poppd — Privacy Policy
Effective: 4 October 2026
This page describes what the app actually does today, in plain language rather than boilerplate. Questions about anything here: privacy@poppd.io.
1. Who we are
poppd is a movie tracking and recommendation app for iPhone and Android, operated by Sami
Rehman, an individual developer, of E1-05 Meydan South Villas, Dubai, United Arab Emirates. Privacy questions and
requests: privacy@poppd.io.
This policy covers the app and the servers behind it.
2. What we collect
We collect only what the product needs:
- Account identity — your email address and the password you set, or — if you use Sign in with Apple — the identifier Apple returns for your Apple ID and the email address you chose to share with us. If you chose Apple's "Hide My Email", that address is Apple's private relay address, and it is what we hold. An account created with Apple has no poppd password. If you use Sign in with Google, Google tells us the identifier for your Google account, its email address, and the name and profile picture link on that Google account. Our sign-in service (Supabase, §7.1) stores the name and picture link automatically; the app does not read, show or use them, and they are deleted with your account. An account created with Google has no poppd password.
- Profile — your username, an optional display name, an optional profile photo, and an optional short bio.
- Launch list (website only) — if you type your email address into the "tell me when it's out" form on poppd.io, we keep that address, and a note of which page the form was on, until we have sent you the one launch email. Nothing else is collected with it, and it is not linked to any app account. Ask privacy@poppd.io to remove it sooner.
- Ratings — the movies you rate, your rating, any optional reaction tags, and when you rated. We also keep a history of your previous ratings for the same movie.
- Watch states — movies you mark as stopped watching (with the optional reason, if you give one). (An earlier version of the app also let you mark a movie "watched, no rating". That option is gone: in August 2026 each of those marks was converted into the middle rating — "Popped", called "Barely Popped" at the time — which shows on your profile like any rating you set yourself, and which you can change or hide at any time.)
- Watchlist — movies you save. People who follow you, and who can see your profile, can see which films are on your watchlist, under the same visibility rules as your ratings.
- Where you watch — the country or region you choose and the streaming services you select, used only to show where a film is available to watch. They are stored with your own preferences, visible only to you, deleted when you delete your account, and never shared or sent to analytics.
- Follows and blocks — who you follow, and who you have blocked.
- Reports — reports you submit about another account: the reason you choose, and anything you write in the optional notes field (free text, up to 1,000 characters). Whatever you type there is stored as you wrote it.
- Privacy settings — your profile privacy level, and which of your ratings you have hidden.
- Recommendation interactions — recommendations we showed you, which you opened, dismissed or postponed, and what you did next.
- Onboarding progress — the genres you chose and how far through onboarding you are.
- AI features — your recent AI searches (the filters you picked — including which followed accounts, if any, you selected — and the results we showed you), and your current AI-assisted home picks, and the current AI-worded description of your taste profile. §7.8 says what leaves our servers to make these.
- Taste profile — the patterns we calculate from your ratings (which genres, eras, runtimes, directors, cast, languages and reaction tags you tend to like), your taste identity, and how similar your taste is to other users'.
- Push notification token — only if you turn notifications on: a device push token (issued by Expo's push service) that lets us send notifications to that device, and whether the device is an iPhone or an Android phone. We keep tokens for up to 10 devices per account — an 11th registration replaces the oldest. §7.9 says who carries the notification, and §6 says when the token is deleted. Guest sessions never register one.
- Technical and security data — basic device information (device model, manufacturer and operating system version) is attached automatically to analytics events and crash reports by the software that sends them. The IP address you sign in from is recorded by our authentication provider as a security log. We do not use either of these to locate you, and our analytics provider's IP-based location lookup is switched off.
We do not collect your location. No precise location, and we switch off our analytics provider's IP-based location lookup. We do not ask for your date of birth, we do not read your contacts, and we do not send marketing notifications. The app does send one kind of optional product notification — a movie was added to a collection you have placed movies in — and only if you turned notifications on. The switch is your device's notification permission: turning it off stops them, and the app deletes the stored token the next time it runs.
Your taste identity is built only from film-taste signals. Which identity you get is decided by fixed rules from the list above — an AI model does not make that decision — so it cannot and does not infer anything about your religion, ethnicity, politics, sexuality, health or any other sensitive characteristic. Five optional features do use an AI model; §7.8 says exactly what they send and to whom.
Why we are allowed to use it
- Your account details, ratings, watch states, watchlist, follows and privacy settings are processed to provide the service you asked for — they are what the app is, there is no recommendation without them, and you gave them to us to get one. That is our contract with you.
