Privacy Policy

Anime Maps (hereinafter “AnimeMaps,” “we,” or “us”) manages the information handled through its website and mobile app in accordance with this Privacy Policy.

Last updated: 2026-10-04

1. Operator and Contact Information

Service name: Anime Maps
Contact: animemapsx@gmail.com

2. Information We Collect and Store

  • Account information: email address, login ID, display name, profile, bio, avatar, and language, time zone, and display settings
  • Usage information: favorites, dates and categories in your personal calendar, private notes, and viewing history
  • Community information: ratings, reviews, replies, likes, reports, and inquiries along with responses from our team
  • Community (message board) feature information: the names, descriptions, and tags of communities, the titles and text of threads, and the text of comments and what each comment replies to, as created in the “Community” tab, along with the language and the creation and update times of each item. We also store records of which replies to your threads and comments you have read (private information used only to show your own unread indicators), records of accepted submissions that prevent resends and duplicate posts (the request ID, the type of action, a SHA-256 hash of the submitted content, and the ID of the processed item and the time it was accepted, but not the text itself), and message board reports (the reporter’s ID, the reported item, the reason category, and the processing status).
  • X/Instagram sharing information: the original URL of a shared post, the shared text, and a snapshot of candidate events at the time of matching. We store this information in share submission records to match posts with events, confirm the candidate you selected, and allow our team to follow up on posts that could not be matched.
  • Technical information: app version, OS, language, authentication sessions, connection information transformed for abuse prevention, and access logs generated by servers and similar systems
  • Location information: your latitude and longitude when you use “My Map (Nearby Events).” While you are logged in, they are sent to our API to return search results and are also included in the API response. The feature is not designed to save coordinates to your account, but they may be recorded temporarily during response processing or in security logs. In addition, to manage the daily search limit on the free plan, we store the dates and number of your searches (including an identifier for each search) in your account for up to 30 days. To match resent requests, we retain a matching value (a keyed HMAC) created with a server-side secret key from your search conditions (user, date, latitude and longitude rounded to four decimal places, and radius) only for the rest of that day. We do not store the coordinates themselves, but this matching value is pseudonymized information that can be checked against search conditions by using the key. You can revoke location permission in your device settings.

Purchase and subscription information: When you make or restore a purchase through the Apple App Store or Google Play, we send RevenueCat a random billing customer ID issued by AnimeMaps that does not contain your email address. AnimeMaps obtains from RevenueCat your verified entitlements, product ID, store, production/sandbox environment, purchase, expiration, and grace-period dates, renewal status, and management URL, and stores them together with the time of the last verification. To prevent the same purchase from being granted to multiple AnimeMaps accounts, we store a one-way HMAC fingerprint created from the store transaction identifier using a server-side secret key. We do not store raw store transaction identifiers, receipts, purchase tokens, card numbers, or webhook bodies in the AnimeMaps account database. For webhooks, we store only what is needed to prevent duplicate deliveries: the event ID, type, environment, product ID, pseudonymous billing customer ID, SHA-256 hash of the payload, and processing status. Payments themselves and payment records are processed by Apple, Google, and RevenueCat under their respective terms.

Advertising and consent: The app updates consent information using the Google User Messaging Platform (UMP) and requests ads through the Google Mobile Ads SDK (AdMob) only if the UMP result permits it and, in regions where it is required, only after you have completed the consent and privacy choices screen. The initial version requests only non-personalized ads. When ads are requested and displayed, Google may process your IP address, device and app identifiers and settings, OS, language, approximate location inferred from your IP address, and interaction information such as ad impressions and clicks for the purposes of ad delivery, fraud prevention, and measurement. AnimeMaps does not intentionally send your account email address, favorites, private notes, purchase details, or precise location as ad-targeting information. You can change the available consent and privacy choices from the corresponding screen in the app. While Premium is active, the app does not send ad requests. Processing by Google is subject to Google’s terms and privacy policy.

