Effective date: [DATE]
This policy explains what [ENTITY NAME, jurisdiction] (“BingeReel”, “we”, “us”), [ADDRESS], collects when you use the BingeReel app and the websites bingereel.tv and bingereel.app, why, who we share it with, and what you can do about it.
The short version:
- We collect what the app needs to play video, keep your coin balance right, and show you ads if you are not on a pass. That is device identifiers, purchase receipts, and what you watch.
- We only get an email address if you sign in with one. Email sign-in uses a one-time sign-in link (a magic link); we never store a password.
- The app is for people 13 and over; the first-launch screen says so. We ask your age band (13 to 17, or 18 and over) once, when you sign in or, as a guest, at the first locked episode before any purchase option. Until you declare a band we treat you as 13 to 17. A guest account with an installation ID, device data and your IP address exists from the moment the app first opens, before that screen; section 1 lists exactly what it holds.
- On iOS we ask before using the advertising identifier. If you say no, ads are not personalised.
- We do not sell your personal information. Ad networks may count as “sharing” under California law; you can opt out in Settings, Privacy.
- You can delete your account and data from Settings, Account, Delete account, or on the web at bingereel.tv/account/delete. Deleting your account does not cancel a pass billed by Apple or Google; cancel it with the store first.
1. What we collect
Information you give us
- Sign-in details: if you sign in with Apple or Google, we receive your name (or the alias Apple gives us), the email address the provider shares, and a provider user ID. If you sign in with email, we store that email address. Sign-in is by a one-time sign-in link (a magic link) sent to your inbox; we do not create or store a password.
- Age band: we ask once whether you are 13 to 17 or 18 and over, inside the sign-in sheet when you sign in or, for guests, at the top of the first locked-episode screen before any purchase option is shown. We store the band, not a birthdate. Until you declare a band the account is treated as 13 to 17: 18+ titles are hidden and ads are not personalised. No purchase and no 18+ title is possible before a band is declared.
- Support messages: whatever you send to support@bingereel.tv, or through the Contact us form in the app’s Help page: the topic, your description, an order ID and a screenshot if you choose to add them, and, filled in by the form, your account ID, app version, operating system and device model. We give each message a ticket number and put a confirmation in your in-app inbox.
- Episode reports: when you report an episode, we record the series, the episode, where in the episode you were, the audio and subtitle tracks you had on, the app version, the reason you picked and any text you add (up to 300 characters). We do not ask for your email and do not tell other users who reported what.
- Reminders: the upcoming series you ask us to remind you about.
- Linked sign-in methods: which of Apple, Google and email are linked to your account.
- Optional profile: a display name and avatar if you set one.
- Comments or lists, if those features are on.
Information collected automatically
- Device and app data: device model, operating system version, app version, language, time zone (used to set when your daily rewards reset), screen size, IP address, and a random installation ID we generate. On Android we also read the Android ID; on iOS we use the identifier for vendor (IDFV).
- Viewing events: which series and episodes you open, how far you watch, swipes, pauses, unlocks, searches, and which screens you see. This is how we resume playback, rank the feed, and measure the product.
- Coin and pass events: coins earned, spent, expired, and purchased; pass status; rewarded-ad completions; check-ins.
- Purchase data: when you buy through Apple or Google, we receive a receipt or purchase token, the product bought, price, currency, and the store’s transaction ID. We never see your card number. Web purchases (when offered) go through Stripe, which handles card data; we receive the transaction ID, amount, and the last four digits.
- Advertising identifier: on iOS, the IDFA, only if you allow tracking when the App Tracking Transparency prompt appears. On Android, the Google Advertising ID, subject to the “Delete advertising ID” or “Opt out of Ads Personalization” settings on your device. We do not send any advertising identifier for accounts in the 13 to 17 band.
- Approximate location: we work out your country and region from your IP address on our server at the moment of each request, in memory, to choose the right storefront and pricing. This is approximate location data derived from the IP address and we declare it as collected in both store privacy forms (section 9). We do not store it, we do not share it, and we never read the device’s location sensors. The IP address itself is kept in server logs for 30 days (section 4).
- Crash and performance data: crash logs, load times, and rebuffer events.
- Push token: if you allow notifications, the token needed to deliver them.
- Terms acceptance record: the terms version, date and time, and your installation or account ID, recorded when you tap Start watching on the first-launch screen and again, with the transaction ID and the prices and sentences shown, when you tap Subscribe on a pass confirmation screen. Coin pack purchases do not create an acceptance record. Your age band is stored separately when you declare it.
