AIMangaMaker
Home Login

Legal Documents

Impressum Terms of Service Privacy Policy Content Policy Copyright & DMCA Cancel contracts here (Verträge hier kündigen)

Last Updated:
September 26, 2026

Effective Date:
September 26, 2026

Privacy Policy

This Privacy Policy explains how we process personal data when you use AIMangaMaker: the website aimangamaker.com, our reader and creation tools, our API and apps that use it, and AI assistants you connect to your account. It fulfils our information obligations under Articles 13 and 14 of the EU General Data Protection Regulation (GDPR).

In short

  • We use your data to run your account, create content with AI on your behalf, process payments and keep the platform safe.
  • We show no advertising, use no analytics or tracking tools and do not sell your data.
  • We only use cookies and browser storage that the site needs to work, so there is no cookie banner.
  • To generate content, your prompts and images are sent to the AI provider of the model you use. Payments are handled by Stripe.
  • You can access, correct, export or delete your data at any time; write to contact@aimangamaker.com.

Table of Contents

  1. Controller and contact
  2. Purposes and legal bases at a glance
  3. Visiting our website
  4. Cookies and browser storage
  5. Your account
  6. Creating content with AI
  7. Content moderation and safety
  8. Public content, profiles and social features
  9. Payments, subscriptions and invoices
  10. Cancellations
  11. E-mails and newsletter
  12. Referral program and invitations
  13. Collaboration and creator earnings
  14. Reports and copyright notices
  15. Connected AI assistants and apps
  16. Recipients and processors
  17. Transfers outside the EU/EEA
  18. Storage periods
  19. Automated decisions
  20. Your rights
  21. Children and young people
  22. Security
  23. Changes to this policy

1. Controller and contact

The controller responsible for the processing of your personal data is:

Armend Meholli (AIMangaMaker)
Georgstr. 10A
31675 Bückeburg
Germany
Email: contact@aimangamaker.com

We have not appointed a data protection officer because we are not legally required to do so (Art. 37 GDPR, § 38 BDSG). Please send all privacy questions and requests to the e-mail address above.

2. Purposes and legal bases at a glance

PurposeLegal basis (GDPR)
Delivering the website, stability and protection against attacksArt. 6(1)(f) - legitimate interest in a secure, working website
Your account, the creation tools, AI generation, subscriptions and purchasesArt. 6(1)(b) - performance of the contract with you
Invoices, bookkeeping, proof of cancellations and consentsArt. 6(1)(c) - legal obligations (tax, commercial and consumer law)
Moderation, fraud prevention, enforcing our terms, defending legal claimsArt. 6(1)(f) - legitimate interest in a lawful, safe platform; Art. 6(1)(c) where the law requires it
NewsletterArt. 6(1)(a) - your consent

Where we rely on legitimate interests, the interests are named in the relevant section below. You can object to such processing (see Your rights).

3. Visiting our website

3.1 Hosting and server log files

Our website, database and e-mail system are hosted by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany, on servers in Germany. STRATO processes data on our behalf under a data processing agreement (Art. 28 GDPR).

Each time you open a page, the web server records your IP address, the date and time, the page or file requested, the HTTP status code, the amount of data transferred, the referring page and your browser and operating system (user agent). We need this to deliver the website, to keep it stable and to detect and defend against attacks (Art. 6(1)(f) GDPR). The log files are deleted after 14 days at the latest, unless a specific incident has to be investigated.

3.2 Images from our content delivery network

Images such as covers, pages and profile pictures are stored with and delivered by bunny.net (BunnyWay d.o.o., Slovenia, EU), with storage in Germany. When your browser loads such an image, bunny.net processes your IP address and the request data to deliver it. bunny.net acts as our processor under a data processing agreement (Art. 28 GDPR). We use it because it makes the site fast and reliable worldwide (Art. 6(1)(f) GDPR) and, for your own uploads and creations, to perform our contract with you (Art. 6(1)(b) GDPR).

