The short version
- MovieShare does not collect your name, email address, phone number, or account details.
- Your Profile, Ratings, Taste Weights, Friend Snapshots, and Movie Night results stay in local app storage.
- The app contacts MovieShare's catalog service for public movie data. It sends a random Install ID, region, language, and the public lookup you requested.
- The website uses no cookies, analytics, advertising, tracking pixels, chat widgets, or remotely hosted fonts.
- The closed-beta page links to Google Groups and Google Play. MovieShare does not collect your email for beta enrollment.
Data inventory
| Data | Where | Purpose | Retention |
|---|---|---|---|
| Profile ID and display name | Your phone | Identify your local Profile and intentional QR shares | Until you delete local data or uninstall |
| Ratings, Seen states, and Taste Weights | Your phone | Calculate your recommendations | Until you delete local data or uninstall |
| Friend Snapshots and Movie Night results | Your phone | Calculate group recommendations | Until you delete them, delete all local data, or uninstall |
| Public movie metadata and catalog region | Your phone | Show and rank current movie candidates | Cached locally until refresh or local deletion |
| Random Install ID | Your phone, then transiently in backend memory | Rate limiting and blocking abuse | The raw value is hashed immediately and is not logged |
| Region, language, search text, and public movie IDs | MovieShare backend and TMDB during a request | Return the public movie data you asked for | Not stored or logged by MovieShare |
| Hashed Install ID status and hourly counters | AWS DynamoDB | Apply service limits and operator blocks | Counters expire after about 48 hours; status remains until changed |
| Aggregate service metrics and sanitized errors | AWS CloudWatch | Detect outages and throttling | Error logs are retained for no more than 7 days |
What the network can still see
Internet services receive normal connection metadata when a request reaches them. AWS CloudFront sees an IP address while routing a catalog request, and TMDB sees connection metadata when it receives a provider request. Poster images load directly from TMDB's image service, so TMDB also receives normal connection data such as your IP address for those image requests.
MovieShare disables CloudFront access logging and does not copy IP addresses, user agents, full URLs, search text, or movie IDs into its own logs. This is why the promise is"personal taste data stays on your phone," not "the server sees nothing."
QR sharing
A Profile QR is an intentional, offline transfer to another phone. It contains a random Profile ID, your display name, a generated time, and up to 250 selected Interactions. The receiving phone previews the snapshot before saving it. Re-scanning replaces the earlier Friend Snapshot for that Profile.
Anyone who can scan your QR can read that snapshot. Show it only to people you intend to share with.
Your controls
Settings lets you change your local display name and catalog region, clear poster memory, or delete all local MovieShare data. Delete all regenerates both random identifiers and returns the app to Onboarding. Operating-system cloud backup is disabled for the private database and Install ID. Uninstalling may permanently erase your history.
Children and policy changes
MovieShare is a general movie-discovery tool and is not directed to children. It does not knowingly collect personal information from children because it does not provide accounts or a personal-data submission service.
Material policy changes will appear on this page with a new effective date. If a future feature changes where personal data is processed, it requires a privacy review before release.