What exists before you declare an age band. The moment the app first opens, before the first-launch screen and before any age band, we create a guest account on our servers keyed by a random installation ID, and we hold the device and app data listed above, your time zone, your IP address in server logs for 30 days, and the first analytics events (the app opening, and whether you allowed notifications). Once you tap Start watching, viewing events and coin events follow as you watch and earn. Nothing else exists until you act: no name or email until you sign in, no purchase and no purchase data until you declare a band, and no 18+ title until you declare the 18-and-over band.
Information from other sources
- Apple and Google: purchase and subscription status, refunds, and chargebacks.
- Ad networks: whether a rewarded ad was completed, so we can credit coins.
- Attribution partners (when we run paid campaigns): which ad or link led to the install.
2. Why we use it
| Purpose | Data used |
|---|---|
| Play video and resume where you left off | device data, viewing events |
| Keep your coin balance and pass status correct, prevent fraud and reward abuse | purchase data, coin events, device IDs, IP |
| Show age-appropriate titles and switch off personalised ads for minors | declared age band (an undeclared account is treated as 13 to 17) |
| Show ads to non-pass users and credit rewarded-ad coins | advertising ID (with consent on iOS; never for the 13 to 17 band), device data |
| Rank the feed and recommend series | viewing events |
| Send push notifications (continue watching, new episodes and releases you asked to be reminded of, recommendations, streak reminders, reward-coin expiry, renewal reminders; each of the six has its own switch in Settings) | push token, viewing events, reminders, pass status |
| Deliver purchase confirmations and renewal reminders | pass status; in-app inbox for everyone; email only if you signed in with one |
| Answer support requests and handle refunds | email, purchase data, support messages and their device details and screenshots |
| Review reported episodes and fix playback problems | episode reports |
| Measure and improve the app, fix crashes | device data, viewing events, crash data |
| Measure ad campaigns | attribution data, install ID |
| Comply with law, enforce our terms, keep proof of consent | any of the above as needed; terms acceptance record |
We do not use your data to make decisions with legal effect about you, and we do not build profiles for anything other than what is listed here.
3. Who we share it with
We share personal information only with providers who work for us under contract, with the app stores and payment processors, with ad networks as described, and when the law requires. At launch these are:
| Provider | Role | What they get | Where |
|---|---|---|---|
| Render | hosts our servers and database | everything we collect, stored on our behalf | United States |
| Cloudflare | delivers video and protects our sites (CDN, storage, edge security) | IP address, request logs, cached video | global edge, US storage |
| PostHog | product analytics and session replay (replay off by default) | viewing and app events, install ID, device data | United States |
| RevenueCat | tracks purchases and subscription state across stores | store receipts, product IDs, install ID, app user ID | United States |
| Google AdMob | serves ads and rewarded video | advertising ID (with consent, adults only), device data, IP | United States |
| Apple (App Store, Sign in with Apple, StoreKit) | app distribution, sign-in, payments | purchase and sign-in data under Apple’s policy | United States |
| Google (Play, Sign in with Google, Play Billing, Firebase Cloud Messaging) | app distribution, sign-in, payments, push delivery | purchase, sign-in, and push data under Google’s policy | United States |
| [Email delivery provider] | sends sign-in links, purchase confirmations, and reminders to signed-in accounts | email address, message content | United States |
| Stripe | card payments on the web (when offered) | payment details you enter, email, transaction data | United States |
We also share information when required by law, subpoena, or court order; to protect our rights, users, or the public; and with a buyer or successor if BingeReel is sold or merged, in which case this policy continues to apply.
We do not sell personal information for money. Showing personalised ads through AdMob may be treated as “sharing” or “targeted advertising” under some US state laws. You can opt out (section 7). We never share data for personalised ads from accounts in the 13 to 17 band.
4. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | until you delete your account, then removed within 30 days |
| Coin ledger and purchase records | 7 years after the transaction, for tax and dispute purposes; unlinked from your account after deletion |
| Terms acceptance and purchase consent records | 3 years after the account closes (California ARL retention) |
| Viewing events and analytics | 24 months, then deleted or aggregated |
| Advertising ID | not stored by us beyond the ad session; held by AdMob under its policy |
| Approximate location from IP | not stored; derived in memory for the request only (declared as collected, ephemeral, in both store forms) |
| IP address | 30 days, in server and security logs |
| Crash logs | 90 days |
| Support emails, in-app support messages and attached screenshots | 2 years after the ticket closes |
| Episode reports | 2 years after the report [counsel: confirm the period] |
| Backups | rolling 35 days, then overwritten |
Guest accounts. A guest account that has never bought anything and holds no coins is deleted after 12 months without activity. A guest account holding purchased coins or an active pass is never deleted for inactivity; it stays until you delete it or sign in and merge it.
