Privacy Policy
Effective 1 October 2026 · version 2026-10
In short. We only collect what the app needs to work: your account, what you watch and what you share with friends. We don't sell your data, we don't show ads and we don't build advertising profiles. You can export your data or delete your account at any time from the app.
1. Who is responsible for your data
Andrea Caselli, Italy (data controller). Contact for any privacy request: [email protected].
This policy covers the Showmates app for Android and the showmates.app website.
2. What we collect
Account
- Email address and password. The password is handled by the sign-in service (Supabase Auth) and stored only in hashed form: we never see it.
- If you sign in with Google: your Google email address, name and profile picture.
- Username, app language, public or private profile choice, date and version of the accepted terms.
Profile (optional)
- Profile photo and bio, if you choose to add them.
What you do in the app
- Shows, anime and movies you follow, episodes and movies watched with their date, ratings, reviews, lists and the streaming services you subscribe to.
- Social activity: people you follow and who follow you, follow requests, blocked users, reactions, watch pacts and their notes, group picks ("Pick together").
- Games: challenges, tournaments, quizzes, the daily challenge, scores and messages exchanged in challenges.
- The 👍/👎 votes you give to content generated by the app and which content you've already seen, so we don't show it again.
- Reports you send or that concern your content.
Netflix import (optional)
If you import your Netflix history, the file is read on your phone. Only the titles reach our servers, to recognise them; the recognised ones are added to your history.
Device data
- A push notification identifier (Firebase Cloud Messaging), if you allow notifications.
- Crash reports (Firebase Crashlytics) when the app closes because of an error: phone model, Android and app version, technical details of the error and an installation identifier. They don't contain your name or email. You can turn them off in your Profile ("Send error reports").
- The country used for streaming services, taken from your phone's settings.
- Technical server logs (for example IP address and time of requests), kept by our providers for security.
We don't collect your location, contacts, microphone or any other phone data.
3. What other users can see
- Your username, photo and bio are visible to other users.
- With a public profile anyone using the app can see what you watch, your reviews and your stats. With a private profile only the people you approve can.
- People in a watch pact or a challenge with you see the progress the game needs. Leaderboards show username and score.
- You can block anyone: blocked people no longer see your profile and can't contact you.
4. Why we use it and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and managing your account, running the app and its social and game features | Performance of the contract (the Terms of Use) |
| Service emails: verification and password recovery codes | Performance of the contract |
| Push notifications | Your consent, given through the Android permission and revocable at any time |
| Security, abuse prevention, usage limits, handling reports | Legitimate interest in protecting users and the service; legal obligations |
| Crash reports to fix bugs | Legitimate interest; you can object by turning them off in your Profile |
We don't send promotional emails and we don't use your data for advertising.
5. Artificial intelligence
The recap ("Previously on…") and some quiz questions are written by an AI model (Groq) from public texts: TVmaze episode summaries and Wikipedia movie plots. We send the AI only the title and these public texts, never personal data. AI-written content may contain mistakes: you can flag it with 👎.
6. Who processes data for us
We use these providers, who process data on our behalf and only for the purposes above:
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, sign-in, files (profile photos), server functions | European Union (Frankfurt) |
| Google Firebase | Push notifications and crash reports | EU and USA |
| Sign in with Google, if you use it | EU and USA | |
| Resend | Sending the emails with codes | USA |
| Groq | Artificial intelligence (no personal data) | USA |
| The Movie Database (TMDB) | Show and movie data and images. Your phone downloads images directly from TMDB, which therefore sees your IP address | USA |
| Cloudflare, GitHub | The showmates.app domain, forwarding of emails sent to support, hosting of this website | EU and USA |
When data leaves the European Union, the transfer relies on the European Commission's adequacy decision (EU-US Data Privacy Framework) for certified providers, or on the standard contractual clauses approved by the Commission.
We don't sell or hand over your data to third parties. We may disclose it to authorities only when the law requires it.
7. How long we keep it
- As long as you have an account. When you delete it we immediately delete the account and all related data, profile photos included.
- Technical copies in our providers' backup systems may remain for a limited time, then they are overwritten.
- Moderation reports may keep a copy of the reported content, no longer linked to your account, to handle abuse and for legal protection.
- Crash reports are kept by Firebase for 90 days.
8. Your rights
You can ask us at any time to access, correct or delete your data, to restrict or object to its processing, or to receive it in a readable format (portability). Many of these you can do directly in the app:
- Edit profile, photo, bio and privacy: in your Profile.
- Export your history: Profile → "Export my data".
- Delete your account: Profile → "Delete account and data", or as explained on the Delete account page.
For anything else write to [email protected]: we reply within 30 days. You also have the right to lodge a complaint with a data protection authority, in Italy the Garante per la protezione dei dati personali (garanteprivacy.it).
9. Minimum age
Showmates is meant for people aged 16 and over. If we find out that an account belongs to someone younger, we delete it.
10. Security
Connections are encrypted (HTTPS). In the database each person can only read the data they're entitled to, and passwords are handled by the sign-in service in hashed form. No system is 100% secure: if a breach affecting you ever happens, we'll notify you as the law requires.
11. Changes
If we change this policy we update the date at the top. If the changes are significant we'll tell you in the app.
12. Contact
Andrea Caselli · [email protected]