Waifu Deck Privacy Policy
- Waifu Deck has no accounts and no servers of ours. We do not collect, receive, or store any personal data from you.
- Your collection lives on your device. If you choose to sync, it goes to storage you own, encrypted on your device with a password only you know.
- No analytics, no crash reporting, no advertising, no tracking — in the app or on this website.
1. Who we are
Waifu Deck is a free, open-source (AGPL-3.0) Android app for collecting anime artwork, developed by an individual developer (fancydirty). There is no company, no user database, and no backend service behind the app. Privacy questions: privacy@waifudeck.app.
2. What the app stores — and where
Everything the app knows is stored on your device, in the app's private storage:
- the images you keep, their source links and tags, and the identities of images you have already seen or dismissed;
- your settings (for example content-rating preferences, enabled sources, language);
- optional API keys you enter for an art source, and optional credentials or tokens for a cloud library you connect (kept in Android's secure storage).
Uninstalling the app deletes all of this. We never see any of it.
3. Art sources (third parties)
The app fetches artwork directly from your device to the public art sources you enable — currently Danbooru, e621, e926, Gelbooru, Konachan, Nekos API, Rule34, Safebooru, waifu.im and yande.re. Those services receive your device's network requests (including its IP address) under their own privacy policies and terms; the app adds nothing to those requests beyond what is needed to fetch images. Requests go directly to them, never through us.
4. Optional cloud library (storage you own)
You may connect the app to storage that you control so your collection is backed up and can be synced between your devices. Supported or planned locations: an S3-compatible bucket (for example Cloudflare R2, MinIO, Wasabi), Google Drive, or a WebDAV server (including self-hosted OpenList/AList, Nextcloud, NAS devices and providers that offer WebDAV).
- What is uploaded: your kept images (original, preview and thumbnail files), their metadata (source link, tags, size) and the state of your library.
- Encryption: the data is encrypted on your device (AES-GCM) with keys derived from a password only you know before it is uploaded. Encryption is on by default. We do not have the password and cannot recover it for you; if you lose it, encrypted data cannot be read by anyone.
- Credentials and tokens for your storage are stored only on your device and are sent only to the storage provider you configured. Disconnecting the cloud library deletes them from the device.
- The storage provider (Google, Cloudflare, your WebDAV host, and so on) processes your data under its own terms and privacy policy.
4a. Google Drive
When you connect Google Drive, the app requests the https://www.googleapis.com/auth/drive.file scope. This scope only lets Waifu Deck see, create and manage the files and the "Waifu Deck" folder that the app itself creates in your Drive. It cannot read, list or change any other file in your Google Drive.
- Google user data received through this scope (the contents and metadata of the app's own folder, and the OAuth tokens) is used solely to store and sync your own collection for you.
- It is not shared with anyone, not sold, not used for advertising or for building profiles, and never transferred to any server operated by us — the app has none. No human reads it, except if you explicitly ask for support and share it yourself, or where required by law.
- OAuth tokens are stored in your device's secure storage and are deleted when you disconnect Google Drive in the app. You can also revoke the app's access at any time at myaccount.google.com/permissions.
- To delete the synced data, delete the "Waifu Deck" folder in your Google Drive.
Waifu Deck's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Permissions the app asks for
- Internet — to fetch artwork from the sources you enable and, if configured, to talk to your own cloud storage.
- Photos / media access — only when you export an image to your gallery or import a backup file.
- Notifications — to show progress while a cloud sync continues in the background.
The app never asks for your camera, microphone, contacts or location.
6. Children
Waifu Deck is not intended for children. Adult content is off by default and can only be enabled after an explicit 18+ confirmation.
7. This website
waifudeck.app is a static site. It sets no cookies and runs no analytics or tracking scripts. It is served by Cloudflare, which as our hosting provider may process connection data such as IP addresses to deliver the site and protect it from abuse, under Cloudflare's privacy policy.
8. Changes
If the app's data handling changes (for example a new sync location or a new permission), this page will be updated and the date at the top will change. Because the source code is public, the actual behaviour can always be verified.
