MiruList is an anime discovery directory and personal tracker. This page describes what we store, why we store it, and how to get rid of it. We sell nothing to anyone and we run no advertising.
What we store
- Account — your email address (held by our authentication provider), plus the profile you create: username, display name, optional bio and avatar URL, region, timezone and privacy setting.
- Your library — the titles on your lists with their status, score, episode progress, notes, favourite flag and per-title mutes.
- Social— who you follow, who follows you, and activity events (e.g. “completed X”). Each event stores the visibility it was written with.
- Notifications— your notification preferences and a log of which episode alerts were already sent, so you don't get duplicates.
- Chat — if you use Rei, your conversations and messages are stored so threads persist between visits.
- Imports— if you link MyAnimeList or AniList, we store the account identifier and the import job's preview data. Access tokens are encrypted at rest.
We do not store payment details (there is nothing to pay for) and we do not ask for your real name, address or phone number.
Cookies
A session cookie keeps you signed in. It is required for the site to work and is not used for tracking. If analytics is enabled on this deployment (see below), that provider sets its own cookies.
Who processes your data
- Supabase — authentication and the Postgres database holding everything above.
- Vercel — application hosting and request logs.
- OpenRouter / OpenAI — only if you use Rei or semantic search: your message text (and, for recommendations, a summary of relevant titles) is sent to the model provider to generate a reply. Your email address is never sent.
- Google Analytics — aggregate traffic measurement, enabled only when the deployment sets an analytics ID.
Catalog data flows the other way: we fetch metadata and availability from AniList, Kitsu, TMDB and JustWatch. Nothing about you is sent to them.
Your choices
- Visibility — set your profile to public, friends-only or private in Settings. Private profiles are also excluded from search-engine indexing.
- Notifications — mute globally or per title at any time.
- Export or deletion — email privacy@mirulist.com from your account address and we will export or permanently delete your profile and everything attached to it. Deletion cascades: lists, follows, activity, notifications and chat history all go with the account.
Retention
Account data is kept until you delete your account. Request logs are kept for a short operational window by our host. Catalog data is not personal data and is retained indefinitely.
Children
MiruList is not directed at children under 13, and accounts should not be created for them.
Changes
If this policy changes materially, the date at the top changes and the update is noted on the site.
Contact
Questions about this policy: privacy@mirulist.com.