- A small, fixed set of technical data (crash reports, product analytics, sign-in and server logs) is processed on our legitimate interest in keeping the app working, fixing it when it breaks and telling whether it is any good. If you object to that, deleting your account stops it.
- We do not sell your data, we do not use it for advertising, and we do not use it to profile you outside the product.
Questions about any of this: privacy@poppd.io.
3. What other people can see
Your profile has three modes — Public, Followers only and Private — and you choose during setup and can change it at any time.
- Nobody can see the ratings on a private profile, and no taste-match score is shown against one.
- A rating you hide is invisible to everyone but you, whatever your profile mode.
- Movies you once marked "watched, no rating" became Popped ratings (the middle level, formerly called "Barely Popped") in August 2026 (§2). They follow the same visibility rules as every other rating — profile mode, hiding and blocking all apply — and you can change or hide them like any rating you set yourself.
- Blocking makes you and the blocked account invisible to each other.
- If your profile is public, your visible ratings may also anonymously inform other users' AI-assisted home picks (§7.8) — you are never told whose picks, and they are never told the suggestion came from you.
Your ratings still help the recommendation engine, even when they are private or hidden. This is how the app keeps working for private users, and how "18 people with similar taste rated it highly" is possible without naming anyone. What this means concretely: your ratings are counted inside anonymous group totals and similarity calculations, but no screen, no API and no explanation ever names you or shows an individual rating that your privacy settings hide. Explanations only ever give counts, never names.
4. How we use it
- To recommend movies, and to explain why we recommended them.
- To calculate your taste profile and taste identity, and how closely your taste matches other users'.
- To show your profile to other people, within the limits you set.
- To keep the service working and safe — spotting abuse, rating manipulation and fake accounts.
- To tell you when a movie is added to a collection you have placed movies in, if you turned notifications on (§7.9).
- To understand how the product is used, in aggregate (see §7).
We do not sell your data, and we do not use it for advertising or profiling outside the product.
5. Match scores
A match score is a compatibility score, not a prediction. "91% match" means the evidence we have suggests the film fits your taste. It is not a probability that you will enjoy it, and we never present it as one.
6. How long we keep things
| What | How long |
|---|---|
| Your profile, ratings, watchlist, follows, blocks and settings | For as long as your account exists — then see §8 |
| Launch list email address (poppd.io form) | Until 30 days after we send the launch email, then deleted — or sooner if you ask |
| Your rating history (previous values for a film you re-rated) | For as long as your ratings exist. We use it for debugging, checking how well recommendations work, and spotting abuse |
| Dismissed and postponed recommendations | Records that are finished — a "remind me later" whose date has passed and that you never restored, or a dismissal you restored — are deleted 90 days after they stop being active |
| Reports you submit | Kept indefinitely, so that repeated reports about the same account can be seen. Reports are reviewed by us, and they are the only record of what was alleged |
| Your AI search history | Your most recent 50 searches; older ones are deleted as new ones are saved. Deleted with your account |
| Your AI-assisted home picks | Up to 10 at a time, replaced no more than once a month. Deleted with your account |
| The AI-worded taste description | One current version per account, replaced when regenerated. Deleted with your account |
| AI usage log | A record per AI request (which feature, when, whether it succeeded — including requests we refused because a daily limit was reached — and size counters; no prompt or answer content). 90 days, and deleted with your account |
| Your push notification token | Until you sign out on that device, turn notifications off in your device settings (the app deletes the stored token the next time it runs), or delete your account. We also delete a token when the push service tells us the device can no longer receive notifications, and we keep at most 10 devices' tokens per account — the oldest is replaced |
| Notification records | When a movie is added to a collection you have placed movies in, we record that a notification is owed to your account — which collection, how many movies, and what happened to it (sent, skipped because you had notifications off, expired unsent, or failed). We keep that record for as long as your account exists, and it is deleted with your account |
| Crash reports | 30 days. Sentry deletes a crash report 30 days after it receives it |
| Analytics events | 1 year. PostHog deletes an event one year after it receives it (the person record held under your account's random identifier is separate — see §8) |
| Technical and security logs (sign-in records held by our authentication provider, including IP address and the email address used to sign in; server request logs, which include your account's internal id) | For as long as our hosting and authentication platform keeps them on our current plan. We have not yet pinned the exact number of days, and we will state it here when we have |
About permanent dismissals. If you dismiss a recommendation permanently, we keep that record for as long as your account exists so the film is not recommended to you again — unless you change that choice yourself. If you restore the film, or replace the permanent dismissal with a "remind me later" that then lapses, the record becomes an ordinary finished record and is deleted 90 days later like the rest. In other words, the record outlives the 90 days only while your choice stands.
