Everything Cinemere knows about you lives in this browser and in your account on one EU server. No analytics, no trackers, no ads, and your email stays private. Take a copy or wipe this device in one click, right here.
Your account, diary, lists and messages live in this browser. They also sync to Cinemere's EU server, so you can sign in anywhere.
🚫
No ads, no tracking, no selling
We run no analytics, no advertising and no third-party trackers. We never sell or share your data.
⤓
Export anytime
Download everything as a portable JSON file whenever you want. It is your data.
⌫
Erase completely
One confirmation deletes your account and all your data, from this browser and from our server. Section 06 names the four places it cannot reach, and why.
Your data & rights
Live · this device
These are your data-subject rights under the GDPR and your consumer rights under the CCPA / CPRA. You exercise them yourself, in one click, with no request form and no waiting: export and erase are wired straight to the real endpoints rather than to an inbox somebody reads on Monday. Erasure deletes the server account first and only then this device, so a refused delete can never leave the server copy orphaned. Section 06 names the four things it cannot reach, and why.
Loading your privacy choices…
Everything stored about you on this device
⌫ Erase my data & account
This permanently deletes your Cinemere account and all data listed above: diary, lists, watchlist, the titles you have marked as watched, the titles you told us you have not seen, messages, posts, follows, your saved password, your email address and your year of birth. It deletes it from this browser and from our server, and then signs you out. It cannot be undone, and we cannot get it back for you.
Two things survive, and you should know before you press it: a copy can remain in our encrypted backups for up to 56 days until they age out, and if you ever bought a subscription we must keep the invoices for seven years because bookkeeping law says so. Section 06 explains both in full.
Tip: download a backup copy first. Keeping that JSON file safe means you can restore your library later. (Import is on the roadmap.)
01Who we are
Cinemere is a film and television tracking and social platform. This page explains, in plain language, what personal data Cinemere handles, why, on what legal basis, and the rights you have over it. It is written to meet the transparency duties of the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), as amended by the CPRA.
Cinemere runs in two modes. As a local demo it is a pure client-side application: no server stores member data. On cinemere.com your account and activity are stored in a database on Cinemere's own server in Nürnberg, Germany (EU), so that you can sign in from any device.
The data controller is:
Cinemere AB — —, Sweden
Company number —
Privacy contact: [email protected]
We have not appointed a Data Protection Officer. We assessed whether one is required under Article 37 and concluded it is not: we are not a public authority, our core activity is not large-scale systematic monitoring, and we process no special-category data on a large scale. The privacy address above reaches a person who can answer, and you can ask us for that assessment.
Your supervisory authority for data protection in Sweden is Integritetsskyddsmyndigheten (IMY). For questions about how we moderate content, the authority is Post- och telestyrelsen (PTS). Section 06 explains how to reach both, and section 12 covers our duties under the Digital Services Act.
02What we collect, and why
Cinemere only holds data you create by using it. We do not ask for your real name, your phone number, your precise location, or any special-category data. We do ask which country you are in, because streaming rights and cinema listings are national and we cannot answer "where can I watch this" without it. We never read your location from your IP address or your device's positioning: we suggest a country from your browser's time zone, you confirm or change it, and you can leave it unset. The table in Your data & rights above is generated live from your own browser and is the authoritative list. In summary:
Account email — collected at sign-up and used for exactly three things: your welcome brief (with an address-confirmation link), password recovery, and, only if you opt in, the Cinemere Dispatch newsletter. Your email is private: it is never displayed on your profile, never served to other members, and never shared. Every Dispatch issue carries a one-click unsubscribe that needs no login; you can also flip it off in Settings → Account.
Your activity — diary entries (reviews, watched dates), your ratings (one per title, with the date you first gave it and the date you last changed it), titles you have marked as watched without a date, watchlist, episode progress, lists, posts, takes, poll votes, stories, follows and favourites.
The titles and people you opened recently — so you can step back to a film whose synopsis you were reading a minute ago. This one never leaves your browser: it is a trail your browsing makes rather than anything you told us, and a browsing history is exactly the kind of record we do not collect centrally. We keep the last few dozen on this device, only while you are signed in, and it is cleared with everything else when you erase your data.
Titles you told us you have not seen — while marking up your history you can answer “not seen”, and we keep that answer so we stop asking. It used to live only in the browser you gave it in, which meant a second device, a reinstalled app or cleared site data quietly threw it away and we asked again. It is now stored with the rest of your account, and it is yours alone: unlike the titles you have marked as watched, this list is never served to another member. You can hand every one of them back into the deck whenever you like.