AnimeMaps profiles are public. When you create or edit your profile, your user ID, display name, selected avatar, the bio you entered, and your membership tier (Free or Premium) can be viewed by other users through a profile API that does not require authentication. Your public profile does not include product IDs, the store of purchase, prices, purchase dates, renewal dates, or expiration dates. Entering a bio is optional, but anything you enter will be public. For published reviews and replies, in addition to the text, the author’s user ID, display name, and avatar are shown even to people who are not logged in, and the author’s profile can be opened from their icon or name (the bio is not included in the review author information itself). The profile of a suspended member is not shown. Comments and replies by a suspended member are shown with the author as “Deleted user” and the body as “This post has been deleted.” (they are only hidden and return when the suspension is lifted). Comments and replies by a member who deleted their account have their body and author association erased and may remain in other members’ conversations with the same display. There is no setting to make your profile private. Please do not enter any personal or confidential information that you do not want made public in your profile, reviews, or replies.

Communities (name, description, and tags), threads (title and text), and comments (text and what they reply to) that you publish through the Community (message board) feature can be viewed through a public API, even by people who are not logged in, together with the creator’s user ID, display name, and avatar (for staff accounts, an indication that the account belongs to our team). If the author is suspended or has deleted their account, the author is shown as “Deleted user” and the descriptions, bodies and comments they wrote are shown as “This post has been deleted.” (for a suspension they are only hidden and return when it is lifted). Community names and tags and thread titles stay public together with other members’ posts. However, if the account was deleted without confirming on the account deletion screen that these names, tags and titles remain (a deletion from an older app version that does not ask for this confirmation, or a deletion by an operator), community names and tags and thread titles are erased as well, those communities and threads are no longer public, including other members’ posts in them, and the author’s comments are no longer shown. Please do not enter any personal or confidential information that you do not want made public. If a community, tag, thread, or comment contains a URL, the submission is not accepted or stored.

To prevent spam in reviews and replies, we process posting frequency, user and event identifiers, an HMAC fingerprint of the text generated with a secret key, features such as the number of URLs and repeated characters, assessment scores and reason codes, status (published, pending review, or rejected), a request_id to prevent duplicate posts, the number of times an administrator has confirmed your posts as spam, and posting suspension end times. We do not store raw IP addresses in the dedicated spam assessment records; instead, for rate limiting we use HMAC identifiers, generated with a secret key, that change every day. These HMAC identifiers do not reveal the original IP address or text, but they are pseudonymized information that can link submissions from the same source or with the same text during the retention period. Separately, raw IP addresses may be recorded in web/CDN access logs or security logs.

Any review or reply that contains even a single URL is automatically rejected. Rejected text is not published and is not sent for translation.

3. Purposes of Use

We use information to provide the service, authenticate users, personalize what you see, sync favorites, calendars, and other data, operate the review and Community (message board) features and counter abuse, respond to inquiries, translate content, investigate outages and errors, and improve quality and safety. Spam assessment is performed on the AnimeMaps WordPress server and within the account database, and we do not send text or assessment metadata to any additional external spam-detection service for this purpose. Posts that are rejected outright and posts pending review are not sent to Google Apps Script or Google LanguageApp; a pending post is added to the translation queue described in Section 4 only after an administrator approves and publishes it.

4. Automatic Translation of Reviews and Community (Message Board) Content Using Google

The full text of a review or reply, the source and target languages, a hash of the original text, a single-use nonce, the time of issue, a pseudonymized request identifier, and a signature are sent from the AnimeMaps WordPress server to a Google Apps Script managed by AnimeMaps and translated with Google LanguageApp. For the Community (message board) feature, community names and descriptions, thread titles and text, and comment text are also translated in the same way: the full text of each item is sent after it is published or edited (tags are not sent). We do not attach your account email address, user ID, display name, favorites, private notes, or current location to translation requests as separate fields. However, if you write your name, email address, or other personal information in the text of a review or reply that you publish, that information will be sent to Google as part of the text. Likewise, any personal information you write in message board titles, text, or other fields is sent to Google as part of the full text. Please do not enter personal or confidential information in publicly posted text. Google’s handling of this information is subject to Google’s terms and privacy policy.