3.3 No third-party code

All fonts, icons and scripts are served from our own server. We do not embed analytics, advertising, social media plug-ins or other third-party tracking. Share buttons are plain links; data only reaches the social network if you click one.

3.4 Protection against abuse

To prevent attacks and automated misuse, we limit how often certain actions can be performed. For this we briefly store your IP address or user ID together with the action (deleted after 24 hours), and we record login attempts with IP address (deleted after 90 days at the latest) to block password-guessing attacks and to detect abuse of the referral program (see section 12). The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the security of the platform and of your account and the prevention of fraud.

3.5 View counts

We count a view of a project, chapter or page only once per visitor and day. If your browser keeps our session cookie, this is noted in your session. For visitors whose browser does not send the cookie back (for example automated clients), we store for that day an empty marker whose name is a keyed hash of the IP address, the browser identification and the item; the IP address itself is not stored and nothing is written to our database. The key changes every day and is deleted together with that day's markers on the following day. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is view counts that cannot be inflated automatically.

4. Cookies and browser storage

We do not use cookies or similar technologies for analytics, advertising or tracking. We only store information on your device, or read it from there, where this is strictly necessary to provide the service you have requested (§ 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG). No consent is required for this, which is why we do not show a cookie banner. The processing of the associated data is based on Art. 6(1)(b) and (f) GDPR.

NameTypePurposeDuration
AIMANGA_SESSION Cookie (our own) Keeps you logged in, protects forms against cross-site request forgery and remembers the page language during your visit Until you close the browser. If you tick "Remember me" when you log in: 30 days, so you stay logged in. Removed when you log out
readerSettings, novel_reader_settings Local storage Reader settings you choose (theme, reading mode, font size, line spacing) Until you delete them in your browser
reading_progress_<chapter> Local storage Where you stopped reading a novel chapter, so you can continue there Until you delete it in your browser
language, reader_language_pref Local storage The interface or content language you pick Until you delete it in your browser
Editor data (logged-in users) Local and session storage Backup copies of unsaved drafts, the chat with the project assistant, editor layout and view settings Session storage: until you close the tab. Assistant chat: 7 days. Drafts: until saved. Other: until you delete them

Browser storage stays on your device and is not sent to us automatically. You can delete cookies and stored site data at any time in your browser settings. If you block the session cookie, you cannot log in or submit forms.

5. Your account

5.1 Registration and login

To create an account we need a username, your e-mail address, a password and your date of birth. We store the password only as a secure hash. We use the date of birth to check that you meet the minimum age (see Children and young people). We confirm your e-mail address with a link; the sending and confirmation are logged together with IP address and browser (deleted after 90 days). If you enable two-factor authentication, we send a one-time code by e-mail (valid for 10 minutes, stored only as a hash); the e-mail names the IP address and browser of the login attempt so you can recognise misuse. If you change your e-mail address in your account settings, we ask for your current password, send a confirmation link to the new address and inform your current address about the request. Until you confirm, your account keeps its current address. For this we store the new address and a hash of the confirmation link, and delete them when you confirm, when you request another change, or after the link has expired (24 hours). Your newsletter subscriptions then move to the new address (see section 11). The legal basis is Art. 6(1)(b) GDPR, and for the security measures Art. 6(1)(f) GDPR.

5.2 Profile and settings

You can add a profile picture, a header image and a bio, choose your language and set notification preferences. Your profile is public by default; you can make it private in your account settings.

5.3 Billing information

If you fill in the billing page, we store your name, company, VAT ID, address and phone number and use them for the invoices and credit notes we issue to you (Art. 6(1)(b) and (c) GDPR).

5.4 Your own AI provider keys

On eligible plans you can store API keys for your own AI provider accounts. They are stored encrypted (AES-256-GCM) and used only to send your requests to that provider on your behalf.