How you saw something, and who with — a diary entry can record the carrier (cinema, streaming, disc, tape, broadcast), the format (70mm, 4K UHD, or the service you streamed it on), the place you saw it, and the members who were there with you. Every part of this is optional and you type it yourself. Two things are worth saying plainly. First, the place is somewhere you physically were, so Settings → Identity → Privacy carries a switch, Keep cinemas to yourself: turn it on and we remove that line from your logs before they are served to anybody else, on the server, not in the page. Second, naming a member writes nothing to their diary. It sends them a note asking whether they want to log it too, they decide, and whoever is named can take their own name off your entry at any time, without telling you. You can only name members who follow you back.
Shared cards — two features publish something about more than one member, and neither can happen without agreement. A Double Bill puts your verdict on a title beside someone else's: it is only published once both of you have said yes in your conversation, and it then shows the rating and the review you already wrote, as you wrote them. A Screening records one evening: what was watched, when, where, and who was in the room. It stores no ratings at all; it counts them from the diaries of the people who have logged it, so nobody is ever shown a verdict they did not enter, and anyone named can take their own name off it.
Messages — direct and group messages you send within Cinemere.
Your password — stored only as a salted hash (Argon2id on cinemere.com), never in plain text. See the security note in section 09.
Your country, and your viewing settings — the country you are in, your content language, whether you are happy to read subtitles, and the highest age rating you want suggested. These decide which catalogue answer you get: the streaming services and cinema listings for your country, synopses in your language, and nothing rated above your ceiling. They are held in private fields, are never shown on your profile and are never served to another member. If you are in the United States you may also give us a state and city. Those are optional, they change nothing today because US streaming rights are national, and we hold them only as groundwork for cinema showtimes, which genuinely are local. Leave them blank, or clear them later, and nothing is lost. Choosing a country outside the United States clears them automatically, because there would be no purpose left for holding them.
Your privacy choices — the consent record set by the banner on this site.
Your year of birth — asked once, when you join or when you accept these terms, so we can tell that you are old enough to be here (see section 10). We keep the year only, never a full date of birth. It is held in a private field, is never shown on your profile, and is never served to another member.
Your acceptance of our terms — which version of the Terms of Service and this notice you accepted, and when. This is what lets us rely on our agreement with you as a lawful basis, and what lets you ask us exactly what you agreed to.
Waitlist and invitations — if you joined the waitlist before you had an account, we hold the email address you gave us, your own referral code, the code that referred you if any, and how many people joined through your link. That is used only to hold your place in line and to let you in. It is deleted when you join, when you leave the list, or after 365 days of nothing happening.
Safety and moderation — reports you file, reports about you, blocks and mutes, and any decision we have taken about your account together with the reason we gave you. Section 12 explains what happens to this.
Clubs, games and quizzes — club memberships and club messages, ScreenPlay scores, daily results and streaks, and quizzes you build.
Follow requests — requests you sent to private profiles, and requests awaiting your approval.
Payments (paid plans only) — if you buy a subscription, we hold your plan, its status and renewal date, and a payment token, the card brand, the last four digits, the expiry and the billing country from Stripe. We never receive or store your full card number. Invoices and transaction records are kept for seven years because bookkeeping law requires it, which is explained in sections 08 and 06.
We collect this data for one purpose only: to provide the features you are using (logging titles, building lists, talking to other members, personalising recommendations, recovering your account, keeping the place safe, and billing you if you chose a paid plan). We do not profile you for advertising and we run no analytics.
Automated processing. Everything you write passes through an automated word filter before it is saved, which can refuse a message outright. That is the only automated decision on Cinemere, it decides about a piece of text and never about you as a person, and no account is ever restricted without a human deciding. Section 12 explains it in full and how to challenge the outcome.
03Where your data goes
To function, Cinemere connects to a small number of services. These connections necessarily reveal your IP address to those services (that is how the web works), so we keep the list short and disclose it fully:
The Cinemere server — your account, activity and email address are stored in a PostgreSQL database on our own server in Nürnberg, Germany (EU), rented from Hetzner Online GmbH, who provide the machine and the data centre and act as our processor under a data-processing agreement. No third-party analytics or ad-tech runs on it.
Cloudflare — sits in front of cinemere.com as our network and security layer, which means every request you make passes through it and it sees your IP address and the address you are visiting. It is there to absorb attacks and to serve the site quickly, not to analyse you: we run none of Cloudflare's analytics or advertising products. Cloudflare acts as our processor under a data-processing agreement, and transfers outside the EEA are covered by the European Commission's standard contractual clauses together with Cloudflare's certification under the EU-US Data Privacy Framework. See Cloudflare's privacy policy.
