1. Who is responsible

Karsten Breit is the controller for the processing described here.

Contact for privacy and data-subject requests: privacy@filmspotter.app

2. What we collect, why, and on what legal basis

  • Account and authentication data — your email address, the one-time login codes sent to it, and the resulting session. Necessary to provide the service you signed up for (Art. 6(1)(b) GDPR).
  • Wrong login-code attempts — the originating IP address and email, kept only long enough to throttle repeated guesses. Legitimate interest in preventing abuse of the login mechanism (Art. 6(1)(f) GDPR).
  • Account-deletion codes — a one-time code sent to your own address to confirm you want to permanently delete your account, kept for at most fifteen minutes. Necessary to provide the deletion feature you asked for (Art. 6(1)(b) GDPR).
  • Admin user overview — visible only to the operator: account identifiers, registration and last-seen timestamps, and account status. Legitimate interest in operating and moderating the service (Art. 6(1)(f) GDPR).
  • Audit log — a record of account and administrative actions (who did what, and when). Legitimate interest in accountability and security (Art. 6(1)(f) GDPR).
  • Availability news items — a per-user history of "movie X gained offer Y" events for titles you follow, including a snapshot of the offer (provider, logo, monetization type) as it looked when the event was recorded. This is a core part of the in-app inbox and has no opt-out. Legitimate interest in showing you updates about the movies you follow (Art. 6(1)(f) GDPR).
  • Notification preferences — whether you've turned on browser push or the weekly digest email. Each setting records when you last turned it on or off, and the version of the consent text shown when you enabled it. Both channels are opt-in and can be withdrawn at any time. Consent (Art. 6(1)(a) GDPR).
  • Push-subscription data — if you enable browser push, the endpoint URL and cryptographic keys your browser issues for that device, used to address and encrypt notifications sent to it. Consent (Art. 6(1)(a) GDPR).

3. Who else receives data, and where

  • Hosting. The application and its database run on a virtual server operated by netcup, in an EU data centre (Nuremberg, Vienna, or Amsterdam depending on the booked location). No transfer outside the EU/EEA is involved in hosting.
  • Email delivery. Login codes and account mail are sent through IONOS's SMTP service (smtp.ionos.de), a German provider, acting as our processor.
  • Streaming Availability API. Movie, provider, and availability data comes from this third-party API. Requests to it carry a country code and the movie or search terms you look up — no account identifier or email address is sent.
  • YouTube trailers. Trailers are embedded from youtube-nocookie.com, YouTube's privacy-enhanced mode, which does not set tracking cookies until you actually press play. Opening a trailer connects you directly to Google; see Google's privacy policy.
  • Movie posters and provider logos. Images are loaded directly from cdn.movieofthenight.com and media.movieofthenight.com. As with any hotlinked image, loading a page discloses your IP address to that host.
  • Browser push relay services. If you enable browser push, delivering a notification routes it through your browser vendor's push relay — Google's FCM for Chrome/Edge, Mozilla's service for Firefox, or Apple's for Safari, depending on which browser you subscribed from. The notification content is encrypted before it leaves our server, so the relay only ever handles ciphertext — it cannot read the movie title or offer details inside it.

4. Cookies and local storage

FilmSpotter runs no analytics and no tracking scripts. The only browser storage in use today is:

  • moviefinder_session (cookie, HttpOnly, SameSite=Lax, up to 30 days) — keeps you signed in. Strictly necessary to provide the service you asked for, so it does not require consent (§ 25(2) no. 2 TDDDG).
  • moviefinder-theme-mode (local storage) — remembers your day/night display choice. Storage exists only because you explicitly set this preference, so it falls under the same necessity exception (§ 25(2) no. 2 TDDDG).

Because everything above is strictly necessary or exists solely to honor a choice you made, no consent banner is shown. If that changes — for example, when advertising is introduced — nothing non-essential will run before you have given consent, and this notice will be updated first.

5. How long we keep data

Several of the rows below are removed by a scheduled clean-up rather than the moment they expire — the same mechanism the audit log already used. That scheduler is part of the hosting infrastructure and is not yet wired into production, so until it is, a row may persist a little past the window stated for it.

  • Account, library, and settings data: for as long as your account exists.
  • Wrong login-code attempts: deleted after about an hour, the same throttle window they are counted within.
  • Account-deletion codes: expire after fifteen minutes and are deleted immediately when an account is deleted with them, along with any older ones for the same account. A code nobody ever confirms is also removed after one day regardless.
  • Login codes: removed after one day — comfortably past both the 30 minutes a code stays valid and the 15-minute window afterward to finish registering with it — whether or not the code was ever used.
  • Audit log: kept for 180 days.
  • Availability news items: once you've read one, it is deleted after 90 days. An item you never read is deleted after 180 days regardless, so nothing is kept indefinitely.
  • Expired sessions: the session row behind an expired moviefinder_session cookie is removed by the same scheduled clean-up.
  • Notification preferences: kept for as long as your account exists.
  • Push-subscription data: turning push off or unsubscribing a device deletes the endpoint URL and cryptographic keys immediately — not only when your account is deleted. The bare fact that a subscription once existed, and when, is kept until account deletion.

6. Your rights

You have the right to access, correct, restrict, or object to the processing of your data, and to receive a copy of it in a portable format (Art. 15–21 GDPR).

Deletion. Signed-in accounts can permanently delete themselves at any time from Settings, after confirming a code sent to the account's own address. This removes your account, movie list, provider subscriptions, recommendations, sessions, API tokens, availability news items, notification preferences and push subscriptions immediately. If you can't sign in, email the contact address above instead and we will delete your account data by hand — except anything we are legally required to keep for longer.

You may also lodge a complaint with a data protection supervisory authority — in particular in the EU/EEA member state of your habitual residence, your place of work, or the place of the alleged infringement (Art. 77 GDPR).

7. Changes to this notice

This page reflects what the application actually does today. As features change — most notably once advertising is added — this notice is updated to match before those changes go live.