Popsie

Privacy Policy

Last updated: 25 August 2026 · Versione italiana

This policy explains what personal data Popsie collects, why, who it is shared with, and what rights you have. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

1. Who processes your data

The data controller is Mattia Stangherlin, a natural person, the developer and operator of the Popsie application.

For anything concerning your personal data, including exercising the rights described in section 11, write to hello@popsieapp.com.

Popsie has no Data Protection Officer: the conditions of Article 37 GDPR do not apply.

2. What data we process

Popsie collects only what the app needs to work. We use no advertising tools, we do not track you across other sites or apps, and we sell data to nobody.

CategoryDataLegal basis
Account Email address, password (stored only as a hash), username, display name, an avatar chosen from those built into the app, account creation date Performance of a contract - Art. 6(1)(b)
Date of birth The date you enter during onboarding, used to filter content unsuitable for your age. It is optional: if you leave it out, nothing is blocked Consent - Art. 6(1)(a)
Preferences Light/dark theme, language, selected streaming platforms, watch region, kids mode, notification preferences Performance of a contract - Art. 6(1)(b)
Viewing activity Titles added to your watchlist, titles and seasons marked as watched or in progress, individual episodes watched, the watch order you set Performance of a contract - Art. 6(1)(b)
Social graph People you follow and who follow you, follow requests, published recommendations, likes, lists you create or take part in, users you have blocked Performance of a contract - Art. 6(1)(b)
Private messages The text of messages exchanged with other users, reactions, in-app attachments (movie or show entries, replies to a recommendation) Performance of a contract - Art. 6(1)(b)
AI chat The text you send to the assistant, the generated replies, and a count of messages used in the last 24 hours Performance of a contract - Art. 6(1)(b)
Push notifications The device identifier issued by the notification service (push token) and the operating system Consent - Art. 6(1)(a)
Reports The reported content, the reason, any notes, and the identifier of the reporting user Legal obligation (Reg. EU 2022/2065) - Art. 6(1)(c)
Technical data IP address and connection information, processed by the providers listed in section 8 to deliver the service and prevent abuse Legitimate interest - Art. 6(1)(f)

Data that stays on your device

Some information never reaches us. It lives in the app's local storage, on your phone, and disappears if you uninstall Popsie or clear the app's data:

3. What we do not do

4. Personalised recommendations

Popsie analyses your viewing activity - genres, directors, production companies, saved and watched titles - to build a taste profile, suggest relevant titles and compute an affinity score with the people you follow. This constitutes profiling under Article 4(4) GDPR and is disclosed here pursuant to Article 13(2)(f).

It affects only what you see recommended inside the app. It produces no legal effect, does not condition access to the service, and is not shared with third parties. You can clear the data behind it from the settings (Settings → Content) or delete your account.

5. AI chat

AI chat replies are generated by an artificial intelligence system, not by a person, and may contain errors or out-of-date information. Always verify anything important.

When you use the AI chat, the text you write is sent to Anthropic PBC (United States), which processes it to generate a reply. Alongside your message, some elements of your profile may be sent to make the suggestion relevant: your selected streaming platforms, your watch region, and the titles you have already saved or watched. Your name, your email, your private messages and your contacts are not sent.

The assistant may also search the web to answer: in that case the search query is passed to the search engine used by Anthropic.

AI chat messages are not used to train artificial intelligence models. You can delete the whole conversation at any time with the "New conversation" button inside the chat.

6. Content you publish, and messages

Recommendations, lists and profiles you make public are visible to other users according to the privacy settings you choose. Private messages are visible to you and the recipient.

Private messages are protected in transit and at rest, but they are not end-to-end encrypted: technically the service operator is able to access them. We only do so where strictly necessary to act on a report or on a request from an authority. Do not use Popsie to exchange confidential or sensitive information.

7. Push notifications

Push notifications are optional and are only sent after you grant the system permission. To deliver them we store a device identifier (push token) issued by the operating system. You can withdraw consent at any time from your phone's settings or by turning notifications off in Popsie; signing out removes that device's token.

8. Who we share data with

Popsie relies on a few external providers, acting as processors under an Article 28 GDPR agreement or, where indicated, as independent controllers:

ProviderWhat it doesData involved
Supabase Inc.Database, authentication and server functionsAll account data listed in section 2
Anthropic PBCGenerating AI chat repliesAI chat message text and viewing preferences
Expo (650 Industries, Inc.)Push notification deliveryPush token, notification text
Apple Inc. / Google LLCFinal notification delivery to the device, app distributionPush token, notification text
The Movie Database (TMDB)Movie and TV catalogue. Requests are made directly from your deviceIP address, search terms sent to the catalogue
YouTube / Google LLCTrailer playback and thumbnailsIP address and data collected by the YouTube player under Google's policies
Netlify, Inc.Hosting of these information pagesIP address of page visitors

Data may also be disclosed to judicial or supervisory authorities where required by law.

9. Transfers outside the European Union

Some of the providers listed above are based in the United States. Transfers rely on the Standard Contractual Clauses adopted by the European Commission (Article 46(2)(c) GDPR) and, where applicable, on certification under the EU–US Data Privacy Framework. You can request a copy of the safeguards in place by writing to the address in section 1.

10. How long we keep data

DataRetention
Account and linked contentFor as long as the account is active
All account dataDeleted within 30 days of an account deletion request
Private messagesUntil you delete them or delete your account. Deleting your account removes the whole conversation, including from the recipient's inbox
AI chatUntil you start a new conversation or delete your account
Push tokenRemoved on sign-out or uninstall
Reports12 months after closure, so that our handling can be accounted for if challenged

11. Your rights

You may exercise the rights under Articles 15-22 GDPR at any time:

Most of this can be done in the app, under Settings → Account: edit your profile, clear your viewing data, delete your account. See also the Account deletion page.

For anything else write to hello@popsieapp.com: we reply within one month, as required by Article 12(3) GDPR.

If you believe the processing infringes the GDPR, you have the right to lodge a complaint with the Italian Garante per la protezione dei dati personali (garanteprivacy.it) or with the supervisory authority of the country where you live.

12. Minors

Popsie requires a minimum age of 14, in line with Article 2-quinquies of Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018. Anyone under 14 may not create an account.

If you become aware that a child under 14 has created an account, report it to hello@popsieapp.com: the account will be closed and the data deleted.

13. Security

Data travels encrypted (TLS) and is stored on infrastructure operated by Supabase. Access to database rows is constrained at the engine level by row level security: each authenticated user can read and write only their own data and what other users have made visible to them. Passwords are never stored in plain text.

14. Changes to this policy

If the processing changes materially we will update this page and, where the change affects you directly, tell you inside the app. The date at the top always reflects the latest revision.