Popsie
Privacy Policy
Last updated: 21 September 2026 · Versione italiana
This policy explains what personal data Popsie collects, why, who it is shared with, and what rights you have. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
1. Who processes your data
The data controller is Mattia Stangherlin, a natural person, the developer and operator of the Popsie application.
For anything concerning your personal data, including exercising the rights described in section 11, write to hello@popsieapp.com.
Popsie has no Data Protection Officer: the conditions of Article 37 GDPR do not apply.
2. What data we process
Popsie collects only what the app needs to work. We use no advertising tools, we do not track you across other sites or apps, and we sell data to nobody.
| Category | Data | Legal basis |
|---|---|---|
| Account | Email address, password (stored only as a hash), username, display name, an avatar chosen from those built into the app, account creation date | Performance of a contract - Art. 6(1)(b) |
| Date of birth | The date you enter during onboarding, used to filter content unsuitable for your age. It is optional: if you leave it out, nothing is blocked | Consent - Art. 6(1)(a) |
| Preferences | Light/dark theme, language, selected streaming platforms, watch region, kids mode, notification preferences | Performance of a contract - Art. 6(1)(b) |
| Parental protection | If a parent turns it on for an account: their email address (verified with a code), a PIN stored as an unreadable hash, and the count of failed attempts. See section 12 | Legitimate interest in protecting minors - Art. 6(1)(f) |
| Viewing activity | Titles added to your watchlist, titles and seasons marked as watched or in progress, individual episodes watched, the watch order you set | Performance of a contract - Art. 6(1)(b) |
| Social graph | People you follow and who follow you, follow requests, published recommendations, likes, lists you create or take part in, users you have blocked | Performance of a contract - Art. 6(1)(b) |
| Private messages | The text of messages exchanged with other users, reactions, in-app attachments (movie or show entries, replies to a recommendation) | Performance of a contract - Art. 6(1)(b) |
| AI chat | The text you send to the assistant, the generated replies, and a count of messages used in the last 24 hours | Performance of a contract - Art. 6(1)(b) |
| Push notifications | The device identifier issued by the notification service (push token) and the operating system | Consent - Art. 6(1)(a) |
| Reports | The reported content, the reason, any notes, and the identifier of the reporting user | Legal obligation (Reg. EU 2022/2065) - Art. 6(1)(c) |
| Abuse prevention | If an account is suspended, or if it is involved in a block (whether you blocked someone or someone blocked you), we keep an irreversible code (a hash) derived from its email address. We do not keep the address itself: the code cannot be turned back into an email. Its only purpose is to stop a suspension from being evaded, or a block from being undone, by deleting the account and signing up again with the same address | Legitimate interest - Art. 6(1)(f); Reg. EU 2022/2065 Art. 23 |
| Technical data | IP address and connection information, processed by the providers listed in section 8 to deliver the service and prevent abuse | Legitimate interest - Art. 6(1)(f) |
Data that stays on your device
Some information never reaches us. It lives in the app's local storage, on your phone, and disappears if you uninstall Popsie or clear the app's data:
- the search history shown on the Search screen;
- the local copy of movie and show entries, kept so the same information is not fetched twice;
- your sign-in session.
3. What we do not do
- No profiling cookies, advertising SDKs or behavioural analytics.
- No tracking of your activity outside Popsie.
- No selling or sharing of personal data with third parties for marketing.
- We do not process special categories of data under Article 9 GDPR, and we ask you not to enter any in free-text fields (messages, notes, list names).
- We take no automated decisions producing legal effects or similarly significantly affecting you (Article 22 GDPR).
4. Personalised recommendations
Popsie analyses your viewing activity - genres, directors, production companies, saved and watched titles - to build a taste profile, suggest relevant titles and compute an affinity score with the people you follow. This constitutes profiling under Article 4(4) GDPR and is disclosed here pursuant to Article 13(2)(f).
It affects only what you see recommended inside the app. It produces no legal effect, does not condition access to the service, and is not shared with third parties. You can clear the data behind it from the settings (Settings → Content) or delete your account.
5. AI chat
AI chat replies are generated by an artificial intelligence system, not by a person, and may contain errors or out-of-date information. Always verify anything important.
When you use the AI chat, the text you write is sent to Anthropic PBC (United States), which processes it to generate a reply. Alongside your message, some elements of your profile may be sent to make the suggestion relevant: your selected streaming platforms, your watch region, and the titles you have already saved or watched. Your name, your email, your private messages and your contacts are not sent.
The assistant may also search the web to answer: in that case the search query is passed to the search engine used by Anthropic.