5.5 API and app logins

When you log in through our API, for example from an app, we issue access tokens. For refresh tokens we store the device information (operating system and IP address) until the token expires. For access tokens, a hash of your IP address and browser is embedded in the token itself to prevent token theft.

5.6 Reading features

When you are logged in, we store your reading progress (to offer "continue reading"), your ratings and comments, and your personal list of saved works.

5.7 Downloading your data and deleting your account

In your account settings (section "Your data") you can download a copy of your personal data and content at any time as a JSON file, and you can delete your account yourself. You can also ask us to do either by writing to contact@aimangamaker.com.

When you delete your account, an active subscription ends immediately (you are not charged again), your remaining credits lapse, and we remove your personal data: your profile and settings, posts, comments, ratings, lists, notifications, stored keys and newsletter subscriptions are deleted at once, and your projects are deleted permanently within 30 days. We only keep what the law requires or what is needed to defend legal claims - for example invoices and payment records, the proof of a cancellation, and records of copyright notices - for the periods listed under Storage periods, linked to an anonymised account. Promotional materials that already feature your public content may remain (see section 6.4 of our Terms). Projects you delete yourself are kept in the bin for 30 days so that you can restore them, and are then deleted permanently.

6. Creating content with AI

When you use an AI feature (text, images, character and location views, the project assistant and similar tools), we send your prompt, the project information the request needs (for example story text, character or location descriptions) and any reference, base or mask images to the AI provider of the model being used. The model is chosen by you in your AI settings or set as the default for the feature. The provider returns the result to us, and we store it in your project. Depending on the model, the provider is OpenAI, Anthropic, Google or BytePlus (see Recipients).

We only use AI providers that process these requests as our processors under a data processing agreement and do not use their content to train their models. To detect misuse, OpenAI and Anthropic keep requests for up to 30 days and Google for 55 days before deleting them; requests flagged for misuse can be kept longer (Anthropic up to 2 years, BytePlus 180 days).

We do not add your e-mail address or payment data to these requests. Please do not enter personal data of other people into prompts unless you are allowed to do so. The legal basis is Art. 6(1)(b) GDPR: generating content is the service you ask us for.

For each AI request we record the provider, model, feature, the length of the prompt and answer, the tokens and the credits used, but not the content itself. We need this to charge credits and to control costs (Art. 6(1)(b) and (f) GDPR; deleted after 2 years).

If you use your own API key, the request is sent to the provider under your own account, and your agreement with that provider applies to its processing.

7. Content moderation and safety

Before an AI generation request is carried out, we check the prompt and any images for prohibited content, in particular sexual content involving minors. We use OpenAI's moderation service for this (also when you use your own API key) together with our own keyword filters. For requests that are flagged or blocked, we store the result scores, the first 500 characters of the prompt or the image address and the provider's response in a moderation log (deleted after 1 year) so that we can review cases and act on repeated violations. Warnings, strikes, suspensions and bans from these checks are kept for as long as your account exists (for copyright strikes see section 14).

The legal basis is Art. 6(1)(f) GDPR; our legitimate interests are preventing illegal content, protecting minors and third parties and enforcing our terms. Where the law obliges us to act, for example under the EU Digital Services Act, the legal basis is Art. 6(1)(c) GDPR.

8. Public content, profiles and social features

Anything you publish is visible to everyone on the internet, including search engines. This covers published projects, chapters and pages, ratings, comments, posts, likes and follows, and your public profile (username, profile picture, bio and published works). Public profiles and works are listed in our sitemap for search engines. Projects stay private until you publish them. You can make your profile private, and your personal list of saved works is private by default.

If you mention or follow someone, comment on their work or interact with their posts, they are notified. We delete read notifications after 90 days. The legal basis is Art. 6(1)(b) GDPR.

9. Payments, subscriptions and invoices

Payments are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland ("Stripe"). You enter your payment details and billing address directly on Stripe's checkout page; we never receive your full card or account details.

