Privacy Policy

Last updated: September 26, 2026. This page explains what data Backlog collects, why, and how you can control it.

Data We Collect

  1. Account data: username, email address, and password hash (if you register with email/password).
  2. OAuth data: if you sign in with Google or Discord, we receive your email address and public profile info (name, avatar) from that provider to create or link your account. We never see or store your Google or Discord password.
  3. Profile content: avatar image, bio, accent color, and any media library entries, ratings, notes, and progress you add.
  4. Cookies and session data: a session cookie keeps you signed in; it is stored server-side in Redis (or memory) and expires automatically.
  5. Technical logs: IP address, user agent, and request timestamps, kept for security purposes such as rate limiting and abuse prevention (e.g. banning malicious IPs).
  6. Anonymous analytics: aggregated usage statistics via Google Analytics (gtag.js), which uses its own cookies. You can block this with browser tracking-protection or an ad blocker without affecting site functionality.
  7. Cloudflare Turnstile: a captcha challenge used on registration to block bots; Cloudflare processes some technical data to verify you are human.

Why We Use It

  1. To create and secure your account, keep you signed in, and let you recover access if you lose your password.
  2. To provide the core service: tracking your media backlog and, if you choose, showing a public showcase profile.
  3. To protect the site from spam, bots, and abuse (rate limiting, IP bans, captcha).
  4. To understand aggregate usage and improve the product.

Who We Share Data With

We do not sell your personal data. Data is shared only with the service providers needed to run Backlog:

  1. Google and Discord — only if you choose to sign in with them, to authenticate you.
  2. Cloudflare — for captcha verification and, where applicable, network protection.
  3. Google Analytics — for anonymous, aggregated usage statistics.
  4. Our email provider — to send account emails such as confirmation and password reset links.
  5. External media databases (RAWG, TMDB, Google Books, Jikan/MyAnimeList, Wikipedia) — only to fetch public information about games, movies, series, books, and anime (titles, covers, descriptions). No personal data is sent to these services.

How Long We Keep It

Account and library data is kept for as long as your account exists. Session cookies expire automatically. Security logs (IP addresses, request logs) are kept only as long as needed for abuse prevention and are periodically purged.

Your Choices & Rights

  1. Privacy controls: you can make your profile private, and hide ratings or statistics, at any time in Settings.
  2. Access and correction: you can view and edit your account data in Settings.
  3. Deletion: to request deletion of your account and associated data, email us at the address below. We will process the request as soon as reasonably possible.
  4. You can disconnect a linked Google or Discord account, or stop using Backlog at any time.

Children

Backlog is not directed at children under 13, and we do not knowingly collect data from them.

Changes to This Policy

We may update this policy as the service evolves. Material changes will be reflected on this page with an updated date.

연락처

For privacy questions or data requests, contact us:
backlog.site@gmail.com