Nunko holds little about you, you can read all of it, and you can delete all of it in one click — your data. This policy explains exactly what “all of it” is.
Last updated: 18 August 2026
ERS Interactive (“Nunko,” “we,” “our,” or “us”) operates the Nunko directory at nunko.ai. This Privacy Policy explains what information the Services collect, how it is used, and the choices you have. By using the Services you agree to the practices described here; if you do not agree, please do not use the Services.
ERS Interactive is the data controller for any personal data processed through the Services.
You do not need an account to use Nunko, and most readers never make one. Whether you do or not, everything below hangs off a single identifier your browser carries, and your data shows you the live contents of it:
2.1. The session cookie (coveting_sid). The first time you interact with the
personalized feed, your browser is given an opaque, random identifier stored in a cookie.
It is a random number — it is not derived from your IP address, device, email, or
anything else about you, and it is not joinable to any subscriber or person. It exists so
the feed can remember the taste your own reactions built.
2.2. The age-confirmation cookie (coveting_age_ok). This records only that you
confirmed you are 18 or older. It is an attestation flag, nothing more.
2.3. Reaction signals. When you react to a listing (for example a like, skip, view, or
hide), we store that reaction tied only to the opaque coveting_sid identifier
and the listing it was about. We store what was rated, never who rated
it: there is deliberately no IP, user-agent, or referer stored alongside a reaction.
2.4. The optional save token. If you choose to save your session so you can resume it on another device, we mint an unguessable resume token and, if you provide one, a label you choose. The token in the resume link is the entire credential; we ask for nothing else and no email is required.
2.5. If you make an account. An account is optional and exists so your taste survives a new device. If you make one we store the email address or the provider account id you signed in with, the display name that provider gave us, and which sign-in door you used. There is never a password — we do not have one to store, lose, or breach.
2.6. What you type. If you talk to the curator we store your side of the conversation and ours, so the thread is still there when you come back. That text is yours, we return it to you in full on request, and how long we keep it depends on your tier — see Section 8. We also keep a short, rebuildable list of things you told us about yourself so replies stay consistent; deleting your data deletes it.
2.7. If you take the weekly letter. Taking it is a separate, double opt-in choice. We then store your consent history, the letters we sent you and what happened to each, and any reply you send back to us in your own words.
2.8. What we do not collect. We do not store a password; we do not log your IP address, user-agent, or referer against your activity; we do not fingerprint your device; and we set no advertising identifiers or third-party tracking cookies. The one place a network address is used is the free-turn allowance, and it is used as a salted hash that is never stored beside anything else about you.
For users in the European Union and the United Kingdom, we process the data above on the basis of our legitimate interest in operating and personalizing a directory in a privacy-preserving way, and, where applicable, your consent. We hold the minimum the Services need to work, and every right in Section 7 is exercisable without contacting us.
We use the limited data above only to:
We do not sell your data, and we do not use it to advertise to you.
5.1. Service providers. We use a third-party service to power feed personalization and aggregate statistics. It receives your identifier and, if you made an account, the email address and display name attached to it — nothing else, and never your IP address. Deleting your data clears the email address and display name from it.
5.2. Legal reasons. We may disclose information if we believe it is necessary to comply with applicable law, regulation, legal process, or a lawful government request.
5.3. Business transfers. If we are involved in a merger, acquisition, or sale of assets, the limited data described here may be transferred as part of that transaction.
5.4. With your consent. We may share information for any other purpose disclosed to you at the time, or with your consent.
6.1. What cookies we use. Nunko sets only the two cookies described in Section 2:
coveting_sid (a functional cookie that carries your opaque session
identifier) and coveting_age_ok (an essential cookie that records your age
attestation). We use no analytics, advertising, or third-party tracking cookies.
6.2. Managing cookies. Most browsers let you control or delete cookies through their
settings. Clearing the coveting_sid cookie stops your browser from presenting the
identifier, which is not the same thing as deleting what is behind it — use
your data for that.
6.3. Do Not Track. We set no cross-site trackers, so there is nothing to signal; we do not need to respond to “Do Not Track” because we do not track you across sites.
7.1. Nothing to log into, and nothing to ask us for. Your rights here are self-serve: your data shows what we hold, downloads all of it as one file, and deletes all of it. No account, no form, and no waiting on us.
7.2. Data-subject rights. Depending on where you live, you may have rights to access, rectify, delete, restrict, or port your personal information, and to object to its processing.
7.3. Additional GDPR rights (EU/UK). You also have the right to withdraw consent at any time and the right to lodge a complaint with your local supervisory authority.
7.4. CCPA (California). We do not sell personal information as “sell” is defined under the California Consumer Privacy Act, and you have the right to non-discrimination for exercising your rights.
7.5. Exercising your rights. Access, portability and erasure are the page above and take effect immediately. For anything else — rectification, restriction, or an objection to processing — contact us at legal@nunko.ai and quote the identifier that page shows you, which is the only way we can find your record.
7.6. If you are listed in the directory. This is separate from the data above. If you are a real person indexed from public sources and want your entry taken down, you have the right to removal — with no proof and no account, honoured within 24 hours. See content removal or request removal directly.
Reaction signals and conversations are kept on a horizon that follows what your account is worth: 30 days from your last activity with no account, one year once you make one, and indefinitely while a subscription is active. A lapse shortens the horizon rather than deleting the conversation you are in the middle of. Anonymous readers are held in a cache that expires 30 days after their last visit, so a reader who never returns is deleted without asking. Save tokens are retained until you stop using them. Deleting your data overrides all of it and takes effect at once.
We take reasonable technical and organizational measures to protect the data we hold from loss, misuse, and unauthorized access. The identifier in your cookie and any resume token you mint are the credentials in this system; both are drawn from a cryptographically secure random source, both are sent only over TLS, and neither is readable by scripts on the page. That is also why a downloaded copy of your data deliberately omits them. No internet service is ever completely secure.
The Services are strictly for adults 18 or older and are age-gated. We do not knowingly collect information from anyone under 18. If you believe a minor has interacted with the Services, please contact us at legal@nunko.ai and we will take appropriate steps.
The limited data described here may be processed in countries other than the one you live in, which may have different data-protection laws. Where required, we put appropriate safeguards in place, such as standard contractual clauses, before transferring data internationally.
Nunko is built of links to third-party websites. We do not control those sites and are not responsible for their content or privacy practices. We encourage you to read the privacy policy of any site you visit through the Services.
We may update this Privacy Policy from time to time. The updated version is indicated by the “Last updated” date above and is effective as soon as it is posted. If we make material changes we will provide a more prominent notice. Please review this policy periodically.
If you have any questions about this Privacy Policy or our practices, contact ERS Interactive at legal@nunko.ai. Our postal address is shown at the foot of this page. The same address serves as the contact point for EU/UK data requests.
15.1. California residents. Under the CCPA you may have the right to know what personal information we collect and how we use it, to request its deletion, and to opt out of its sale. We do not sell personal information. Knowing and deleting are self-serve at your data; for anything else contact legal@nunko.ai.
15.2. EEA and UK residents. Under the GDPR and UK GDPR you have the rights described in Section 7, including access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with a supervisory authority. Access, erasure and portability are served immediately at your data, without contacting us.
15.3. Nevada residents. Nevada residents have the right to opt out of the sale of certain covered information. We do not sell covered information as defined by Nevada law and have no plans to.
Everyone in here is a real creator who chose to be public, and we send you straight to them — their pages, their links. Nothing plays on this site.
By entering you confirm you are 18 or older, or the age of majority where you live.