5. Children and age bands
BingeReel is not for children under 13, and we do not knowingly collect personal information from anyone under 13. BingeReel is a general-audience service with an age floor, not a service directed to children: the first-launch screen states that the app is for people 13 and over and asks anyone under 13 not to continue, and tapping Start watching there is the user’s statement that they are 13 or over. We do not ask for a birthdate and do not run a separate age screen at first launch. The age band (13 to 17 or 18 and over) is asked once, at sign-in or before the first purchase option, and until it is declared the account is treated as 13 to 17. A guest who ignores the floor and watches is therefore treated as a minor (no personalised ads, no 18+ titles); the data held on such a guest account is the list in section 1 under “What exists before you declare an age band”. If we learn we have collected data from a child under 13, we delete it and close the account. Parents who think a child under 13 has used the app can write to support@bingereel.tv.
Accounts in the 13 to 17 band, and accounts that have not yet declared a band, do not see titles marked 18+, do not receive personalised ads, and have “Do not share my info for ads” switched on and locked. We do not send their advertising identifier to any ad network and we pass the under-age-of-consent flag to AdMob.
6. Your choices
- Tracking on iOS: you decide at the App Tracking Transparency prompt, and can change it any time in iOS Settings, Privacy & Security, Tracking.
- Ads personalisation on Android: device Settings, Google, Ads.
- Do not share my info for ads: Settings, Privacy, “Do not share my info for ads”. This stops your advertising ID and device data going to ad networks for personalised ads on both platforms.
- Push notifications: turn off in your device settings or, one type at a time, in Settings, Notifications.
- Analytics: Settings, Privacy, “Share usage analytics”. Essential events (purchases, coin ledger) still run because the product cannot work without them.
- Marketing email (signed-in accounts only): unsubscribe link in every message.
- Delete your account: Settings, Account, Delete account; on the web at https://bingereel.tv/account/delete; or email support@bingereel.tv. A request from the web or by email goes ahead only after we confirm it comes from the account holder, for example with a one-time link sent to the contact email you give. For a guest account (never signed in) that still holds purchased coins or a pass, the link is not enough: support confirms ownership first, from a confirmation made in the app on the device or a store order number that belongs to the account, and closes the request without deleting anything if ownership cannot be confirmed within 30 days. We confirm in the app and, if you are signed in with an email address, by email, and complete deletion within 30 days. Deletion does not cancel a pass billed by Apple or Google; the deletion screen and the web page link to the store’s subscription page so you can cancel it there first. Purchase records are kept in de-identified form as noted in section 4.
- Access or export your data: email support@bingereel.tv and we will send a copy within 30 days after verifying it is you.
7. California and other US state rights
If you live in California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or another state with a consumer privacy law, you have the right to know what personal information we collect and how we use it; to get a copy; to correct it; to delete it; to opt out of the sale or sharing of personal information and of targeted advertising; and not to be treated differently for exercising these rights. We do not use or disclose sensitive personal information for anything beyond what the law allows without an opt-in.
Categories of personal information collected in the last 12 months, mapped to the California Consumer Privacy Act (CCPA):
| CCPA category | Collected | Examples | Sold | Shared for cross-context behavioral advertising |
|---|---|---|---|---|
| Identifiers | yes | install ID, device IDs, IP, email, provider user ID, advertising ID | no | yes (advertising ID, IP, device data to AdMob; adults only, opt-out available) |
| Customer records | yes | name (if provided), email, purchase records | no | no |
| Protected classifications | age band only | 13 to 17 or 18 and over | no | no |
| Commercial information | yes | coins purchased and spent, pass status | no | no |
| Biometric information | no | |||
| Internet or network activity | yes | viewing events, screens, searches, crash data | no | yes (limited event data to AdMob for ad measurement) |
| Geolocation | approximate only, not stored | country and region derived from IP in memory per request; no precise location; no device sensors | no | no |
| Sensory data | no | |||
| Professional information | no | |||
| Education information | no | |||
| Inferences | yes | what you are likely to watch next | no | no |
| Sensitive personal information | no | no account password exists (email sign-in uses a one-time sign-in link), no precise geolocation, no biometrics, no government IDs, no financial account numbers (the stores and Stripe hold card data), no health or sex-life data, no message contents beyond the support messages and episode reports you choose to send | no | no |
Sources: you, your device, Apple and Google, ad networks, attribution partners. Business purposes and recipients are described in sections 2 and 3.
How to exercise your rights: email support@bingereel.tv with “Privacy request” in the subject, or use the privacy request link in Settings, Privacy in the app. We verify requests by sending a confirmation to the email on the account, or by asking you to confirm from inside the app on the device you use. You can appoint an authorised agent; we will ask the agent for proof of authority. We respond within 45 days and may extend once by 45 days with notice.
