Manga Vision Privacy Policy
How personal data is processed in the app and in its backend
Language of the binding version. This is a translation provided for convenience. The Russian version is the one that has legal effect; in case of any discrepancy, the Russian text prevails.
This Privacy Policy (the “Policy”) describes what data is processed when the Manga Vision mobile application and its backend are used, why it is needed, who it is shared with and how long it is kept. The Policy is adopted by the Operator and is the document required by Part 2 of Article 18.1 of Russian Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” (“Law 152-FZ”).
In short. The Operator does not know what a user reads: the app contacts source websites directly from the device, and bookmarks, reading history and settings never leave the device.
The servers store only what the account and the subscription cannot work without: an account identifier, an email address, the display name from the sign-in provider, the premium expiry date and payment records. Bank card details never reach the Operator.
Data is stored in the Russian Federation. An account, together with all data linked to it, can be deleted inside the app — no support request required.
1. General provisions
1.1. The personal data operator is a self-employed individual (payer of the professional income tax) who has adopted this Policy. The Operator’s details and contacts are given in Section 17.
1.2. The Policy covers all personal data that the Operator receives from and about a user in connection with the use of the Service.
1.3. The Policy does not cover processing carried out by source websites, app stores, sign-in providers, the payment service and advertising networks: these organisations act as independent operators under their own policies. They are listed with links in Section 9.
1.4. The current version of the Policy is permanently available at the address where this document is published. Section 16 governs how the Policy is amended.
1.5. The Policy applies together with the Terms of Use and the public offer. Terms not defined in Section 2 have the meaning given to them in those documents.
2. Definitions
- Operator
- The person who organises and carries out the processing of the personal data of the Service’s users and determines the purposes of processing and the data processed.
- Service
- The Manga Vision mobile application and its backend, taken together.
- User
- An individual who uses the Service. Under Law 152-FZ — the personal data subject.
- Account
- The User’s account in the Service, created upon sign-in through a sign-in provider and required for paid functionality.
- Sign-in provider
- Google (Firebase Authentication) or HUAWEI ID (Account Kit) — the service that confirms the User’s identity when signing in.
- Payment service
- YooKassa (YooMoney NBCO LLC) — the organisation that accepts payments and stores the User’s payment credentials.
- Source (source website)
- A publicly available third-party website that the app contacts at the User’s request in order to display the materials published on it. A Source belongs to third parties and is not controlled by the Operator.
- Premium
- The Account status that unlocks the paid functionality of the Service for the period paid for.
- Processing of personal data
- Any operation performed on personal data by automated means: collection, recording, storage, updating, use, transfer, anonymisation, blocking, deletion and destruction.
3. Processing principles
3.1. Processing is lawful and fair, limited to purposes defined in advance, and is not combined with purposes incompatible with one another.
3.2. The set of data processed is minimal and not excessive in relation to the purposes: the Operator does not collect data “for later” and does not collect anything the Service works without.
3.3. Data is kept no longer than the purposes of processing require, after which it is deleted or anonymised. Retention periods are set out in Section 12.
3.4. The Operator keeps processed data accurate and takes steps to delete or correct incomplete or inaccurate data.
4. Data processed on the Service’s servers
4.1. Account data:
- the account identifier issued by the sign-in provider — a technical string taken from the token, by which the Service recognises the User on the next sign-in;
- the internal Account identifier — a random value used to refer to the Account in logs and in support correspondence instead of the provider’s identifier;
- the email address;
- the display name, if the User allowed the sign-in provider to share it;
- the date and time when Premium expires.
4.2. Subscription and payment data:
- payment identifiers issued by the Payment service, amounts, statuses and dates;
- the subscription status, the boundaries of the paid period, the next charge date, and the number of and reasons for failed charge attempts;
- the recurring-payment reference stored by the Payment service and its user-visible description — normally the card scheme and the last four digits of the card number. The card number itself is not part of that description.
4.3. Promo code redemptions: the code, the number of Premium days granted and the redemption date.
4.4. A log of Premium operations performed manually by the Operator: the type of operation, the number of days, the expiry date before and after the operation, and its reason. The log exists so that a user’s enquiry can be answered with evidence of where a period they did not pay for came from.
4.5. Technical data:
- backend request logs: date and time, method, request path and response code. Account identifiers and request payloads are not written to them;
- the IP address — used at the moment of the request to rate-limit it and to verify that a payment notification really came from the Payment service. The application logs do not record the IP address, but the network infrastructure (the reverse proxy) may record it in its standard access logs.