Waifu Deck 隐私政策
- Waifu Deck 没有账号,也没有我们运营的服务器。我们不收集、不接收、不保存你的任何个人数据。
- 你的收藏只存在你自己的设备上。如果你选择同步,数据只会去你自己拥有的存储,并且在上传前已在设备上用只有你知道的密码加密。
- 没有统计分析、没有崩溃上报、没有广告、没有追踪——应用里没有,这个网站上也没有。
1. 我们是谁
Waifu Deck 是一个免费、开源(AGPL-3.0)的 Android 二次元图片收藏应用,由个人开发者(fancydirty)开发。应用背后没有公司、没有用户数据库、没有任何后端服务。隐私相关问题请发邮件至 privacy@waifudeck.app。
2. 应用保存什么、保存在哪
应用知道的一切都保存在你的设备上,位于应用的私有存储中:
- 你收藏的图片、它们的来源链接和标签,以及你已经看过或划掉的图片的标识;
- 你的设置(例如分级偏好、启用的图源、语言);
- 你为某个图源自行填入的 API 密钥(可选),以及你连接云库时的凭证或令牌(可选,保存在 Android 的安全存储中)。
卸载应用会删除以上全部内容。我们从来看不到这些数据。
3. 图源(第三方)
应用直接从你的设备向你启用的公开图源请求图片——目前包括 Danbooru、e621、e926、Gelbooru、Konachan、Nekos API、Rule34、Safebooru、waifu.im 和 yande.re。这些站点会按它们自己的隐私政策和条款收到你设备发出的网络请求(包括 IP 地址);应用不会在请求里附加任何取图之外的信息。请求直接发往它们,不经过我们。
4. 可选的云库(你自己的存储)
你可以把应用连接到你自己控制的存储,用来备份收藏并在你的多台设备之间同步。已支持或计划支持的位置:S3 兼容存储(例如 Cloudflare R2、MinIO、Wasabi)、Google Drive,或 WebDAV 服务器(包括自建的 OpenList/AList、Nextcloud、NAS,以及提供 WebDAV 的网盘)。
- 上传的内容:你收藏的图片(原图、预览图、缩略图)、它们的元数据(来源链接、标签、大小)以及你的图库状态。
- 加密:数据在上传前会在你的设备上用由你的密码派生的密钥加密(AES-GCM)。加密默认开启。我们没有你的密码,也无法帮你找回;密码丢失后,加密数据任何人都读不出来。
- 存储的凭证和令牌只保存在你的设备上,只会发送给你自己配置的那个存储提供方。断开云库会把它们从设备上删除。
- 存储提供方(Google、Cloudflare、你的 WebDAV 服务商等)按它们自己的条款和隐私政策处理你的数据。
4a. Google Drive
连接 Google Drive 时,应用申请的权限范围是 https://www.googleapis.com/auth/drive.file。这个范围只允许 Waifu Deck 查看、创建和管理它自己在你的云端硬盘里创建的「Waifu Deck」文件夹及其中的文件;它无法读取、列出或修改你 Google Drive 里的其他任何文件。
- 通过该权限获得的 Google 用户数据(应用自己那个文件夹的内容与元数据,以及 OAuth 令牌)只用于为你保存和同步你自己的收藏。
- 这些数据不会分享给任何人、不会出售、不会用于广告或画像,也永远不会传到我们运营的任何服务器——应用根本没有服务器。没有人会阅读这些数据,除非你自己主动求助并分享,或法律要求。
- OAuth 令牌保存在你设备的安全存储中;在应用里断开 Google Drive 即会删除。你也可以随时在 myaccount.google.com/permissions 撤销应用的访问权限。
- 要删除已同步的数据,直接在 Google Drive 里删除「Waifu Deck」文件夹即可。
Waifu Deck 对从 Google API 获取的信息的使用,以及向任何其他应用的传输,均遵守 Google API 服务用户数据政策,包括其中的「有限使用」要求。
5. 应用会申请的权限
- 网络——从你启用的图源取图;如已配置,与你自己的云存储通信。
- 照片/媒体访问——仅在你把图片导出到相册或导入备份文件时。
- 通知——云同步在后台继续时显示进度。
应用从不申请相机、麦克风、通讯录或位置权限。
6. 未成年人
Waifu Deck 不面向未成年人。成人内容默认关闭,只有在明确的 18+ 确认之后才能开启。
7. 本网站
waifudeck.app 是一个静态网站,不设置 Cookie,不运行任何统计或追踪脚本。网站由 Cloudflare 托管;作为托管方,Cloudflare 可能为了提供服务和防护滥用而处理 IP 地址等连接数据,适用 Cloudflare 的隐私政策。
8. 变更
如果应用的数据处理方式发生变化(例如新增同步位置或新增权限),本页会更新,顶部的日期也会随之改变。由于源码公开,应用的实际行为随时可以核验。