LEGAL
Privacy Policy
Effective date: June 30, 2026
Spoilrs ("we", "us", or "our") is committed to protecting your privacy. This policy explains what information we collect, how we use it, and your rights regarding that data. By using Spoilrs you agree to these terms.
1. Information We Collect
We collect the following categories of information:
- Account data — email address and display name when you create an account.
- Authentication tokens — securely stored session tokens to keep you signed in (via Supabase).
- Usage data stored locally — your watchlist, spoiler history, and stories read are stored on your device using AsyncStorage / localStorage.
- OAuth profile data — if you sign in with Google or Apple we receive your name and profile picture as provided by those services.
- Log data — standard server logs including IP address, browser type, and pages visited, retained for up to 30 days.
2. How We Use Your Information
- To authenticate you and maintain your session across devices.
- To sync your watchlist and preferences when you are signed in.
- To improve the app by analysing aggregate usage patterns (never individual behaviour).
- To send transactional emails (e.g. email confirmation) — no marketing without your explicit consent.
3. Movie Data & Third-Party APIs
Movie posters, metadata, cast information, and ratings are fetched from The Movie Database (TMDB). Spoiler content is generated by AI models and cached in our Supabase database. We do not share your personal data with TMDB.
YouTube trailer links are opened in an external browser or embedded via iframe; your interaction with YouTube is governed by Google's privacy policy.
4. Data We Do NOT Collect
- We do not collect payment information (no in-app purchases currently).
- We do not track your location.
- We do not use advertising SDKs or third-party analytics trackers.
- We do not sell, rent, or broker your personal data to any third party.
5. Data Storage & Security
Account credentials and session tokens are stored in Supabase (hosted on AWS in the EU-West-1 region) with row-level security enabled. Sensitive tokens on native devices are stored in the device's secure keychain via expo-secure-store.
We use HTTPS/TLS for all data in transit. We regularly review our security practices, but no method of transmission over the internet is 100% secure.
6. Children's Privacy
Spoilrs is not directed at children under 13 (or 16 in the EU/UK). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us immediately at privacy@spoilrs.com and we will delete it.
7. Your Rights
Depending on your location you may have the following rights:
- Access — request a copy of your personal data.
- Correction — update your display name via the profile tab at any time.
- Deletion — delete your account from Profile → "Delete Account". This removes your Supabase record immediately.
- Portability — request an export of your data by emailing us.
- Opt-out — clear your local spoiler history from the Profile tab at any time.
To exercise any right, email privacy@spoilrs.com. We will respond within 30 days.
8. Cookies & Local Storage
On web we use localStorage to persist your authentication session. We do not use advertising cookies or third-party tracking cookies. You can clear local storage at any time via your browser settings.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via an in-app notice or email. Continued use of the app after changes constitutes acceptance of the updated policy.