We send Stripe your e-mail address, your username, your user ID, the product you buy and, when you cancel a subscription, the reason you give. Stripe tells us the payment status, the amount, the tax, the country of your billing address, the IDs of the customer, payment and subscription, and a fingerprint of the payment method (a code that recognises the same card or account without revealing it, used against referral fraud, see section 12). We also store the time and wording of your consent to the immediate start of the service (see the withdrawal policy in our Terms) as proof. Stripe additionally processes data as an independent controller for its own purposes, for example to prevent fraud and to meet financial regulations; see stripe.com/privacy. Stripe may transfer data to Stripe, Inc. in the USA (see Transfers).

We keep a record of your subscriptions, purchases, credit transactions and invoices. Payment events are logged together with IP address and browser to prevent fraud and to deal with disputed payments (deleted after 1 year). Stripe sends us notifications about payments; we keep their contents for 90 days and afterwards only an event ID that prevents a payment from being processed twice. Invoices and other accounting records are kept for the periods required by commercial and tax law (up to 10 years, § 147 AO, § 257 HGB).

If you dispute a payment with your bank, Stripe informs us and provides the dispute details (see Automated decisions).

The legal bases are Art. 6(1)(b) GDPR (contract), Art. 6(1)(c) GDPR (retention obligations) and Art. 6(1)(f) GDPR (preventing fraud and defending legal claims).

10. Cancellations

If you cancel a contract on our page Cancel contracts here, we process the details you enter (name, e-mail address, optionally username and contract reference, type of cancellation, reason and requested end date), the time of receipt, your IP address, browser and language. We use them to carry out the cancellation, to send you the confirmation the law requires (§ 312k BGB) and to be able to prove that your cancellation was received. We keep this record for three years after the end of the year in which it was received. The legal bases are Art. 6(1)(b) and (c) GDPR.

11. E-mails and newsletter

We send you e-mails that belong to the service: address confirmation, security codes, password resets, notices about a requested change of your e-mail address, order and cancellation confirmations and notifications according to your settings (Art. 6(1)(b) and (f) GDPR). They are sent through our e-mail provider STRATO in Germany. Our e-mails contain no tracking pixels and no click tracking.

We may also send you service messages about the platform or your account, for example about changes to our terms, security notices or outages. They contain no advertising (Art. 6(1)(b) and (f) GDPR); you can switch off system e-mails in your notification settings.

We only send our newsletter if you have subscribed to it, for example with the checkbox at registration or in your notification settings, and confirmed the subscription (Art. 6(1)(a) GDPR). After you subscribe, we send you an e-mail with a confirmation link; only when you confirm with it do we start sending the newsletter (double opt-in). We store your e-mail address, the time and source of the request, and the time and IP address of the confirmation as proof of your consent. If you change your account's e-mail address, your subscriptions move to the new, confirmed address; the record of your original consent stays unchanged. Every newsletter contains a link to unsubscribe from all newsletters; you can also unsubscribe in your notification settings or by writing to contact@aimangamaker.com. Unsubscribing does not affect the lawfulness of the e-mails sent before. Requests that are never confirmed are deleted after 30 days; the record of a confirmed consent is kept for 3 years after you unsubscribe so that we can prove it.

12. Referral program and invitations

Every account has a referral code and link that you can share yourself; we do not send invitation e-mails. If someone registers through your link, we store the link between the two accounts and the new user's IP address at registration. When the referred user buys credits, a bonus is credited to you; it is held for 30 days and reversed if the purchase is refunded or charged back.

To prevent self-referrals, we compare the referred user's registration IP address and the fingerprint of the payment method used for a purchase (provided by Stripe) with the IP addresses of your recent successful logins and with the payment methods of your own purchases and those saved with Stripe. If they match, a person reviews the case, and your bonuses are held until the review is finished. The legal bases are Art. 6(1)(b) GDPR (referral program) and Art. 6(1)(f) GDPR; our legitimate interest is preventing fraud.

