Privacy Policy
Last updated 9 October 2026
The short version: your artwork and your stories are yours. We do not train models on them, we do not sell them, and we do not hand them to anyone who would. The rest of this page is the specific, checkable version of that sentence.
Who we are
MangaForge is operated by Mangaforge Pvt Ltd, a company registered in India. For anything in this policy, including requests about your data, write to privacy@mangaforge.jp. Our registered postal address is available on request.
What we collect
If you joined the waitlist
- Your email address.
- Your language preference, so we write to you in English or Japanese.
- Optionally, what tool you use today, if you choose to tell us. This shapes what we build.
- A record of the consent you gave: the exact wording you agreed to, the time, and the IP address the request came from. We keep this because consent is only meaningful if it can be proven, and because Japanese law requires us to be able to show it.
If you use the studio
- Your account email and display name. If you sign in with Google, also your Google profile picture (see “Google user data” below).
- Pages you upload to the translation feature, and the translated output. See “What the AI features send, and where”.
- Billing records for credits and purchases: amount, date and plan. Card details are handled by our payment processors and never reach us.
- The work you create: stories, scene cards, storyboards, pages and artwork. We store this so the product functions. We do not read it, mine it, or use it to build anything.
- Technical diagnostics when something breaks: error messages, browser and device type. These help us fix faults and nothing else.
Google user data (Sign in with Google)
When you choose Continue with Google, or use the Google One Tap prompt, Google shares with us your email address, name and profile picture (the openid, email and profile scopes). We do not request access to your Google Drive, Gmail, Calendar, contacts or any other Google data.
- How we access it: once, at sign-in, through Google’s OAuth consent screen. We receive an ID token containing those three fields and nothing else. We do not read any other Google data and we hold no ongoing access to your Google account.
- How we use it: only to create your MangaForge account and sign you in, to show your name and picture in the studio, and to contact you about your account. We do not use it for advertising, profiling, or any purpose beyond operating your account.
- How we store it: in our Supabase database, encrypted at rest and in transit, for as long as your account exists. It is deleted when your account is deleted.
- How we protect it: we treat Google user data as sensitive data. Security procedures are in place to protect its confidentiality: it is encrypted in transit with TLS and encrypted at rest with AES-256, access is limited by database row-level security so only your own signed-in account can read it, and staff access is restricted to what is needed to answer a support request you make. See “How we protect your data” below for the full list.
- How we share it: we do not sell it, transfer it, or share it with any third party other than the processors listed below who host it on our behalf. We do not use it to train any machine learning model, and no human at MangaForge reads it except to answer a support request you make.
- Revoking and deleting: you can remove MangaForge’s access at any time at myaccount.google.com/permissions, and you can ask us to delete your account and data (see “Your rights”).
MangaForge’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data for advertising, we do not sell or transfer it to data brokers, we do not use it to make credit or lending decisions, and we do not use it to develop, improve or train any generalized or non-personalized AI or machine learning model.
What we never do
We do not use your work to train, fine-tune, evaluate or benchmark any machine learning model. We do not license, sell or otherwise provide it to any third party for that purpose. This is not a preference we may revisit. It is a term of the agreement between us, stated again in our Terms of Service.
If that ever changes, it would apply only to work created after the change, only with your explicit opt-in, and we would tell you plainly rather than by amending a document quietly.
What the AI features send, and where
MangaForge does not generate artwork. Nothing draws on your behalf. Two features use a language model, and both use Google’s Gemini API for text only:
- Storyboard shot planner. When you stage a storyboard page, the written scene (title, location, time of day, action, emotional tone, hook, character names and dialogue, plus the panel dimensions of the page) is sent to Gemini, which returns a suggested shot list. A deterministic renderer places the panels. If the service is unavailable the app falls back to deterministic rules.
- Translation. Pages you upload are processed on our own infrastructure (Modal, with file storage on AWS S3) to find and replace text. Only the text extracted from the page is sent to Gemini for translation. Uploaded pages and translated output are deleted after 30 days.
- Your artwork is never sent to a third-party model. No image you draw or upload is sent to Gemini or any other outside model, at any time, for any reason.
- Training: we use the paid Gemini API tier, under which Google does not use submitted content to train its models.
Who processes data on our behalf
We keep this list short on purpose, and we will update it here when it changes.
- Supabase — database, authentication and file storage. This is where your account and your work live.
- Cloudflare — content delivery, security, bot protection on our forms, and email routing for our own addresses.
- Google (Sign-In) — authenticates you if you choose Continue with Google.
- Google (Gemini API) — the storyboard shot planner and translation described above. Text only.
- Modal — runs the translation processing on our behalf.
- Amazon Web Services (S3) — temporary storage of translation uploads and output.
- Resend — sending the email you asked us to send.
- Sentry — error diagnostics, so faults surface before you have to report them. Sentry receives code errors and technical context only, not the content of your work.
- Stripe and Pay.jp — payment processing, if and when you pay us. We never see or store your card details.
How we protect your data
We treat your account data, your work and any Google user data we receive as sensitive data. Security procedures are in place to protect the confidentiality, integrity and availability of that data, and we use encryption to protect your information. Specifically:
- Encryption in transit. Every connection to MangaForge, and between MangaForge and the processors listed above, uses HTTPS (TLS) encryption.
- Encryption at rest. Our database, file storage and backups (Supabase on AWS, and AWS S3) are encrypted at rest with AES-256.
- Access controls. Row-level security in the database ensures each account can read and change only its own data. Administrative access to production systems is limited to a small number of named staff, protected by strong authentication, and used only to operate the service or answer a support request you make.
- Minimal Google data. We request only the
openid,emailandprofilescopes. We do not store Google access or refresh tokens; sign-in gives us a one-time identity token, and we hold no ongoing access to your Google account. - Secrets management. API keys and credentials are kept in our hosting providers’ encrypted secret stores, never in application code or in your browser.
- Payment data. Card details never reach us; they are handled entirely by Stripe and Pay.jp, which are PCI DSS certified.
- Breach response. If we become aware of a security incident affecting your personal data, we will contain it, notify affected users without undue delay, and notify regulators where the law requires it.
How long we keep things
Your work is kept while your account exists, and deleted when you delete it. Waitlist records are kept until you unsubscribe, plus the period we are required to retain proof of consent. Translation uploads and output are deleted after 30 days. Diagnostics are kept for 30 days and then discarded.
Your rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. On a deletion request we permanently delete your account, your work and any translation files, including the Google profile data described above. You can withdraw consent to email at any time, using the unsubscribe link in any message or by writing to us. Write to privacy@mangaforge.jp and we will respond within 30 days.
Cookies and local storage
We use browser storage to keep you signed in and to remember interface preferences such as your theme. If you use Google sign-in, Google’s sign-in script loads from accounts.google.com and Google may set its own cookies. We do not use advertising cookies and we do not run third-party analytics or trackers.
Children
MangaForge is not directed at children under 13 (or under 16 where local law sets a higher age), and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top. For any change that materially affects your rights or how your work is handled, we will tell you directly rather than rely on you noticing.