5. Data that stays on the device
5.1. The following is stored on the User’s device and nowhere else:
- bookmarks, lists and ratings;
- reading history and position within chapters;
- app and reader settings;
- the cache of pages and images loaded from Sources;
- sign-in data for accounts on Sources, including session files.
5.2. None of the above is transmitted to the Operator’s servers, and the Operator has no access to it. Accordingly, the Operator does not know which titles a User searches for, opens or reads.
5.3. This data is deleted when the app is uninstalled or its data is cleared through the operating system. Preserving it is up to the User: it is not restored when the app is reinstalled or the device is changed.
6. What the Operator does not process
6.1. Bank card numbers, expiry dates and verification codes. Card details are entered on the Payment service’s side and never reach the Operator in any form.
6.2. Passwords for accounts with sign-in providers or on Sources.
6.3. Special categories of personal data (health, political or religious beliefs, intimate life and others listed in Article 10 of Law 152-FZ) and biometric personal data.
6.4. Precise device location. The app does not request the location permission.
6.5. Contacts, messages, call records and files on the device outside the app’s own directory.
6.6. Whether emails are opened and whether links in them are followed: the Service’s emails contain no tracking images or counters, and the logo is embedded in the message itself rather than loaded from an external server.
7. Purposes of processing and legal grounds
| Purpose | Data | Legal ground |
|---|---|---|
| Creating an Account and signing in | Account identifiers, email address, display name | Performance of a contract to which the User is a party — the Terms of Use (Art. 6(1)(5) of Law 152-FZ) |
| Providing Premium, accepting payment and renewing the subscription | Account identifiers, email address, subscription and payment data | Performance of a contract — the public offer (Art. 6(1)(5) of Law 152-FZ) |
| Issuing fiscal receipts and paying the professional income tax | Email address, amounts and dates of settlements | Compliance with obligations imposed on the Operator by law — Federal Law No. 422-FZ of 27 November 2018 (Art. 6(1)(2) of Law 152-FZ) |
| Subscription-related notifications: a failed charge, a stopped renewal | Email address, display name, subscription data | Performance of a contract — the public offer (Art. 6(1)(5) of Law 152-FZ) |
| Redeeming promo codes and preventing repeated redemption | Account identifier, code, redemption date | Performance of a contract (Art. 6(1)(5) of Law 152-FZ) |
| Handling and answering User enquiries | Email address and the information provided in the enquiry | Performance of a contract and handling an enquiry initiated by the User (Art. 6(1)(5) of Law 152-FZ) |
| Keeping the Service available and secure: rate limiting, detecting failures and abuse | Technical logs, IP address | Legitimate interests of the Operator, provided the User rights and freedoms are not infringed (Art. 6(1)(7) of Law 152-FZ) |
| Showing ads in the free version of the app and collecting anonymised usage statistics | Technical device data, advertising identifier (see Section 10) | Consent of the User (Art. 6(1)(1) of Law 152-FZ), which may be withdrawn as described in Section 14 |
7.1. No processing takes place for purposes other than those listed above. The Operator makes no decisions producing legal effects solely on the basis of automated processing.
7.2. The Operator does not profile Users. Ad personalisation is performed by the advertising network on the device and under its own rules (Section 10).
8. Sources of the data
8.1. From the User — when entering an email address on the payment screen, redeeming a promo code and contacting support.
8.2. From the sign-in provider — the account identifier, email address and display name, to the extent the User allowed at sign-in.
8.3. From the Payment service — the outcome and status of a payment and the stored recurring-payment reference.
8.4. Automatically — the technical data listed in clause 4.5, at the moment the app contacts the backend.
9. Sharing data with third parties
9.1. The Operator does not sell personal data, does not share it for third-party marketing and does not disclose it other than as described in this Section.