5. Translation Cache and Retention Periods

For as long as a review or reply remains, its original text and translation results are cached in our server database so they can be displayed without repeatedly sending the same text externally. When the text is edited, the old translation is no longer displayed. When a review or reply is deleted or hidden by our team, its active translation cache is deleted and its translation jobs are set to a canceled state. Separately, Google Apps Script (GAS) temporarily stores translation results in its Script Cache for up to approximately 6 hours, after which they expire automatically (they may expire sooner due to capacity limits or other factors). Even if a review or reply is deleted or hidden, this external temporary cache cannot be cleared immediately from the WordPress side and may remain until it expires. Technical metadata for completed and canceled jobs is normally deleted after 30 days, and diagnostic metadata for jobs confirmed as failed after 180 days, in both cases progressively in limited batches.

Translation results for the Community (message board) feature are likewise cached in our server database for as long as the original item remains, and after an item is edited, its old translations are no longer used for display. When a community, thread, or comment is deleted, or is hidden by our team, the translation cache and translation jobs for that item are deleted. The temporary storage in Script Cache described above applies to message board translations as well. Technical metadata for completed and canceled message board jobs (which does not include the text) is deleted progressively in limited batches after 30 days. Message board jobs confirmed as failed (which do not include the text) are not subject to deletion after 180 days. They are retried automatically once 7 days have passed since the failure was confirmed (except for certain errors for which retrying would not change the outcome); jobs that are then completed or canceled follow the 30-day rule above, and any other jobs confirmed as failed may remain until the original item is deleted or hidden or the account is deleted.

6. Private Notes

Private notes on favorites are returned only to your own authenticated screens and are not included in public profiles, events, reviews, calendar sharing, image sharing, or GAS translation. Notes are stored in our server database and backups and are not end-to-end encrypted. We may access them to the extent necessary for maintenance, security, troubleshooting, and responding to inquiries. Please do not enter passwords or other sensitive information. When you remove a favorite, its note is also deleted from the active database.

7. Calendar Share Links

When you share your calendar, we create a fixed snapshot that includes the selected month and categories, event names, your planned dates, event start and end dates, and event images. Anyone who knows the link can view it. A link can be viewed for up to 30 days from creation. Each user can have up to 20 active links; if you have reached this limit when creating a new link, your oldest active link may be deactivated before 30 days have passed. You can revoke links from the corresponding screen or through the authenticated API. If the option to revoke links is not shown in your current version of the app, please contact us at the address above. Please choose carefully whom you share links with. For active snapshots, the database row stores a hash of the link token (not the token itself), the owner’s user ID, and the snapshot. However, raw share links may be recorded in web/CDN access logs or security logs. Private notes are not included in snapshots.

My Calendar push notifications: If you choose to enable notifications about your plans for the next day, we store a random installation ID, the Expo push token currently in use and its hash, device type, IANA time zone, language, app version, notification settings, the target date and number of events, a pseudonymized fingerprint of the set of events, and the technical status of send jobs, tickets, receipts, and errors. When sending, we send the token, the public event name (for a single event) or the total count (for multiple events), the target date, and minimal navigation data (notification type and target date) to the Expo Push Service, which may pass them on to Apple’s or Google’s push infrastructure. Private notes are never included in notification jobs, logs, or external payloads. Turning notifications off erases all registered tokens, and unregistering a device or logging out deactivates that device and cancels any unsent notifications. Tokens are also deactivated if the authentication session used for registration is revoked or expires. Tokens reported as DeviceNotRegistered are also deactivated immediately. Inactive device rows and technical metadata for completed, failed, or canceled items are normally deleted progressively starting after 30 days. We normally begin checking receipts about 15 minutes after sending and treat a receipt as expired if it still cannot be retrieved after 24 hours. Backups expire through normal rotation, and authorized staff can access this data to the extent necessary for maintenance, safety, troubleshooting, or support.

The app keeps a random unregistration secret on your device, which is used to unregister the device when you log out. When you log out, the app sends the installation ID and this secret to AnimeMaps to request unregistration. Our server processes the secret for verification but stores only a one-way HMAC hash of it, not the raw secret. This HMAC hash is normally kept in the inactive device row for up to 30 days to confirm the completion of delayed unregistration requests.