We also keep short-lived technical logs of our own background jobs — for example, whether the nightly job that refreshes recommendations succeeded for an account. These record what the system did, not what you did, and are deleted after 30 days. The notification record described in the table above is the exception: it is kept for as long as your account exists.
7. Who else is involved
We use a small number of companies to run the service.
7.1 Supabase — hosts our database, authentication and file storage. Everything in §2 is stored there. Our Supabase project is in Supabase's eu-west-1 (Ireland) region.
7.2 Sentry — crash reporting.
When the app crashes, we send a crash report to Sentry so we can fix it. We never tell Sentry
who you are — the app does not attach your account id, email or username to any crash report,
and the SDK's "send default personal information" setting is off. Before a report leaves your
device we strip it back to a reviewed allowlist: log messages, tapped-control breadcrumbs and
navigation history are dropped entirely rather than sent, and network breadcrumbs are reduced to
the shape of the request — the method, the status code, and the endpoint with its query string
removed and any identifier in the path cut off (so …/avatars/<your id>/photo.jpg becomes
…/avatars). The crash report therefore contains the error, the code path and the device and
app version, but no film you rated and no person you follow. We do not attach the text you write
in the app — your username, bio, report notes and search terms are never sent as such — but we
cannot promise that no text you typed ever appears in a crash report, because an error message
can quote the input that caused it. Crash reports are sent to Sentry's EU region and stored
there; Sentry's EU region is hosted in Germany. Access from outside the EU is governed by
Sentry's own terms — see §7.6. Sentry keeps a report for 30 days and then deletes it.
7.3 PostHog — product analytics.
We record a small, fixed list of product events — a recommendation was shown, opened, dismissed, postponed, marked watched or rated afterwards; a profile or taste comparison was viewed; a follow, unfollow, block or report happened — so we can tell whether the product works. Events are tied to your account's random identifier so we can measure things like whether people come back after a week. Nothing you wrote or chose about another person travels with them: the follow, unfollow, block, report and profile-view events carry no payload at all — no other account's identifier, ever. Recommendation events do carry a reference to the recommendation we showed you. They also carry where it sat in your list, its score band, and — if you went on to rate the film — the rating you gave. The movie identifier is removed before the event leaves your device, so PostHog is not told which film it was — but we can match that reference back to the film in our own database, and we would rather say so than imply a link that does not exist cannot be made. Basic device information (device model, manufacturer and operating system version) is attached automatically by the analytics software. We do not send your email, username, bio or any location; the provider's IP-based location lookup is switched off, and its automatic "app opened" tracking is disabled because it would otherwise capture the link used to open the app. Events are sent to PostHog's EU region and stored there. Access from outside the EU is governed by PostHog's own terms — see §7.6. PostHog keeps an event for one year and then deletes it.
7.4 TMDB — movie information, posters and artwork come from The Movie Database. When you search, your search text is sent to TMDB from our servers to get results. The app shows:
Movie data from TMDB. This product uses TMDB and the TMDB APIs but is not endorsed, certified, or otherwise approved by TMDB.
7.5 Expo / app distribution — used to build and distribute the app; Apple and Google handle the app stores under their own privacy policies.
7.6 Where your data goes
Your data is stored in the EU. Our database, authentication and file storage are in Ireland (Supabase eu-west-1). Crash reports go to Sentry's EU region, hosted in Germany. Analytics events go to PostHog's EU region. Account emails go through Resend, in the region configured for our Resend account: the EU. AI requests (§7.8) go to Anthropic in the United States — Anthropic's API has no EU region option in the way we call it, so the movie titles and taste summaries described in §7.8 are processed outside the EU. Push notifications (§7.9) travel through Expo's push notification service in the United States and then through Apple's push notification service, so your device's push token and the notification text described in §7.9 are processed outside the EU too. A region is not a guarantee of absolute processing locality: each of these companies may access data from outside the EU under its own terms, and for Anthropic the processing location itself is the US.
Where a processor named above processes your data outside the EU — Anthropic in the United States, Expo's push notification service in the United States, or access from outside the EU by any of the others under their own terms — that processing is covered by the standard contractual clauses in that processor's data processing terms, with the UK addendum where UK law applies. If this matters to you, ask at privacy@poppd.io.
7.7 Resend — email delivery.
The account emails the app has to send you — today, the message that confirms your email address when you create an account — are delivered through Resend. To deliver them, Resend receives your email address and the contents of that message, and nothing else: no ratings, no profile text, no analytics. Our sender address is no-reply@poppd.io. We do not send marketing email. The one exception is the single launch email to people who asked for it on poppd.io (see "Launch list" in §2); it is also delivered through Resend.