As the person who referred someone, you see only their username, the date they joined and the status of your bonus (none, on hold, paid out), plus your totals. You do not see their plan, their purchases or the amounts they spent. The registration IP addresses and payment-method fingerprints are deleted after 12 months; referrals that are never completed are deleted after 30 days, and reviewed fraud alerts 180 days after the review.

13. Collaboration and creator earnings

If you invite someone to work on a project, we send an invitation to the e-mail address you enter. The usernames and e-mail addresses of a project's collaborators are visible to the other editors of that project.

If a reader buys a premium chapter, the creator is credited with a share of the price and sees the buyer's username in the earnings overview and notifications. The legal basis is Art. 6(1)(b) GDPR.

14. Reports and copyright notices

If you report content or a profile, we process your account, the reported item, the reason and your description to review the report. If you submit a copyright notice, we process the details you provide (name, e-mail, phone, address, company, description of the work and the infringement, evidence, statements, signature and attached files). As part of the notice-and-counter-notice procedure, we pass the notice, including your contact details, to the user whose content is affected, and we pass a counter-notice, including its contact details, to the person who submitted the notice. We keep these records for three years after the case is closed - when the notice is rejected, when the content is restored, when a court case about it ends, when the affected user accepts the notice, or, if no counter-notice is filed, 30 days after the content was removed (a later counter-notice re-opens the case). A copyright strike recorded against an account because of a notice is deleted together with the case record, so it expires three years after the case is closed. The legal bases are Art. 6(1)(c) GDPR (obligations to handle notices, e.g. under the Digital Services Act) and Art. 6(1)(f) GDPR (handling and defending legal claims).

15. Connected AI assistants and apps

On eligible plans you can connect AI assistants such as Claude or ChatGPT to your account (via OAuth and the Model Context Protocol). We store which app you connected, its return address, the permissions you granted and when. A connected assistant can read and change your projects through our interface. What it retrieves is processed by the provider of that assistant under your own agreement with that provider. You decide what to connect, and you can revoke access at any time on the page "Connected apps". The legal basis is Art. 6(1)(b) GDPR.

16. Recipients and processors

We only share personal data where this is necessary for the purposes described above. Processors act on our instructions under data processing agreements (Art. 28 GDPR).

RecipientLocationPurpose
STRATO GmbH (processor)GermanyHosting, database, e-mail delivery
bunny.net - BunnyWay d.o.o. (processor)Slovenia (EU), storage in GermanyStoring and delivering images
Stripe Payments Europe, Ltd. (processor and independent controller)Ireland; Stripe, Inc. in the USAPayment processing, fraud prevention
OpenAI Ireland Ltd. (processor)Ireland; OpenAI's US company processes the requests in the USAText and image generation, content moderation
Anthropic Ireland, Limited (processor)Ireland; Anthropic's US company processes the requests in the USAText generation
Google Cloud EMEA Limited (processor, Gemini API)Ireland; Google LLC in the USA and other countriesText and image generation
BytePlus Pte. Ltd. (processor)Singapore; processing in Malaysia, Indonesia or the EUImage generation (Seedream models)

Content you publish can be seen by other users and the public. Other users also receive the data described in the sections on referrals, collaboration, creator earnings and copyright notices. We disclose data to authorities, courts or our tax advisor where the law requires it or where it is necessary to establish or defend legal claims.

17. Transfers outside the EU/EEA

Some recipients process data outside the European Union and the European Economic Area, in particular in the USA and, for BytePlus, in Singapore, Malaysia and Indonesia. For recipients in the USA that are certified under the EU-U.S. Data Privacy Framework, such as Google, the transfer is based on the European Commission's adequacy decision (Art. 45 GDPR). Otherwise - in particular for OpenAI, Anthropic and BytePlus - the transfer is based on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR), which are part of the providers' data processing agreements. You can request a copy of these safeguards from us.

