Skip to main content
WanascopeCompanion for WaniKani
Connect WaniKani

Privacy

Your data, explained simply.

What stays in your browser, what Wanascope receives, and how to remove it.

Effective and last updated: July 28, 2026 · Policy version 2026-07-28-v4

Short version

Most data stays in your browser. The limited server records are explained below.

  • Stays in your browser

    Your API key, detailed WaniKani data, progress history, and Reader content stay in this browser.

  • Limited server records

    After a successful connected sync, Wanascope privately keeps your WaniKani ID, username, current level, first and latest sync times, and when its first-connection alert was sent. Reminders and messages are stored only when you use them.

  • Your PostHog choice

    PostHog stays off until you allow it. Privacy-focused Vercel traffic and performance measurements run separately on production visits.

  • Your control

    You can turn analytics off, log out, clear local data, revoke your key, or ask Wanascope to delete data it holds.

Wanascope · privacy@wanascope.com

Your browser and WaniKani

What stays in my browser?

Your read-only API key, synced WaniKani data, progress history, goals, settings, and Reader books stay in this browser. Wanascope uses IndexedDB, local storage, session storage, and a one-year language cookie to support these local features and remember your choices. Pasted Reader text disappears when you reload. Browser storage is not encrypted, so avoid connecting on a shared device. Wanascope cannot submit reviews, start lessons, or change your WaniKani account.

What leaves my browser?

Your API key goes only to WaniKani's official API over HTTPS for read-only sync and reminder checks. Reader text and books are not sent anywhere. After a connected account syncs successfully, Wanascope privately records its WaniKani user ID, username, current level, first and latest successful sync times, and when its first-connection alert was sent. This account registry recognizes returning accounts and avoids duplicate adoption counts; it is separate from analytics. Hosting providers also receive normal request data such as your IP address, requested page, browser, and time so they can serve and protect the site. Production visits use the limited Vercel measurements described below. Reminders, messages, and optional PostHog analytics send data only in the circumstances explained below.

PostHog choice and Vercel measurements

What happens if I allow PostHog analytics?

If you allow it, PostHog Cloud EU receives a random ID for this browser, a normalized Wanascope page address, selected feature use, broad browser and device type, browser time zone, and session IDs that connect one visit. Query strings, URL fragments, and unrecognized paths are removed or grouped before sending. An allowed session may also include a masked replay of page layout, navigation, clicks, and scrolling. Connected study dashboards, Reader, message forms, account panels, images, study-detail dialogs, and network or console content are blocked from replay; input values and remaining text are masked. PostHog stays off until you allow it.

What is never included in PostHog analytics?

PostHog never receives your API key or password, WaniKani user ID, username or level, detailed study data, review questions or answers, Reader text or books, feedback or privacy-request messages, reminder delivery details, URL query strings or fragments, or other browser-stored data. Wanascope does not use ads, cross-site tracking, PostHog autocapture, console logs, network bodies or headers, canvas recording, or advertising profiles. A replay is a masked reconstruction of layout and interactions, not an unfiltered video of your screen.

What does Vercel measure on production visits?

Vercel Web Analytics receives anonymous page-view data for aggregate traffic reporting, including a normalized allowlisted page, referrer, broad location, browser, operating system, and device type. Query strings, fragments, and unrecognized paths are removed or grouped before sending. It uses no third-party cookies and does not provide Wanascope with a cross-site identity. Vercel Speed Insights receives real-user Web Vitals, normalized page or route, broad browser, device, network, and country information, and available performance-element attribution. These Vercel measurements run on production visits independently of your PostHog choice and exclude Wanascope's known internal traffic.

Account registry, reminders, and messages

What does Wanascope store on its servers?

The private account registry stores WaniKani user ID, username, current level, first and latest successful sync times, and when its first-connection alert was sent. It never stores your API key or detailed study data. If you enable reminders, Wanascope stores the browser delivery details, reminder times, language, and summary counts needed to send them. Feedback sent through the in-app form stores your message, category, submission ID, page, device type, app version, time, and reply email if provided. The privacy button opens your email app; this page does not collect the request. If you send it, your email provider and the services used to route and host Wanascope's privacy inbox process your email address, message, and standard email metadata.

How long is data kept?

Local data remains until you remove the relevant item or clear site data. Logging out removes your API key and synced WaniKani data, but it does not remove Reader books, interface preferences, the language cookie, your analytics choice, the analytics browser ID, or the private account-registry row; remove those separately or request registry deletion. Account-registry rows remain while Wanascope operates the registry unless you request earlier deletion. Session replay recordings are kept for up to 30 days. Other PostHog analytics may remain searchable for up to 84 months unless you request earlier deletion. In-app feedback is automatically deleted after 180 days. Privacy emails remain in Wanascope's privacy inbox according to the routing and inbox services' retention and backup settings. Reminder records are generally removed after about 1, 7, or 90 days depending on their status. Other hosting and security copies follow each provider's settings.

Your choices and rights

How do I turn analytics off or delete data?

Change PostHog analytics here or in Settings → Data. Turning it off stops future PostHog events but does not delete events already received or disable the separate aggregate Vercel measurements. Log out to remove your API key and synced WaniKani data, remove Reader books separately, or clear site data to remove everything stored by Wanascope in this browser; revoke your key in WaniKani as well. To access, correct, or delete the private account registry, email a privacy request with only the username or user ID needed to find the row—never your API key. For past PostHog analytics, keep and provide the analytics ID shown here until the request is complete. PostHog is not linked to the account registry, and browser analytics without its ID may not be identifiable from an email alone. Vercel's aggregate measurements are not exposed to Wanascope as an identifiable user record.

Who handles data and where?

Wanascope is responsible for the limited server data described here. Contact privacy@wanascope.com. Vercel hosts and protects the site and provides privacy-focused aggregate Web Analytics and real-user performance measurements. PostHog stores consented analytics, including masked replays, in Germany in its EU region and is configured to discard client IP addresses without adding location, although IP addresses pass through network infrastructure first. Supabase stores the private account registry, feedback, and reminder records in Singapore. Resend sends a new-account alert without the WaniKani ID, username, or level, plus other operational alerts. Your email provider and the services used to route and host Wanascope's privacy inbox handle any privacy email you choose to send. WaniKani receives direct API requests, and the browser's push provider delivers reminders. Providers may process data across borders. The account registry is used only to recognize returning accounts, avoid duplicate adoption counts, and operate the service. Optional PostHog analytics relies on your consent; Vercel measurements are used to understand aggregate traffic and performance; reminder and message data is used to provide features you request; basic hosting and security data is needed to run and protect Wanascope. Wanascope does not sell personal data.

What rights do I have?

Depending on applicable law, you may ask for access, a copy, correction, deletion, restriction, or an explanation; object to processing; withdraw consent; or complain to your local data-protection authority. Contact privacy@wanascope.com. Wanascope may ask for enough information to verify the request and will explain if it cannot fulfill it in full.

What about children or policy changes?

Wanascope is not designed for children below the age at which they can make their own data choices. A parent or guardian can contact Wanascope if they believe a child submitted information. Material changes update the effective date and policy version; Wanascope asks again before enabling anything that requires a new choice.

Privacy requests

Ask about or delete your data.

Email Wanascope to ask a question or request access, correction, or deletion. Include only the username or user ID needed to find records, and never include your API key.

Email privacy@wanascope.com