Privacy Policy
Effective 1 September 2026
TV Binge Diary is a private diary for the TV you watch. This policy describes everything the service collects, why, who else touches it, how long it is kept, and what you can make us do with it. The short version: we collect only what the diary needs to work, we run no advertising and no analytics, we do not track you across other apps or sites, and we never sell or share your personal data.
One thing is worth reading before the rest, because it is the only part of the service other people can see: comments are public. Everything else — the shows you follow, what you have watched, the ratings you leave — is private to your account.
Who is responsible for your data
TV Binge Diary is operated by Geri Luga, a sole trader established in Albania, who is the data controller for the purposes of the EU and UK General Data Protection Regulation. You can reach us at any time at g.luga@codevider.com, and we answer privacy requests within 30 days.
What we collect
Because you gave it to us
- How you sign in. Either an email address and a password, or a phone number. They identify your account and nothing else — we send no marketing of any kind. Passwords are hashed by our authentication provider and are never visible to us, and one-time codes are generated and sent by our messaging provider.
- Your handle. A unique name between three and twenty characters, chosen once when you join. It is shown beside every comment you write, so choose it accordingly. It is public.
- Profile settings. An optional display name — shown beside your handle on your comments, so also public — and the timezone your schedule is drawn in, which is private.
- Your diary. The shows you follow, the status you give each one, the episodes you mark watched, the ratings you leave on shows and episodes, and the recommendations you dismiss. All private.
- Comments. What you write in a show or episode discussion, which comments you like, and any report you file about somebody else's comment. Comments and likes are public; a report is seen only by us.
- Blocks. The accounts you have blocked. Private — the person you blocked is never told.
Because the software creates it
- A push token, if you turn alerts on. An identifier for one installation of the app, issued by Apple or Google. It is created only when you enable episode alerts, and it is deleted when you turn them off, when you sign out on that device, and when you delete your account.
- Rate-limit counters. A count of recent requests against your account, so that no one account can exhaust the service for everybody. Counters hold numbers and timestamps, never the content of what you asked for.
- Technical logs. Our hosting, database, and content-delivery providers record connection data — IP address, timestamp, the path requested, and the browser or app version — to deliver responses and to detect abuse. We do not join those logs to your diary, and we do not use them to build a profile of you.
What we do not collect
There is no advertising software, no analytics software, and no third-party tracking software anywhere in the website or the app. We do not collect your location, your contacts, your photos, your calendar, your device's advertising identifier, or anything about what you do in other apps. We do not build advertising profiles, and we do not take part in any cross-context behavioural advertising. Under Apple's definition, the app carries out no tracking at all, which is why it never asks you for tracking permission.
Why we are allowed to hold it
If you are in the EEA or the UK, the GDPR requires us to name a legal basis for each purpose. Ours are:
- To provide the service you asked for — signing you in, storing your diary, drawing your schedule in your timezone, showing discussions, and honouring your blocks. Legal basis: performance of a contract (Art. 6(1)(b)).
- To send episode alerts — only after you switch them on. Legal basis: your consent (Art. 6(1)(a)), which you withdraw by switching them off.
- To keep the service working and safe — rate limits, abuse prevention, acting on reports, and security logging. Legal basis: our legitimate interests in running a service that is not degraded or overrun (Art. 6(1)(f)).
- To show community averages — a title's average rating, computed across accounts. Legal basis: legitimate interests, and an average is published only once enough people have rated a title that no individual's rating can be worked out from it.
- To answer you and to meet legal duties — replying to support and privacy requests, and keeping what the law requires us to keep. Legal basis: legitimate interests and legal obligation (Art. 6(1)(c)).
Nothing in the service makes an automated decision that produces legal or similarly significant effects for you. The “Recommended for you” shelf ranks shows from the ones you follow, rate, and drop; it is a sorted list of television and nothing turns on it.
Who else touches your data
We use a small number of providers to run the service. Each is bound by a data-processing agreement, each may use your data only on our instructions, and none of them is permitted to use it for their own purposes. This is the complete list:
- Supabase — the database and the authentication system. Holds your account, your diary, and your comments.
- Render — hosting for the server that answers the website and the app. Sees requests in transit and keeps short-lived access logs.
- Cloudflare — storage and delivery of series artwork, and a cache in front of it. Sees the requests for images, which carry an IP address; artwork requests are not tied to your account.
- Twilio — sends the one-time code when you sign in with a phone number. Receives the phone number and nothing else, and only at the moment a code is sent.
- Expo, Apple, and Google — carry episode alerts to your device, if you turn them on. They receive the push token and the text of the notification, which names a show and an episode.
- An email provider — sends confirmation and password-reset messages. Receives your email address and the message.
Series names, artwork, summaries, and air dates come from TheTVDB. That traffic runs one way: we ask them about television, and your searches, your diary, and your identity are never sent to them.
