.
Legal basis, where the GDPR applies: publishing a share is carried out on the basis of your consent, given by creating the link, and you can withdraw it at any time by cancelling the link.
Analytics
Analytics are off unless you turn them on — during onboarding, or later in Settings → Privacy. When they are off, no analytics events are sent at all.
If you do turn them on, Tsumihon sends product-analytics events so we can see which features are used and prioritise what to build. These events:
- Contain no library titles, tags, authors, or other content from your collection.
- Are pseudonymous, not anonymous: they are keyed to an app-install identifier and, while you are signed in, to your account. That is still personal data under the GDPR, and we say so rather than calling it anonymous.
- Are not used for advertising or cross-site tracking, and the app requests no advertising identifier on either platform.
Crash and error reports
If the app crashes or hits an unexpected error, we receive a stack trace so we can fix the bug. Reports include device model, OS version, and the crashing code path. This is a separate switch from analytics, in Settings → Privacy, and it is on by default — without it a failure in the field leaves no trace at all.
Crash reports are not designed to carry your library and do not deliberately include it. We cannot promise it absolutely: an error raised while fetching something can carry the address it was fetching in its message. They are never used for anything but diagnosing the failure.
Support logs
Separate from the anonymous crash reports above, the app has a Send Logs to Support action (Settings → Advanced & Safety). It is never automatic — a log is uploaded only when you tap it, so that we can investigate a problem you have reported.
- The log is a record of what the app did — screens opened, sync activity, errors — and it does include titles and source addresses from your library, whether or not you turned on debug logging: an error raised while downloading a book names that book. It is tied to your account. Treat it as your reading history and send it only when you want us to see it.
- Each upload gets a short reference code you quote to us. You can review everything you have sent, and withdraw any of it, under Settings → Advanced & Safety → Sent Diagnostics — withdrawing deletes it from our systems immediately.
- We keep support logs for at most 14 days and then delete them automatically. They are also removed when you withdraw them, and when you delete your account.
- To keep this from becoming a way to fill our storage, each account can send at most 3 logs per day.
This is the one place the app can send library content off your device, and it never does so without your explicit, per-upload action.
Optional AI features
Some features — for example, extracting text from a cover photo — are off by default and require you to provide a credential for an external AI provider of your choice. When you enable such a feature and explicitly trigger it, the single image or text you selected is sent from your device directly to that provider. We do not proxy the request and we do not receive the image. We do store the credential, encrypted, if you have cloud sync on — so it follows your account to your other devices; we cannot read it and we never use it ourselves. See Cloud sync.
The provider’s handling of your request is governed by their terms — read them before enabling a feature that uses an external provider.
Purchases
If you buy Tsumihon or an in-app subscription, purchases are processed by the platform you installed Tsumihon from (the device’s app store). We do not see your payment details. We do receive a confirmation that your account is entitled to the features you bought, so we can unlock them across your devices.
External catalog sources
Tsumihon can query public catalog sources you choose to enable. These requests go directly from your device to the source — they do not pass through our servers. If you log in to a source, the session credentials are stored locally on your device and only sent back to that source.
We are not affiliated with any catalog source, do not control them, and have no insight into their data practices. Review their terms before using them.
Children
Tsumihon is not directed at, and not appropriate for, anyone under 18. Some catalog sources surface adult content. Do not use Tsumihon if you are a minor.
Your rights
You can, at any time:
- See what’s stored locally — everything is visible in the app’s library and settings screens.
- Export your library — use the backup feature in the app’s settings.
- Sign out — drops account state from the device.
- Delete your account — removes the synced copy from our backend. Steps and full detail: Delete your account.
- Reset the app — wipes all local data.
- Opt out of analytics — toggle in onboarding and settings.
If you’d like a copy of any data we hold about you, or want it deleted, email support@tsumihon.app from the address tied to your account.
Changes to this policy
If we make material changes, we will update the date at the top of this page and, where appropriate, surface a notice in the app. Continued use after a change means you accept the updated policy.
Contact
Questions, concerns, or requests:
- Email: support@tsumihon.app