Privacy Policy
This policy explains what Let’s Watch (letswatch.xyz, operated by Anthony Katwan; “we”, “us”) collects, why, and what you can do about it. We collect as little as we can to run the Service.
What we collect
What you enter
- The name you enter when you start or join a room, and an optional room name.
- Your survey answers, including any free-text answers and the streaming services you choose.
- Your activity in a room: films you save, mark as seen or pick, and requests for more options.
If you sign in (Pro)
- Your email address, used to sign you in and to link your subscription.
- If you choose to add them, your first name, last name and birthday. They’re optional, kept with your account, never sent to the AI model, and you can remove them at any time.
- Your taste profile: the answers to your taste quiz (including films you love or hated), the films you’ve saved, picked, marked as seen, rated, marked “not for me” or passed over, and the genres you’ve ruled out, from rooms you were in while signed in. It’s used only to build your future lists.
What’s collected automatically
- IP address. Used to limit how many lists one connection can generate each day. It’s stored in a rate-limit record that resets every 24 hours.
- Usage events. We log events such as “room created” or “list generated” to understand how the Service is used. In these logs, visitors are identified by a salted, one-way hash of the IP address, not the address itself. They contain no names or survey answers.
- Product analytics (PostHog). Unless your browser sends Do Not Track, we use PostHog to count named events such as page views and taps on key buttons. We don’t send PostHog your name, room name, survey answers or room codes, and we don’t build person profiles. PostHog sets a cookie and uses local storage to recognise a returning browser.
- Browser storage. Your browser keeps a small token for each room you’re in, so you’re still in it when you come back. It isn’t used for tracking. If you sign in, it also keeps your sign-in session.
Payments
If you buy a paid plan, payment is handled by Stripe, which collects your payment details under its own privacy policy. We receive only what we need to manage your plan, such as your email address and payment status, never your full card number.
How we use it
- To run the Service: build suggestions, show rooms to their members, and keep your place.
- To keep it working and fair: rate limits, abuse prevention and debugging.
- To improve it, using usage data.
- To process payments and answer support requests.
We don’t sell your personal information, and we don’t use it for advertising.
Who it’s shared with
- Other people in your room see the name you entered and what you saved and marked as seen. Anyone with a room’s link can see the film that was picked.
- Anthropic, our AI provider, receives the names and survey answers of everyone in a room to generate suggestions.
- Google Cloud hosts the Service and its database.
- TMDB provides movie details, and streaming availability via JustWatch. We send it film titles, not information about you.
- PostHog receives the analytics events described above.
- YouTube plays trailers, only when you press play, using its privacy-enhanced (no-cookie) player.
- Stripe processes payments, if you buy a paid plan.
- Supabase handles sign-in and stores your email address, if you create an account. Resend delivers the sign-in emails.
- Authorities, where we’re legally required to disclose information.
How long we keep it
Room data (names, answers, saves and picks) is kept so rooms keep working when you return to them. Usage logs are kept for as long as they’re useful for understanding the Service. Rate-limit records reset every 24 hours. You can ask us to delete a room or your data at any time.
Your choices
- Turn on Do Not Track in your browser and PostHog analytics won’t run.
- Clear your browser’s site data to remove room tokens and analytics identifiers.
- Clear your taste profile at any time from the Pro page.
- Email us to access, correct or delete your data, including your account. Depending on where you live (for example California, the EU or the UK) you may have additional rights, and we’ll honour them.
Children
The Service isn’t directed at children under 13, and we don’t knowingly collect their information. If you think a child has given us information, email us and we’ll delete it.
Security
Data is sent over HTTPS and stored with our hosting provider. Room access relies on hard-to-guess tokens kept in your browser. No system is perfectly secure, so please don’t enter sensitive information.
Where it’s processed
The Service runs in the United States, and your information is processed there.
Changes
We’ll post changes here and update the effective date at the top.
Contact
Privacy questions or requests: anthony.katwan1@gmail.com.