This policy describes what happens to information about you when you read Hentai. It covers the data our servers record automatically, the data you hand over when you write to us, the third-party services that see any of it, and the rights you can exercise over all of it. The site is an editorial reference resource: it explains terminology, formats, publishing history and the law surrounding a category of Japanese-style adult media. It is not a platform, a store, a streaming service or a publisher of the works it describes, and it hosts no explicit material of any kind.
Questions about anything below go to [email protected]. We answer data requests ourselves; there is no ticketing system in between.
Who runs this site
The site operates at the domain homesteadlodgemotel.co.nz and is run by an independent editorial project of the same name. The operator acts as the data controller for the processing described here. Correspondence about privacy, data access requests and deletion requests should be sent to [email protected]; general editorial correspondence belongs at the addresses listed on our contact page. Background on who publishes the site is on the about page, and the standards the writing is held to live in the editorial policy.
Most of our audience is in the United States, so the California Consumer Privacy Act as amended by the CPRA applies to visitors from that state. Readers in the European Economic Area are covered by Regulation (EU) 2016/679 (GDPR), readers in the United Kingdom by the UK GDPR and the Data Protection Act 2018, and the New Zealand Privacy Act 2020 applies to us through the domain registration and hosting arrangements. Where those regimes differ, we apply whichever gives the reader more control.
What we collect
Information you send us
If you email us, we receive whatever you put in the message: your email address, any name you sign with, and the content of what you wrote. Nothing about that is automated, and we do not enrich it with data from other sources. There is no contact form on this site and no newsletter signup, so those two common collection points do not exist here.
We never collect payment details, card numbers, government identity documents, age-verification records, passwords or credentials for any other service. If you send any of that to us by mistake, we delete it and confirm the deletion in reply.
Information collected automatically
Serving a web page requires a small amount of technical data, all of which is recorded in server logs and in our analytics:
- IP address
- Used to route the response back to you, to derive an approximate country for traffic reporting, and to filter automated abuse such as scraping and denial-of-service traffic. Analytics receives it in truncated form.
- Browser type and version (User-Agent)
- Used to check that the layout renders correctly on the browsers our readers actually use, and to identify bot traffic that declares itself.
- Operating system and device class
- Used to decide how much of our layout work goes into mobile rather than desktop, since the split between them changes over time.
- Pages viewed and time spent on each
- Used to see which reference sections get read to the end and which get abandoned, which tells us where the writing needs work.
- Referrer URL
- Used to understand whether a visit came from a search engine, a link on a forum, or a direct entry, and to spot sites republishing our text without attribution.
- Browser language and screen resolution
- Used for layout testing and to confirm that the English-language scope of the site matches who is reading it.
Cookies
Cookies fall into two groups here. Strictly necessary ones store your consent choice, keep a session coherent and let the content delivery network separate human traffic from bots; they load regardless, since the site cannot serve pages without them. Analytics cookies, set by Google Analytics, count visits and expire after two years for the visitor identifier and twenty-four hours for the daily one. The analytics group loads only after you accept it in the consent banner, and clearing site data in your browser withdraws that consent. No advertising, marketing or referral cookies are set on this site, as our affiliate disclosure explains.
Why we process it
Running the site produces exactly six processing purposes, and none of them involve building a profile of you as an individual.
- Delivering the content
- Serving HTML, stylesheets and images to your device, and keeping the response times reasonable through a content delivery network.
- Editorial improvement
- Aggregate reading patterns tell us which explanations fail. A glossary entry that readers hit and immediately leave usually means the definition is unclear, and that is how sections get rewritten.
- Traffic statistics
- Google Analytics 4 gives us visit counts, traffic sources and device breakdowns in aggregate. Reports are read at the level of countries and page groups, never at the level of a single visitor.
- Security
- Blocking credential-stuffing attempts against the admin interface, filtering bot traffic, and keeping enough log history to investigate an incident after the fact.
- Correspondence and legal obligations
- Answering your email, and retaining what the law requires us to retain for as long as it requires.
Legal bases under GDPR Article 6
Consent under Article 6(1)(a) covers every cookie that is not strictly necessary, meaning the analytics cookies and nothing else. You give it through the consent banner on your first visit and can withdraw it at any time by clearing the consent cookie or changing your browser settings, with no effect on the lawfulness of what happened before the withdrawal.
Legitimate interests under Article 6(1)(f) cover server security logging and aggregate traffic measurement. Our interest is in keeping the site online and understanding which reference material is worth expanding; the processing involves no profiling and no decisions that affect you, and that is what tips the balance in favour of processing.