9.2. Data is shared with organisations without which the Service cannot work — and only to the extent each of them needs:
| Organisation and its role | What data | Why |
|---|---|---|
| Google LLC / Google Ireland Limited — Firebase Authentication Privacy Policy |
Account identifier, email address, display name | Confirming identity at sign-in and deleting the account at the request of the User |
| Huawei Tech Company LLC / Huawei — HUAWEI ID (Account Kit) Privacy Policy |
Account identifier, email address, display name | Confirming identity at sign-in in the app build for HUAWEI devices |
| YooMoney NBCO LLC — YooKassa, the payment service Legal documents |
Email address, payment amount and description, Account identifier | Accepting payment, recurring charges, issuing receipts and making refunds |
| Federal Tax Service of Russia | Settlement details contained in the fiscal receipt | Compliance with the obligations of a professional income tax payer |
| The email delivery provider | Email address, display name and the text of the message | Delivering subscription-related notifications |
| Yandex LLC — Yandex Ads and AppMetrica Privacy Policy |
Technical device data and the advertising identifier — from the app only, with no Account data | Showing ads in the free version and collecting anonymised usage statistics |
| Google LLC — Google Analytics for Firebase and Firebase Crashlytics Privacy and Security in Firebase |
Technical device data, operating system and app versions, crash details — with no Account data | Anonymised usage statistics and crash reports |
| App stores: Mnogo Prilozheniy LLC (RuStore), Google (Google Play), Huawei (AppGallery) | Data the store processes on its own when the app is installed and updated. The Operator shares nothing with the store | Distributing and updating the app |
9.3. Data may be disclosed to state authorities upon a reasoned request, in the cases, manner and scope established by the legislation of the Russian Federation.
9.4. The Operator does not share User data with Sources. How the app contacts Sources is described in Section 11.
10. Advertising and analytics in the app
10.1. The free version of the app shows ads served by the Yandex advertising network. The network receives anonymised technical data about the device, including the Android advertising identifier, and uses it under its own policy. The Operator does not determine which ads are shown.
10.2. Premium turns off ads in the app and the requests to the advertising network. This does not extend to ads placed on the pages of Sources themselves: those pages do not belong to the Operator.
10.3. For anonymised usage statistics and crash reports the app uses AppMetrica, Google Analytics for Firebase and Firebase Crashlytics. These services receive data about the device, the operating system and app versions, events that occurred in the app and crashes. The Account identifier, email address and name are not shared with them, and the Operator cannot match the statistics to a particular Account.
10.4. What a User searches for, opens and reads is not sent to analytics: the events describe how the app works, not what is being read.
10.5. A User can limit this collection through the device:
- reset the advertising identifier or opt out of its use — in Android settings (“Privacy” → “Ads”, or “Google” → “Ads” on some devices);
- turn off ads in the app entirely — by subscribing to Premium;
- withdraw consent to processing for advertising and analytics — as described in Section 14.
10.6. Technologies similar to cookies are used in the app only by the services listed above and only to the extent described. The Operator neither creates nor stores counters or advertising identifiers of its own.
11. How the app contacts Sources
11.1. Searching, opening a title and moving to a chapter are performed by a request sent from the device directly to the Source chosen by the User. These requests do not pass through the backend of the Service, and the Operator knows neither their content nor which Source was contacted.
11.2. During such a request the Source sees what any website sees when it is visited: the IP address of the device, information about the client software, and cookies previously set by that Source. The Operator does not receive this information and has no influence over how the Source processes it.
11.3. If a User has signed in to an account on a Source, the sign-in data and session files are stored on the device only (clause 5.1). The Operator has no access to them.
11.4. Processing by Sources is governed by their own policies. The Operator is not a party to the relationship between a User and a Source and is not responsible for that processing.
12. Where and how long data is kept
12.1. The databases of the Service that contain personal data are located in the Russian Federation. Recording, systematisation, accumulation, storage, updating and retrieval of personal data of citizens of the Russian Federation are carried out using those databases (Art. 18(5) of Law 152-FZ).
12.2. Retention periods:
| Data | Retention period |
|---|---|
| Account data, subscription, payment and promo code records, the log of Premium operations | Until the Account is deleted. Deletion is performed by the User in the app and removes this data immediately (Section 15) |
| Technical backend request logs | No more than 90 days from the date of the entry, after which they are deleted automatically |
| Correspondence about User enquiries | No more than one year after the enquiry has been dealt with |
| Records of completed settlements | Kept by the Payment service and the Federal Tax Service for the periods set by law, regardless of Account deletion (clause 12.3) |
12.3. Records of completed settlements remain with the Payment service and in the information system of the Federal Tax Service through which receipts are issued. These organisations keep them as required by law, and deleting an Account does not affect that. Refund requests submitted under the public offer are also decided on the basis of those records.
