Privacy Policy
プライバシー
Last updated July 2026
The short version: AniCore stores as little about you as it can get away with, and everything it does store exists to make your own features work.
Browsing as a guest
- My List, watch progress, watch history, profile name/avatar, and site preferences live in your browser's local storage. Signed out, they never leave your device.
- Clearing your browser data erases them entirely.
If you sign in or connect with AniList
- Connecting is optional. When you do, AniList issues this site an access token for your AniList account; the sign-in itself happens on anilist.co and your AniList password is never seen by AniCore.
- Using Log in with AniList creates a normal AniCore account keyed to your AniList user id — no email address and no password are stored for it. Connecting AniList while already signed in simply links the two, and either sign-in opens the same account.
- The token is stored with your other site data — in your browser as a guest, or in your synced account data when signed in — and is used only to read your AniList anime list and to write list status and episode progress as you watch (that's the point of the feature). Those updates go from your browser directly to AniList.
- Anime you watch while auto-sync is on will therefore be visible on your AniList profile, subject to your AniList privacy settings.
- Disconnecting in Settings deletes the stored token everywhere it was stored. You can additionally revoke AniCore's access from your AniList account settings ("Apps").
If you create an account
- We store your email address, username, and a salted cryptographic hash of your password (never the password itself), used solely to operate your account. Signing in uses one strictly-necessary session cookie.
- While signed in, the data listed above (list, progress, history, preferences, profile) syncs to the server so it follows you across devices. It's tied to your account, used for nothing else, and shown to no one else.
- You can export all of it as JSON from Settings at any time, turn history collection off, clear individual stores, or delete the account — deletion removes the account and every piece of synced data with it.
What the server sees
- Standard web-server request logs (IP address, requested page, timestamp) kept transiently for abuse prevention and debugging, not analytics.
- Search and browse queries are forwarded to public metadata APIs (AniList, TMDB, ani.zip, Kitsu) to fetch results, without any account identifier attached.
- Watch Together rooms are a live relay only: room codes, playback position, display names, and chat lines pass through the server to the people in your room and are never written to disk — a room ceases to exist the moment the last person leaves. If you choose to make a room public, its show title, episode, and viewer count are shown in the live lobby for as long as it's open; private rooms never appear anywhere.
- Episode downloads are streamed through the server from the source to you; nothing about what you download is recorded.
What we don't do
- No advertising, no trackers, no third-party analytics scripts
- No selling, sharing, or profiling of any data
- No cookies beyond the strictly-required session cookie for signed-in accounts