Privacy Policy
Last updated: September 2026
Information We Collect
VRJAV.net can be browsed without an account. We collect only the information needed to operate accounts, improve the site, and keep it secure:
- Server logs: Standard nginx access logs (IP address, timestamp, requested URL, user agent) are kept for 7 days for debugging and security purposes, then automatically deleted.
- First-party analytics: We collect aggregate counts of page views, searches, game launches, and magnet-link clicks. When you open an intentionally tagged campaign link, we also collect its short source and campaign labels (for example,
reddit and jav_sivr500_sep2026) to measure aggregate campaign results. These metrics do not include IP addresses, user agents, full referrers, post URLs, or search terms. A random browser-session identifier is retained for up to 7 days solely to estimate unique sessions.
- Account data: If you register, we store your username, email address, securely hashed password, favorites, ratings, account-backed comments, and messages you send to the site owner. Passwords are never stored in readable form.
- App beta activity: App downloads require an account. For beta support, administrators can view your account’s download starts (platform, build version and dates) and completed app sign-ins (platform and dates). Repeated download requests for the same build are grouped by UTC day. A download start does not prove installation. This activity does not include playback history, local filenames, media libraries, or credentials. It is private to site administrators and remains until account deletion.
- Optional app playback diagnostics: Quest 63 and Windows 69 tester builds enable diagnostics by default when no preference has been saved, with a first-launch notice and a Settings opt-out. Previously saved opt-outs stay off. Earlier supported builds require opt-in. While enabled, the app sends playback events, video codes, app versions, coarse device models, codec/dimension information, timing measurements and symbolic error codes to help diagnose failures. Reports distinguish the tester default from an explicit user choice. Reports have random IDs and are visible only to site administrators; an internal account ID supports ownership and abuse limits. Reports contain no video, subtitle text, private file paths, filenames, magnets, credentials or raw crash logs. You can turn sharing off in app Settings, which clears pending reports. Disabling sharing does not recall reports already received.
- Recovery data: Password-reset requests create a one-time, hashed reset token that expires after one hour. Recovery emails are sent only to the address associated with the account.
- Cookies: Third-party advertising partners (ExoClick) may set cookies for ad delivery and frequency capping. See their privacy policy for details.
Third-Party Services
We use ExoClick for advertising. ExoClick may collect anonymized data about your visit for ad targeting purposes. You can opt out of interest-based advertising through ExoClick's privacy center.
Data Retention
Server logs and temporary analytics session identifiers: up to 7 days. Password-reset tokens expire after one hour. Account information and account activity remain until you request deletion. Aggregate analytics totals may be retained longer because they cannot identify an individual visitor.
Your Rights
Playback diagnostics expire after 30 days and are deleted on the next diagnostics upload or administrator access. Pending app reports expire after seven days and are cleared on sign-out or opt-out. The diagnostics database is separate from long-lived account activity.
Under GDPR (EU) and CCPA (California), you may request access to, correction of, or deletion of personal data associated with your account. Contact: privacy@vrjav.net
Contact
privacy@vrjav.net