A receipt status of “ok” only indicates a successful handoff to the push infrastructure; it does not guarantee that the notification is received or displayed on the device.

8. Retention, Deletion, and Backups

We retain account information for as long as necessary to maintain your account, and each type of usage information for as long as necessary to provide features and operate the service safely. When you use a deletion feature, the relevant information is deleted from the active service database, or its text is erased. However, report reasons, details entered by the reporter, and a snapshot of the text at the time of the report may remain in audit records even after the original post has been deleted or hidden. We may also retain records necessary for security or legal compliance for a reasonable period. Data in backups is not erased immediately; it is erased progressively as backups rotate normally and may temporarily reappear if a backup is restored.

The billing customer mapping, verified entitlements, and purchase-owner HMACs held by AnimeMaps are retained for as long as needed to securely link accounts with purchase entitlements, and are deleted from the active database when your AnimeMaps account is deleted. If a billing customer mapping exists, we also request deletion of the corresponding customer profile at RevenueCat. Minimal technical records kept to detect duplicate webhooks are normally deleted progressively after 400 days, and the pseudonymous billing customer ID in those records is cleared when your account is deleted. However, purchase and transaction records retained by Apple, Google, or RevenueCat for legal, accounting, fraud-prevention, or other purposes are not deleted by this process, and store subscriptions are not automatically canceled. If you register again, you will be assigned a new billing customer ID, so automatic transfer or restoration of purchase entitlements to the new account is not guaranteed.

HMAC identifiers used for spam-prevention rate limiting logically expire on a daily basis and are normally deleted by an hourly cleanup within about 48 hours of logical expiration. Records that use request_id to prevent duplicate posts do not contain the text itself; they store the text’s HMAC fingerprint and assessment codes for up to 30 days. The text, score, and reasons for posts pending review are kept for up to 30 days for administrator review, and text that reaches this limit without being processed is erased. Upon approval, the score and reasons kept for moderation are erased; however, while the post remains published, the text’s HMAC fingerprint is kept with the post to prevent duplicate posts on the same event, and it is erased when you delete the post or our team hides it. When a pending post is approved or confirmed as spam, an audit record of the administrative decision and reason codes, which does not include the text, is kept for up to 365 days. When an administrator confirms a post as spam, the text, the post’s HMAC fingerprint, the score, and the reasons are erased immediately. The history of administrator spam confirmations (strikes) is kept for up to 365 days from the most recent confirmation. Posting suspensions (blocked_until) escalate in stages to 24 hours, 7 days, or 30 days, and are kept after the suspension ends only for as long as the strikes are retained. An immediate rejection by automated assessment alone does not add a strike. These retention periods exist to prevent abuse and to allow investigation of appeals and technical issues.

9. Service Providers, Third-Party Disclosure, and Staff Access

Providers of services such as hosting, email delivery, translation, and billing verification may process information to the extent necessary to provide the service. For in-app purchases, Apple, Google, and RevenueCat process payments and purchase status. We do not sell personal information.

We may disclose information with your consent, when required by law, or when reasonably necessary to protect life, safety, or the service. Authorized staff may access stored information to the extent necessary for service operation, maintenance, moderation, security, troubleshooting, responding to inquiries, or legal compliance. This includes reviewing the text, scores, and assessment reasons of posts pending review and either approving them for publication or confirming them as spam.

10. Security

We take reasonable measures such as access controls, encryption of communications, protection of authentication tokens, and separation of privileges. However, we cannot guarantee absolute security for data stored or transmitted over the internet.

11. Your Choices and Contacting Us

You can view, change, or delete your profile, history settings, posts, favorites, and other information from the corresponding screens in the app. You can delete your entire account, after identity verification, from “Account → Settings → Delete Account” in the app or from “/account-deletion/” on the website. Monthly and annual store subscriptions are not canceled automatically, so please cancel them through Apple or Google Play before deleting your account. For other requests regarding disclosure, correction, deletion, or your account, please contact us at the address above in a way that allows us to verify your identity.

12. Changes to This Policy

We may update this policy in response to changes in our features or how we handle information. We will announce material changes on the website or in the app.

