Privacy Policy

Filmy is committed to protecting your privacy. We collect only the data necessary to provide and improve our service.

Data We Collect

  • Account & Identifiers: Email address (for account signup), profile name, device identifier or guest token
  • User Content: Photos you upload, film details (title, description, dates, settings)
  • Purchases: Purchase receipts and product IDs validated via RevenueCat
  • Usage & Diagnostics: App analytics events, general location (city/region), device/OS, performance metrics, crash logs, optional session replay via PostHog
  • Camera & Photos: Camera and photo library access only when you use those features and grant permission

How We Use Data

  • Provide and operate Filmy (create films, invite participants, upload and view photos)
  • Process purchases and prevent fraud
  • Communicate with you (invites, uploads, reveal times, support, service updates)
  • Improve reliability and performance (analytics, diagnostics, session replay)
  • Comply with law and enforce our terms

How We Share Data

  • We do not sell personal information
  • Within a Film: Film details and photos are visible to invited participants according to the film's settings
  • Service Providers: Supabase (database, authentication, storage), RevenueCat (purchase validation)
  • Service providers access data only to perform services and must protect it

Data Retention

  • Account data: kept while your account is active
  • Deleted accounts: personal data removed within 30 days
  • Photos: kept until the film is deleted, your account is closed or 30 days (whichever is earliest)
  • Purchase records: kept for up to 7 years for tax/legal reasons
  • Aggregated or anonymized analytics may be kept longer

Security

  • Encryption in transit (HTTPS/TLS)
  • Encryption at rest provided by our cloud vendors
  • Role-based access and monitoring
  • No security method is perfect. Security incidents involving your personal data will be reported to you and regulators when legally required.

Your Rights & Choices

  • Delete your account: Settings → Delete Account (permanent within 30 days)
  • Manage push notifications in your device settings
  • Contact us to access, correct, export, or delete your personal data
  • California (CCPA/CPRA): right to know, delete, correct, and opt-out
  • EEA/UK (GDPR): rights to access, rectification, erasure, portability, objection, and restriction

Children

Filmy is not for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided data, please contact us and we will delete it.

Questions? Contact us at hello@filmy.app