AI chat messages are not used to train artificial intelligence models. You can delete the whole conversation at any time with the "New conversation" button inside the chat.
6. Content you publish, and messages
Recommendations, lists and profiles you make public are visible to other users according to the privacy settings you choose. Private messages are visible to you and the recipient.
Private messages are protected in transit and at rest, but they are not end-to-end encrypted: technically the service operator is able to access them. We only do so where strictly necessary to act on a report or on a request from an authority. Do not use Popsie to exchange confidential or sensitive information.
7. Push notifications
Push notifications are optional and are only sent after you grant the system permission. To deliver them we store a device identifier (push token) issued by the operating system. You can withdraw consent at any time from your phone's settings or by turning notifications off in Popsie; signing out removes that device's token.
8. Who we share data with
Popsie relies on a few external providers, acting as processors under an Article 28 GDPR agreement or, where indicated, as independent controllers:
| Provider | What it does | Data involved |
|---|---|---|
| Supabase Inc. | Database, authentication and server functions | All account data listed in section 2 |
| Anthropic PBC | Generating AI chat replies | AI chat message text and viewing preferences |
| Expo (650 Industries, Inc.) | Push notification delivery | Push token, notification text |
| Apple Inc. / Google LLC | Final notification delivery to the device, app distribution | Push token, notification text |
| The Movie Database (TMDB) | Movie and TV catalogue. Requests are made directly from your device | IP address, search terms sent to the catalogue |
| YouTube / Google LLC | Trailer playback and thumbnails | IP address and data collected by the YouTube player under Google's policies |
| Resend | Sending transactional emails (signup confirmation, security alerts, parental protection) | The recipient's email address - including the parent's, when the protection is active - and the email's content |
| Functional Software, Inc. (Sentry) | App error diagnostics (section 14). Organisation configured in the service's European region | Technical error details, device model, app version, pseudonymous identifier |
| Cloudflare, Inc. | Hosting of these information pages | IP address of page visitors |
Data may also be disclosed to judicial or supervisory authorities where required by law.
9. Transfers outside the European Union
Popsie's database is hosted in the European Union (Ireland): your account, your content, your messages and your lists live on European soil. The same goes for the error diagnostics described in section 14, also configured in the European region.
Some of the providers listed in section 8 are nonetheless based in the United States - among them Supabase, which runs the infrastructure while hosting the data in Europe, and Anthropic, which receives the text of AI chat messages. Any access or transfer arising from that relies on the Standard Contractual Clauses adopted by the European Commission (Article 46(2)(c) GDPR) and, where applicable, on certification under the EU–US Data Privacy Framework. You can request a copy of the safeguards in place by writing to the address in section 1.
10. How long we keep data
| Data | Retention |
|---|---|
| Account and linked content | For as long as the account is active |
| All account data | Deleted within 30 days of an account deletion request |
| Private messages | Until you delete them or delete your account. Deleting your account removes the whole conversation, including from the recipient's inbox |
| AI chat | Until you start a new conversation or delete your account |
| Push token | Removed on sign-out or uninstall |
| Reports | 12 months after closure, so that our handling can be accounted for if challenged |
| Email code of a suspended account | For as long as the suspension lasts, including after the account is deleted. It is removed the moment the suspension is lifted |
| Parent email and PIN of the parental protection | Until the account holder’s 18th birthday: the date is computed when the protection is turned on and the deletion happens automatically on that day. Sooner, if the protection is removed |
| App usage events (section 13) | 12 months. Events recorded before sign-in are deleted after 90 days |
| Crash reports sent to Sentry (section 14) | 30 days |
| Email code tied to a block | For as long as the block is in force. It is deleted when the block is removed, or when the account of the person who set it is gone |
11. Your rights
You may exercise the rights under Articles 15-22 GDPR at any time:
- Access: know what data we process and obtain a copy.
- Rectification: correct inaccurate or incomplete data.
- Erasure: delete your account and the linked data.
- Restriction and objection to processing.
- Portability: receive your data in a machine-readable format.
- Withdrawal of consent, at any time, without affecting the lawfulness of processing already carried out.
Most of this can be done in the app, under Settings → Account: edit your profile, clear your viewing data, export a copy of all your data (we email it to you, the download link stays valid for 7 days), delete your account. See also the Account deletion page.
For anything else write to hello@popsieapp.com: we reply within one month, as required by Article 12(3) GDPR.
If you believe the processing infringes the GDPR, you have the right to lodge a complaint with the Italian Garante per la protezione dei dati personali (garanteprivacy.it) or with the supervisory authority of the country where you live.