13. Email Verification, Consent to Terms, User Reports, and Blocking

When you sign up, we send a 6-digit code to your email address. The database stores only the request ID, normalized email address, a one-way HMAC of the code, a 15-minute expiration, the resend time, and the attempt count (up to 5); the plaintext code and your password are not stored. Requests for completed registrations are normally deleted immediately. Used requests that remain because deletion failed, and expired requests that were never completed, are deleted by periodic cleanup in limited batches. Our email provider processes this information to the extent necessary for delivery.

Before you post user-generated content (UGC), we store your user ID, the current versions of the Terms of Service and Privacy Policy, and the time of your consent. For user reports, we store the reason, additional details, the display name and bio at the time of the report, related comments, the IDs of the reporter and the reported user, and the report status; authorized staff review reports in WordPress. When we receive a user report, a comment report or a Community forum report, we also email the report’s reason and details, for a user report the reported member’s display name and bio at the time of the report, for a comment or forum report the body or an excerpt of the reported post, and the reporter’s ID and the ID of the reported member or post to the operations mailbox (Google Gmail) for review. These emails are kept in the operations mailbox for as long as the operators need them for review and records. They are not deleted automatically from the operations mailbox when an account is deleted. For blocks, we store both users’ IDs and the time, and the blocked user’s profile, reviews, and replies are excluded from the blocking user’s authenticated views. When an account is deleted, its consents and blocks are deleted, and in reports that are retained, the reporter’s ID is anonymized and the reported user’s ID, the display name and bio, and related comments are erased. For a suspended member, a one-way HMAC of the email address and a partly masked email address are kept in the registration denylist, together with the member ID, the ID of the operator who suspended the account and the time, to prevent re-registration with the same mailbox, and are removed when the suspension is lifted (they remain after an account deletion made while suspended).

14. Storage Limits by Feature

Viewing history is limited to 200 entries per account and to 365 days from the last view; viewing the same event again moves it to the most recent position. You can delete your entire history from the app. My Calendar holds up to 500 entries. When the limit is reached, only past entries are deleted, oldest first; entries for today or future dates are never deleted automatically, so if no past entries can be removed, new entries are not accepted. X/Instagram share submissions are limited to 200; submissions pending review are protected, and resolved submissions are deleted after approximately 365 days and rejected submissions after approximately 90 days. Inquiries are limited to 100; inquiries in progress are protected, and answered or closed inquiries are deleted progressively starting 24 months later. You can block up to 500 users; existing blocks are not automatically removed because of this limit.

Expired or revoked authentication sessions are deleted progressively starting 30 days later. For announcements from our team, the latest 200 that have not ended or been withdrawn are delivered to members. Announcements without an end date remain displayed until newer announcements push them out of the 200-item window, and “mark all as read” also covers a maximum of 200 announcements. Read records for announcements that are no longer delivered because they have ended or been withdrawn are deleted progressively in limited batches starting 90 days later, and those for older announcements that have fallen out of the 200-item window may be deleted sooner. Announcement text and its six language versions may be retained on our side for auditing purposes.

Published reviews, replies, ratings, and likes, as well as purchase entitlements, consents to the terms, and records necessary for legal compliance or fraud prevention, are not automatically deleted solely because of count limits. Hidden text is, as a rule, erased after 30 days; records without text, such as those for deleted posts or spam, are deleted in limited batches 90 days or more after they are no longer referenced; and resolved or dismissed reports are deleted in limited batches after 2 years or more. For translation jobs, completed and canceled jobs are deleted in limited batches after 30 days or more, and diagnostic metadata for confirmed failures after 180 days or more. Backups follow normal rotation.

Each account can have a combined maximum of 50 profile reports and review reports awaiting confirmation by our team. When this limit is reached, existing pending reports are not automatically deleted, and new reports are not accepted. Reports that have already been processed are retained in accordance with the rules above.

