Privacy Policy
Last updated: 20 July 2026
Preamble
This privacy policy explains what kinds of personal data we process, for what purposes and to what extent. It applies to all processing of personal data we carry out, both when providing our services and in particular on our website.
Controller
Kevin Lenhart Forststraße 10 76756 Bellheim Germany
Email: info@theshortcutagency.de
Overview of processing
Types of data processed: account data (email address, username, display name); content data (watchlist entries, episode progress, ratings); relationship data (friendships, group memberships); usage data; meta and communication data such as IP addresses and timestamps; log data.
Categories of data subjects: users of this service.
Purposes of processing: providing the service and its core functions; information technology infrastructure; security measures.
What we store, and who can see it
This section describes what this specific application stores. It is derived from how the software actually works.
- Email address — used to sign in and to send password reset links. Stored by Supabase. Not visible to other users.
- Username and display name — so other users can find and recognise you. Visible to every signed-in user.
- Your watchlist: series, status, episode progress and star ratings. Private by default.
- Friendships and group memberships — visible to the people involved.
Your watchlist is private unless you enable "Let friends see my watchlist" in your profile. Friends and members of your groups can then view it. Community leaderboards show totals only — average ratings and counts — never who rated what.
Services we use
- Vercel — hosting. Server logs include IP addresses.
- Supabase — database and authentication. Stores your account and all content described above. Database region: West Europe (London).
- Brevo — sending confirmation and password reset emails.
- TMDB — series metadata and images. Images are loaded directly from their servers, so your IP address becomes visible to them when a page with posters is displayed.
Legal bases
The following is an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the GDPR, national data protection rules may apply in your or our country of residence.
- Consent (Art. 6(1)(1)(a) GDPR) — the data subject has given consent to the processing of their personal data for one or more specific purposes.
- Legal obligation (Art. 6(1)(1)(c) GDPR) — processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1)(1)(f) GDPR) — processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided the interests and fundamental rights of the data subject do not override those interests.
National provisions in Germany: in addition to the GDPR, national data protection rules apply in Germany, in particular the Federal Data Protection Act (BDSG). The BDSG contains special provisions on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, transmission and automated decision-making in individual cases including profiling. State data protection acts may also apply.
Security measures
We take appropriate technical and organisational measures in accordance with legal requirements, taking into account the state of the art, implementation costs, the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.
TLS/SSL encryption (HTTPS): to protect data transmitted through our online services against unauthorised access, we use TLS/SSL encryption. When a website is secured by an SSL/TLS certificate, this is signalled by HTTPS in the URL.
Transfer of personal data
In the course of processing personal data, it may happen that data is transferred to or disclosed to other bodies, companies, legally independent organisational units or persons. Recipients may include service providers tasked with IT services or providers of services and content embedded in a website. In such cases we comply with legal requirements and in particular conclude corresponding contracts or agreements that serve to protect your data with the recipients of your data.
International data transfers
Where we transfer data to a third country (outside the EU or EEA), or where this occurs in the context of using third-party services, this is always done in accordance with legal requirements.
For data transfers to the USA we rely primarily on the Data Privacy Framework (DPF), recognised as a secure legal framework by an adequacy decision of the EU Commission dated 10 July 2023. In addition, we have concluded standard contractual clauses with the respective providers. Further information on the DPF and a list of certified companies is available at dataprivacyframework.gov.
Storage and deletion of data
We delete personal data we process in accordance with legal requirements as soon as the underlying consent is withdrawn or there is no further legal basis for processing. This applies where the original purpose of processing no longer applies or the data is no longer needed. Exceptions apply where legal obligations or particular interests require longer retention or archiving.
Your account: we store your account data for as long as your account exists. You can delete your account at any time yourself under Profile → Danger zone. Deleting your account permanently removes your profile, your watchlist, your ratings, your friendships and your group memberships. This cannot be undone.
Server log files: log file information is stored for a maximum of 30 days and then deleted or anonymised. Data whose further retention is required for evidentiary purposes is exempt from deletion until the respective incident has been finally resolved.
Your rights as a data subject
As a data subject you have various rights under the GDPR, arising in particular from Art. 15 to 21 GDPR:
- Right to object: you have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR.
- Right to withdraw consent: you have the right to withdraw consent you have given at any time.
- Right of access: you have the right to request confirmation as to whether data concerning you is being processed, and to information about that data as well as a copy of it.
- Right to rectification: you have the right to request the completion of data concerning you or the correction of inaccurate data concerning you.
- Right to erasure and restriction of processing: you have the right to request that data concerning you be deleted without delay, or alternatively to request a restriction of processing.
- Right to data portability: you have the right to receive data concerning you which you have provided to us in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
- Right to lodge a complaint: you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work or the place of the alleged infringement.
Provision of the online service and web hosting
We process users' data in order to provide our online services. For this purpose we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or device.
Access data and log files:access to our online service is logged in the form of server log files. These may include the address and name of the retrieved pages and files, date and time of retrieval, transferred data volumes, notification of successful retrieval, browser type and version, the user's operating system, referrer URL and, as a rule, IP addresses and the requesting provider. Server log files are used for security purposes and to ensure server stability. Legal basis: legitimate interests (Art. 6(1)(1)(f) GDPR).
Cookies
Cookies are functions that store information on users' devices and read information from them.
This service sets no advertising or analytics cookies. The only cookies used are those required to keep you signed in. These are strictly necessary to provide the functionality you explicitly request, which is why no consent banner is shown. You can delete these cookies at any time through your browser settings; you will then be signed out.
Changes and updates
We ask you to inform yourself regularly about the content of this privacy policy. We adapt it as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as changes require an action on your part, such as consent.
Definitions
- Personal data: any information relating to an identified or identifiable natural person.
- Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: any operation performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, whether collecting, analysing, storing, transmitting or deleting.
- Account data: information required to identify and manage user accounts, such as email address, username and display name.
- Content data: information generated when creating and editing content — here your watchlist entries, episode progress and ratings.
- Usage data: information about how users interact with the service, such as pages visited and time spent.
- Log data: information about events or activities logged in a system, typically including timestamps, IP addresses and error messages.
Based on a template created with the free Datenschutz-Generator.de by Dr. Thomas Schwenke, translated and adapted to this service.