ReelOnes ("we", "our", "the app") is a movie discovery and social matching application. This policy explains what personal data we collect, why we collect it, and how we handle it.
1. Information We Collect
Information you provide
- Email address and password (required to create an account)
- First name and last name (optional)
- Phone number (optional, used for friend discovery)
- Date of birth (optional)
- Profile image (optional, uploaded by you to help friends recognise you)
Information generated by your use of the app
- Username (auto-generated from your name)
- Movie and TV show swipe history (like or dislike decisions, along with the content metadata such as title, genre, and release year)
- Watchlist, shortlist, and wishlist contents
- Playlist sharing activity (which friends you share with, which movies are shared, and match results)
- Friend connections and blocked user records
- Notification preferences and notification history
Information collected automatically
- Push notification token (an Expo Push Token used to deliver notifications to your device)
- Device platform (Android or iOS) for interface adaptation
- IP address at signup, used for rate limiting and stored on your account for security and administration purposes
- Approximate location (country and city) derived from your IP address at the time of signup
- Device model and operating system at the time of signup (e.g. "iPhone 12 (iOS)")
- A timestamp of your most recent app session, updated each time you open the app
- Login activity data: each time you sign in, we record your device name, device model, operating system version, app version, and the date and time of the login. We store up to 20 recent login events per account.
Information we do not collect
We do not collect your precise location, contacts, device advertising identifiers, or browsing history. We do not use any advertising or analytics tracking SDKs. The approximate location mentioned above is a one-time lookup from your IP address at signup only and is not tracked or updated thereafter. If you choose to upload a profile image, it is resized and compressed before upload, and any embedded metadata (including GPS location data) is automatically stripped.
2. How We Use Your Information
- Authenticate your account and keep it secure
- Enable friend discovery by letting other users search for you by name, username, email, or phone number
- Power the movie swiping and matching experience between friends
- Maintain your watchlist, shortlist, and wishlist
- Deliver push notifications about friend requests, playlist shares, movie matches, and watchlist updates
- Generate your personal taste analytics (genre preferences, era preferences, director affinity) calculated from your own swipe history and shown only to you
- Prevent abuse through IP-based signup rate limiting
- Administer the service and understand our user base across regions
- Identify suspicious or fraudulent account creation
- Show you recent login activity so you can identify any unrecognised access to your account
3. Information Visible to Other Users
When you use the app's social features, certain information is visible to others:
- Your display name and username are visible to anyone searching for friends
- Your email and phone number are searchable for exact-match friend lookups only
- Friends you are connected with can see your display name, username, profile image (if set), and any movie match results from playlists you share with each other
- Your profile image, if uploaded, is visible to all authenticated app users
- No other personal data (such as your full swipe history, watchlist, or date of birth) is visible to other users
4. Third-Party Services
ReelOnes relies on the following third-party services. No personal data beyond what is described below is shared with any third party.
Firebase by Google
We use Firebase Authentication to manage sign-in and Cloud Firestore to store your account data, movie preferences, friend connections, and playlists. Firebase processes your data under Google's privacy policy.
TMDB (The Movie Database)
We fetch movie and TV show information (titles, posters, cast, ratings) from TMDB's public API. No personal data is sent to TMDB — only search queries and content identifiers.
Expo Push Notifications
We use Expo's push notification service to deliver notifications to your device. Your Expo Push Token and the notification content (e.g. "You have a new friend request") are sent to Expo's servers for delivery.
5. Information Sharing
We do not sell, trade, rent, or share your personal information with third parties for advertising or marketing purposes. We will never monetise your data.
We may disclose information only:
- To the third-party services listed above, solely to operate the app
- To other users through the social features described in Section 3
- If required by law, regulation, or legal process
- To protect the safety, rights, or property of our users or the public
6. Data Storage and Security
Your data is stored in Google Cloud Firestore and Firebase Storage, secured by Firebase's infrastructure, which provides encryption in transit (TLS) and at rest. Authentication is handled through Firebase Auth with secure password hashing.
Profile images are stored on Google Cloud infrastructure (Firebase Storage). Data is processed in Google Cloud data centres, and international data transfers are protected by Standard Contractual Clauses as provided by Google's Data Processing Terms.
The app also caches movie data, your filter preferences, and notification history locally on your device using AsyncStorage. This data never leaves your device and is removed when you uninstall the app.
7. Data Retention and Deletion
We retain your data for as long as your account is active.
When you delete your account through the app, we permanently delete:
- Your profile, authentication credentials, and all personal details
- Your entire swipe history, watchlist, shortlist, and wishlist
- All friend connections, friend requests, and blocked user records
- All playlists, movie matches, and sharing history involving you
- Your profile image (if uploaded) from Firebase Storage
- All notifications and metadata associated with your account
- Your login activity history
- Your signup metadata (IP address, approximate location, device information)
Your signup IP address, approximate location, and device information are retained for the lifetime of your account and deleted when you delete your account.
Temporary rate-limiting records (IP address counts used to prevent abuse) are automatically purged after 24 hours.
Locally cached data on your device is removed when you uninstall the app.
8. Your Rights
- Access and edit your profile information at any time through the app
- Export your watchlist data in multiple formats
- Control your notification preferences for each notification type
- Control your search visibility through Privacy Settings (choose whether others can find you by name, email, username, or phone number)
- Remove your profile image at any time from Settings > Account
- Block other users to prevent them from interacting with you
- Request a copy of the personal data we hold about you by contacting us
- Delete your account and all associated data permanently from within the app
9. Children's Privacy
ReelOnes is rated 13+ on the App Store. Account creation requires users to be at least 13 years old. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will delete that data promptly.
10. Changes to This Policy
We may update this privacy policy from time to time. When we make changes, we will update the "Last Updated" date at the top of this page. We encourage you to review this policy periodically.
11. Contact Us
If you have questions about this privacy policy or how your data is handled, please contact us at support@reelones.co.uk.