Privacy Policy

Privacy Policy

Effective August 1, 2026Beta

Moviemash ("Moviemash," "we," "us," or "our") is a movie-tracking service operated by Anton Fomin, an individual based in the United States, available at moviemash.app (the "Service"). This policy explains what information we collect, how we use it, and the choices you have.

Moviemash is currently in beta. The Service is intentionally small, and we collect only what is needed to run it. As we add features, we will update this policy and note the changes. By using the Service, you agree to this policy.

01

Information we collect

Information you provide
  • Display name and email address — used to create your account and sign you in.
  • Your movie activity: the movies you log as watched, your 1–5 star ratings, any short written reaction you add to a watched movie, the movies on your watchlist and their interest level (must-see / curious / maybe), and any movies and optional notes you send as suggestions to a paired partner.

We do not collect profile pictures (avatars are generated from your initials), and the Service has no public reviews, comments, or social feed.

Information from your sign-in provider

You sign in with Google or with a one-time code sent to your email. If you use Google, we receive your name, email address, and a unique account identifier from Google. We never receive your Google password.

Information collected automatically

Moviemash uses privacy-friendly, cookieless analytics and error monitoring — no advertising trackers:

  • Usage and performance analytics (via Vercel) — aggregate page views and performance timings, collected without cookies or persistent identifiers. We see counts and trends, never an individual's browsing history.
  • Web analytics on our public pages (via Umami) — aggregate page views, referrers, and button clicks on our public pages (the landing, sign-in, and legal pages), collected without cookies or persistent identifiers and served from our own domain. As with our other analytics, we see counts and trends, never an individual's browsing history.
  • Error monitoring (via Sentry) — if something breaks, we receive a technical error report (the type of error, browser and device type, app version) together with a pseudonymous account identifier, so we can fix bugs that affect real users. Error reports are configured to exclude your IP address, cookies, request contents, and anything you have typed.

If you arrive at Moviemash through a campaign link — for example, a link we posted on social media that carries tags identifying where it was posted — we record those link tags with your account when you sign up, so we can tell which channels bring new users. The tags describe the link you clicked, never your browsing history, and they are recorded only once, at account creation.

In addition, like any website, our hosting providers (see Section 5) automatically receive standard technical data — such as your IP address, browser type, and request times — as a necessary part of delivering and securing the Service.

02

How we use your information

  • Create and operate your account and sign you in.
  • Provide the core features: logging watched movies, ratings, watchlists, and partner suggestions.
  • Enable partner pairing and sync shared library information between paired users.
  • Keep the Service secure and prevent abuse.
  • Measure overall usage and performance of the Service and diagnose errors.
  • Respond to you when you contact us.
  • Comply with legal obligations.
Legal bases (GDPR)
Where GDPR applies, we rely on: performance of a contract (to provide your account and the Service), our legitimate interests (to keep the Service secure and to improve it), and legal obligations (to comply with applicable law).
03

Pairing and what your partner can see

Moviemash lets you pair with one other person. Pairing is mutual and is designed for sharing: once you pair, you and your partner can each see the other's full library — every movie logged as watched, star ratings and written reactions, the watchlist and interest levels, and the associated dates.

There are currently no per-item privacy controls, so pairing shares your library as a whole rather than selected parts; to stop sharing, you can unpair at any time in Settings. (We may add finer-grained sharing controls in the future; if we do, we will update this policy.) It's worth keeping this in mind when you decide what to log.

04

Cookies and local storage

We use only strictly necessary cookies and on-device storage:

  • A session cookie (via Supabase) that keeps you signed in.
  • Local browser storage for your preferences, such as your theme and layout choices. These stay on your device and are not sent to us.

We do not use advertising or third-party analytics cookies — our analytics and error monitoring (see Section 1) work without cookies or persistent identifiers. Because we use only essential and preference storage, no cookie-consent banner is required. You can clear these at any time through your browser settings, though you will then need to sign in again.

05

Service providers

We share information only with the providers needed to run the Service, and only as needed:

  • Supabase — authentication and database hosting.
  • Vercel — application hosting, including privacy-friendly, cookieless web analytics and performance measurement (aggregate data only, no persistent identifiers).
  • Umami — cookieless web analytics for our public pages (aggregate data only, no persistent identifiers; served from our own domain).
  • Sentry — error monitoring. When an error occurs, technical details (the type of error, browser and device type, app version) and a pseudonymous account identifier are sent to Sentry so we can diagnose and fix the problem. Sentry is configured not to store IP addresses and to exclude cookies, request headers, and message contents; session recording is disabled.
  • Resend — email delivery, including your one-time sign-in codes and partner-invite notifications. Your email address and login codes pass through Resend in order to reach you.
  • The Movie Database (TMDB) — movie information. We send limited technical requests to TMDB to retrieve movie details and images. This product uses TMDB and the TMDB APIs but is not endorsed, certified, or otherwise approved by TMDB.

We do not sell your personal information, and we do not share it for advertising.

06

Data location and international transfers

Our providers process and store data in the United States. If you use Moviemash from outside the US, your information will be transferred to and processed in the US, where privacy laws may differ from those in your country. Where European data-protection law (GDPR) applies, these transfers rely on recognized safeguards: the EU-U.S. Data Privacy Framework, under which Vercel and Sentry are certified participants, and the European Commission's Standard Contractual Clauses, which are incorporated in our providers' data-processing terms — see the Supabase DPA, Vercel DPA, Sentry DPA, Resend DPA, and Umami DPA.

07

Data retention

We keep your information for as long as your account is active. If you ask us to delete your account (see Section 8), we delete or anonymize your personal information within 30 days, except where we must retain something to comply with the law or resolve a dispute. Residual copies may persist in encrypted backups for a short period before being overwritten.

08

Your rights and choices

You can ask us to:

  • Access the personal information we hold about you,
  • Correct inaccurate information,
  • Delete your account and personal information,
  • Export a copy of your data,
  • Object to or restrict certain processing, or withdraw consent where applicable.

During the beta, account deletion and data requests are handled by email — contact support@moviemash.app and we will action your request within 30 days. (Self-serve account deletion and data export are planned.) You can also change your display name and remove individual watched or watchlist entries yourself at any time, and you can unpair from a partner in Settings.

09

Security

We use reasonable technical and organizational measures to protect your information, including encrypted connections (HTTPS) and the access controls provided by our hosting platforms. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a data breach affects your personal information, we will notify you and any required authorities without undue delay, as required by law.

10

Children

Moviemash is not directed to children under 13 (or under 16 in the EEA, where a higher age of digital consent applies), and we do not knowingly collect personal information from them. If we learn that we have, we will delete it. If you believe a child has provided us information, contact support@moviemash.app.

11

California residents

We do not sell or share your personal information. If you are a California resident, you may request to know, delete, or correct the personal information we hold about you by emailing support@moviemash.app. We will not discriminate against you for exercising these rights.

12

Changes to this policy

We may update this policy as Moviemash evolves. We will post the updated version here with a new effective date, and for material changes we will provide notice through the Service or by email. Continued use after an update means you accept the revised policy.

13

Contact

The data controller for Moviemash is Anton Fomin (United States). Questions or privacy requests: support@moviemash.app.

Moviemash · Effective August 1, 2026