Effective date: [DATE]
This policy explains what [ENTITY NAME, jurisdiction] (“BingeReel”, “we”, “us”), [ADDRESS], collects when you use the BingeReel app and the websites bingereel.tv and bingereel.app, why, who we share it with, and what you can do about it.
The short version:
- We collect what the app needs to play video, keep your coin balance right, and show you ads if you are not on a pass. That is device identifiers, purchase receipts, and what you watch.
- We only get an email address if you sign in with one. Email sign-in uses a one-time sign-in link (a magic link); we never store a password.
- We ask your age band (13 to 17, or 18 and over) on the first-launch screen. The app is for people 13 and over; nothing is stored until a band is chosen.
- On iOS we ask before using the advertising identifier. If you say no, ads are not personalised.
- We do not sell your personal information. Ad networks may count as “sharing” under California law; you can opt out in Settings, Privacy.
- You can delete your account and data from Settings, Account, Delete account.
1. What we collect
Information you give us
- Sign-in details: if you sign in with Apple or Google, we receive your name (or the alias Apple gives us), the email address the provider shares, and a provider user ID. If you sign in with email, we store that email address. Sign-in is by a one-time sign-in link (a magic link) sent to your inbox; we do not create or store a password.
- Age band: on the first-launch screen we ask whether you are 13 to 17 or 18 and over. We store the band, not a birthdate. The screen says the app is for people 13 and over and asks anyone under 13 not to continue; until a band is chosen the app goes no further and nothing is stored.
- Support messages: whatever you send to support@bingereel.tv.
- Optional profile: a display name and avatar if you set one.
- Comments or lists, if those features are on.
Information collected automatically
- Device and app data: device model, operating system version, app version, language, time zone (used to set when your daily rewards reset), screen size, IP address, and a random installation ID we generate. On Android we also read the Android ID; on iOS we use the identifier for vendor (IDFV).
- Viewing events: which series and episodes you open, how far you watch, swipes, pauses, unlocks, searches, and which screens you see. This is how we resume playback, rank the feed, and measure the product.
- Coin and pass events: coins earned, spent, expired, and purchased; pass status; rewarded-ad completions; check-ins.
- Purchase data: when you buy through Apple or Google, we receive a receipt or purchase token, the product bought, price, currency, and the store’s transaction ID. We never see your card number. Web purchases (when offered) go through Stripe, which handles card data; we receive the transaction ID, amount, and the last four digits.
- Advertising identifier: on iOS, the IDFA, only if you allow tracking when the App Tracking Transparency prompt appears. On Android, the Google Advertising ID, subject to the “Delete advertising ID” or “Opt out of Ads Personalization” settings on your device. We do not send any advertising identifier for accounts in the 13 to 17 band.
- Approximate location: we work out your country and region from your IP address at the moment of each request, in memory, to choose the right storefront and pricing. We do not store the location and we never read the device’s location sensors. The IP address itself is kept in server logs for 30 days (section 4).
- Crash and performance data: crash logs, load times, and rebuffer events.
- Push token: if you allow notifications, the token needed to deliver them.
- Terms acceptance record: the terms version, time, and age band you accepted on the first-launch screen and at each purchase.
Information from other sources
- Apple and Google: purchase and subscription status, refunds, and chargebacks.
- Ad networks: whether a rewarded ad was completed, so we can credit coins.
- Attribution partners (when we run paid campaigns): which ad or link led to the install.
2. Why we use it
| Purpose | Data used |
|---|---|
| Play video and resume where you left off | device data, viewing events |
| Keep your coin balance and pass status correct, prevent fraud and reward abuse | purchase data, coin events, device IDs, IP |
| Show age-appropriate titles and switch off personalised ads for minors | declared age band |
| Show ads to non-pass users and credit rewarded-ad coins | advertising ID (with consent on iOS; never for the 13 to 17 band), device data |
| Rank the feed and recommend series | viewing events |
| Send push notifications (new episodes, resume reminders, streak reminders, reward-coin expiry, renewal reminders; each has its own switch in Settings) | push token, viewing events, pass status |
| Deliver purchase confirmations and renewal reminders | pass status; in-app inbox for everyone; email only if you signed in with one |
| Answer support requests and handle refunds | email, purchase data, support messages |
| Measure and improve the app, fix crashes | device data, viewing events, crash data |
| Measure ad campaigns | attribution data, install ID |
| Comply with law, enforce our terms, keep proof of consent | any of the above as needed; terms acceptance record |
We do not use your data to make decisions with legal effect about you, and we do not build profiles for anything other than what is listed here.
