Privacy Policy
Your data, plainly explained
Effective 12 August 2026
At a glance
- WatchDraft never sees your TMDB password — you sign in directly with TMDB, and WatchDraft only receives a session token.
- Your watch history, ratings, and lists live on your TMDB account. WatchDraft only copies the parts you choose to share with your Friends & Family network.
- We don't run ads, sell data, or use third-party trackers.
- You can permanently delete your WatchDraft account and data from Settings, at any time.
Who this policy covers
WatchDraft is developed and operated by Steven Carr-Rollitt, an individual developer ("WatchDraft", "we", "us"). This policy explains what data the WatchDraft mobile app collects, why, and how to control or delete it. It applies to the app on iOS and Android and to this website.
Information we collect
Account & sign-in
WatchDraft doesn't have its own account system — you sign in with your existing TMDB (The Movie Database) account through TMDB's own login page. WatchDraft never sees or stores your TMDB password. After you approve access, TMDB gives WatchDraft a session token and your basic account details (account ID, username). We store those on your device, in the operating system's secure storage (Keychain on iOS, Keystore on Android) — not in plain text, and not on our servers beyond what's described below.
Friends & Family network
If you connect with friends or family, WatchDraft creates a matching identity in our database (Firebase, operated by Google) so the two of you can see each other's shared lists. This is where WatchDraft stores data of its own, separate from TMDB:
- Profile — your display name, an invite code, and your sharing preferences.
- Share snapshot — a copy of whichever categories you've turned on sharing for (favourites, watchlist, ratings, or specific lists). Only what you explicitly enable is copied here.
- Connections — who you're connected to, created only when someone uses your invite link or you use theirs.
- Hidden titles — titles you've marked "not interested." This list is private to you; it is never visible to your connections.
None of this exists until you sign in and connect with your first friend — browsing and searching movies and TV shows works without any of it.
Usage & diagnostic data
We use Firebase Analytics and Firebase Crashlytics to understand how the app is used and to catch crashes, both operated by Google. This can include app events (e.g. which screens you open), device model and OS version, and crash logs. You can turn analytics off entirely in Settings — this switch is respected before any data is sent. Crash reporting stays on, since it contains no personal content and is what lets us fix bugs.
How we use this data
- To sign you in and keep your session working across app restarts.
- To run the Friends & Family network — matching invite links, showing connections their shared lists, and nothing more.
- To diagnose crashes and understand which features are actually used, so we know what to fix or improve.
We do not use your data for advertising, and we do not sell it to anyone.
Who we share it with
WatchDraft works with a small number of service providers, each acting strictly as infrastructure:
- TMDB — the source of all movie and TV data, and your sign-in provider. Anything you do directly with your TMDB account (searches, ratings, watchlist, favourites, custom lists) is governed by TMDB's own privacy policy, not this one.
- Google Firebase — hosts the Friends & Family database, authentication, analytics, and crash reporting described above. Data held here is stored in Google's europe-west2 (London) region.
- The people in your network — a connection can see whatever you've explicitly chosen to share (see "Friends & Family network" above), and nothing else. Your hidden titles and unshared categories are never visible to anyone but you.
We don't work with advertising networks, data brokers, or analytics trackers beyond Firebase.
How long we keep it
Your WatchDraft profile, shares, connections, and hidden list are kept for as long as your account exists. If you sign out without deleting your account, this data is simply left as-is for when you sign back in. Deleting your account (see below) removes it immediately and permanently.
Deleting your account
Open Account → Settings → Delete Account at any time. This permanently deletes your WatchDraft profile, share snapshot, hidden list, and every connection you're part of, and removes the WatchDraft identity tied to your TMDB account. It happens immediately — there's no waiting period, and no need to contact support first.
This does not delete your TMDB account, since that account belongs to TMDB, not WatchDraft. After deleting your WatchDraft data, the app offers a direct link to TMDB's account settings if you'd also like to close that account.
Your rights
If you're in the UK or EU, you have rights under UK/EU GDPR to access, correct, export, or object to our processing of your data, in addition to deletion. Most of these are self-service in the app already — your profile and share preferences are editable directly, and account deletion is described above. For anything else, or if you're elsewhere and want the same, contact us at the address below. If you're in the UK and unhappy with our response, you can complain to the Information Commissioner's Office (ICO).
Children's privacy
WatchDraft is not directed at children, and signing in requires a TMDB account, which TMDB itself does not issue to children under 13. We don't knowingly collect data from children. If you believe a child has provided us data, contact us and we'll remove it.
Security
All traffic between the app and TMDB or Firebase is encrypted in transit (TLS). Session tokens are stored in your device's secure storage, not in plain text. Access to Friends & Family data in our database is restricted by rules enforced on Google's servers: only you can read your hidden list, and only accepted connections can read what you've chosen to share.
Changes to this policy
If this policy changes materially, we'll update the effective date above. Continued use of the app after a change means you accept the update.
Contact
Questions, data requests, or anything else: support@watchdraft.com.