Privacy Policy
Last updated: September 9, 2026
I'm Watching This ("the app", "we", "us") is a tracker for TV shows and movies operated by Code Éclair (NEQ 2271379655), based in Québec, Canada. This policy explains what we collect, why, and how we look after it. The short version: we keep what the app needs to work and nothing else, and we don't sell your data or run advertising trackers. Our only analytics are privacy-friendly and anonymous (Plausible, which we self-host, no cookies, can't identify you).
What we collect
- Account details: your email address, a securely hashed password if you set one, and the language, country and time zone you choose.
- What you track: the shows and movies you add, their status, your ratings, the dates you watched them, and the episodes you tick off. You add these yourself.
- A security log: account events such as sign-ins, with the IP address and device. It is kept for up to 90 days (see Data retention).
- Basic technical data: standard server logs (such as IP address and timestamps) needed to run and secure the service.
For basic web analytics we use Plausible, an open-source, privacy-friendly analytics tool that we host on our own servers, to see aggregate traffic (such as how many people visit and which pages are popular). Because we self-host it, no analytics data is sent to any third-party provider. It is cookieless, collects no personal data, sets no persistent identifiers, and does no cross-site tracking, so it cannot identify you as an individual. We do not use Google Analytics, ad pixels, or advertising trackers, and we do not sell or share your data for advertising. To understand product health we also keep a simple internal dashboard of aggregate counts (e.g. number of users and tracked titles), not individual tracking.
How we use it
- To provide the app: your library, your progress, Up next, and the calendar.
- To send essential account emails: email confirmation, password resets, sign-in links, and security alerts.
- To keep the service secure and prevent abuse.
We do not sell your data or share it for advertising.
Where the shows and movies come from
Titles, posters, overviews and air dates come from The Movie Database (TMDB). When you search, our server asks TMDB on your behalf: the search text goes out, your account details do not. Poster images are served from our own servers (we keep a copy of the ones the app shows), so your browser does not contact TMDB. The "where to watch" lists come from JustWatch through TMDB and are looked up for the country in your profile. This product uses the TMDB API but is not endorsed or certified by TMDB.
Where your data lives
- Our servers are hosted at OVH, in their Beauharnois (BHS) datacentre in Québec, Canada. So your primary data stays in Québec.
- Traffic is served through Cloudflare's DNS and a Cloudflare Tunnel (Cloudflare is a US company), so the origin server is not exposed directly to the internet. As a proxy, Cloudflare handles requests in transit at its nearest global edge and keeps limited technical logs (such as IP addresses) for security and performance; it may also cache public files like our app's scripts. Your account and your library are not stored on Cloudflare, they live on our servers at OVH.
- Backups are encrypted on our server before they leave it, then stored with our backup partner BorgBase, in the United States. BorgBase only ever holds encrypted data it cannot read. Backups are kept for up to three months.
- Account emails (confirmation links, password resets, sign-in links, security alerts) are sent through Resend (resend.com), a US email provider. Resend processes your email address and the message content to deliver it, and keeps limited delivery logs.
- Web analytics are collected by Plausible, which we host ourselves, on the same infrastructure as the rest of our data (OVH, in Québec). No analytics data is sent to any third party: it stays on our servers. Plausible collects only anonymous, cookieless page events (no account or library data, nothing that identifies you).
Your primary data stays in Québec (OVH BHS). Encrypted backups are held in the US (BorgBase only ever sees ciphertext), traffic is proxied by Cloudflare's global network, and account emails are delivered by Resend in the US. Searches leave our server for TMDB in the US with no account details attached. Our web analytics stay on our own servers (self-hosted Plausible), with no transfer to a third party. These transfers are covered by each provider's privacy policy (linked above).
Cookies
We use a single essential cookie: a secure, httpOnly session cookie that keeps you signed in. We don't use advertising or tracking cookies. Your theme and language choices are kept in your browser's local storage, not on our servers.
How we protect it
- Your connection is encrypted in transit with HTTPS.
- Passwords are hashed, not stored in plain text.
- Two-factor authentication is available on any account, and is optional.
- Rate limiting and rotating login sessions guard against abuse; changing your password or using "log out everywhere" revokes every session.
- Servers are locked down and hosted with a reputable provider (OVH).
- Data is backed up automatically, multiple times a day, encrypted before it leaves our server.
Your choices
- Export: download your whole library, in JSON and CSV, from Settings at any time. It is yours to take somewhere else.
- Access & correct: everything you store is visible and editable in-app.
- Delete: delete your account and its data; residual copies in encrypted backups age out within three months.
Data retention
We keep your data for as long as your account is active. When you delete your account we remove your data from the live service; encrypted backup copies are cycled out within three months.
To protect accounts and investigate abuse, we keep a security log of account events (for example sign-ins, with the IP address and device). It is stored separately from your library, kept for up to 90 days, then deleted. Because its only purpose is to catch an accident or a compromise, this log can briefly outlast the deletion of an account, but no more than 90 days. After that, with backups also cycled out, nothing about a deleted account remains.
Session records (what keeps you signed in between visits, along with the IP address they were opened from) expire after 14 days and are deleted at most 30 days after that.
We also keep a minimal, non-identifying record of deletions (an internal account identifier and the date, no email or library data) so that, if we ever restore a backup, deleted accounts stay deleted.
Children
I'm Watching This isn't directed at children and isn't intended for anyone under 16.
Changes
We may update this policy from time to time. When we do, we'll change the date at the top of this page.
Person in charge of personal information
Code Éclair is responsible for the personal information I'm Watching This holds. For any question, or to access, correct, or delete your information, contact our person in charge of personal information (privacy officer), Danny Ferguson, at privacy@imwatchingthis.com.
If you're not satisfied with our response, you can file a complaint with Québec's Commission d'accès à l'information.
Contact
Questions about your privacy? Reach us through the Contact page or at privacy@imwatchingthis.com.