← Back to Home

Privacy Policy

Last updated: August 10, 2026. What we collect, why, and how you take it away.

1. Data Controller

Data processing is managed by Episodely, an independent one-person project. We handle your data in compliance with the European Union General Data Protection Regulation (GDPR). For anything concerning your data, write to support@episodely.tv.

2. What we collect

Only what the service needs to work. None of it feeds advertising profiling — there are no ads on Episodely.

  • Account: your email address, a user identifier we generate, and your first and last name if you choose to add them. If you sign in with Google we receive your email, name, and profile picture from your Google account; we never receive your password.
  • Profile: your public handle, bio, and profile picture if you upload one. That picture is served from a public address: anyone with the link can see it.
  • Your library: shows and movies you follow, episodes marked as watched with the check-in date and time, watchlist, ratings, custom lists, and viewing preferences.
  • What you post: comments, reactions, images attached to comments, character votes, and reports you submit.
  • Your social graph: who you follow, who follows you, and users you block.
  • TV Time import: the file you upload (GDPR ZIP, Liberator JSON, or CSV) and what we extract from it — watch history, comments, and your friends list as numeric identifiers, when present. See section 5.
  • Service usage: technical events about which screens you open and which actions you complete, tied to your user identifier. We use them to find where the product breaks, not to build an ad profile.
  • Crash diagnostics (mobile): if the app crashes, we automatically send a technical message and the call sequence (stack trace) at the moment of the crash — even before you've signed in, so we can see where the first launch breaks. We don't include your email, password, or anything you typed: that data is minimized on purpose. If you were signed in it stays linked to your account; otherwise it stays anonymous. When the app shuts down abruptly there's no call sequence to send: at the next launch we send the app version and the kind of screen you were on — “a show page”, not which show.
  • Notification preferences and, if you turn them on, the device tokens needed to deliver them. If you opt in at sign-up (or later in Settings), also your consent to product emails — mobile app launch and important Episodely news.
  • Waitlist: if you joined the waiting list before having an account, the email you left and where the link came from. It's separate from your account — see section 8.

3. Why we process it, and on what legal basis

  • To run the service — account, library, comments, the notifications you asked for, and importing your watch history from TV Time when you choose to use it after signing in. Basis: performance of our contract with you.
  • To keep it safe and usable — moderating reported content, anti-abuse limits, error diagnostics. Basis: legitimate interest in a service that doesn't break and doesn't turn hostile.
  • To meet legal obligations — in particular the child sexual abuse material reporting duties described in section 6. Basis: legal obligation.
  • For features that need your consent — the TV Time friend rematch (section 5), push notifications, and product emails (app launch, news) if you asked for them. Basis: consent, which you can withdraw any time from Settings → Notification preferences.

We don't sell, trade, or share your data with third parties for marketing or advertising. There are no ads in the product, and none are planned.

4. Who processes data on our behalf

Episodely runs no data centers of its own. It relies on providers that process data on our instructions — these, and no others:

  • Supabase (database, authentication, file storage) — European region.
  • Vercel — running the application.
  • Cloudflare — delivering user-uploaded images, with the scanning described in section 6.
  • Resend — sending transactional email (confirmations, access notices) and, only if you consented, product emails (e.g. “the mobile app is out”).
  • TMDB and JustWatch — show and movie metadata, posters, and streaming availability. They receive the content request, not your identity.

Data and files live on servers in the European Union. Some of these providers operate global networks: where a transfer outside the EU is technically unavoidable, it happens under the standard contractual clauses adopted by the European Commission.

5. "Reunite with your TV Time friends" feature

Your TV Time GDPR export may contain your friends list. If you choose to enable this feature (it requires your explicit consent at import time), Episodely uses only pseudonymous numeric identifiers — your TV Time user ID and those of your friends — to check whether anyone on your list has also joined. We do not extract or store your friends' emails, names, or any other personal data. Matching only happens between users who have both registered on Episodely and uploaded their own export: when a match is found, both users receive a suggestion to follow each other again. You can disable the feature at any time; the identifiers are permanently deleted together with your account.

6. Images: what happens to the ones you upload

Before anything is sent, your browser resizes and re-encodes the image: EXIF metadata, GPS location included, never leaves your device.

The bytes are then analyzed by an automated classifier before anything is stored. If the image is rejected it isn't kept anywhere — only a technical fingerprint of the file (a hash) and the reason for the rejection remain, so we can answer you if you dispute the decision.

Published images are delivered through Cloudflare, which automatically compares their fingerprints against databases of known child sexual abuse material. It's a fingerprint check, not a human reading your content. On a match, the law requires us to block the content, preserve what the authorities need, and file a report: it's the one case where your data reaches an authority without you asking.

7. Security and retention

Every uploaded file sits in an isolated folder tied to your account, so it can't be read by other users or mixed up with someone else's. Import files and rejected images are short-lived by design. Everything else stays as long as you keep your account: we don't hold your data longer than you want to hold it. Bug reports are an exception, since they aren't tied to an account you can delete (some arrive before you've even registered): we keep them for at most 12 months from submission, then delete them automatically.

8. Deleting your account, and what actually goes

You can delete your account yourself, without asking anyone: Settings → Privacy → Delete account. You'll be asked to type DELETE to confirm. It's permanent, and there's no trash to recover it from.

Gone in the same moment: your profile and profile picture, shows, movies and watched episodes, lists and watchlist, comments, reactions and attached images, follows and blocks, preferences and notifications, your import data, and your TV Time friend identifiers.

Two caveats, so that "everything" stays an honest word. Bug reports you sent us remain, but lose their link to you: they exist to fix problems that affect everyone. And if you joined the waitlist before having an account, that email lives in a separate list untouched by account deletion — write to support@episodely.tv and we'll remove it.

9. Your rights

Under GDPR you can access your data, correct it, ask for its deletion or export, object to processing based on legitimate interest, and withdraw consent you previously gave. Exporting your library is available in the app, free and forever. For everything else write to support@episodely.tv: we answer within one month, as the regulation requires. You also have the right to lodge a complaint with your country's supervisory authority.

10. Minimum age

You must be at least 13 to create an account, or the minimum age required in your country if it's higher. We don't knowingly collect data from children below that age: if we find out we have, we delete the account.

11. Changes

If we change this policy in a material way, we change the date at the top and tell you before it takes effect. Episodely is in beta and the product moves: this page moves with it.