1. Data we process
- Account data: email, sign-in method, display name, and security records.
- Profile data: avatar, bio, birthday, gender, and preferences when you choose to provide them.
- Film and TV data: watch history, per-season TV status, per-episode playback progress, ratings, reviews, lists, persona data, and recommendation feedback.
- Viewing platforms: platform stats are enabled by default. Automatic scrobbles save only the standardized platform name with the corresponding watch entry and summarize it in your personal viewing overview. You can turn this off in Settings at any time; doing so removes platform information from those entries.
- Browser extension viewing data: on supported playback pages, the extension reads film or show titles, season and episode numbers, page details, and playback progress to identify what you are watching. When you are signed in and an automatic scrobble is triggered, the corresponding watch entry and standardized platform name are saved to your CinePersona library and personal viewing overview; unrelated browsing history is not logged. Douban sync uses the current browser session only after you initiate a sync to request your own marks from Douban. Douban cookie values and passwords are not sent to CinePersona or unrelated third parties or stored as import data. Cloud writes require your separate confirmation.
- Social data: matches, public profile fields, chats, reports, and blocks.
- Connection and device data: Trakt authorization, push tokens, sessions, IP, device, and error logs.
- Media server plugin data: after you connect your account in the Jellyfin or Emby plugin with a device code or API key, the plugin reports the film or show title, season and episode numbers, and playback progress you play, to sync your watch history. It does not read media file contents.
- Extension connection records: when a signed-in account connects to CinePersona through the extension, we retain its first and most recent extension connection times and extension version for connection diagnostics and account-level usage statistics. These records survive sign-out and are retained until account deletion. We do not generate anonymous installation identifiers, upload additional browsing history, or use periodic heartbeats. These records do not prove that the extension is still installed.
2. AI analysis and third-party services
When you actively generate an AI taste report, the data needed for the report—such as watch history, ratings, review summaries, and persona data—may be sent to the model provider you selected. You can choose a provider, disable fallback services, or withdraw AI authorization in Settings.
Possible recipients of website data include the model provider you select (System, Gemini, OpenAI, DeepSeek, Qwen, or a custom endpoint), Trakt when you connect it, TMDB or other movie-data services used for lookup, Google or Microsoft for sign-in, and browser Web Push services. Each feature calls only the services it needs; we do not send unapproved movie or social data to these services in bulk.
Website notifications use browser Web Push. Expo configuration in the mobile source belongs to the mobile build path and is not a recipient of website data. If mobile system notifications are enabled in the future, their processing will be disclosed separately in the mobile app.
Trakt sync, push notifications, and public profile/matching each use separate authorization. Third parties process received data under their own policies; you are responsible for checking the terms, region, and retention policy of a custom model endpoint.
3. Imports and film and TV data
You may upload or import Douban, IMDb, Letterboxd, Trakt, or other platform exports that you have the right to use. Imports are used to match films and TV seasons, build watch history, and generate your profile; TV rows that cannot be matched automatically are kept so you can pick the show yourself or ask an administrator to help with that single row; do not upload credentials or data you are not allowed to migrate. Posters, summaries, ratings, and people data may come from third-party film and TV data services (TV metadata mainly from TheTVDB and TVmaze, external scores via OMDb) and are subject to their terms and availability; see Data sources.
4. Purposes and retention
We use data to provide sign-in, watch history, persona, recommendations, matching, chat, sync, support, and abuse-prevention features. Data is retained only as long as needed for these purposes. After account deletion, account-linked data is deleted except records that must be retained for legal, security, or audit reasons.
5. Your choices and rights
- Review, change, or withdraw optional authorizations in Settings.
- Disconnect Trakt, delete push tokens, and turn off public profile or matching.
- Download a copy of core account, list, watch-history, and saved platform statistics; submit a privacy request for access to, correction of, or details about other data.
- Start account deletion in the App, or use the deletion guide and support contact.
View account deletion instructions · Export my data · View community guidelines · Contact support
6. Contact and updates
For privacy requests, deletion, or security issues, contact [email protected]. We will update the version date here when this policy changes and request confirmation in the App for material changes.