Privacy Policy
Last updated: May 11, 2026
The Film Reality ("we", "us", "the service") is a film, TV show, and soundtrack tracking platform. This Privacy Policy explains what we collect, why we collect it, who we share it with, and the rights you have over your information.
If you don't agree with this policy, please don't use the service.
1. Who we are
The Film Reality is operated by Diego Tobias. General contact: support@thefilmreality.com. Privacy-specific questions or data requests: privacy@thefilmreality.com.
2. Information we collect
Information you give us directly
- Account info: email address, username, display name, password (stored hashed with bcrypt, never in plain text).
- Profile content: avatar/profile picture, bio, location, favorite films/shows/soundtracks, accent color, background image, custom journal pages.
- Activity: films, TV shows, and soundtracks you log; ratings; reviews; lists you create; comments; likes; who you follow; watch providers you subscribe to.
- Communications: if you email us, we keep that thread to respond to you.
Information we collect automatically
- Session data: a secure HTTP-only authentication cookie (
fr_auth) so you stay signed in. JavaScript on the page cannot read this cookie.
- Technical data: IP address, browser and device type, pages visited, response times, and error reports — used to keep the service running and to find and fix bugs. Collected via Azure Application Insights.
- Local data: we store some preferences and cached data in your browser's localStorage and IndexedDB so the app feels fast offline.
Information from third parties
- Google Sign-In: when you sign in with Google, we receive your email, name, and profile picture from Google. We do not receive your password.
- Stripe: if you purchase a premium subscription, Stripe processes the payment and shares a billing identifier with us. We never see or store your card details.
- TMDB / iTunes / Apple Music: we fetch film, TV, and music metadata from these public sources. We don't send your personal info to them — we only ask for content data.
3. How we use your information
- To create and run your account, and to authenticate you on return visits.
- To save your activity (logs, reviews, likes) so it follows you across devices.
- To deliver social features — show your reviews to your followers, send notifications when someone likes or comments on your activity.
- To process premium subscription payments via Stripe.
- To send you transactional emails (password resets, verification, gift codes, important account changes). We do not send marketing email.
- To find and fix bugs, measure performance, and prevent abuse (rate limiting, fraud detection).
- To comply with legal obligations.
4. Who we share information with
We do not sell or rent your information. We share data only with the following service providers, and only to the extent they need it to run the service:
| Provider | What they receive | Why |
| Microsoft Azure (Canada Central) | Account data, activity, telemetry | Hosting and database |
| Stripe | Email, payment info | Premium subscription billing |
| Google | Sign-in token validation | Google Sign-In |
| Apple | (future) Sign in with Apple token validation | Sign in with Apple, MusicKit playback |
| TMDB / iTunes | Content queries only (titles, IDs) — no personal data | Film, TV, and music metadata |
We may also disclose information if required by law (subpoena, court order) or to protect users from harm.
5. Where your data lives
Your account and activity data are stored in Microsoft Azure SQL in the Canada Central region. Image uploads go to Azure Blob Storage in the same region.
6. How long we keep data
- Account data: kept as long as your account is active. When you delete your account, we remove your profile, reviews, journal, lists, and uploads within 30 days. Some data (subscription receipts) may be retained longer for accounting/tax compliance.
- Telemetry / logs: Application Insights retention is 90 days by default.
- Backups: automated database backups are kept up to 35 days.
7. Your rights
- Access: see everything we have on you — your profile page already shows most of it.
- Correction: edit your profile, reviews, and lists from inside the app.
- Deletion: Settings → "Delete account" removes your data. Or email privacy@thefilmreality.com.
- Export: request a data export at privacy@thefilmreality.com; we'll respond within 30 days.
- Object/Restrict: EU and UK residents can object to or restrict processing under GDPR. Email privacy@thefilmreality.com.
- California: California residents have CCPA rights, including the right to know, delete, and not be sold (we don't sell your data anyway).
8. Cookies and similar technologies
We use one essential cookie:
fr_auth — keeps you signed in. HTTP-only, Secure, SameSite=None, expires in 30 days. Not readable by JavaScript.
We do not use third-party advertising cookies. We do not track you across other sites.
9. Children
The Film Reality is not directed at children under 13 (or 16 in the European Economic Area). We don't knowingly collect data from kids in that age range. If you believe a child has signed up, email privacy@thefilmreality.com and we'll delete the account.
10. Security
We protect your data with the standard set: HTTPS-only transport with HSTS, JWT-based auth via HTTP-only cookies, bcrypt password hashing, rate limiting on auth endpoints, CORS allowlisting, and a strict Content-Security-Policy. No system is perfectly secure, but we take it seriously.
11. International transfers
Your data is processed primarily in Canada. If you access the service from outside Canada, you understand your information will be transferred to and stored on servers in Canada (and, for some sub-processors like Stripe, the United States).
12. Changes to this policy
We may update this policy from time to time. If we make material changes, we'll post a notice on the home page and update the "Last updated" date above. Continued use of the service after a change means you accept the new policy.
13. Contact
General: support@thefilmreality.com
Privacy / GDPR / CCPA: privacy@thefilmreality.com
Content reports: reports@thefilmreality.com
Security disclosures: security@thefilmreality.com
© 2026 The Film Reality. All rights reserved.