Legal

Privacy

Last updated August 30, 2026

This describes what the software actually does today, written from the code. It has not been reviewed by a lawyer. If you need a policy you can rely on for a regulatory filing, have counsel review it first.

MovieKnight helps a group decide what to watch. That needs some information about you. This page says exactly what, why, and how to get rid of it.

What you can do without an account

Browsing, searching and the Tonight picks all work signed out. In that state we do not create a record for you. Your theme choice and the current party are held in your own browser, not on our servers, and your picks are worked out from what you type in the prompt rather than from a profile.

What we store when you sign up

  • Account — your email address and an authentication record, held by Supabase. We never see or store your password; it is hashed by the authentication provider.
  • Profile — a display name, an optional username, and an avatar selection. Default avatars are generated images, not uploaded photos.
  • Library — what you mark as watched, watching, want to watch, dropped or not interested; your ratings; your lists and watchlist; and anything you record on your shelf as physically owned.
  • Social — friend connections, direct messages you send, and notifications generated for you.
  • Party activity — votes and vetoes you cast in a group session, visible to the other people in that session.

Diagnostics

For signed-in sessions only, the app reports browser errors, failed network requests and page-performance timings so we can find breakage we cannot reproduce. Text in those reports is stripped of recognisable personal data — email addresses, tokens and similar — both in your browser before it is sent and again on our server before it is stored. Signed-out visitors send no diagnostics at all.

Analytics

We use PostHog to count page views and see which screens get used. It is configured to build a person-level profile only for signed-in users. If the analytics key is not configured for a deployment, no analytics code loads at all.

Who else your data reaches

  • Supabase — our database, authentication and realtime provider. Everything in the list above lives here.
  • Vercel — hosting. Sees request metadata such as IP address and user agent, as any web host does.
  • PostHog — product analytics, as described above.
  • TMDB — the source of film and television metadata and artwork. Your browser loads poster images from their image host, so they see those image requests. We do not send them your library.
  • YouTube — trailers play in an embedded player on the privacy-preserving youtube-nocookie.com domain, sandboxed, and only after you press play.
  • DiceBear — generates default avatar images.

We do not sell your data, and we do not share it with advertisers.

Getting your data out

Your viewing history is exportable as a CSV at any time from your profile, with no request or waiting period. The export is always free.

Deleting your data

You can remove individual entries — a rating, a list, a shelf item, a watch record — from the app directly, and that deletes the row. To delete your whole account and everything attached to it, contact us and we will remove it. Diagnostics and analytics records age out on their own and are not kept indefinitely.

Cookies

We set a session cookie so you stay signed in, and store your theme preference and current party locally in your browser. There are no advertising or cross-site tracking cookies.

Children

MovieKnight is not intended for children under 13, and we do not knowingly collect information from them.

Changes

If this changes materially we will update the date at the top of this page.

Contact

Questions about any of the above, or a deletion request: privacy@movieknight.ca.