Stripe (paid plans only) — Stripe Payments Europe, Ltd. takes the payment. Your card details go straight to Stripe and never touch our servers. We send them the amount, your email address and your billing country; they send us back whether it worked, a token, and the last four digits. Stripe is our processor for taking the payment, and its own controller for fraud prevention and for the financial-regulation duties it has to meet. See Stripe's privacy policy.
Our email provider — sends the welcome brief, address confirmation, password resets, moderation notices and the opt-in Dispatch. It receives your email address and the content of those messages, acts as our processor, and is contractually barred from using either for anything else.
TMDB (The Movie Database) — supplies film and TV metadata and poster images. When you search or open a title, your query and IP reach TMDB. See the TMDB privacy policy. TMDB is based in the United States.
YouTube (optional) — embeds trailers on the title page. YouTube can set its own cookies, so it is treated as non-essential: nothing loads from YouTube until you switch trailer playback on. When you do, we use YouTube's privacy-enhanced "no-cookie" mode. See Google's privacy policy.
Push notifications (optional) — if you turn notifications on, your browser registers with its own push service (Apple, Google or Mozilla, depending on your device) and we deliver alerts through it. It is strictly opt-in (your device asks permission first) and reversible any time in Settings → Notifications. Notification contents are encrypted to your device; the push service only relays them and cannot read them. We store only the subscription needed to reach your device, and drop it when you turn notifications off or delete your account.
Fonts — our typefaces are self-hosted. Unlike most sites, Cinemere does not load fonts from Google. No data about you reaches Google for fonts.
We do not use any advertising network, analytics provider, social-media pixel, or data broker. We never sell, rent, or "share" (as the CCPA/CPRA defines that term) your personal information.
Transfers outside Europe
Your account data lives in the EU and stays there. Three of the connections above can involve a transfer out of the EEA, and each has a lawful basis for it: Cloudflare and Stripe under the European Commission's standard contractual clauses together with their EU-US Data Privacy Framework certifications, and TMDB, which receives a catalogue lookup and your IP address when you search or open a title, and no account data. We do not transfer your diary, your messages, your lists or your email address outside the EEA.
When the law asks
We disclose member data to an authority only where we are legally required to. We will tell you if that happens to you, unless the law forbids us from telling you.
04Cookies & local storage
Cinemere sets no advertising, analytics or tracking cookies, in either mode. It never profiles you across other sites, and there are no third-party trackers on this page.
As a local demo, Cinemere sets no cookies at all: it uses your browser's localStorage as the application's database (your account and your library).
On cinemere.com, signing in sets one first-party cookie, cin_session. It holds a signed token that tells the server which member you are, so you stay signed in as you move between pages. It is httpOnly (JavaScript cannot read it), SameSite=Lax and sent only over HTTPS, and it is used for nothing but keeping you signed in. Under the EU ePrivacy rules, storage that is strictly necessary to deliver a service you have asked for does not require consent, and a sign-in cookie is the textbook example; we still tell you it is there. Signing out removes it. On cinemere.com your localStorage additionally acts as a fast local cache of your account and activity, so pages render instantly and keep working through a brief connection drop; the authoritative copy lives on the server (see section 03).
Because Cloudflare protects the site (section 03), it may also set its own strictly-necessary cookie, typically __cf_bm, which lasts about half an hour and exists to tell a browser apart from a bot. It carries no advertising or analytics purpose and is not used to profile you.
If you buy a subscription, Stripe sets the cookies its fraud checks need on the checkout it serves. Those are strictly necessary to take a payment you asked us to take.
The only consent-relevant item is the optional YouTube trailer embed, which is a third party that can set cookies. That is why the banner gives you a clear choice, defaulted to off, and why you can change it at any time with Manage choices above.
05Legal bases (GDPR Art. 6)
Performance of a contract (Art. 6(1)(b)) — storing your account, diary, lists, follows and messages so the product works for you; sending the account emails you ask for (the welcome brief, address confirmation, password-reset links); and, on a paid plan, taking your payment, renewing it and issuing your receipt. The contract is the Terms of Service you accepted.
Legal obligation (Art. 6(1)(c)) — keeping invoices and transaction records for seven years, because Swedish bookkeeping law requires it; and acting on a valid order from an authority. Section 06 explains why this is the one thing deletion cannot reach.
