Poppd — Privacy Policy

Effective: 9 August 2026

Poppd is in beta. This page describes what the app actually does today. Where a section is marked under legal review, we are finalising the formal wording with legal advisers before public release — the description of what happens is accurate now, but the formal legal statement is not final. We would rather tell you that plainly than publish something that reads finished and is not. Questions about anything here: privacy@poppd.io.


1. Who we are

Poppd is a movie tracking and recommendation app for iPhone and Android, operated by Sami Rehman, an individual developer, of E1-05 Meydan South Villas, Dubai, United Arab Emirates. Privacy questions and requests: privacy@poppd.io.

This policy covers the app and the servers behind it.

2. What we collect

We collect only what the product needs:

We do not collect your location. No precise location, and we switch off our analytics provider's IP-based location lookup. We do not ask for your date of birth, we do not read your contacts, and we do not send marketing notifications.

Your taste identity is built only from film-taste signals. It is generated by fixed rules from the list above — there is no AI model involved — so it cannot and does not infer anything about your religion, ethnicity, politics, sexuality, health or any other sensitive characteristic.

Why we are allowed to use it — under legal review

The formal statement of our legal bases for each purpose is being finalised with legal advisers before public release. In plain terms, in the meantime:

If you want a fuller answer before the formal statement is published, write to privacy@poppd.io and we will tell you what we know.

3. What other people can see

Your profile has three modes — Public, Followers only and Private — and you choose during setup and can change it at any time.

Your ratings still help the recommendation engine, even when they are private or hidden. This is how the app keeps working for private users, and how "18 people with similar taste rated it highly" is possible without naming anyone. What this means concretely: your ratings are counted inside anonymous group totals and similarity calculations, but no screen, no API and no explanation ever names you or shows an individual rating that your privacy settings hide. Explanations only ever give counts, never names.

4. How we use it

We do not sell your data, and we do not use it for advertising or profiling outside the product.

5. Match scores

A match score is a compatibility score, not a prediction. "91% match" means the evidence we have suggests the film fits your taste. It is not a probability that you will enjoy it, and we never present it as one.

6. How long we keep things

What How long
Your profile, ratings, watchlist, follows, blocks and settings For as long as your account exists — then see §8
Your rating history (previous values for a film you re-rated) For as long as your ratings exist. We use it for debugging, checking how well recommendations work, and spotting abuse
Dismissed and postponed recommendations Records that are finished — a "remind me later" whose date has passed and that you never restored, or a dismissal you restored — are deleted 90 days after they stop being active
Reports you submit Kept indefinitely for now, so that repeated reports about the same account can be seen. There is no moderation team and no case-management system: reports are read by one person. The retention period for them is under legal review
Crash reports 30 days. Sentry deletes a crash report 30 days after it receives it
Analytics events 1 year. PostHog deletes an event one year after it receives it (the person record held under your account's random identifier is separate — see §8)
Technical and security logs (sign-in records held by our authentication provider, including IP address and the email address used to sign in; server request logs, which include your account's internal id) For as long as our hosting and authentication platform keeps them on our current plan. We have not yet pinned the exact number of days, and we will state it here when we have

About permanent dismissals. If you dismiss a recommendation permanently, we keep that record for as long as your account exists so the film is not recommended to you again — unless you change that choice yourself. If you restore the film, or replace the permanent dismissal with a "remind me later" that then lapses, the record becomes an ordinary finished record and is deleted 90 days later like the rest. In other words, the record outlives the 90 days only while your choice stands.

We also keep short-lived technical logs of our own background jobs — for example, whether the nightly job that refreshes recommendations succeeded for an account. These record what the system did, not what you did, and are deleted after 30 days.

7. Who else is involved

We use a small number of companies to run the service.

7.1 Supabase — hosts our database, authentication and file storage. Everything in §2 is stored there. Our Supabase project is in Supabase's eu-west-1 (Ireland) region.

