Privacy Policy

Last updated: 7 August 2026

Preamble

This privacy policy explains what kinds of personal data we process, for what purposes and to what extent. It applies to all processing of personal data we carry out, both when providing our services and in particular on our website.

Controller

Kevin Lenhart Forststraße 10 76756 Bellheim Germany

Email: info@theshortcutagency.de

Overview of processing

Types of data processed: account data (email address, username, display name); content data (watchlist entries, episode progress, ratings); relationship data (friendships, group memberships); usage data; meta and communication data such as IP addresses and timestamps; log data.

Categories of data subjects: users of this service.

Purposes of processing: providing the service and its core functions; information technology infrastructure; security measures.

What we store, and who can see it

This section describes what this specific application stores. It is derived from how the software actually works.

  • Email address — used to sign in and to send password reset links. Stored by Supabase. Not visible to other users.
  • Username and display name — so other users can find and recognise you. Visible to every signed-in user.
  • Profile photo and bio — both optional. Shown on your public profile and next to your reviews and comments. Photos are stored by Supabase and can be retrieved by anyone who knows the image URL.
  • Your watchlist: series, status, episode progress and star ratings. The detailed list is never shown to anyone else. New profiles do show an overview to signed-in users — totals, top genres and favourite shows — which you can switch off at any time under Public profile in your profile settings.
  • Reviews and episode comments, including whether you marked them as a spoiler. These are public: every signed-in user can read them, together with your display name and photo.
  • Likes and reports — which reviews and comments you liked, and any content you reported. Like counts are public; who liked what is not shown. Reports are visible to administrators only.
  • Friendships and group memberships — visible to the people involved.

Your watchlist is private unless you enable "Let friends see my watchlist" in your profile. Friends and members of your groups can then view it. Community leaderboards show totals only — average ratings and counts — never who rated what.

Reviews and comments work differently: they are meant to be read by others and always carry your name. Anything you post there is public to signed-in users until you delete it.

Push notifications

If you use our iOS app and allow notifications, Apple gives the app a device token — a random identifier for that one installation. We store it together with your account so we can tell you when a series on your watchlist airs a new episode.

  • The token identifies a device, not a person. It carries no name, no email address and no watch history.
  • To deliver a notification we hand the token, the title and the text to Apple (Apple Push Notification service). Apple needs this to route the message to your device.
  • Turn notifications off in iOS Settings and nothing more is sent. Delete the app, and Apple reports the token as invalid on the next attempt — we then remove it automatically.
  • Deleting your account deletes your tokens with it.

Legal basis: performing the contract (Art. 6(1)(b) GDPR) for notifications you asked for, on top of the permission you granted in iOS.

Services we use

  • Vercel — hosting. Server logs include IP addresses.
  • Supabase — database and authentication. Stores your account and all content described above. Database region: West Europe (London).
  • Brevo — sending confirmation and password reset emails.
  • TMDB — series metadata and images. Images are loaded directly from their servers, so your IP address becomes visible to them when a page with posters is displayed.
  • Vercel Analytics — privacy-friendly usage statistics (page views, country, device type). Works without cookies and does not track you across other websites.

Affiliate links

Some pages contain affiliate links, currently to NordVPN. These are labelled as an "Affiliate" link. If you click such a link and take out a subscription, we receive a commission from the provider. The price stays exactly the same for you — there are no additional costs.

When you click an affiliate link you leave our website. The provider then processes your data on its own responsibility and under its own privacy policy; for the technical processing of the click it may set cookies or store your IP address. We have no influence over this and receive no personal data about you from these providers, only aggregated statistics such as the number of conversions. Legal basis: legitimate interests in financing the service (Art. 6(1)(1)(f) GDPR).

Legal bases

The following is an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the GDPR, national data protection rules may apply in your or our country of residence.

  • Consent (Art. 6(1)(1)(a) GDPR) — the data subject has given consent to the processing of their personal data for one or more specific purposes.
  • Legal obligation (Art. 6(1)(1)(c) GDPR) — processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6(1)(1)(f) GDPR) — processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided the interests and fundamental rights of the data subject do not override those interests.

National provisions in Germany: in addition to the GDPR, national data protection rules apply in Germany, in particular the Federal Data Protection Act (BDSG). The BDSG contains special provisions on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, transmission and automated decision-making in individual cases including profiling. State data protection acts may also apply.

Security measures

We take appropriate technical and organisational measures in accordance with legal requirements, taking into account the state of the art, implementation costs, the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.

TLS/SSL encryption (HTTPS): to protect data transmitted through our online services against unauthorised access, we use TLS/SSL encryption. When a website is secured by an SSL/TLS certificate, this is signalled by HTTPS in the URL.

Transfer of personal data

In the course of processing personal data, it may happen that data is transferred to or disclosed to other bodies, companies, legally independent organisational units or persons. Recipients may include service providers tasked with IT services or providers of services and content embedded in a website. In such cases we comply with legal requirements and in particular conclude corresponding contracts or agreements that serve to protect your data with the recipients of your data.

