Privacy policy
Last updated
This policy explains what Filmatic does with your personal data. It covers the Filmatic website at filmatic.io and the Filmatic app on the web, iOS and Android.
We have tried to write it in plain language. Where we have had to use a legal term, we have said what it means.
Who is responsible for your data
The data controller is TODO_LEGAL_ENTITY_NAME, TODO_REGISTERED_ADDRESS, Cyprus (company number TODO_REGISTRATION_NUMBER).
For anything to do with your personal data, including any of the requests described under your rights, contact privacy@filmatic.io. That address is monitored separately from general support because data requests carry legal deadlines.
We have assessed whether we are required to appoint a Data Protection Officer and concluded that we are not, on the basis that we do not carry out large-scale processing of special category data and profiling is not our core public-facing activity in the sense intended by Article 37. We keep that assessment on file and revisit it as the service grows.
What we collect
When you create an account
- Your email address.
- An authentication identifier — if you sign in with Apple or Google, we receive an identifier from them and, depending on your choice, your email address. We never receive your password.
- A display name, if you set one.
When you use the app
- Your swipe and rating history. Every liked, seen, saved and skipped film, with a timestamp. This is the core of the service and the largest category of data we hold about you.
- Your lists, and any notes you attach to a film.
- Your settings, including the streaming services you have told us you subscribe to and your country.
Automatically
- Device and app information: device type, operating system version, app version, language.
- Your IP address, and the country we derive from it. We use the country to show correct streaming availability.
- Product analytics events — but only if you consent to them when the app first launches. If you decline, we do not collect them. See the cookie policy.
- Error and crash diagnostics.
When you contact us
- Your name, email address and whatever you write to us, plus our reply.
What we do not collect
We do not ask for or receive your streaming service passwords, and we have no access to your Netflix, Prime, Disney+ or any other streaming account. We do not collect payment details, because the service is free. We do not collect special category data — we do not ask about your health, beliefs, politics or sexuality. ⟦CHECK: still true if you ever add a paid tier.⟧
Why we use it, and our legal basis
Under Article 6 of the GDPR we need a lawful basis for each purpose. They are not interchangeable, so here is each one mapped explicitly.
| What we do | Data used | Legal basis |
|---|---|---|
| Create and run your account; authenticate you | Email, auth identifier, display name | Contract — Art. 6(1)(b). We cannot provide the service without it |
| Generate recommendations | Swipe and rating history, lists, settings, country | Contract — Art. 6(1)(b). This is the service you signed up for |
| Show streaming availability where you are | Country derived from IP, chosen services | Contract — Art. 6(1)(b) |
| Send service emails — password resets, security notices, changes to these terms | Email address | Contract — Art. 6(1)(b) |
| Send optional digests and product news | Email address | Consent — Art. 6(1)(a). Opt-in, and you can withdraw at any time |
| Product analytics in the app | Analytics events, device data | Consent — Art. 6(1)(a). Opt-in on first launch |
| Keep the service secure; prevent abuse, fraud and automated scraping | IP address, device data, request logs | Legitimate interests — Art. 6(1)(f). Our interest is running a service that works and is not abused; the processing is limited to what security requires |
| Fix crashes and diagnose faults | Error diagnostics, app version, device type | Legitimate interests — Art. 6(1)(f) |
| Improve recommendation quality in aggregate | Aggregated, non-identifying swipe patterns | Legitimate interests — Art. 6(1)(f) |
| Answer your emails | Contact details and message content | Legitimate interests — Art. 6(1)(f), or contract where the query concerns your account |
| Comply with legal obligations | Whatever the obligation requires | Legal obligation — Art. 6(1)(c) |
Where we rely on legitimate interests, we have balanced them against your rights and concluded the processing is proportionate. You can object — see your rights — and we will stop unless we have overriding grounds.
Where we rely on consent, you can withdraw it at any time: for cookies on this website, in the cookie policy; for analytics and optional email in the app, in the app’s settings; or by emailing us in either case. Withdrawing consent is as easy as giving it, and does not affect processing that already happened.
Automated decision-making and profiling
We should be straightforward about this, because it is the heart of the product.
Filmatic profiles your taste, automatically. Every swipe updates a mathematical model of what you appear to like, and your recommendations are generated from that model without a human looking at them. That is automated processing, and it is profiling in the sense the GDPR means.
Three things follow, and we want to be clear about each:
- It has no legal or similarly significant effect on you. It decides which films to suggest. It does not affect your access to credit, employment, insurance, healthcare, or anything else that matters materially. Article 22 — the right not to be subject to solely automated decisions with legal or significant effects — does not bite here, because the decision is which film to put at the top of a list.
- You can reset it. The app’s settings include an option to clear your taste model. Your swipe history is deleted and recommendations start from nothing. You can also delete individual swipes.
- You can see what drives it. Recommendations show why a film was suggested. ⟦CHECK: only claim this once the reason-text feature actually ships.⟧
We do not use your taste data to make any decision about you other than which films to recommend, and we do not sell it or share it with advertisers.
