1. Controller and contact
I've Seen is operated by Tiago Santos in Portugal, who is the controller of account data. Privacy questions and rights requests can be sent to [email protected]. More information about the creator is available at https://tiagosantos.pt.
2. Data we process
Guest tracking stays on your device. If you create an account, we process account identifiers and contact information; profile and privacy settings; country and provider preferences; viewing history, episode progress, ratings and lists; reviews, comments, likes and follows; reports, moderation and appeals; notification preferences and delivery tokens; import and export records; and limited security and diagnostic records. We do not request precise location, contacts, photos or advertising identifiers.
3. Purposes and legal bases
We use account, tracking, social and notification data to provide the service you request and perform our contract with you. We use security logs, abuse controls, reports and moderation records for our legitimate interests in protecting members, enforcing the terms, defending legal claims and maintaining a reliable service. Optional PostHog and Plausible product analytics are used only with your consent. You can refuse or withdraw analytics consent without losing any app feature. Where law requires us to retain, disclose or act on information, processing is based on that legal obligation.
4. Optional analytics
Product analytics are off by default. If you opt in, PostHog EU Cloud and our self-hosted Plausible service receive a pseudonymous device identifier, screen names, app and platform information, and limited feature events. Events may include catalogue title identifiers and general action metadata, but never your name, email, username, search text, review text, comments or private notes. We do not use analytics for advertising or identify your analytics profile with your account. You can withdraw consent in Settings at any time.
5. Diagnostics
We use our self-hosted GlitchTip service through the Sentry SDK for crash and error diagnostics. Reports can include stack traces, app version, platform and recent technical breadcrumbs. Screenshots, session replay, default PII collection, user-interaction tracing and performance tracing are disabled. Signed-in users may also send throttled warning and error logs to our administration database. We use these records under our legitimate interest in diagnosing failures and securing the service.
6. Recipients and other services
Supabase hosts authentication and account data in its Frankfurt region. Resend processes email addresses to deliver account emails. PostHog processes consented analytics in its EU Cloud region. Our own servers operate Plausible, GlitchTip and the catalogue proxy. TMDB supplies catalogue data, JustWatch supplies provider data through TMDB, and YouTube receives device and network information only when you choose to load or open a trailer. These providers may act as processors or independent controllers under their own notices.
7. International transfers
Some providers or their subprocessors may process information outside the EEA or UK. Where required, we rely on an adequacy decision, the EU-US Data Privacy Framework for participating organisations, or approved contractual safeguards such as Standard Contractual Clauses. You may request information about the safeguard relevant to your data by contacting us.
8. Visibility and public content
Profile, list, diary, review and activity visibility follows the audience controls shown in the app. Public content can be viewed and copied by other people. You can require approval for followers and block another member. We may restrict content when required by law or these terms and will provide a reason and an appeal route where required.
9. Retention
Account and tracking data remain until you delete them or your account. Client warning and error logs are normally deleted after 60 days. Operational backups follow the rolling retention configured by our hosting providers and expire after their backup cycle. Reports, moderation decisions, appeals, security records and anonymised evidence may be retained for up to 24 months after closure, or longer where reasonably required for legal claims, repeated abuse or a legal duty. Analytics and diagnostics follow the retention configured in PostHog, Plausible and GlitchTip; current periods are available on request and are reviewed at least annually.
10. Your rights
You can correct profile information, change visibility, export a tracking backup, reset tracking data or delete your account in the app. A tracking backup is not a complete legal access export. To request a complete copy, correction, deletion, restriction, objection, portability information or withdrawal of consent, email [email protected]. We may need to verify your identity. EEA residents may complain to the CNPD in Portugal or their local supervisory authority. UK residents may complain to the ICO. Applicable US state rights, including non-discrimination for exercising a right, will be honoured where the relevant law applies.
11. California and US disclosures
During the previous 12 months, we have not sold personal information or shared it for cross-context behavioural advertising. We do not offer financial incentives for personal information. Categories collected and disclosed for service purposes are described above. We do not currently respond differently to browser Do Not Track signals because the public site does not use advertising tracking; consent choices in the app control optional product analytics.
12. Children
The service is for people aged 13 or older and is not directed to children under 13. Do not create an account if you are under 13. If we learn that an under-13 user supplied personal information without valid parental authorisation, we will restrict the account and delete the information as required. A parent or guardian can contact [email protected]. Additional protections and local consent ages may apply to users under 18.
13. Security and incidents
We use access controls, row-level database policies, encrypted network transport, environment-separated credentials, logging and administrative audit records. No service can guarantee absolute security. We investigate suspected incidents and notify affected people and authorities when required by applicable law.
14. Changes
We will update the effective date and provide an in-app or similarly prominent notice before a material change where required. Previous versions and the reason for material changes will be retained internally.
Questions? Contact [email protected].