Privacy Policy
Last updated: June 2026
1. Data Controller
FIComics is operated as a personal project. The data controller can be reached via the contact information provided at the bottom of this page.
2. Data We Collect
When you create an account or use the site, we collect:
- Account data: email address and display name (optional). Passwords are stored as bcrypt hashes and never visible in plain text.
- Session data: login sessions tracked for authentication. No personal browsing history is recorded.
- Feedback: messages you submit via the feedback form, including category, subject, and optional related URL.
- Analytics: this site uses self-hosted, in-house analytics (Umami) to measure page views and basic visitor statistics (browser, device, screen size, language, country, referrer) for site improvement. Data is aggregated, stored on our own server, and not shared with any third party. No Google Analytics, Facebook pixels, or other third-party trackers are used.
3. Cookies
We use a single httpOnly cookie for authentication (JWT refresh token). This cookie is not accessible to JavaScript and cannot be read by cross-site scripts. No persistent tracking cookies are used. You can log out at any time to clear the session.
4. How We Use Your Data
- Authentication: to verify your identity and grant access to your profile and admin features.
- Feedback: to process and respond to your submissions about comic data corrections, bugs, or feature requests.
- Comic browsing: all comic reference data (series, issues, prices) is publicly accessible without an account.
We do not use your data for marketing, profiling, or automated decision-making.
5. Data Sharing
We do not sell, rent, or share your personal data with third parties. No data is transferred outside the European Union.
6. Data Retention
- Account data: retained until you delete your account.
- Session data: automatically expires 7 days after creation.
- Feedback messages: retained until removed by an administrator.
- Audit logs: anonymized when you delete your account.
7. Your Rights
Under the GDPR, you have the right to:
- Access: request a copy of your personal data (available under Profile → Your Data → Export My Data).
- Rectification: correct inaccurate data (edit your display name in Profile).
- Deletion: delete your account and all associated data (available under Profile → Danger Zone → Delete My Account).
- Portability: receive your data in a machine-readable format (JSON export).
- Restriction: request that we limit processing of your data.
- Objection: object to processing of your data.
To exercise these rights, you can use the self-service options in your Profile or contact us directly.
8. Security
We implement appropriate technical measures to protect your data:
- Passwords are hashed with bcrypt (12 rounds) and never stored in plain text.
- Authentication tokens are stored in httpOnly cookies, immune to cross-site scripting (XSS) attacks.
- Rate limiting prevents brute-force attacks on login and password reset endpoints.
- All admin actions are logged to an audit trail.
9. Changes to This Policy
This privacy policy may be updated from time to time. Significant changes will be announced via site announcements (visible on the homepage). Continued use of the site after changes constitutes acceptance of the updated policy.
10. Contact
For questions about this privacy policy or to exercise your data rights, you can:
- Use the Feedback form (available from the sidebar).
- Contact the data controller via the email address associated with this site.
You also have the right to lodge a complaint with your local data protection authority (tietosuojavaltuutettu in Finland).