Privacy Policy

Twinema · Last updated: August 2, 2026 · Version 1.7

Twinema recommends movies based on the shared taste of you and your friends. This policy explains what data we collect, why we collect it, who we share it with, and the rights you have over it.

We do not store your email address in your Twinema account. A Google or Apple sign-in token may contain provider claims during verification; the code writes only the provider's unique identifier to your account and discards the other claims. Your password and contacts never reach us.

1. Data controller

Twinema is developed and operated by Mustafa İlter as an individual. Contact: ilter6282@gmail.com

2. Data we process

DataSourcePurpose
Provider identifier (sub) Google / Apple sign-in Recognizing your account. This identifier is not an email address and cannot be reversed to reveal one.
Display name A random nickname generated by the app, or a name you enter later Helping your friends find and recognize you
Your profile image choice A ready-made image you choose in the app Making your profile easy to recognize
Your language and app preferences Your device or app settings Showing the app with the language and settings that suit you
Your viewing region, selected streaming services, time zone, and quiet hours Your device region/time-zone settings or values you choose in the app Showing availability for the correct country and, only when you opt in and have active Pro access, sending no more than one bundled watchlist alert per local day outside your quiet hours. The same movie/service/region match is not notified twice.
Your movie ratings, watchlist, skipped movies, and movies you are not interested in Information you enter or a Letterboxd export you upload Generating recommendations and managing your movie library
Your friendships, invite codes and redemptions, groups, shared decisions, permissions you grant, and people you block Your actions Determining who can see what
Your messages (text and attached movie) Messages you send Letting you chat with your friends
Your movie comments and spoiler flag Information you write Showing your comment only to you and accepted friends whom you have not blocked
Notification token Your device — only if you give permission Delivering message, friendship, reward, or streaming-availability notifications you choose to enable
A pending invite code and the invite-redemption record An invite link; Google Play Install Referrer on Android; your action accepting the invite Keeping the invite from being lost during installation and sign-in, creating the friendship, and granting any invite reward. The code is not used for advertising tracking.
Your taste-discovery matching preference ("Find a Movie Friend") An opt-in setting you turn on in the app Matching you with other users who have also opted in, based on taste compatibility — see section 3b
A random installation-specific analytics identifier and limited product events The app (for example, app open, onboarding, recommendation lock, paywall/purchase result, invite, and provider-setting actions) Understanding which product steps work. Your account identifier, movie/message content, and text you enter are not added to analytics.
Technical connection record (network prefix masked to /24 for IPv4 or /48 for IPv6; time, requested path, response status, and basic client information) The app or browser connecting to our server; for an invite link, the path contains the invite code Establishing the connection, rate-limit/abuse protection, diagnosing errors, and securing the service. It is not used for advertising.
Your subscription status Apple / Google through RevenueCat Unlocking subscription features
Reports and blocking records; a review copy of a reported comment Your reports and actions Reviewing abuse — required by app store rules

Invites and data kept on your device

The app keeps some information only on your device so it can work:

For a Letterboxd import, the app reads only the ratings.csv you select through the file picker. It does not request access to your other files. The CSV text is sent to the server for matching; the raw file is not stored permanently on the server, and only matched ratings are written to your account.

Data we do not store or access

We do not store your email address as an account or contact field. We do not access your password · phone number · contacts · GPS/precise location · advertising identifier · other apps on your device · payment card information. Apple and Google process payments entirely on their systems; we never receive your card details.

3. Anonymous recommendation pool

Recommendations are generated by comparing your ratings with a broad pool of movie ratings. The pool contains anonymous rating records compiled from public sources.

The identities of people in the pool are never shown — there are no usernames, links, or profiles. You only see aggregate, identity-free information such as “Recommended by 12 people with similar taste.”

Your ratings may also contribute to this pool anonymously; you can turn this setting off in your account settings. While your account is active, the pool source keeps only an internal user reference so your contribution can be updated or deleted if you turn the setting off. This reference is not shown to other users and never appears in any API response. Turning the setting off deletes your entire contribution from the pool, so it is no longer used in other people's recommendations. If you delete your account while the setting is on, the internal user reference is permanently replaced with a random identifier that cannot be linked back to your account; your rating contribution remains in the pool without an identity.