Opt out of sharing: Settings, Privacy, “Do not share my info for ads”, or turn off tracking at the OS level as in section 6. We also honour Global Privacy Control signals on our websites (section 8).
We do not offer financial incentives in exchange for personal information. Coin rewards for tasks such as turning on notifications are rewards for using a feature, not payment for data.
8. Cookies and the websites
bingereel.tv and bingereel.app use two kinds of cookies and similar storage:
- Strictly necessary: session and security cookies that keep you signed in, protect forms, and (once web checkout ships) complete a purchase. These cannot be switched off.
- Analytics: PostHog measures page views and how the site is used, keyed to a random ID. No advertising cookies, no third-party ad trackers, and no cross-site tracking on the web.
If your browser sends a Global Privacy Control (GPC) signal, we treat it as an opt-out of sharing and disable analytics cookies for that browser. You can also switch analytics off from the cookie banner or the footer link “Cookie settings”. The full list of cookies, with purpose and lifetime, is in the cookie policy at bingereel.tv/cookies, which the app links from Settings, Legal. Web purchases, when offered, go through Stripe, whose cookies are covered by Stripe’s policy.
9. Google Play Data Safety mapping
For the Play Console Data Safety form, our answers are:
| Data type | Collected | Shared | Purpose | Optional | Encrypted in transit | Deletable |
|---|---|---|---|---|---|---|
| Personal info: email address, name | yes (signed-in users) | yes (email delivery provider, for signed-in accounts) | account management, app functionality (sign-in links, purchase confirmations) | yes (guest use possible) | yes | yes |
| Personal info: user IDs | yes | yes (RevenueCat, PostHog, AdMob) | app functionality, analytics, advertising | no | yes | yes |
| Personal info: other (age band) | yes, once declared at sign-in or before the first purchase option | no | app functionality (content gating) | no | yes | yes |
| Financial info: purchase history | yes | yes (RevenueCat) | app functionality, fraud prevention | no | yes | yes |
| App activity: app interactions, in-app search history, other user-generated content (comments if enabled) | yes | yes (PostHog) | analytics, personalisation | analytics opt-out available; core events not optional | yes | yes |
| App info and performance: crash logs, diagnostics | yes | yes (PostHog) | analytics | no | yes | yes |
| Device or other IDs (install ID, Android ID, advertising ID, IP address) | yes | yes (AdMob, PostHog, RevenueCat, Cloudflare) | advertising (adults only), analytics, fraud prevention | advertising ID: yes via device setting and in-app toggle; others: no | yes | yes (IP ages out of logs after 30 days) |
| Location: approximate location | yes, with the ephemeral-processing flag set (derived from the IP address on our server for each request, held in memory only, never stored) | no | app functionality (storefront and pricing) | no | yes | nothing stored, so nothing to delete |
| Location: precise location | no | |||||
| Messages: other in-app messages (support form text, episode report text) | yes, only when you send one | no | app functionality (customer support, content review) | yes | yes | yes |
| Photos | yes, only a screenshot you attach to a support message | no | app functionality (customer support) | yes | yes | yes |
| Videos, audio, files | no | |||||
| Contacts, calendar, health, web browsing | no |
Security practices: data encrypted in transit (TLS); users can request deletion in the app and at https://bingereel.tv/account/delete; the app is not designed for children under 13 (age floor stated at first launch; age band declared before any purchase); independent security review: no.
Why approximate location is declared. Google’s Data Safety page says data processed ephemerally still has to be included in the form (it is then not displayed in the store if the ephemeral standard is met) and that approximate location inferred from an IP address must be disclosed. Declaring it as collected with the ephemeral flag set is accurate under every reading of that page; leaving it out is accurate under only one. The App Store form says the same thing under Coarse Location.
The App Store privacy labels are drafted in store-listing.md from this same table. The two forms and this policy must agree, and item 4.11 of the checklist assigns one reviewer to all three.
10. International transfers
We operate from the United States and our providers store data there. If you use BingeReel from outside the United States, your data is transferred to and processed in the United States, where privacy laws may differ from your country’s. BingeReel launches in the United States only. If we later offer the app in the European Economic Area, the United Kingdom, or Switzerland, we will add the lawful-basis, data-controller, and transfer-mechanism disclosures those laws require before doing so.
11. Security
We use TLS for all traffic, encrypt the database at rest, restrict staff access, and keep audit logs of coin and purchase changes. No system is perfectly secure; if a breach affects you we will notify you as the law requires.
12. Changes to this policy
We will post updates here with a new effective date and, for material changes, notify you in the app’s inbox before they take effect, and by email as well if you are signed in with an email address.
13. Contact
Privacy questions and requests: support@bingereel.tv [ENTITY NAME], [ADDRESS]