Privacy Policy
Last updated: July 27, 2026
This policy explains what personal data YagaHentai collects, why, how long it is kept, and what rights you have. The data controller is [[ TO COMPLETE — legal name of the operator (individual or company) ]], [[ TO COMPLETE — full postal address of the operator ]], reachable at [[ TO COMPLETE — contact email, e.g. [email protected] ]].
1. Data we collect
We collect only what the Service needs to work:
- Account data: username, email address, password (stored hashed, never in clear text), role, account creation date.
- Profile data: avatar, biography, and anything else you choose to publish.
- Activity data: reading history, library, galleries, favourites, comments, posts, group memberships, direct messages, votes, credits and transactions.
- Uploads: the files you submit for publication and their metadata (title, tags, artists, languages…), including submissions that are rejected.
- Technical data: IP address, browser and device information, pages viewed, and timestamps. IP addresses are also used in aggregated form to count gallery views without counting the same visitor twice.
- Payment data: we receive confirmation of a payment, its amount, plan and an identifier from the provider. We never receive or store your card number or wallet credentials.
- Moderation data: reports you submit, decisions taken on your uploads, and download activity used to enforce daily limits.
2. Why we use it, and on what basis
- To provide the Service (accounts, publishing, reading, community features) — performance of our contract with you.
- To process purchases and grant Premium access — performance of our contract with you.
- To moderate content, prevent abuse, fraud and unauthorised access, and enforce our rules — our legitimate interest in operating a lawful and safe service.
- To measure audience and improve performance — our legitimate interest, using minimal and aggregated data.
- To respond to legal requests and to comply with obligations regarding illegal content — compliance with a legal obligation.
3. How long we keep it
- Account and profile data: for as long as your account exists, then deleted or anonymised.
- Published content: until you remove it or your account is deleted.
- Rejected uploads: retained for a short review window (currently 3 days) and then permanently deleted, files included.
- Technical logs: a limited period, in principle no longer than 12 months.
- Payment records: for the period required by accounting and tax rules.
4. Who processes data on our behalf
We use third-party providers strictly as processors. Each is bound by its own contractual and security commitments. Verify and keep this list current:
- Hosting of the website and application layer — Vercel Inc. (United States).
- Hosting of the backend API — Render Services, Inc. (United States).
- Database — Supabase (managed PostgreSQL).
- File storage and content delivery — Amazon Web Services (S3, CloudFront).
- Network protection and caching — Cloudflare, Inc.
- Session storage and caching — Upstash (Redis).
- Payments — the providers listed on the payment page, acting as merchant of record.
[[ TO COMPLETE — verify each provider's legal entity and address on its own legal page before publishing ]]
5. International transfers
Some providers are located outside your country, including in the United States. Where such a transfer takes place, it is framed by the appropriate safeguards offered by the provider, such as standard contractual clauses or an adequacy mechanism.
6. Your rights
Subject to the law applicable to you, you may:
- access the data we hold about you;
- have inaccurate data corrected;
- have your data deleted, in particular by deleting your account;
- object to or restrict certain processing;
- receive your data in a portable format;
- withdraw your consent at any time, where processing is based on consent;
- lodge a complaint with a supervisory authority.
To exercise these rights, write to [[ TO COMPLETE — contact email, e.g. [email protected] ]]. We may ask for proof of identity before acting on a request. Competent supervisory authority: [[ TO COMPLETE — competent data protection authority ]].
7. Security
Passwords are stored hashed. Access to the database is restricted to the application server and administrators. Traffic is encrypted in transit. Sensitive tables are not exposed to the public API.
No system is perfectly secure. If a breach were to affect your data and present a risk to you, we would inform you and the competent authority as required by applicable law.
8. Minors
The Service is strictly reserved for adults. We do not knowingly collect data relating to minors. If we become aware that an account belongs to a minor, it is deleted immediately together with its data.
9. Changes
This policy may be updated. The revision date appears at the top of the page; material changes will be announced on the Service.