Privacy baseline

Your watch history belongs to you.

This implementation baseline describes the current system. A production operator must add jurisdiction-specific company and contact details before public launch.

Device-only by default

Guest tracking is stored in your browser and is not uploaded while you remain anonymous. Choosing guest mode creates a revocable anonymous session cookie; signing in with an account claims and syncs the device list.

No stored passwords

Email codes are short-lived and hashed. Session cookies are HTTP-only, same-site, revocable, and secure in HTTPS production.

Minimal account data

An account stores the email, profile settings, sessions, and tracking data required to provide the service. Browser caches are isolated per account so switching users does not merge watch histories.

Self-service deletion

Signed-in users can permanently delete their account and synced history from the account page. Leaving guest mode deletes the anonymous server identity while preserving the device-only list.

Retention and security

Active sessions can last up to 90 days and slide forward with use so regular viewers are not logged out unnecessarily. Users can revoke other sessions at any time. Rate limits, origin checks, CSRF defenses, restrictive browser headers, and encrypted transport reduce account abuse.

Optional diagnostics and analytics

There is no advertising or ad personalization. Self-hosted performance diagnostics and Google product analytics are separate, optional choices. Google Analytics is not loaded and sends no data before you allow product analytics. If allowed, Google receives a pseudonymous first-party browser identifier kept for up to 90 days, normalized route categories, session and engagement events, approximate country or region derived from the connection, language and coarse browser/device/platform information, acquisition information, and deliberately coarse product events. We do not send Google account identity, search terms, show or person identifiers, watch history, form input, request bodies, or authentication data. Advertising consent remains denied. Google Analytics event and user data is configured for two-month retention; Google is the analytics recipient and processor. If you separately allow self-hosted diagnostics, browser performance events, traces, and sanitized operational logs may include a capped search phrase after credential, email, network-address, and identifier patterns are masked. They also include the cloud region serving the same-origin diagnostics-context request, the three-letter Cloudflare processing/origin-connecting POP code, a coarse two-character visitor country code, and—when Cloudflare supplies it—a bounded subdivision code. The diagnostics-context region is a strong page/session proxy, not proof that every later API request used that region. Cloudflare routing features can change the POP, so it is not guaranteed to be the viewer ingress or nearest data center. These regional fields are issued to consented signed-in, guest, and anonymous browsers; they never include an IP address, full Cloudflare Ray ID, city, coordinates, or precise location. Signed-in and guest sessions may also receive a pseudonymous reference derived from the internal user ID so authorized developers can correlate a browser failure with its server requests. Raw email addresses and user IDs are not stored in diagnostics, and these diagnostic fields are not sent to Google Analytics. Self-hosted diagnostics currently use a reviewed 180-day retention baseline. That baseline changes only through a reviewed policy update; disk pressure or other operational conditions stop collection rather than silently shortening it. Replay, watch history, credentials, cookies, request or response bodies, and HTTP headers are excluded. The self-hosted pipeline removes client IP addresses and any unreviewed or precise geolocation before storage. Global Privacy Control and Do Not Track keep both optional purposes off.

Loading preferences…