18. Storage periods

We delete personal data as soon as it is no longer needed for the purpose it was collected for, unless the law requires us to keep it longer. Specifically:

DataDeleted
Server log filesafter 14 days at the latest
Rate-limiting records (IP address or user ID)after 24 hours
View-count markers (keyed hash, no IP address)on the following day
Session datawhen the browser is closed; with "Remember me": 30 days after the last activity
Login attempts (with IP address)after 90 days
Two-factor codeswhen they expire (10 minutes)
Password reset requestsafter 30 days
E-mail confirmation logafter 90 days
Pending change of your e-mail address (new address, hash of the confirmation link)when you confirm it or request another change; otherwise after the link has expired (24 hours)
Read notificationsafter 90 days
Contents of payment notifications from Stripeafter 90 days
Payment event log (with IP address and browser)after 1 year
Moderation logafter 1 year
AI usage statistics (no content)after 2 years
Application log filesafter 30 days
Account, profile and contentwhen you delete your account (deleted projects stay in the bin for 30 days)
Unconfirmed newsletter requestsafter 30 days
Newsletter consent record (confirmation time and IP address)3 years after you unsubscribe
Referral registration IP addresses and payment-method fingerprintsafter 12 months
Uncompleted referrals / reviewed fraud alertsafter 30 days / 180 days after the review
Cancellation records3 years after the end of the year of receipt
Copyright notices and counter-notices, and the copyright strikes they led to3 years after the case is closed
Invoices and accounting recordsafter the statutory retention period (up to 10 years)

19. Automated decisions

We do not make decisions based solely on automated processing that have legal effects on you or affect you similarly significantly, with two exceptions that are necessary to perform our contract with you (Art. 22(2)(a) GDPR):

  • Moderation: an AI generation request that our moderation check flags as prohibited content is refused automatically.
  • Disputed payments: if you dispute a payment with your bank, your account is suspended automatically until the case is resolved.

In both cases you can contact us to have a person review the decision, to express your point of view and to contest the decision. In the referral program, a match of IP addresses or payment methods only holds the bonus until a person has reviewed the case.

20. Your rights

You have the right to:

  • access the personal data we hold about you (Art. 15 GDPR),
  • have incorrect data corrected (Art. 16 GDPR),
  • have your data deleted (Art. 17 GDPR),
  • have the processing restricted (Art. 18 GDPR),
  • receive the data you provided to us in a structured, commonly used, machine-readable format (data portability, Art. 20 GDPR),
  • withdraw a consent at any time with effect for the future (Art. 7(3) GDPR).

You can download your data and delete your account yourself in your account settings (see section 5.7). For everything else, or if you prefer, write to contact@aimangamaker.com. We answer within one month and may ask you to confirm your identity first.

Right to object (Art. 21 GDPR)

Where we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to this processing at any time on grounds relating to your particular situation. We will then stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims. You can object to the use of your data for direct marketing, such as the newsletter, at any time without giving reasons.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live or work or where the alleged infringement took place (Art. 77 GDPR). The authority responsible for us is: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany.

21. Children and young people

Our service is not directed at children. According to our Terms of Service, you must be at least 16 years old to use the platform and at least 18 years old to create an account and content. We ask for your date of birth at registration. If we learn that an account belongs to someone below the minimum age, we delete it.

22. Security

We protect your data with technical and organisational measures that match the risk, including encrypted connections (TLS), passwords stored only as secure hashes, encrypted storage of your own API keys, protection against automated attacks and restricted administrative access. Providing your data is voluntary, but without the data needed for an account or a purchase we cannot provide these services.

23. Changes to this policy

We update this Privacy Policy when our services or the law change. The current version is always available on this page; the date of the last update is shown below.

Last Updated: September 26, 2026

Effective Date: September 26, 2026