Who else processes your data
We use third-party providers (“processors”) to run the service. Each is bound by a data processing agreement, may only act on our instructions, and may not use your data for their own purposes.
| Processor | What they do | Where |
|---|---|---|
| Supabase | Database, authentication, server functions | EU (Frankfurt / Ireland) |
| Cloudflare | Website hosting, DNS, CDN, email routing, bot protection | Global edge network |
| Resend | Sending transactional email | Sends from the EU; account data and sending logs in the US |
| PostHog | Product analytics in the app, only with your consent | EU cloud |
| Sentry | Error and crash diagnostics | EU region |
| Apple | Sign in with Apple, app distribution, push notifications | US |
| Google Sign-In, app distribution, push notifications | US | |
| TMDB | Film metadata (titles, synopses, posters, credits) | US |
| OpenAI | Generating text embeddings used for similarity | US |
Two of those rows deserve a note, because they are the ones people reasonably worry about.
TMDB and OpenAI do not receive your personal data. Requests to TMDB are made by our servers for film metadata; your identity is not part of them. With OpenAI we embed film descriptions — the text about the films themselves — so that we can measure how similar two films are. Your swipe history is never sent. Your taste profile is computed inside our own database from your swipes and those film embeddings, and it never leaves it.
We may also disclose data to professional advisers, or to authorities where we are legally required to. If the business is ever sold or reorganised, your data may transfer to the acquirer, who would be bound by this policy or notify you of a replacement.
We do not sell your personal data, and we do not share it with advertisers or data brokers.
Sending data outside the EEA
Some processors above are in the United States. Where we transfer personal data outside the European Economic Area we rely on:
- the European Commission’s Standard Contractual Clauses, and where applicable the provider’s certification under the EU–US Data Privacy Framework; and
- supplementary measures — encryption in transit and at rest, data minimisation so that only what is necessary is transferred, and a documented assessment of each transfer.
You can ask us for details of the safeguards applied to a particular transfer.
How long we keep it
“As long as necessary” is not a retention period, so here are the actual ones.
| Data | Kept for |
|---|---|
| Account record (email, auth identifier, display name) | Until you delete your account, then removed within 30 days |
| Swipe and rating history, lists, notes | Until you delete them, or until account deletion, then removed within 30 days |
| Analytics events, if you consented | 14 months from collection, then deleted |
| Error and crash diagnostics | 90 days |
| Server and security logs, including IP addresses | 30 days, unless retained longer for a specific security investigation |
| Contact emails | 24 months from the last message in the thread |
| Records we must keep by law (for example to show consent was given) | As long as the relevant law requires |
| Aggregated, anonymised statistics | Indefinitely — these are no longer personal data and cannot be traced back to you |
Backups are overwritten on a rolling cycle and deleted data disappears from them within 35 days. ⟦CHECK against your actual Supabase backup retention.⟧
Your rights
Under the GDPR you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted. The app can do this itself: see deleting your account.
- Portability — receive your data in a structured, machine-readable format, or have it sent to another provider. The app exports your swipe history and lists as JSON and CSV.
- Restriction — ask us to pause processing while a dispute is resolved.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent — for analytics or optional email, at any time, without affecting anything else.
How to exercise them. Most of this you can do yourself in the app’s settings — export, delete, reset your taste model, change your email preferences — which is faster than asking us. Otherwise email privacy@filmatic.io. We will respond within one month. If a request is genuinely complex we may extend that by up to two further months and will tell you why within the first month. We do not charge for this.
We may ask you to confirm your identity before we act, so that we do not hand your data to someone else.
If you are unhappy with how we have handled your data, please tell us first — most problems are a misunderstanding we can fix. You also have the right to complain to a supervisory authority. Ours is the Office of the Commissioner for Personal Data Protection in Cyprus (https://www.dataprotection.gov.cy/). You may instead complain to the authority where you live or work.
Children
Filmatic is not intended for children. You must be at least 16 to create an account, and we ask for confirmation of this at sign-up.
We do not knowingly collect data from anyone below that age. If you believe a child has created an account, email privacy@filmatic.io and we will delete it and the associated data.
Security
We protect your data with encryption in transit (TLS) and at rest, row-level access controls in the database so that one account cannot read another’s data, restricted and logged administrative access, and least-privilege credentials for every service.
No system is perfectly secure. If a breach occurs that is likely to risk your rights and freedoms, we will notify the supervisory authority within 72 hours of becoming aware of it and tell you without undue delay.
Changes to this policy
If we change this policy we will update the date at the top. Where a change materially affects you — a new purpose, a new legal basis, a new category of data — we will tell you by email or in the app before it takes effect, and where the change requires your consent we will ask for it.
Previous versions are available on request.
Contact
- Data and privacy: privacy@filmatic.io
- Everything else: support@filmatic.io
- Or use the contact form
Postal: TODO_LEGAL_ENTITY_NAME, TODO_REGISTERED_ADDRESS, Cyprus.