12. Minors
Popsie requires a minimum age of 14, in line with Article 2-quinquies of Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018. Anyone under 14 may not create an account.
If you become aware that a child under 14 has created an account, report it to hello@popsieapp.com: the account will be closed and the data deleted.
Parental protection
A parent can lock an account’s age limits behind a PIN. To do so they enter their own email address, which has to be different from the account’s and which they verify with a code: that is where the alerts go (failed PIN attempts, removal requests) and where the code for recovering a forgotten PIN is sent.
That address is used for nothing else - no profiling, no marketing, no sharing with third parties - and it has an expiry written into it: it is deleted on the account holder’s 18th birthday, together with the PIN. If the protection is removed sooner, it is deleted then. A parent can ask for its deletion by writing to hello@popsieapp.com: the request amounts to removing the protection.
If a protected account is deleted and created again with the same email address, the protection is restored and the parent is notified. To make that possible we keep an irreversible code derived from the address, not the address itself, with the same expiry.
13. Measuring how the app is used
To understand which parts of Popsie work and where people get stuck, we record some usage events. These are usage data, not content: we record that something happened, never what you were watching, searching for or writing.
| What we record | What we do not record |
|---|---|
| The event name (for example "sign-up completed") | Film or series titles, text you write, messages, the names of your lists |
| The screen as a category (for example "title detail"), not the specific title | The terms you search for |
| Operating system and app version | IP address |
| A session identifier and a pseudonymous device identifier | Your username or email inside the event |
This data never leaves our own infrastructure: it stays on Supabase alongside the rest of the application and is not shared with any external analytics service. We do not use it to profile you or for advertising, and there is no advertising in Popsie at all.
The device identifier is not stored on your device before you sign in: until then it exists only in memory and disappears when you close the app.
Legal basis: our legitimate interest in measuring and improving our own product (Art. 6(1)(f) GDPR). The impact on you is minimal precisely because the data carries no content. You have the right to object at any time, and you can do it yourself, immediately, under Settings → Privacy → Usage statistics: from that moment nothing further is recorded and the device identifier is deleted.
These events are included in the export of your data (section 11).
14. Diagnostics and crash reporting
When the app hits an error or closes unexpectedly, the technical details are sent to Sentry (Functional Software, Inc.), acting as a processor under Art. 28 GDPR. Without it, a problem happening on your phone would stay invisible to us.
| What Sentry receives | What it does not receive |
|---|---|
| The point in the code where the error occurred | Your email and username |
| Device model and operating system version | Your IP address, which we explicitly disable |
| App version | Content: titles, messages, lists, searches |
| The last screens visited, as categories | Screen recordings: we do not use that feature |
| The same pseudonymous identifier as section 13 | Your account identifier |
The identifier we send is deliberately the pseudonymous device one, not your account's: Sentry therefore has no way of tracing it back to you.
Popsie's Sentry organisation is configured in the service's European region: this data stays within the European Union and section 9 does not apply.
Legal basis: our legitimate interest in keeping the app stable and secure (Art. 6(1)(f) GDPR). Here too you can object at any time under Settings → Privacy → Crash reporting.
15. Security
Data travels encrypted (TLS) and is stored on infrastructure operated by Supabase. Access to database rows is constrained at the engine level by row level security: each authenticated user can read and write only their own data and what other users have made visible to them. Passwords are never stored in plain text.
16. Changes to this policy
If the processing changes materially we will update this page and, where the change affects you directly, tell you inside the app. The date at the top always reflects the latest revision.
17. The popsieapp.com website and cookies
This section covers the website only, the one you are reading now (popsieapp.com). For the app, see sections 13 and 14.
- We do not use cookies, technical or otherwise, and no third-party analytics or tracking tools (Google Analytics and similar).
- We record a small set of navigation events anonymously (page visits, clicks on the social/store buttons, clicks on "share") to count visits to the site and roughly tell mobile from desktop. No identifier of your visit is stored - no cookie, no IP address, no session id - so it is not possible to reconstruct your path through the site or tell you apart from another visitor. Only Popsie's administrators can view these aggregate counts.
- The site's fonts are hosted directly on popsieapp.com rather than loaded from Google's servers: visiting the site does not send your IP address to a third party.
- The only thing saved on your device is a note in your browser's local storage (technically distinct from a cookie) remembering that you closed the notice at the bottom of the page. It does not identify you, never reaches our servers, and you can clear it at any time by clearing the site's data from your browser settings.