01
Privacy Policy
How your data is handled
What you can do without an account
You can discover shows, view episodes, ratings, cast information, and streaming availability without creating an account.
Account information
When you continue with Apple or Google, TV Tracker receives an account identifier and, when provided by the sign-in service, your email address and name.
Your library content
Shows in your library, favorites, ratings, watched-episode progress, custom lists, and diary entries—including dates, ratings, and notes—are linked to your TV Tracker account. Your private diary is separate from a review you explicitly publish to the community.
Why it is used
Account information and library content support authentication, synchronization, restoration, personal recommendations, social features you use, moderation, security, and account deletion.
On-device storage
TV Tracker keeps a local SwiftData copy for fast launch and offline access. Cached posters, metadata, and ratings may also remain on the device until cleared by the app or iOS.
Search and show metadata
Search terms, show and episode identifiers, requested language, region, and ordinary network information such as an IP address may be processed by metadata providers to return requested content.
Profiles, followers, and profile photos
Your display name, profile photo, and follow relationships support people discovery and social features. An initial display name may come from your sign-in provider or email prefix; you can edit it in Profile. Public profiles expose selected favorites and summary counts. Private profiles require approval for new followers before they can see protected profile details. A private profile does not make a community review private.
Profile photos are optional and uploaded to Supabase Storage using the system photo picker. Avatar files use public URLs: anyone with the exact URL may access an image, even if your profile is private or you block someone. Blocking limits authenticated in-app visibility and interaction; it does not revoke copies or screenshots already saved by others.
Community reviews, ratings, and moderation
When you publish a show review or an episode reaction, its text, rating, timestamps, and author information may be visible to other users. Likes are linked to the account that submits them. Ratings contributed through the community-rating setting are stored with your account to maintain averages and prevent duplicate votes; they are not anonymous to TV Tracker.
You can report reviews or profiles and block users. Reports include the reporter and reported account or content identifiers, a reason, optional details, timestamps, and review status. We use this information to investigate abuse and enforce the community rules. Private diary text is not automatically published; any explicit community-sharing option creates a separate community contribution.
Friend activity and sharing choices
If activity sharing is enabled, new watch, library, favorite, rating, and review activity can appear in the feed of accepted followers. Settings → Community and Privacy → Share My Activity controls this feature. Turning it off stops new activity recording and hides existing activity from followers while it remains off. Previously recorded activity may become visible again if you enable sharing later. Existing private diary entries are not backfilled into the feed.
The activity-sharing control is separate from the community-rating control. Turning off a setting does not delete reviews you already published. Delete a review from its community screen or delete your account to remove associated content.
Recommendations, imports, exports, and notifications
Personal recommendations are calculated on your device from your library, ratings, genres, and viewing progress. Related show and genre requests are sent through our metadata proxy to obtain candidates. TV Time import files are parsed on the device; resulting library records synchronize with your account. Exported files are saved or shared only through the destination you choose.
Optional episode and recap reminders use local iOS notifications. Device settings control notification permission. The app does not use an advertising identifier or request permission for cross-app tracking. Performance diagnostics handled by MetricKit remain in local system logging in the current app; there is no app analytics upload pipeline.
Service providers
TV Tracker uses Supabase for authentication and account-linked cloud storage; Apple and Google for sign-in; TMDB and OMDb for show metadata, images, and external ratings; and TMDB's JustWatch integration for regional streaming availability. Their own privacy and retention practices also apply.
TV Tracker uses TMDB under its non-commercial developer terms and displays the required TMDB notice and logo in the app. TMDB states that it collects API usage data, search information, and indirect identifiers such as IP addresses; see the TMDB privacy policy. Streaming availability is supplied through TMDB's JustWatch integration with visible JustWatch attribution. External IMDb ratings are retrieved through the OMDb API by Brian Fritz; OMDb content is available under the CC BY-NC 4.0 license. See the OMDb terms.
Sharing, tracking, and retention
TV Tracker does not sell personal data and does not contain advertising, data-broker, or cross-app tracking SDKs. Data is shared with service providers as needed to operate these features, and with other users according to your profile, publication, and activity-sharing choices. Account-linked data is retained while your account remains active or as needed to provide the service, protect the service, and meet legal obligations.
Your choices and deletion
You can export your library, remove individual items, clear downloaded metadata, sign out, or permanently delete your account in Profile → Delete Account. Account deletion removes the TV Tracker account and associated cloud library, diary, custom lists, profile, uploaded avatar files, follow/block relationships, reviews, likes, reports tied to the account, and activity records. Apple-linked accounts require Apple reauthorization so the app can revoke the sign-in authorization. Service-provider backups and operational logs may remain subject to their retention practices; saved copies held by other users are outside our control. Local personal data is removed from the device when you sign out or delete the account.