12.4. Once the purposes of processing have been achieved or the need for them has ceased, data is deleted or anonymised within 30 days, unless another period is set by law (Art. 21(4) of Law 152-FZ).
13. Security measures
13.1. Traffic between the app and the backend, and with the Payment service, uses the secure HTTPS protocol.
13.2. Access to the servers and databases is restricted and granted to the Operator only; administrative operations require a separate access key.
13.3. The rate of requests to the backend is limited, which impedes automated enumeration and excessive load.
13.4. The account identifier issued by the sign-in provider is never written to logs or shown in administrative interfaces: outside the database an Account is referred to by an internal identifier that means nothing beyond the Service.
13.5. Bank card details are neither processed nor stored (clause 6.1), so they cannot leak on the Operator side.
13.6. No security measure is absolute. In the event of an incident affecting personal data, the Operator takes the measures required by the legislation of the Russian Federation.
14. Rights of the User
14.1. A User has the right to:
- obtain confirmation that their data is processed and the information listed in Art. 14(7) of Law 152-FZ, including the categories of data processed, the purposes and the retention periods;
- request correction of data that is incomplete, inaccurate or out of date;
- request blocking or deletion of data obtained unlawfully or no longer necessary for the stated purpose;
- withdraw consent to processing;
- object to processing for advertising and analytics purposes;
- challenge the Operator’s actions in the manner established by the legislation of the Russian Federation.
14.2. Some of these rights are exercised without contacting the Operator: everything listed in Section 4 is removed by deleting the Account in the app (Section 15), processing for advertising is limited through the device (clause 10.5), and the email address and name are corrected in the account with the sign-in provider and reach the Service at the next sign-in.
14.3. Other requests are sent to the email address given in Section 17. A request must make it possible to identify the User: it should be sent from the email address recorded in the Account, or state the internal Account identifier. The Operator may refuse to disclose information if it cannot establish that the request comes from the data subject.
14.4. Response deadlines:
- for a request for information about processing — 10 working days from receipt; the deadline may be extended by no more than 5 working days with notice of the reasons (Art. 20(1) of Law 152-FZ);
- for a demand to correct, block or delete incomplete, inaccurate or unlawfully obtained data — 7 working days from the date the supporting evidence is provided (Art. 21 of Law 152-FZ);
- for a withdrawal of consent — processing stops and the data is deleted within 30 days (Art. 21(5) of Law 152-FZ).
14.5. Withdrawing consent to the processing of data required to perform the contract makes the paid functionality unavailable and leads to deletion of the Account. Withdrawing consent for advertising and analytics does not affect the Account.
15. Deleting the Account and the data
15.1. An Account can be deleted inside the app. No request to the Operator is needed.
15.2. Deletion is irreversible. All data linked to the Account and listed in Section 4 is deleted with it: the Premium expiry date, subscription and payment records, promo code redemptions and the log of Premium operations. The account with the sign-in provider through which the Account was created is deleted as well.
15.3. Deleting the Account terminates the auto-renewing subscription: the stored recurring-payment reference is deleted together with the Account, so no further charges are made, and the previous subscription cannot be resumed — it would have to be taken out again.
15.4. A paid but unused Premium period is not preserved when the Account is deleted and is not refunded automatically. The refund procedure is set out in the public offer. The Operator therefore recommends cancelling the renewal first, using the paid period to the end or requesting a refund, and deleting the Account after that.
15.5. Data on the device (Section 5) is unaffected by Account deletion: it is removed when the app is uninstalled or its data is cleared through the operating system.
15.6. Records of completed settlements are unaffected by Account deletion for the reasons given in clause 12.3.
16. Changes to the Policy
16.1. The Operator may amend this Policy by publishing a new version at the address where this document is published. The version date is stated in its heading.
16.2. A new version takes effect upon publication unless it states another date.
16.3. Material changes — a wider set of data processed, new purposes of processing or new recipients of data — are additionally communicated to the User: in the app or by email to the address recorded in the Account.
16.4. Continuing to use the Service after a new version is published constitutes agreement with it. A User who does not agree with the changes stops using the Service and may delete the Account as described in Section 15.
17. Contacts
- Personal data operator
- Nikita Grigoryevich Ishevskikh, self-employed (payer of the professional income tax), TIN 221001700735
- Email for enquiries about personal data processing
- ishevskikhdev@gmail.com
- Other documents of the Service
- Terms of Use · Public offer