7.8 Anthropic — AI wording, AI Search, AI-assisted home picks, and poppdAI reads of your ratings.
Five features send data to Anthropic (the maker of the Claude AI model). First, the short written description on your taste profile: it is generated when you view your own profile, and the model receives poppd-computed taste summaries (genre leanings, era leanings and similar aggregates) together with your current taste-identity label and traits, and turns them into sentences — it does not receive your ratings list and it does not decide your taste identity. Hiding your taste identity (§9) turns this off. Second, AI Search, only when you run a search: the model receives the filters you picked and a list of movie titles with their release years — your own top-rated films (excluding any rating you have hidden), plus, only when you select people you follow, a single combined list of their top-rated films limited to ratings you can already see in the app, with nothing marking which film came from whom. Third, the AI-assisted picks on your home screen work the same way, except the app chooses for you: up to three PUBLIC profiles whose taste best matches yours, chosen anonymously — you are never told who, they are never told it was you — under the same limits, no more than once a month in the normal case — if a request fails with nothing generated, a limited number of retries follows, capped at 6 attempts in any 24-hour period (in rare crash cases an attempt that reached Anthropic may be retried within that same cap), then the full month's wait applies. Fourth and fifth, poppdAI's reads of your own ratings: the "Will I like this?" button on a movie page (only when you tap it, up to five times a day), and a background read of your recommendations that runs shortly after you create an account and then at most a few times a day while you use the app (you see "poppdAI is reading your list" while it runs). Both send the model your rated movie titles with their release years and how you rated them (excluding any rating you have hidden), poppd's own descriptive tags for the films in question, and the movies being judged; the model returns a rating-level estimate and a short reason that poppd blends into your match scores. In all cases Anthropic receives no account identity — not your name, not your email, not your username — and we send nothing else. Anthropic's API terms state that data sent this way is not used to train its models.
7.9 Expo and Apple — push notifications.
If you turn notifications on, the notifications we send travel through Expo's push notification service and then through Apple Push Notification service (APNs) to your device. Those two services receive your device's push token and the content of the notification — today that is the name of a collection, how many movies were added to it, and the in-app route a tap opens; never your ratings, your username or anything about another user. Notifications are currently delivered on iPhone only: on Android the app cannot obtain a push token today, so no token is stored and nothing is sent. (If Android delivery ships it will use Google's Firebase Cloud Messaging, and this section will name it.) If Expo tells us a device can no longer receive notifications, we delete its token.
7.10 Google — sign-in.
If you choose Continue with Google, Google confirms who you are and sends us a signed sign-in token carrying the details listed in §2. We ask only for your basic profile and email address: we get no access to your Gmail, contacts, files or anything else in your Google account, and we keep no Google password or long-lived Google credential. Your Google account itself is governed by Google's own privacy policy. You can remove poppd from your Google account at any time at myaccount.google.com → Security → Third-party connections; that ends poppd's current access, signing in with Google again will ask for your permission again, and it does not delete your poppd account.
8. Deleting your account
You can delete your account from Settings. If you have not signed in recently, you will be asked to sign in again first, because it cannot be undone — for an account created with Sign in with Apple, that means confirming with Apple again, and for one created with Sign in with Google, choosing your Google account again. If Google cannot be used on your device, you can confirm with your poppd password instead if your account has one, or ask us to delete it at poppd.io/delete-account.
If your account uses Sign in with Google and you confirmed with Google, once the deletion has gone through we also ask Google to remove poppd from your Google account's third-party connections. This is a best-effort tidy-up: if it does not go through, your poppd account is still deleted, and you can remove poppd yourself in your Google account settings (§7.10).
If your account uses Sign in with Apple, deletion starts by disconnecting it from your Apple ID: we use the fresh confirmation from the Apple prompt to tell Apple to revoke poppd's sign-in grant, so the app no longer appears as connected to your Apple ID. Nothing Apple gives us in that exchange is kept. If Apple cannot be reached, the deletion stops there — nothing is half-deleted — and trying again is the recovery.
Then, in order:
- Your profile photo is deleted from storage, and we check afterwards that it is actually gone before continuing.
- Your ratings are detached from you. They are kept under a random id that isn't linked to you — detached from your account, not erased. Their dates are blurred to the month so they cannot be matched back to the moment you deleted. This keeps community averages honest without keeping them attached to you. Your reaction tags stay attached to those detached ratings.
- Your sign-in identity is deleted, and with it your profile, username, bio, watchlist, watch states, hidden-rating settings, follows, followers, blocks, dismissals and reminders, onboarding progress, taste profile, taste-match scores, stored recommendations and any push notification tokens your devices registered.