3. Who we share it with
We share personal information only with providers who work for us under contract, with the app stores and payment processors, with ad networks as described, and when the law requires. At launch these are:
| Provider | Role | What they get | Where |
|---|---|---|---|
| Render | hosts our servers and database | everything we collect, stored on our behalf | United States |
| Cloudflare | delivers video and protects our sites (CDN, storage, edge security) | IP address, request logs, cached video | global edge, US storage |
| PostHog | product analytics and session replay (replay off by default) | viewing and app events, install ID, device data | United States |
| RevenueCat | tracks purchases and subscription state across stores | store receipts, product IDs, install ID, app user ID | United States |
| Google AdMob | serves ads and rewarded video | advertising ID (with consent, adults only), device data, IP | United States |
| Apple (App Store, Sign in with Apple, StoreKit) | app distribution, sign-in, payments | purchase and sign-in data under Apple’s policy | United States |
| Google (Play, Sign in with Google, Play Billing, Firebase Cloud Messaging) | app distribution, sign-in, payments, push delivery | purchase, sign-in, and push data under Google’s policy | United States |
| [Email delivery provider] | sends sign-in links, purchase confirmations, and reminders to signed-in accounts | email address, message content | United States |
| Stripe | card payments on the web (when offered) | payment details you enter, email, transaction data | United States |
We also share information when required by law, subpoena, or court order; to protect our rights, users, or the public; and with a buyer or successor if BingeReel is sold or merged, in which case this policy continues to apply.
We do not sell personal information for money. Showing personalised ads through AdMob may be treated as “sharing” or “targeted advertising” under some US state laws. You can opt out (section 7). We never share data for personalised ads from accounts in the 13 to 17 band.
4. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | until you delete your account, then removed within 30 days |
| Coin ledger and purchase records | 7 years after the transaction, for tax and dispute purposes; unlinked from your account after deletion |
| Terms acceptance and purchase consent records | 3 years after the account closes (California ARL retention) |
| Viewing events and analytics | 24 months, then deleted or aggregated |
| Advertising ID | not stored by us beyond the ad session; held by AdMob under its policy |
| Approximate location from IP | not stored; used in memory for the request only |
| IP address | 30 days, in server and security logs |
| Crash logs | 90 days |
| Support emails | 2 years after the ticket closes |
| Backups | rolling 35 days, then overwritten |
Guest accounts. A guest account that has never bought anything and holds no coins is deleted after 12 months without activity. A guest account holding purchased coins or an active pass is never deleted for inactivity; it stays until you delete it or sign in and merge it.
5. Children and age bands
BingeReel is not for children under 13, and we do not knowingly collect personal information from anyone under 13. The first-launch screen asks for an age band before anything else is stored, states that the app is for people 13 and over, and asks anyone under 13 not to continue. If we learn we have collected data from a child under 13, we delete it. Parents who think a child under 13 has used the app can write to support@bingereel.tv.
Accounts in the 13 to 17 band do not see titles marked 18+, do not receive personalised ads, and have “Do not share my info for ads” switched on and locked. We do not send their advertising identifier to any ad network and we pass the under-age-of-consent flag to AdMob.
6. Your choices
- Tracking on iOS: you decide at the App Tracking Transparency prompt, and can change it any time in iOS Settings, Privacy & Security, Tracking.
- Ads personalisation on Android: device Settings, Google, Ads.
- Do not share my info for ads: Settings, Privacy, “Do not share my info for ads”. This stops your advertising ID and device data going to ad networks for personalised ads on both platforms.
- Push notifications: turn off in your device settings or, one type at a time, in Settings, Notifications.
- Analytics: Settings, Privacy, “Share usage analytics”. Essential events (purchases, coin ledger) still run because the product cannot work without them.
- Marketing email (signed-in accounts only): unsubscribe link in every message.
- Delete your account: Settings, Account, Delete account, or email support@bingereel.tv. We confirm in the app and, if you are signed in with an email address, by email, and complete deletion within 30 days. Purchase records are kept in de-identified form as noted in section 4.
- Access or export your data: email support@bingereel.tv and we will send a copy within 30 days after verifying it is you.
7. California and other US state rights
If you live in California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or another state with a consumer privacy law, you have the right to know what personal information we collect and how we use it; to get a copy; to correct it; to delete it; to opt out of the sale or sharing of personal information and of targeted advertising; and not to be treated differently for exercising these rights. We do not use or disclose sensitive personal information for anything beyond what the law allows without an opt-in.
Categories of personal information collected in the last 12 months, mapped to the California Consumer Privacy Act (CCPA):
| CCPA category | Collected | Examples | Sold | Shared for cross-context behavioral advertising |
|---|---|---|---|---|
| Identifiers | yes | install ID, device IDs, IP, email, provider user ID, advertising ID | no | yes (advertising ID, IP, device data to AdMob; adults only, opt-out available) |
| Customer records | yes | name (if provided), email, purchase records | no | no |
| Protected classifications | age band only | 13 to 17 or 18 and over | no | no |
| Commercial information | yes | coins purchased and spent, pass status | no | no |
| Biometric information | no | |||
| Internet or network activity | yes | viewing events, screens, searches, crash data | no | yes (limited event data to AdMob for ad measurement) |
| Geolocation | approximate only, not stored | country and region derived from IP in memory per request; no precise location; no device sensors | no | no |
| Sensory data | no | |||
| Professional information | no | |||
| Education information | no | |||
| Inferences | yes | what you are likely to watch next | no | no |
| Sensitive personal information | no | no account password exists (email sign-in uses a one-time sign-in link), no precise geolocation, no biometrics, no government IDs, no financial account numbers (the stores and Stripe hold card data), no health or sex-life data, no message contents beyond support email | no | no |
Sources: you, your device, Apple and Google, ad networks, attribution partners. Business purposes and recipients are described in sections 2 and 3.