International data transfers

Where we transfer data to a third country (outside the EU or EEA), or where this occurs in the context of using third-party services, this is always done in accordance with legal requirements.

For data transfers to the USA we rely primarily on the Data Privacy Framework (DPF), recognised as a secure legal framework by an adequacy decision of the EU Commission dated 10 July 2023. In addition, we have concluded standard contractual clauses with the respective providers. Further information on the DPF and a list of certified companies is available at dataprivacyframework.gov.

Our database is hosted in the United Kingdom (London). Since Brexit the UK is a third country under the GDPR, so this transfer rests on the European Commission's adequacy decision for the United Kingdom, which certifies a level of protection essentially equivalent to that of the EU. Standard contractual clauses with our provider apply in addition.

Storage and deletion of data

We delete personal data we process in accordance with legal requirements as soon as the underlying consent is withdrawn or there is no further legal basis for processing. This applies where the original purpose of processing no longer applies or the data is no longer needed. Exceptions apply where legal obligations or particular interests require longer retention or archiving.

Your account: we store your account data for as long as your account exists. You can delete your account at any time yourself under Profile → Danger zone. Deleting your account permanently removes your profile and photo, your watchlist, your ratings, your reviews and comments, your likes and reports, your friendships and your group memberships. This cannot be undone.

Server log files: log file information is stored for a maximum of 30 days and then deleted or anonymised. Data whose further retention is required for evidentiary purposes is exempt from deletion until the respective incident has been finally resolved.

Your rights as a data subject

As a data subject you have various rights under the GDPR, arising in particular from Art. 15 to 21 GDPR:

  • Right to object: you have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR.
  • Right to withdraw consent: you have the right to withdraw consent you have given at any time.
  • Right of access: you have the right to request confirmation as to whether data concerning you is being processed, and to information about that data as well as a copy of it.
  • Right to rectification: you have the right to request the completion of data concerning you or the correction of inaccurate data concerning you.
  • Right to erasure and restriction of processing: you have the right to request that data concerning you be deleted without delay, or alternatively to request a restriction of processing.
  • Right to data portability: you have the right to receive data concerning you which you have provided to us in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
  • Right to lodge a complaint: you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work or the place of the alleged infringement.

You can download a copy of your data yourself at any time: open your profile and choose Download my data under “Account & safety”. You get a JSON file with your watchlist, ratings, reviews, posts and connections.

Provision of the online service and web hosting

We process users' data in order to provide our online services. For this purpose we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or device.

Access data and log files: access to our online service is logged in the form of server log files. These may include the address and name of the retrieved pages and files, date and time of retrieval, transferred data volumes, notification of successful retrieval, browser type and version, the user's operating system, referrer URL and, as a rule, IP addresses and the requesting provider. Server log files are used for security purposes and to ensure server stability. Legal basis: legitimate interests (Art. 6(1)(1)(f) GDPR).

Cookies

Cookies are functions that store information on users' devices and read information from them.

This service sets no advertising cookies and no cookie that recognises you across other websites. Three cookies are used, all first-party:

Signing you in. Strictly necessary to provide the functionality you explicitly request. Delete it through your browser settings at any time; you will then be signed out.

The compatibility quiz. If you tap shows on a shared compatibility link before creating an account, your selection is kept for 24 hours so it is still there once you have signed up. It contains only the shows you tapped.

Which channel you arrived from. If you reach us through one of our own short links (for example /go/tiktok in a social media profile), a cookie stores the name of that channel and nothing else for up to 30 days. It holds no identifier and cannot recognise you as an individual. If you then create an account, a counter for that channel is increased by one — we store no record of which account came from where. This is aggregate reach measurement, which is why no consent banner is shown. Legal basis: legitimate interests (Art. 6(1)(1)(f) GDPR) in knowing which channels our service reaches people through.

For usage statistics we use Vercel Analytics, which works without cookies: it does not store or read information on your device. It collects aggregated data such as page views, approximate country and device type, and does not track you across other websites. Legal basis: legitimate interests (Art. 6(1)(1)(f) GDPR) in understanding how the service is used.

Changes and updates

We ask you to inform yourself regularly about the content of this privacy policy. We adapt it as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as changes require an action on your part, such as consent.

Definitions

  • Personal data: any information relating to an identified or identifiable natural person.
  • Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing: any operation performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, whether collecting, analysing, storing, transmitting or deleting.
  • Account data: information required to identify and manage user accounts, such as email address, username and display name.
  • Content data: information generated when creating and editing content — here your watchlist entries, episode progress and ratings.
  • Usage data: information about how users interact with the service, such as pages visited and time spent.
  • Log data: information about events or activities logged in a system, typically including timestamps, IP addresses and error messages.

Based on a template created with the free Datenschutz-Generator.de by Dr. Thomas Schwenke, translated and adapted to this service.