1. Scope
This Privacy Policy explains how Watch'n'Roll (the “App”) processes personal data when you use the App. It applies to the mobile applications and related services provided under the name Watch'n'Roll.
2. Data controller
3. Categories of personal data
3.1 Account & identifiers
- Account identifiers (e.g., email, Apple/Google sign-in identifiers) used to authenticate you.
- Basic profile information you provide (e.g., display name, optional avatar), if applicable.
3.2 Usage & in-app interactions
- Likes, watchlists, and list sharing (including members you add).
- Swipe sessions (solo or with a friend) and results (e.g., mutual likes).
- Search queries in the App (processed to return results).
- Selected settings (language, country, IP-based and weather-aware recommendations toggle).
3.3 Push notifications
- Device push token and delivery metadata to send transactional notifications (e.g., swipe invites, session events).
3.4 IP-based location & weather recommendations (optional)
- If you enable IP-based recommendations, we may request an approximate location (e.g., city/region) derived from your IP address via a third-party provider (FreeIPAPI) to tailor content tiles (e.g., “Because you are in Berlin…”).
- The approximate city/region or corresponding coordinates may then be sent to OpenWeather through the OpenWeather One Call API to retrieve current and forecast weather data. We use this weather data to tailor recommendations based on local conditions such as temperature, rain, and season.
- If you disable IP-based and weather-aware recommendations, we do not request IP-based geolocation or weather data for that purpose.
3.5 Ads & analytics
- Advertising identifiers and related signals for serving and measuring ads (AdMob), only if you consent.
- Analytics events and app usage measurement (Google Analytics / Firebase Analytics), only if you consent.
- We also collect first-party usage analytics about interactions such as content opens, likes, watchlist actions, swipe actions, search-result displays, and selected discovery filters. These analytics may include movie/TV/person identifiers, genre or production-company identifiers, result counts, top displayed results, and an approximate country code. They are not stored with your account identifier.
- For these first-party analytics, your IP address may be used temporarily to derive the approximate country via FreeIPAPI. The IP address itself is not stored in our analytics data. We do not store the text of your search queries in this first-party analytics dataset.
3.6 AI chat & AI recommendations
- Your AI prompts and relevant conversation context are sent through our service to the AI provider to generate responses. Your chat history is also kept in the App.
- For signed-in AI chat, a completed response containing chat history is temporarily stored in private server storage so you can recover it if the connection drops. A request record linked to your account is used to check the status and retrieve that response.
- System-generated AI responses may be logged for up to 30 days for quality, debugging, and safety monitoring (without intentionally storing your direct identifiers inside the logged text). Please avoid including sensitive personal data in AI prompts.
4. Purposes & legal bases (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Contract performance (Art. 6(1)(b) GDPR) — to provide core app functionality (account, watchlists, friends, swiping, search, AI chat and recovery of completed replies, premium entitlements).
- Consent (Art. 6(1)(a) GDPR) — for ads and Google/Firebase Analytics where consent is required.
- Legitimate interests (Art. 6(1)(f) GDPR) — to secure and improve the service, including first-party usage analytics and optional IP-based and weather-aware recommendations, fraud prevention, security, and basic diagnostics, limited to what is necessary.
- Legal obligations (Art. 6(1)(c) GDPR) — where required (e.g., accounting records related to purchases handled via app stores/RevenueCat).
5. Consent management
When required, Watch'n'Roll asks for your consent before enabling:
- Ads (AdMob) and related ad measurement
- Analytics (Google Analytics / Firebase Analytics)
You can withdraw consent at any time in the App settings. Withdrawal does not affect the lawfulness of processing before withdrawal.
Website local storage
On our website/landing page, we use localStorage to store strictly necessary preferences:
- Language preference (key: "sa_lang") to display the site and legal pages in English or German without asking each time.
- Theme preference (key: "sa_theme") to remember your selected theme (e.g., light/dark) on the landing page.
This storage is used to provide the requested display preferences and is not used for advertising or tracking. You can delete these entries at any time via your browser settings (clearing site data).
6. Service providers (processors) & third parties
We use the following categories of providers to operate Watch'n'Roll:
- AWS (Amazon Web Services) — hosting, databases and storage (e.g., DynamoDB and S3), and authentication infrastructure.
- AWS Cognito — authentication and account management.
- RevenueCat — subscription management and entitlement tracking (no direct billing by us).
- Google AdMob — advertising (banner, interstitial, rewarded) only with consent.
- Google Firebase — push notifications and (if enabled) analytics only with consent.
- FreeIPAPI — IP-derived approximate location for recommendations and approximate country for first-party analytics.
- OpenWeather (One Call API) — current and forecast weather data for the approximate city/region or corresponding coordinates, used for weather-aware recommendations when this feature is enabled.
- Google Gemini — AI chat and AI-assisted recommendations (your prompts are sent to the provider to generate responses).
- TMDB — content metadata for movies and shows (see Credits for attribution and disclaimer).
7. AI features (important notice)
The AI chat and recommendation features are intended for entertainment and discovery. AI output may be inaccurate or incomplete. Please do not share sensitive personal data in AI prompts.
8. Data retention
- Account & core feature data (likes, watchlists, friends, swipe sessions): retained while your account is active, and deleted upon account deletion, subject to legal obligations.
- AI chat recovery request records: available for up to 24 hours; automatic database cleanup may complete later.
- AI chat recovery copies (completed responses including chat history): stored privately and scheduled for automatic deletion after 3 days.
- AI system response logs: retained up to 30 days.
- Consent records: retained as needed to demonstrate compliance.
- First-party usage analytics: temporary analytics records may be retained in DynamoDB for approximately 5 days. Archived analytics that are not linked to account identifiers may be retained long-term for statistical analysis and service improvement.
9. Account deletion
You can delete your Watch'n'Roll account directly in the App by navigating to Side Menu → Profile → Delete account. Deleting your account permanently removes your account and associated core app data, including likes, watchlists, friendships, and swipe-session data, subject to any data we must retain to comply with legal obligations. First-party analytics that are not linked to your account identifier may remain in archived analytics records. Temporary AI chat recovery data follows the retention periods in section 8.
10. Your rights
Depending on your location, you may have rights to access, rectify, erase, restrict, object, and data portability, and the right to withdraw consent. You also have the right to lodge a complaint with a supervisory authority.
11. Security
We implement appropriate technical and organizational measures to protect personal data (e.g., access controls, encryption in transit, least-privilege access). No method of transmission or storage is 100% secure.
12. Age / children's privacy
Watch'n'Roll is intended for users aged 16+. We do not knowingly collect personal data from children below the applicable minimum age.
13. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will post the updated version in the App and update the “Last updated” date.
14. Contact
For privacy questions or requests, contact us at: privacy@watchnroll.com