Beyond that list, we disclose personal data only where the law compels it — a valid order from a competent authority — or to establish or defend a legal claim. If the service is ever sold or transferred, your data would move with it, and we would tell you here first. We do not sell personal data, and we never have.
Where your data goes
Our servers and our providers are in the United States and the European Union, so if you are in the EEA or the UK your data is transferred out of it. Those transfers rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where the UK GDPR applies), which our providers have entered into with us, together with encryption in transit and at rest. Ask us at g.luga@codevider.com if you want the details of a particular transfer.
How long we keep it
- Your account and your diary — until you delete your account. There is no inactivity sweep; a diary you do not open for two years is still yours.
- Comments — until you delete them, we remove them under the Community Guidelines, or you delete your account, whichever comes first.
- Reports you file — kept while the report is being handled and for up to 12 months afterwards, so that a repeated pattern is visible rather than starting from zero each time.
- Push tokens — until alerts are switched off, the device stops accepting them, or the account is deleted.
- Technical logs — kept by our providers for up to 30 days, then rotated out.
- Backups — infrastructure snapshots that expire on their own within 30 days. Deleted data disappears from them as they roll over; we do not restore an account out of a backup.
Your rights
Wherever you are, you can ask us to do all of the following, and we will not charge you for it or treat you any differently for asking. If you are in the EEA or the UK these are rights under Articles 15 to 22 of the GDPR; if you are in California or another US state with a privacy law, they are the equivalent rights there.
- See what we hold and get a copy of it in a portable, machine-readable form.
- Correct anything that is wrong. Your display name and timezone you can change yourself on the Profile screen; write to us for a handle, which is fixed once claimed so that a comment cannot change signature after the fact.
- Delete everything. Do it yourself from the Profile screen, in the app or on the website — see deleting your account.
- Restrict or object to a particular use, including anything we do on the basis of legitimate interests.
- Withdraw consent to episode alerts at any time, by turning them off. Withdrawing does not undo what was sent before.
- Complain. If you are in the EEA or the UK you may lodge a complaint with your local data protection authority; you do not have to come to us first, though we would like the chance to fix it.
Write to g.luga@codevider.com from the address on your account, or from the app if you signed up with a phone number. We may need to confirm it is you before we act — never by asking for a password, only by proving control of the account.
If you are in the United States
In the past twelve months we have collected the categories of personal information described above — identifiers (email, phone number, handle, account identifier), internet activity limited to the requests you make to us, and the content you create — all for the purposes listed above, and from you. We have not sold personal information, we have not shared it for cross-context behavioural advertising, and we do not use or disclose sensitive personal information for any purpose that would give you a right to limit it. We do not knowingly collect or sell the personal information of anyone under 16. Californian residents may exercise the rights to know, delete, correct, and be free from retaliation through the same address above, and may use an authorised agent.
Deleting your account
You can delete your account at any time from the Profile screen, in the app or on the website. It takes one confirmation, it happens immediately, and it is permanent — there is no recovery window and no grace period. Your account, profile, handle, follows, watched episodes, ratings, comments, likes, blocks, and push tokens are removed together. The full description of what deletion does is on its own page, readable without signing in.
Cookies and what is stored on your device
The website sets no advertising or analytics cookies, and there is nothing here to consent to or refuse — everything below is strictly necessary for a service you asked for, which is why you are not shown a cookie banner.
- A session cookie that keeps you signed in. Removing it signs you out.
- Local storage holding which account is active in this browser, so that signing out clears the previous account's data before the next one loads.
- An offline copy of your own My Shows and Schedule, in the browser's own database, so the site still shows your diary with no connection. It never leaves your device, it is cleared when you sign out, and it expires after 30 days.
- A service worker cache holding the app's own files and artwork, so pages load without a round trip.
- In the mobile app, your session is held in the platform keychain — iOS Keychain or the Android Keystore — rather than in ordinary app storage.
Security
Every connection to the service is encrypted with TLS, and data is encrypted at rest by our database provider. Access to a member's rows is enforced by the database itself through row-level security rather than only by application code, so a mistake in one screen cannot expose another account's diary. Passwords are stored only as hashes. Administrative access is limited to the operator named above. No service is perfectly secure, and if a breach ever affects your personal data we will notify you and the relevant authority as the law requires.
Children
The service is not directed at children. You must be at least 13 to use it, and at least 16 if you are in the EEA or the UK, where we do not rely on parental consent as a basis for anything. We do not knowingly collect personal data from anyone below those ages; if you believe a child has created an account, write to g.luga@codevider.com and we will delete it.
Changes to this policy
If this policy changes, the new version is posted here with a new effective date. A change that affects what is collected, how it is used, or who it is shared with is announced in the app before it takes effect, and where the law requires your consent for the change we will ask for it rather than assume it.
Contact
Questions about this policy, or a request about your data: g.luga@codevider.com. For anything else, there is a support page.
See also the Terms of Service and the Community Guidelines, and TheTVDB, whose data the catalogue is built from.