How to exercise your rights: email support@bingereel.tv with “Privacy request” in the subject, or use the privacy request link in Settings, Privacy in the app. We verify requests by sending a confirmation to the email on the account, or by asking you to confirm from inside the app on the device you use. You can appoint an authorised agent; we will ask the agent for proof of authority. We respond within 45 days and may extend once by 45 days with notice.
Opt out of sharing: Settings, Privacy, “Do not share my info for ads”, or turn off tracking at the OS level as in section 6. We also honour Global Privacy Control signals on our websites (section 8).
We do not offer financial incentives in exchange for personal information. Coin rewards for tasks such as turning on notifications are rewards for using a feature, not payment for data.
8. Cookies and the websites
bingereel.tv and bingereel.app use two kinds of cookies and similar storage:
- Strictly necessary: session and security cookies that keep you signed in, protect forms, and (once web checkout ships) complete a purchase. These cannot be switched off.
- Analytics: PostHog measures page views and how the site is used, keyed to a random ID. No advertising cookies, no third-party ad trackers, and no cross-site tracking on the web.
If your browser sends a Global Privacy Control (GPC) signal, we treat it as an opt-out of sharing and disable analytics cookies for that browser. You can also switch analytics off from the cookie banner or the footer link “Cookie settings”. Web purchases, when offered, go through Stripe, whose cookies are covered by Stripe’s policy.
9. Google Play Data Safety mapping
For the Play Console Data Safety form, our answers are:
| Data type | Collected | Shared | Purpose | Optional | Encrypted in transit | Deletable |
|---|---|---|---|---|---|---|
| Personal info: email address, name | yes (signed-in users) | yes (email delivery provider, for signed-in accounts) | account management, app functionality (sign-in codes, purchase confirmations) | yes (guest use possible) | yes | yes |
| Personal info: user IDs | yes | yes (RevenueCat, PostHog, AdMob) | app functionality, analytics, advertising | no | yes | yes |
| Personal info: other (age band) | yes | no | app functionality (content gating) | no | yes | yes |
| Financial info: purchase history | yes | yes (RevenueCat) | app functionality, fraud prevention | no | yes | yes |
| App activity: app interactions, in-app search history, other user-generated content (comments if enabled) | yes | yes (PostHog) | analytics, personalisation | analytics opt-out available; core events not optional | yes | yes |
| App info and performance: crash logs, diagnostics | yes | yes (PostHog) | analytics | no | yes | yes |
| Device or other IDs (install ID, Android ID, advertising ID, IP address) | yes | yes (AdMob, PostHog, RevenueCat, Cloudflare) | advertising (adults only), analytics, fraud prevention | advertising ID: yes via device setting and in-app toggle; others: no | yes | yes (IP ages out of logs after 30 days) |
| Location | not declared: approximate region is derived from the IP address in memory for the request and never stored, which is ephemeral processing under Google’s definition; the IP address itself is declared under Device or other IDs above | |||||
| Messages | no | |||||
| Photos, videos, audio, files | no | |||||
| Contacts, calendar, health, web browsing | no |
Security practices: data encrypted in transit (TLS); users can request deletion in the app and at https://bingereel.tv/account/delete; the app is not designed for children under 13 (age gate at first launch); independent security review: no.
The App Store privacy labels are drafted in store-listing.md from this same table. The two forms and this policy must agree, and item 4.11 of the checklist assigns one reviewer to all three.
10. International transfers
We operate from the United States and our providers store data there. If you use BingeReel from outside the United States, your data is transferred to and processed in the United States, where privacy laws may differ from your country’s. BingeReel launches in the United States only. If we later offer the app in the European Economic Area, the United Kingdom, or Switzerland, we will add the lawful-basis, data-controller, and transfer-mechanism disclosures those laws require before doing so.
11. Security
We use TLS for all traffic, encrypt the database at rest, restrict staff access, and keep audit logs of coin and purchase changes. No system is perfectly secure; if a breach affects you we will notify you as the law requires.
12. Changes to this policy
We will post updates here with a new effective date and, for material changes, notify you in the app’s inbox before they take effect, and by email as well if you are signed in with an email address.
13. Contact
Privacy questions and requests: support@bingereel.tv [ENTITY NAME], [ADDRESS]