Article 6(1)(b), performance of a contract, applies narrowly: when you write to us with a question, handling your message is what you asked for. Article 6(1)(c), legal obligation, applies where retention or disclosure is compelled by law.
Who else sees the data
We do not sell personal data, we do not share it with advertising networks for behavioural targeting, and we do not pass reader data to any platform we write about. Four categories of processor are involved:
- Google Analytics 4 (Google LLC, United States)
- Receives truncated IP address, page views, session duration, device class and traffic source. IP anonymisation is enabled and Google Signals is disabled, so no cross-device advertising profile is built from our property.
- Cloudflare (Cloudflare Inc., United States)
- Runs in front of the site as a content delivery network and bot filter. It processes IP address, request headers and timestamps, and sets short-lived technical cookies for bot filtering and rate limiting.
- Hosting and email providers
- Our hosting provider stores the server access logs that every web server produces. Our mail provider stores the messages you send us for as long as the thread is open.
International transfers
Google and Cloudflare are United States companies, so data reaching them leaves the EEA and the United Kingdom. Those transfers rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the recipient is certified, and on Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914 as the fallback. A copy of the safeguards in force for a specific processor is available on request to [email protected].
How long anything is kept
- Email correspondence
- Twelve months after the last message in the thread, then deleted. Threads that establish a correction to published content are kept longer, because the correction log is part of our editorial record.
- Server access logs
- Ninety days: long enough to investigate an intrusion, short enough that the logs never become an archive.
- Analytics cookies
- The
_gaidentifier expires after two years and_gidafter twenty-four hours. Aggregate reports in the analytics account are retained for fourteen months. - Records kept for legal reasons
- Up to six years where tax or limitation periods require it, then deleted or irreversibly anonymised.
Your rights
Under GDPR Article 15 you can ask for a copy of the personal data we hold about you, and we have thirty days to answer. Article 16 gives you the right to have inaccurate data corrected, and Article 17 the right to have it erased where no lawful ground for keeping it survives. Article 18 lets you freeze processing while a dispute over accuracy is resolved, and Article 20 lets you take what you gave us in a machine-readable file, which for a site like this one means a JSON or CSV export of your correspondence.
Article 21 gives you the right to object to anything we do on the basis of legitimate interests, and consent can be withdrawn at any point without explanation. Readers in California may request disclosure of the categories of personal information collected and shared, request deletion, and correct inaccurate information; we do not sell or share personal information as those terms are defined by the CPRA, so there is no opt-out link to serve.
To use any of these, email [email protected]. We confirm receipt within seventy-two hours and complete the request within thirty days. If the answer does not satisfy you, EEA readers may complain to their national supervisory authority, UK readers to the Information Commissioner's Office at ico.org.uk, and readers dealing with the New Zealand side of the operation to the Office of the Privacy Commissioner at privacy.org.nz.
Security measures
Every connection to the site runs over TLS with 256-bit ciphers. That is what the https in the address bar means, and why an intermediary on a public network cannot read what you are looking at. The site is static HTML with no database and no user accounts. Those two components are behind most breaches of small publishing sites, and neither exists here.
Administrative access to the hosting account and the analytics property is protected by two-factor authentication, restricted to the people who need it, and reviewed when anyone stops working on the project. Server software and dependencies are patched on the provider's release schedule, and backups are encrypted at rest. No system is immune, and we would rather say so plainly than promise otherwise.
Adults only
This site is intended for readers aged eighteen and over, and its subject matter is unsuitable for minors. We do not knowingly collect data from anyone under eighteen, and we have no mechanism that would invite it: no accounts, no profiles, no forms.
If we learn that information from a minor has reached us, we delete it immediately without keeping a copy. A parent or guardian who believes their child has sent us something should write to [email protected] and we will confirm the deletion. Household-level filtering is more effective than anything a single site can do, and the tools we consider worth setting up are named on our responsible play page.
Changes to this policy
This policy changes when the site changes: a new analytics tool or a new hosting arrangement requires an update here before it goes live. The revision date at the top of the page always reflects the current version, and material changes are flagged with a notice on the homepage for thirty days.
Continuing to use the site after a revision means the revised version applies to you. If a change would broaden what we collect, we ask for fresh consent instead of relying on the old banner. Anything unclear in the text above is worth an email to our contact page, and we will either explain it or rewrite the passage.
