Privacy Policy
How Nanko uses data when you create an account and preview themes.
Accounts and authentication
We store email, display name, a password hash for email sign-in, a Google identity if connected, and profile pictures. Plaintext passwords are not stored. Google sign-in is optional when configured; Google tokens are not retained as account data.
Theme packages and previews
Uploaded files are inspected for validation and building. Theme source and configuration are processed in a restricted environment to produce a preview. Do not include secrets, customer data or code you cannot share: anyone with the preview URL can access its interface subject to the available dummy authentication.
Retention and deletion
Ready previews last one hour. Undeployed uploads last one hour; failed builds are cleaned up after 15 minutes. File cleanup runs about every 15 seconds, or when the service resumes. Preview access is denied after expiration. Minimal deployment history, accounts and profile pictures are retained; there is no automatic account deletion schedule or self-service delete-account button yet. You can delete deployments and replace/remove a custom picture in the app.
Cookies and preferences
An HttpOnly session cookie supports sign-in for up to seven days and is scoped to the dashboard host. It is not shared with preview subdomains. Language is stored in a preference cookie; theme is stored in your browser. Legacy session migration uses a short-lived, single-use code. Logout revokes the current session.
Operational logs
Build status, compiler errors, deployment timestamps and technical HTTP/server logs support progress reporting, diagnostics and abuse limits. IP addresses can appear in reverse-proxy logs; application security counters use hashed IPs. Operational logs follow server log rotation; a fixed product retention period has not been established. Do not write secrets into theme logs.
Third parties and questions
Nanko uses VPS hosting, Cloudflare DNS, Let’s Encrypt TLS certificates, and Google OAuth when enabled. Original panel previews may request fonts/assets from providers used by Pterodactyl or the theme. Nanko does not yet provide a ticket system or self-service account deletion. Configured operator contact channels appear on Contact and Support; no unspecified identity or certification is claimed.
