Privacy Policy

プライバシーポリシー · How we handle your data

Last updated: April 2026

Your privacy matters to us. This policy explains what information we collect, how we use it, and what rights you have. OshiDoki keeps data collection to an absolute minimum.

Information we collect

OshiDoki is a fan-made website. You can browse all content without creating an account.

If you create an account, we store your email address, display name, and a securely hashed version of your password. We also store any follows, oshi picks, bookmarks, and live-attendance marks you add while logged in. Your raw password is never stored or readable — only a one-way hash.

When you use our contact form, we collect your name, email address, and message content to respond to your inquiry. If you are logged in when you submit, the message is linked to your account internally.

We run our own privacy-first analytics. Every page visit records the URL path, locale, referrer domain, country (derived server-side from your IP address — the IP itself is never stored), device type (mobile/desktop), and an anonymous daily session identifier. This identifier is a one-way hash of your IP, browser type, and the current date; it resets every midnight and cannot identify you personally or across sessions.

Cookies & tracking

We use a small number of cookies strictly necessary for the site to function:

• Cookie consent preference — remembers whether you accepted or declined. • Session cookie (user_token) — set when you log in to an account. This is an httpOnly, secure cookie that expires after 30 days. It is used solely to keep you logged in and is never shared with third parties.

We do not use advertising cookies or cross-site tracking cookies of our own.

For logged-out visitors, we use browser localStorage (not cookies) to remember follows, bookmarks, and read articles. This data stays entirely on your device, is never sent to our servers, and is cleared when you clear your browser storage.

Third-party embedded content (YouTube, Spotify, Instagram, X/Twitter) may set their own cookies when you interact with embedded players. These are governed by the respective platform's privacy policies.

This site may display advertisements and participate in affiliate programmes (such as Amazon Associates). Partner networks may use cookies or similar tracking technologies when ads or affiliate links are present. You can manage these through your browser or device settings.

How we use your data

Information we collect is used for the following purposes:

• Account management — your email and display name are used to operate your account, send verification and password-reset emails, and respond to account-related requests. • Site analytics — anonymous page-view data is used to understand how the site is used and improve its content and performance. This data is not sold or shared with third parties. • Security — IP addresses are used server-side only to enforce rate limits on login attempts and contact form submissions. They are never stored in our database. • Contact form — your name, email, and message are used solely to respond to your inquiry.

We do not sell your personal data. Affiliate links may earn us a small commission at no extra cost to you. We only link to products and services we consider relevant to our audience.

Your rights

You have the right to access, correct, or delete any personal data we hold about you.

If you have an account, you can update your display name and delete your account entirely from your account settings page. Deleting your account permanently removes your email address, display name, follows, oshi picks, bookmarks, and all other associated data from our database.

If you do not have an account or need further assistance, contact us through our contact page and we will respond within 30 days.

If you are located in the European Economic Area (EEA), you have additional rights under the GDPR, including the right to data portability and the right to lodge a complaint with your local data protection authority.

Third-party services

Our site may contain links to external websites and embedded content from platforms like YouTube, Spotify, Instagram, X, and other social media networks. We are not responsible for the privacy practices of these external services.

We recommend reviewing the privacy policies of any third-party service you interact with through our site.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal and regulatory reasons. Any changes will be posted on this page with an updated revision date.

We encourage you to review this page periodically. Continued use of the site after changes constitutes acceptance of the updated policy.

Questions?

If you have any questions about this Privacy Policy, please reach out via our Contact page