Legitimate interests (Art. 6(1)(f)) — three things, each narrow. Keeping the service up and safe: rate limiting, blocking attacks, and the moderation record described in section 12, because a platform that cannot enforce its own rules cannot protect the people on it. Showing you film data: connecting to TMDB and TVmaze, with no profiling or advertising involved. Keeping our own records straight: the audit log of moderation decisions. We weighed each against your rights and concluded they are what you would reasonably expect from a service like this; you can object at any time using the address in section 11, and you can ask us for the assessment.
Consent — the Cinemere Dispatch newsletter (off by default, a deliberate opt-in at sign-up or in Settings, withdrawable with one click in every issue), push notifications (off by default, enabled only when you allow them on your device), and loading optional third-party trailers from YouTube. You may withdraw consent at any time, as easily as you gave it.
06Your rights under the GDPR
If you are in the EU, EEA or UK, you have the rights below. Most of them are self-service and instant on this page:
Access & portability — see and download all your data: use Export my data above (GDPR Arts. 15 & 20).
Erasure ("right to be forgotten") — wipe everything: use Erase my data above (Art. 17).
Rectification — correct your profile in Settings, and edit or delete any diary entry, list or post (Art. 16).
Restriction & objection — turn off optional connections via Manage choices; object to anything we do on legitimate interests by writing to us; stop processing entirely by erasing your data (Arts. 18 & 21).
Withdraw consent — switch trailer playback, push notifications or the Dispatch back off at any time, as easily as you turned them on (Art. 7(3)).
Not to be subject to automated decisions — no decision about you as a person is made automatically. See section 12 for the one automated step and how to challenge its outcome (Art. 22).
Lodge a complaint — with Integritetsskyddsmyndigheten (IMY) (imy.se), our lead supervisory authority, or with the authority where you live. You do not have to come to us first, though we would like the chance to fix it.
You exercise these yourself, immediately: no request form and no 30-day wait. Export downloads your data straight from your browser. Erase my data (the control above, also in Settings → Privacy & Data) asks for your password and then deletes your account on the server before wiping this device, in one step: your profile, posts, takes, stories, diary, your ratings, watchlist, the titles you marked as watched, the titles you told us you have not seen, episode progress, lists, notifications, your own message threads, quizzes, game scores, push subscriptions, follow requests, blocks and mutes, your consent record, your waitlist entry, and any queued email, plus your saved password, email address and year of birth. It also removes your footprint from other members' pages: your club memberships and club messages, the comments, reactions, reposts and poll votes you left on their posts, your likes on their takes and lists, your name from any log where they recorded you as company, your name from any Screening you were part of, your handle from their follower lists, and any notification about your activity sitting in their notification centre. Any Double Bill you appeared in is deleted outright, not left standing with one side missing: it carried your rating and your words, and half of that card is not a card.
The four honest limits
Deletion is immediate and it is thorough. It is not magic, and we would rather tell you exactly where it stops than let you discover it later:
Messages you sent remain in the recipient's copy of the conversation, the same way a sent email stays in someone's inbox. We cannot reach into another person's mailbox, and it would not be right if we could.
Backups. We take an encrypted database backup every day and keep a weekly copy for longer, so that a failure does not destroy everybody's library. That means a copy of your data can survive in a backup for up to 56 days after you delete it, until that backup ages out and is destroyed. Backups are never used to restore a deleted account, they are only ever used to recover the whole database after a disaster, and if that ever happened we would re-run your deletion against the restored copy. This is a recognised limit on the right to erasure, and it is the honest answer to "is it really gone": gone from Cinemere immediately, gone from the last backup within 56 days.
Invoices and payment records, if you ever bought a subscription. Swedish bookkeeping law makes us keep them for seven years and we are not allowed to delete them on request. We keep only what that law requires, we separate it from your member account, and we use it for nothing else.
The moderation record. If we ever had to act on your account, the decision, the reason and the date survive your account. Section 12 explains why and what it contains.
Everything not in that list is genuinely, permanently gone.
07California rights (CCPA / CPRA)
If you are a California resident, you have the right to:
Know what personal information is collected and how it is used: see sections 02 and 03, and the live table above.
Access & delete your personal information: use Export and Erase above.
Opt out of sale or sharing: there is nothing to opt out of. Cinemere does not sell or share your personal information, for any value, ever.
Non-discrimination: exercising any of these rights never changes the service you receive.
We do not knowingly process the personal information of consumers we know to be under 16 without the consent required by law (see section 10).
08Data retention
Everything you make is kept until you delete it, either item by item or by erasing your account. That is the promise for your own library, and we will not expire your diary out from under you. Everything else has a fixed window, and a job runs on our server every day that actually enforces the table below. It is a schedule, not an intention.
