Privacy Policy

Effective 2026-07-20

This Privacy Policy explains what What2Watch (the "Service") collects, how we use it, and the choices you have. We collect only what we need to run the Service, and we do not sell your personal data.

What we collect

  • Account: your email address, a display name, and an avatar color. Sign-in uses one-time email codes, so we do not store a password.
  • Your activity: the titles you rate (thumbs up/down), save to your watchlist, or mark as watched, and the search queries you make to find something to watch.
  • Household: which household you belong to, and whether you administer it.
  • Optional Trakt data: if you connect Trakt, the watch history, ratings, and watchlist we import on your instruction.

How we use it

  • to sign you in and operate your account;
  • to generate recommendations tailored to your taste and, within a household, to a combined taste signal; and
  • to keep the Service secure and working.

The household privacy boundary

Your individual ratings, watchlist, watch history, and preferences are private to you. Other members of your household cannot see your individual data. When the Service tailors a shared search to a household, it uses only an aggregatetaste signal (for example, how many members like a genre) that does not reveal who liked or disliked what. A household roster shows only display names and avatars, never anyone's activity.

Third parties we share data with

  • TMDB: we send title names to TMDB to look up movie and TV metadata. This product uses the TMDB API but is not endorsed or certified by TMDB.
  • Trakt (optional): only if you connect it. We exchange your watch history, ratings, and watchlist with Trakt on your instruction, and can send titles you mark as watched back to Trakt. Disconnect any time in Settings.
  • AI provider: your search queries are processed by an AI model (via a gateway) to produce recommendations.
  • Infrastructure: our hosting and database providers process data on our behalf to run the Service.

We do not sell your personal data or share it for third-party advertising.

How we protect your data

Access to your data is enforced at the database with row-level security, so the application can only read or write rows you are entitled to. Sensitive per-user secrets (such as a personal API key or your Trakt tokens) are stored encrypted in a dedicated vault, never in plain text.

Retention and deletion

We keep your data while your account is active. You can remove data yourself: disconnect Trakt, leave a household, or delete saved titles. If you delete your account, we delete the personal data associated with it, except where we must retain something to meet a legal obligation.

Your choices

  • set your content-language preferences in Settings;
  • connect or disconnect Trakt at any time;
  • leave your household; and
  • request deletion of your account and its data.

Children

The Service is not directed to children under 13, and we do not knowingly collect their data.

Changes

If we make a material change to this policy, we update the effective date above and ask you to agree again the next time you sign in.

Contact

Questions about your privacy or a data request? Contact us at support@tlh88app.store.

Terms · Privacy