3b. Taste-match discovery ("Find a Movie Friend")

"Find a Movie Friend" is an optional feature and is off by default. When you turn it on in settings, we compare your ratings with other users who have also turned it on and match you based on taste compatibility. While it is off, you are never shown as a candidate to anyone else and no candidates are shown to you — this is a separate setting from name-search discoverability (section 2); the two work independently.

A match shows only a short taste-compatibility summary; it does not grant chat access or full profile access. If you want to become friends with a match, you use the normal friend-request flow, which requires the other person's acceptance.

For a match, only the following is shown about the other person:

The other person's full rating history, watchlist, movie comments, or other profile information are not shown — those only unlock once an accepted friendship exists between you, under the same friendship visibility rules described in section 2. Daily match suggestions are generated as a fixed batch on the server and kept for no more than 90 days.

You can report or block a match; both use the same reporting/blocking paths available from any profile and go through the same 24-hour review process (see our Terms of Use, section 3). Anyone you block, or who blocks you, is no longer shown to you as a candidate.

4. Who we share your data with

We do not sell your data or share it for advertising. We use the following providers to operate the service:

ProviderPurposeData sent
Apple · GoogleSign-in and paymentsAuthentication; payments are processed entirely on their systems
RevenueCatSubscription verificationYour account identifier and subscription status
TMDBMovie information and postersOnly the movie identifier — not who requested it
ExpoNotification deliveryYour notification token and message text (only when sending a notification)
Sentry (Germany) Error and crash reporting Technical details about the error. Your identity is not sent: your account identifier is removed from logs, and IP addresses and device identifiers are not collected
PostHog (EU) Limited product statistics and remote configuration A predefined action name and only the necessary numerical/yes-or-no properties. Not linked to your account: the app uses a random installation identifier it creates and does not send your account identifier. Automatic screen/touch capture and session replay are disabled; movie titles, message content, and text you enter are not sent
Hetzner (Germany)Server hostingYour data is stored here
Backblaze B2 (EU)BackupsBackups are encrypted before upload; the provider cannot read their contents
Third-party error and product analytics are not linked to your account. Sentry does not receive your account identifier; PostHog uses only a random installation identifier. Automatic screen recording, touch capture, and session replay are disabled. There is a tradeoff — we cannot know exactly how many different people an error affects — but we designed it this way intentionally.

We may also have to share data with competent authorities when legally required, such as in response to a court order.

5. Where and how long data is stored

Data is stored on servers in the European Union and kept while your account remains open. When you delete your account, movie ratings linked to your account, your lists, messages, movie comments, friendships, invite records, decision responses, provider/notification settings, taste-match candidate/skip records, and push tokens are permanently deleted; streaming alerts stop. If your recommendation-pool setting is off, your pool contribution is also deleted. If the setting is on, the internal link to your account is permanently replaced with a random identifier and your identity-free rating contribution remains in the pool. Raw Letterboxd CSV content is never stored permanently.

The main exceptions are: (a) encrypted rotating backups are kept for no more than 90 days and then expire automatically; (b) reports, feedback, and the comment snapshot captured when a report is made may be kept with identity fields removed for abuse prevention and support history; (c) daily taste-match batches are kept for no more than 90 days and then deleted automatically. Account-linked daily “where to watch” counters, previously sent provider-alert deduplication entries, and individual/pair experiment arms containing the user are deleted as part of account deletion.

PostHog product events and Sentry error records never receive your account identifier, so an account-deletion request cannot automatically match and delete them. They may remain as a random-installation event or identity-free technical event under those services' retention settings. You can contact us about a specific record.

Server access records store a network prefix masked to /24 for IPv4 or /48 for IPv6 instead of the full IP address. Files rotate every day at midnight or when they reach 25 MiB; no more than 90 rolled files are retained, and rolled files older than 90 days are deleted. These records are not used for product analytics or advertising profiles.

6. Exercising your rights

Under Article 11 of Turkey's Personal Data Protection Law (KVKK) and the GDPR, you have the right to access, correct, and delete your data; object to its processing; and request a portable copy.

7. Security

Connections are encrypted, backups are encrypted on our systems before they are uploaded, and the database is not exposed to the public internet. No system is completely secure, however. If a security incident affects you, we will notify you in the app.

8. Children

Twinema is not intended for children under 13, and we do not knowingly collect their data. If you live in the European Union and are under 16, you need permission from a parent or guardian. If we learn that we have collected such data, we will delete it.

9. Changes

If this policy changes, we will update the date at the top. If a change materially affects how your data is used, we will also notify you in the app.