7.2 Sentry — crash reporting.

When the app crashes, we send a crash report to Sentry so we can fix it. We never tell Sentry who you are — the app does not attach your account id, email or username to any crash report, and the SDK's "send default personal information" setting is off. Before a report leaves your device we strip it back to a reviewed allowlist: log messages, tapped-control breadcrumbs and navigation history are dropped entirely rather than sent, and network breadcrumbs are reduced to the shape of the request — the method, the status code, and the endpoint with its query string removed and any identifier in the path cut off (so …/avatars/<your id>/photo.jpg becomes …/avatars). The crash report therefore contains the error, the code path and the device and app version, but no film you rated and no person you follow. We do not attach the text you write in the app — your username, bio, report notes and search terms are never sent as such — but we cannot promise that no text you typed ever appears in a crash report, because an error message can quote the input that caused it. Crash reports are sent to Sentry's EU region and stored there; Sentry's EU region is hosted in Germany. Access from outside the EU is governed by Sentry's own terms — see §7.6. Sentry keeps a report for 30 days and then deletes it.

7.3 PostHog — product analytics.

We record a small, fixed list of product events — a recommendation was shown, opened, dismissed, postponed, marked watched or rated afterwards; a profile or taste comparison was viewed; a follow, unfollow, block or report happened — so we can tell whether the product works. Events are tied to your account's random identifier so we can measure things like whether people come back after a week. Nothing you wrote or chose about another person travels with them: the follow, unfollow, block, report and profile-view events carry no payload at all — no other account's identifier, ever. Recommendation events do carry a reference to the recommendation we showed you. They also carry where it sat in your list, its score band, and — if you went on to rate the film — the rating you gave. The movie identifier is removed before the event leaves your device, so PostHog is not told which film it was — but we can match that reference back to the film in our own database, and we would rather say so than imply a link that does not exist cannot be made. Basic device information (device model, manufacturer and operating system version) is attached automatically by the analytics software. We do not send your email, username, bio or any location; the provider's IP-based location lookup is switched off, and its automatic "app opened" tracking is disabled because it would otherwise capture the link used to open the app. Events are sent to PostHog's EU region and stored there. Access from outside the EU is governed by PostHog's own terms — see §7.6. PostHog keeps an event for one year and then deletes it.

7.4 TMDB — movie information, posters and artwork come from The Movie Database. When you search, your search text is sent to TMDB from our servers to get results. The app shows:

Movie data from TMDB. This product uses the TMDB API but is not endorsed or certified by TMDB.

7.5 Expo / app distribution — used to build and distribute the app; Apple and Google handle the app stores under their own privacy policies.

7.6 Where your data goes — under legal review

Our database, authentication and file storage are in Ireland (Supabase eu-west-1). Crash reports go to Sentry's EU region, hosted in Germany. Analytics events go to PostHog's EU region. Account emails go through Resend, in the region configured for our Resend account: the EU. A region is not a guarantee of absolute processing locality: each of these companies may access data from outside the EU under its own terms.

The formal statement of the safeguards for those transfers — standard contractual clauses, the UK addendum or equivalent — is being finalised with legal advisers before public release. We are not going to name a mechanism we have not confirmed. If this matters to you now, ask at privacy@poppd.io.

7.7 Resend — email delivery.

The account emails the app has to send you — today, the message that confirms your email address when you create an account — are delivered through Resend. To deliver them, Resend receives your email address and the contents of that message, and nothing else: no ratings, no profile text, no analytics. Our sender address is no-reply@poppd.io. We do not send marketing email.

8. Deleting your account

You can delete your account from Settings. If you have not signed in recently, you will be asked to sign in again first, because it cannot be undone. Then, in order:

  1. Your ratings are detached from you. They are kept under a random id that isn't linked to you — detached from your account, not erased. Their dates are blurred to the month so they cannot be matched back to the moment you deleted. This keeps community averages honest without keeping them attached to you. Your reaction tags stay attached to those detached ratings.
  2. Your profile photo is deleted from storage, and we check afterwards that it is actually gone before continuing.
  3. Your sign-in identity is deleted, and with it your profile, username, bio, watchlist, watch states, hidden-rating settings, follows, followers, blocks, dismissals and reminders, onboarding progress, taste profile, taste-match scores and stored recommendations.
  4. Reports you submitted, or that were submitted about you, are kept — with your account identifier removed from both kinds of report, but the free-text notes kept exactly as written. The other account's identifier is not removed by your deletion: it stays on the report until that account is deleted too. If you named yourself or anyone else in those notes, that text survives your deletion. We keep the notes because they are the evidence for the report and the only record of what was alleged. Whether they should instead be shortened or purged when an account is deleted is under legal review.

