Seen is a private movie and TV tracker run by Giacomo Cerquone (“we”, “us”). This policy explains what personal data we collect when you use seen.movie and app.seen.movie, why we collect it, and what choices you have.
We don’t sell your data. We don’t run ads. We don’t have a social feed — your catalog is for you.
What we collect
Account information. When you sign up we store your name, email address, and a hashed password. If you sign in with Google, we also receive your Google profile name and avatar URL from Google. We use this to authenticate you and show your profile inside the app.
Your catalog. Everything you put into Seen — watches, reactions, notes, lists, episode progress, watchlist entries, and import history — is stored in our database so the app can work. This data is private to your account; we don’t publish it or share it with other users.
Chat and AI. If you use the chat feature, we store your messages and the assistant’s replies in our database. We keep one active conversation per account — your current thread. Starting a “new conversation” archives the old one and opens a fresh thread; archived conversations are permanently deleted in a nightly sweep (within about 24 hours). There is no way to recover a previous thread after that, or to delete individual messages today — only starting a new conversation (which queues the old one for deletion) or deleting your whole account.
To generate answers we send your chat transcript to third-party AI providers — currently Moonshot AI — on each turn. The model also receives a short, distilled summary of your taste (built from your reactions and notes, not a raw dump of your whole catalog) and can look up parts of your catalog through server-side tools when needed (e.g. what you’ve watched, your lists). Suggestion requests may trigger a web search through the provider. We may switch or add providers over time; this policy will be updated if that changes what data they receive.
Chat messages are limited to 4,000 characters. Usage is capped at 12 messages per 24 hours (you can send several in a row, then the bucket refills gradually over the day). Write actions the assistant proposes — marking something watched, adding to a list — only happen after you explicitly confirm them.
Separately from the visible transcript, we keep short-lived technical records for in-flight turns (for recovery if your connection drops). Those are deleted automatically after 30 minutes.
Taste profile. Seen builds a short text summary of your viewing taste from your reactions and notes. It’s stored on your account and used to ground chat suggestions. You can’t edit it directly today, but it updates as your catalog changes.
Onboarding answers. If you complete onboarding, we store your answers (how you track today, what frustrates you about other apps, etc.) in your account settings.
Imports. If you import watch history (e.g. from TV Time), we process the file you upload, match titles against our catalog, and store the resulting watches and watchlist entries. The raw import file is not kept after processing.
Contact. If you use the contact form on the landing page, we receive your name, email, and message.
Analytics. We use PostHog, hosted in the EU, to understand how the product is used — things like sign-ups, onboarding, and chat errors. PostHog is loaded through our own domain (/ingest) so it isn’t blocked as easily as third-party trackers. We also record a sample of sessions (currently about half) to debug UX issues, and we capture JavaScript exceptions. When you’re logged in, analytics events are tied to your user ID and email. In local development, analytics is turned off by default.
AI observability. Server-side AI calls (chat, taste summaries) may be logged in PostHog for debugging, including the text sent to and received from the model unless we’ve enabled privacy mode on the server.
Server logs. Our API writes structured logs (requests, errors, operational events) to disk on our server. Logs may include your IP address, user agent, and user ID. They’re used for security and debugging, not for profiling.
Cookies. We set a session cookie when you log in so you stay signed in. PostHog may set its own cookies for analytics. We don’t use cookies for advertising.
What we don’t collect
We don’t ask for your real name beyond what you choose to enter. We don’t access your streaming accounts. We don’t read your contacts, photos, or files. We don’t track you across other websites.
Where data is stored and processed
Seen runs on a VPS hosted by OVH (EU). Our database (PostgreSQL) lives on the same machine. Backups are stored on that infrastructure.
Third-party services that may process your data:
| Service | Purpose | Location |
|---|---|---|
| Optional sign-in (OAuth) | US / global | |
| Resend | Transactional email (verification, password reset, account deletion) | US |
| PostHog | Product analytics and AI observability | EU |
| Moonshot AI | Chat replies and taste summaries | China (API) |
| TMDB / TheTVDB / OMDb | Public movie & TV metadata (title searches — not your personal catalog) | US |
We choose providers we trust, but no online service is risk-free. We minimise what we send to each one.
How long we keep data
Your account. We keep your account data — including your catalog, taste profile, and your active chat conversation — for as long as your account exists.
Chat. Archived conversations (previous threads you’ve moved on from) are deleted automatically every night at about 05:00 UTC. Your current thread is kept until you start a new one or delete your account.
Account deletion. If you delete your account (Settings → Delete account), we remove your user record and associated data from our database immediately, including all conversations and messages. There is no grace period or recovery window.
Backups and logs. We take daily database backups, kept for about 14 days on our server. A deleted account may still appear in a backup until that backup rotates out. Server logs are rotated on a similar schedule (roughly two weeks of retained files) and may contain request metadata such as your IP address or user ID.
Analytics. Data in PostHog may persist in their systems according to their retention settings; you can ask us to delete or anonymise what we can reach.
Imports. Raw import files are not kept after processing.
Your rights
If you’re in the EU/EEA (or a jurisdiction with similar laws), you have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing.
- Delete your account: Settings → Delete account in the app. We’ll email you a confirmation code.
- Export your data: not available in the app yet — contact us and we’ll do our best to help manually.
- Anything else: use the contact form or email us via the address on that page.
We’ll respond within a reasonable time. You can also lodge a complaint with your local data protection authority.
Children
Seen isn’t directed at children under 16. We don’t knowingly collect data from anyone under 16. If you believe a child has created an account, contact us and we’ll delete it.
Changes
We may update this policy as the product evolves. The “last updated” date at the top will change, and significant updates will be noted on the landing page or in the app.
Contact
Questions about privacy? Reach out via the contact form on this site.