- Reports you submitted, or that were submitted about you, are kept — with your account identifier removed from both kinds of report, but the free-text notes kept exactly as written. The other account's identifier is not removed by your deletion: it stays on the report until that account is deleted too. If you named yourself or anyone else in those notes, that text survives your deletion. We keep the notes because they are the evidence for the report and the only record of what was alleged. We keep them as written after your account is deleted, because a shortened report is no longer evidence of anything.
We use the word pseudonymous, not "anonymous", deliberately. The detached ratings are kept together under one random id, so we describe them accurately: no part of the app or database can turn that id back into a person, and no other user's screen can ever reach those rows — but they are still a set, and we will not claim more than that. We keep them indefinitely, because removing them would silently distort the community averages other people rely on. That is our settled position: the detached ratings stay, and there is no route back from them to you.
If deletion fails partway (for example your connection drops), nothing is left half-done that cannot be finished: try again with the same signed-in session and it resumes safely. The app offers you a retry rather than a dead end.
Analytics events we already sent. Product events already sent to PostHog before you deleted are not deleted from PostHog. They stay under your account's random identifier, which after deletion no longer resolves to anything in poppd — and it is a different identifier from the one your detached ratings are kept under, so the two cannot be joined. PostHog removes the events one year after each event reached it. Signing in also creates a person record in PostHog, held under that same random identifier. The one-year window covers events; we have not yet confirmed what happens to the person record, so we are not going to tell you it disappears. This is under review and we will update this page when we have a definite answer.
Security and server logs. Our authentication provider keeps a security log of sign-in events — the time, the IP address you signed in from, your account's internal id, and the email address you signed in with. Our own server request logs carry your account's internal id. Neither is deleted when you delete your account, because they exist so we can investigate abuse, fraud and failures. They hold nothing you rated and no profile text; they are not meant to contain anything you typed, though an error recorded in a server log can quote the input that caused it. So: after deletion, the email address you used remains in the sign-in security log until that log ages out. We would rather say so than leave you to find out. We keep those logs for as long as our hosting and authentication platform retains them on our current plan (§6), and we use them for nothing but investigating abuse, fraud and failures.
Backups. Our database plan has no automated backups. There is no backup copy of your data sitting anywhere after deletion — when the sequence above finishes, that is the end of it. The other side of that coin: deletion is final, and we could not restore your account if you asked.
9. Your controls
- Change your profile privacy at any time — the change is immediate.
- Hide any individual rating.
- Block an account; remove a follower; unfollow.
- Approve or decline a follow request.
- Edit your bio and profile photo.
- Report an account.
- Dismiss or postpone a recommendation.
- Turn notifications on or off — the switch is your device's notification permission, and the app's settings screen links straight to it.
- Hide your taste identity — this also stops the AI-worded taste description being generated (§7.8).
- Delete your account.
Your rights
The two things the app lets you do yourself, immediately, without asking anyone are the ones above: delete your account, and control who sees what.
Depending on where you live, you also have the right to:
- Access — ask for a copy of the data we hold about you.
- Correction — ask us to correct anything that is wrong. Your profile, ratings and settings you can also correct yourself in the app.
- Deletion — delete your account from Settings, which erases or detaches your data as §8 describes. You can also ask us to do it for you.
- Objection — object to our use of your data for product analytics and crash reporting. Deleting your account stops it.
- Complaint — complain to your local data protection authority (see below).
Requests other than the in-app ones are handled by hand. Ask at privacy@poppd.io and we will deal with it and tell you honestly what is and is not possible.
Complaints
If you are unhappy with how we have handled something, tell us first at privacy@poppd.io.
You may also complain to the data protection authority where you live. In the UK that is the Information Commissioner's Office (ICO); elsewhere it is the supervisory authority for your own country.
10. Age
You must be 13 or over to use poppd. When you create your profile you must confirm that you are, and we record that confirmation; an account cannot be created without it. We do not verify it. We do not ask for your date of birth, and we hold no age information beyond the confirmation itself. The app has no direct messaging, no comments, no location sharing, no contact discovery, and it never shows anyone's age or date of birth.
11. Security
Access to your data is enforced in the database itself, per account, and tested automatically. Sign-in tokens are held in the device's secure storage. Sensitive actions such as account deletion require a recent sign-in. Usernames and bios are screened against a blocked-terms list, and reporting is rate-limited to prevent abuse.
12. Changes and contact
We change this policy by updating this page and changing the effective date at the top. There is no separate notification; the current version is always the one here. If a change is significant, the effective date is the thing to watch.
Contact for anything on this page: privacy@poppd.io.