We use the word pseudonymous, not "anonymous", deliberately. The detached ratings are kept together under one random id, so we describe them accurately: no part of the app or database can turn that id back into a person, and no other user's screen can ever reach those rows — but they are still a set, and we will not claim more than that. We keep them indefinitely, because removing them would silently distort the community averages other people rely on. Whether "indefinitely" is the right answer, and how it should be expressed formally, is under legal review.

If deletion fails partway (for example your connection drops), nothing is left half-done that cannot be finished: try again with the same signed-in session and it resumes safely. The app offers you a retry rather than a dead end.

Analytics events we already sent. Product events already sent to PostHog before you deleted are not deleted from PostHog. They stay under your account's random identifier, which after deletion no longer resolves to anything in Poppd — and it is a different identifier from the one your detached ratings are kept under, so the two cannot be joined. PostHog removes the events one year after each event reached it. Signing in also creates a person record in PostHog, held under that same random identifier. The one-year window covers events; we have not yet confirmed what happens to the person record, so we are not going to tell you it disappears. This is under review and we will update this page when we have a definite answer.

Security and server logs. Our authentication provider keeps a security log of sign-in events — the time, the IP address you signed in from, your account's internal id, and the email address you signed in with. Our own server request logs carry your account's internal id. Neither is deleted when you delete your account, because they exist so we can investigate abuse, fraud and failures. They hold nothing you rated and no profile text; they are not meant to contain anything you typed, though an error recorded in a server log can quote the input that caused it. So: after deletion, the email address you used remains in the sign-in security log until that log ages out. We would rather say so than leave you to find out. Whether that is the right balance, and how long the log should be kept, is under legal review.

Backups. Our database plan has no automated backups. There is no backup copy of your data sitting anywhere after deletion — when the sequence above finishes, that is the end of it. The other side of that coin: deletion is final, and we could not restore your account if you asked.

9. Your controls

Your rights — under legal review

The two things the app lets you do yourself, immediately, without asking anyone are the ones above: delete your account, and control who sees what. We are not going to describe a self-service rights portal we have not built.

Depending on where you live, you may also have the right to ask for a copy of your data, to have it corrected, to object to some uses of it, or to complain to a regulator. Those requests are handled by hand, by one person. The formal statement of your rights — including the response times we commit to — is being finalised with legal advisers before public release.

In the meantime, ask at privacy@poppd.io and we will deal with it and tell you honestly what is and is not possible.

Complaints — under legal review

If you are unhappy with how we have handled something, tell us first at privacy@poppd.io.

You may also have the right to complain to a data protection regulator. Which regulator that is depends on where you live, and Poppd's launch markets (the UK, the US and the UAE) do not share one. We are confirming the correct route for each with legal advisers before public release rather than naming one and being wrong.

10. Age

You must be 13 or over to use Poppd. When you create your profile you must confirm that you are, and we record that confirmation; an account cannot be created without it. We do not verify it. We do not ask for your date of birth, and we hold no age information beyond the confirmation itself. The app has no direct messaging, no comments, no location sharing, no contact discovery, and it never shows anyone's age or date of birth.

11. Security

Access to your data is enforced in the database itself, per account, and tested automatically. Sign-in tokens are held in the device's secure storage. Sensitive actions such as account deletion require a recent sign-in. Usernames and bios are screened against a blocked-terms list, and reporting is rate-limited to prevent abuse.

12. Changes and contact

We change this policy by updating this page and changing the effective date at the top. There is no separate notification; the current version is always the one here. If a change is significant, the effective date is the thing to watch.

Contact for anything on this page: privacy@poppd.io.