WhatKept for
Your account, diary, ratings, watchlist, titles marked as watched, titles marked as not seen, lists, posts, takes, clubs, messages
Until you delete it
Tonight stories
24 hours
Password-reset links
60 minutes
Address-confirmation links
7 days
Sent email in our outgoing queue
30 days
Read notifications
180 days
Closed safety reports
365 days
Waitlist entries that never became accounts
365 days
Encrypted database backups
56 days
Invoices and transaction records (paid plans)
7 years, by law
Moderation decisions about an account
See section 12
Open reports are never swept, however old they are: an unresolved report is a live obligation, and the answer to an old one is to deal with it, not to delete it. Server logs are capped and rotate within roughly a fortnight, and we do not record your IP address in them.
09Security (and an honest caveat)
Passwords are never stored in plain text: Cinemere keeps only a salted hash. In the local demo, understand the limit of client-side software: storing credentials in the browser is obfuscation, not real authentication. Anyone with access to this device and its developer tools could read the local data. cinemere.com runs a real backend behind the same interface: passwords are hashed with Argon2id on the server, sessions are secure HTTP-only cookies over HTTPS, your email lives in a private database column that is never served to other members, and reset links are one-time and short-lived.
Keep your device secure, and use the Erase tool before handing a shared or public computer to someone else.
10Age, and younger members
Cinemere is for members aged 16 and over. We ask for your year of birth when you create an account, and again once for accounts made before we introduced the rule. The check runs on our server, not only in your browser, so it cannot be clicked past.
We chose 16 rather than the lowest age the law permits. It is the highest threshold any EU member state sets under Article 8, which means one honest rule covers everyone and we never have to build a parental-consent system we could not verify. On a service with private messaging, that felt like the right call. In the United States we follow COPPA and do not knowingly collect data from children under 13; our own limit is higher.
We keep the year of birth only, never a full date, and it is never shown to another member. If we learn that an account belongs to someone under the limit, we close it and delete the data. If you believe a child is using Cinemere, tell us at [email protected] and we will act on it.
12Moderation, and decisions about your account
Cinemere is an online platform under the EU Digital Services Act. That gives you a set of rights about how we police content, and gives us duties we would want anyway.
What is automated, and what is not
Everything written on Cinemere passes an automated word filter before it is saved. An unambiguous slur or explicit threat is refused outright; a borderline match is published but flagged for a person to read. The filter judges a piece of text. It never suspends, restricts or bans anyone: every decision about a person is made by a human being, which is why Article 22 of the GDPR, on decisions taken solely by automated means, does not bite here.
If we act, we tell you why
If we remove something you posted or restrict your account, you get a written statement of reasons: what we did, whether it was because the content is unlawful or because it breaks our Community Guidelines and which rule, whether a report or our own review started it, whether automated tools were involved, and how to challenge it. It arrives in your notifications and by email, because a suspended member cannot sign in to read a notification.
You can appeal for six months, and a person reviews every appeal. If we got it wrong we reverse it and say so.
Your decisions
Every decision we have made about your account, with the reason we gave you and the state of any appeal:
What we keep, and for how long
Reports, blocks and mutes are erased when you delete your account. The record of a moderation decision is not. It holds a handle, the action, the date and the reason, and it survives the account it concerns, because a safety record that disappears when someone deletes their account makes a ban unenforceable and erases the history of what happened to the people they affected. We rely on our legitimate interest in keeping the service safe, we use it for nothing but safety, and we never use moderation data for profiling or advertising.
We also send an anonymised copy of each statement of reasons to the European Commission's public DSA Transparency Database, as Article 24(5) requires. It never contains your handle, your name or anything else that identifies you: that database is public, and publishing a moderation record about a named person is exactly what the law is trying to prevent.
To complain about how we moderate, write to [email protected], take it to a certified out-of-court dispute settlement body under Article 21, or contact Post- och telestyrelsen (PTS) (pts.se), the Digital Services Coordinator for Sweden. Our point of contact for authorities is [email protected], in Swedish or English.
13Changes & contact
If this notice changes materially, the version and date at the top change, we tell you in the app and by email at least 30 days beforehand, and where the change needs your agreement we ask for it rather than assuming it. We keep the old versions, so you can always ask us what applied when.
We answer data-rights requests within one month, as Article 12(3) requires, and usually far sooner because most of them are the two buttons at the top of this page. We do not charge for them.
Cinemere AB — —, Sweden
Company number —
Written to meet what the GDPR, the ePrivacy rules, the CCPA/CPRA and the Digital Services Act expect, and to be readable while doing it. See also the Terms of Service.