Published communities, threads, and comments in the Community (message board) feature are not automatically deleted solely because of their number or how much time has passed. When you delete a community, thread, or comment, its name, description, title, and text are erased immediately, and its tags, translation cache, and translation jobs are deleted. A record without any text remains in order to preserve the reply structure. Items hidden by our team are not published, and their translation cache and translation jobs (and, for communities, their tags) are deleted when they are hidden; however, their names, descriptions, titles, and text are not erased automatically and may remain until our team deletes them or the account is deleted. Items inside a community or thread that has been deleted or hidden are not published, but their text and translation cache are not erased automatically and may remain until our team deletes them or the account is deleted. Records of accepted submissions are deleted 90 days after creation, and processed message board reports 90 days after processing, in both cases progressively in limited batches. Each account can have up to 50 message board reports awaiting confirmation by our team; once this limit is reached, new reports are not accepted. Records of which replies you have read are kept until your account, or the account of the user who posted the reply, is deleted. Account deletion deletes the body of the comments you wrote, the body of your threads and the description of your communities, together with their translation cache and translation jobs, and erases the author ID of each item. The names and tags of your public communities and the titles of your public threads (and their translations) are not erased: they stay public together with other members’ posts, with the creator shown as “Deleted user” and your erased comments shown as “This post has been deleted.” Reports about the communities and threads that remain this way are kept; reports about your other items are deleted. The names and titles of communities and threads that are not public are erased as well. However, if the account was deleted without confirming on the account deletion screen that these names, tags and titles remain (a deletion from an older app version that does not ask for this confirmation, or a deletion by an operator), the names and tags of your communities and the titles of your threads (and their translations) are erased as well and the reports about them are deleted; those communities and threads are then no longer public, including other members’ posts in them, and your comments are no longer shown. Your records of accepted submissions, the message board reports you made, and your read records are also deleted.

15. Inquiry Conversation History and Response Notifications

For inquiries, we store the inquiry ID, type, status, message text, follow-up replies, responses from our team, related event and report information, app build, OS, and language, timestamps of creation, updates, responses, and completion, the sender type and related user and staff IDs, an ID to prevent duplicate submissions, email notification status, attempt times, and minimal error codes, and a reference time indicating how far you have read in your inquiry history. Each message from you and from our staff is appended to the same inquiry without overwriting earlier messages or responses, and is kept as a history for handling the inquiry and keeping track of how it progressed. Authorized staff can view this history and respond in the WordPress admin dashboard.

When you submit a new inquiry or a follow-up reply, the notification email sent to our support contact includes the message text and inquiry details. If you choose to receive response notifications at your registered email address, the email sent when we respond only lets you know that a response is available in the app; it does not include the response text, and AnimeMaps does not set a reply-to address (Reply-To). Please send follow-up questions from “Inquiry History” in the app. Inquiries and messages in the account database are deleted when your account is deleted, but emails already sent and backups are not erased immediately and may remain in accordance with the provisions of this policy on retention, deletion, backups, and service providers. If a staff account is deleted, the response text is retained to preserve the conversation history, and the sender’s staff ID is anonymized.

The unread count is the number of messages from our team created after the reference time stored for each user. It is neither a read receipt for individual messages nor a read notification sent to our team. Marking an inquiry as “Completed” does not delete its history, and there is no feature for editing or deleting individual messages. To limit how often inquiries can be submitted, we create HMAC identifiers with a server-side secret key from your user ID or from range-based values derived from a valid IP address or similar data, and we do not store the original user ID or IP address directly in the rate-limiting rows. Rate-limiting rows logically expire when each fixed one-hour window ends, and old rows are deleted gradually in limited batches. Separately, raw IP addresses may be recorded in web/CDN access logs or security logs. A notification status of “accepted” only indicates that the sending process accepted the email; it does not guarantee actual delivery or display on a device or screen. Even if you choose not to receive response notifications (reply_requested=false), the notification emails informing our team of new inquiries or follow-up replies still include the message text.




↑(Click img above for hotel reservations)
This is the biggest and the most popular travel company in Japan!! You can reserve hotel at reasonable price!! There are English, Thai, Korean and Chinese version for Rakuten!! You can switch it from language. If you're using Smartphone, change website to PC version and switch the language to your language. To stay in Japan, Japanese site is always the cheapest.