Privacy Policy
1. What we store
- Account: your email address, display name, and password (stored only as a bcrypt hash — we cannot read it). Optionally an avatar image URL you provide.
- Your library: shows you track, per-episode watch progress, ratings, reviews, and notes.
- Taste data: taste tags you pick, feedback you give on recommendations (including free text), and the taste profile ("Show DNA") we derive from all of it.
- Friends: friend connections, requests, and the messages, reactions, and show recommendations you exchange with friends.
- Safety records: the accounts you block, and the reports you send us (who you reported, where from, and any reason text you write). Your block list is visible only to you; reports — including your identity as the reporter — are visible only to the service operator. Neither is ever shown to the person concerned.
- Streaming setup: which streaming services you say you have, and any costs or renewal dates you choose to enter.
- Preferences: notification and email digest settings, appearance settings, pacing plans.
- Push subscriptions: only if you turn on browser notifications.
- Sign-in history: when you sign in, we record the time and a coarse device family (for example "iPhone" or "Windows") so you can review your own recent sign-ins in Settings → Account. We do not record your IP address, your location, or what you do in the app. Sign-in records are deleted after 90 days. Account-security events (password changes, account deletion) are kept as permanent audit records.
- Operational records: server request logs (kept briefly by our hosting provider), AI usage counters per account, and administrative audit records.
- Marketing signup (optional): if you leave your email address on one of our public pages to hear about updates, we store that address, which page it came from, and when. We don't send anything to it yet — a confirmation step will come before any update email does. Deleting an account removes any stored marketing signup for that account's email address; if you never create an account, contact us at any time to have your address removed.
- How you found us: when you create an account, we record the campaign tag on the signup link (for example a "ref" value from one of our own pages) and the address of the referring page, without its query parameters. Recorded once at signup, never updated afterwards.
2. What we don't do
- No card data. When paid plans exist, payment details go directly to Stripe. Card numbers never touch our servers.
- No ads, no ad tracking, no data brokers. There is no advertising SDK, no tracking pixel, and no sale or sharing of your data for advertising. Our revenue model is subscriptions, not you.
- No training on your data. We do not train AI models on your data, and we use AI providers under API terms that state your inputs are not used to train theirs (see section 4).
3. Cookies, local storage, analytics
- One essential cookie:
__Host-bw_session(namedbw_sessionin local development), an HttpOnly session cookie that keeps you signed in. No third-party cookies are set by us. - Your browser's local storage holds convenience hints (your theme choice, last-sync time). They never leave your device.
- Analytics: Cloudflare Web Analytics, which is cookie-less and does not build individual profiles or track you across sites. We see aggregate page-view counts, not who you are.
4. AI processing
Recommendation, taste-profile, recap, and search features are powered by an external AI provider, OpenAI. What gets sent to them: show metadata, your taste signals (liked shows, tags, ratings), and free text you write into AI-backed features (reviews and feedback, vibe searches, questions you ask). OpenAI states in its API terms that data submitted through the API is not used to train their models. We cache AI outputs so the same question isn't asked twice.
5. Service providers
These companies process data to run BingeWise, each only for the purpose listed:
| Provider | Purpose | What they handle |
|---|---|---|
| Fly.io | Hosting (US) | The application and its database run there |
| Cloudflare | DNS, proxy, cookie-less analytics, backup storage (R2) | Traffic passes through their network; encrypted-at-rest backups |
| Resend | Email delivery | Your email address and the digest/announcement content we send you |
| OpenAI | AI features | Show data, taste signals, free text you write (section 4) |
| Stripe | Payments (when paid plans launch) | Payment details, billing email — handled entirely by Stripe |
| Sentry | Error monitoring (only when enabled) | Error reports with stack traces and request metadata — not your library or messages |
Some content loads directly from third parties in your browser: posters and photos from TMDB and TVmaze image servers, avatars from Gravatar if you set a Gravatar URL, and — only when you press play on a trailer or recap — an embedded YouTube player (Google's privacy policy applies to that playback). Like any web request, those hosts see your IP address.
6. What friends can see
BingeWise is not public: only people you accept as friends see anything about you, and Settings → Sharing controls exactly what (ratings, reviews, activity, and so on — the defaults are conservative). Your export never includes other people's data, and theirs never includes yours beyond what you sent them.
Blocking someone ends the friendship, hides your activity from each other, and prevents new contact in both directions. The other person is not notified, and unblocking does not restore the friendship.
7. Export, deletion, retention
- Export: Settings → Data & privacy → "Export my data" downloads a complete JSON copy of everything you've put in: profile, preferences, your shows with ratings and reviews, episode-level watch history, rewatches, taste feedback, followed actors, pacing plans, streaming-service states, your friend list (as account ids) with the recommendations, messages, and reactions you sent, and import history (including saved movie rows). You can export everything at any time, on every plan, free.
- Deletion: Settings → Account → "Delete account" removes your account and your data — profile, library, taste data, friend links and messages, alerts, caches, usage counters, sign-in history, and any marketing signup stored for your account's email address — in a single immediate database transaction. There is no recovery, so export first if you want a copy.
- Backups: deleted data ages out of our encrypted backups within about 7 days (continuous backups are kept 72 hours; daily snapshots about 5 days).
- What can outlive deletion: short-lived server request logs; payment and administrative audit records where we are required to keep them; a minimal record that the account was deleted (internal account id, time, and coarse device family — no email, no name, no library data); and cached AI text analyses that are keyed to the text itself, not to your account. Emails already delivered to you remain in your inbox and in our email provider's sending logs.
8. Security
All traffic is HTTPS. Sessions use an HttpOnly cookie. Passwords are hashed with bcrypt (cost 12) and are never stored or logged in plain text. Backups are stored encrypted at rest. No security is perfect — if we ever discover a breach affecting your data, we will tell you what happened and what we are doing about it.
9. Children
BingeWise is not directed at children under 13, and we do not knowingly keep accounts for them. If you believe a child under 13 has an account, email us and we will delete it.
10. Changes and contact
When this policy changes, the version and effective date at the top change with it, and we will flag material changes in-app or by email before they take effect. Questions or requests about your data: [email protected].