Local use and optional accounts
You can use WatchWatch without an account. Local queue, movie and season history, ratings, sender details, and notes stay in the app container unless you search an external catalog, explicitly share an artifact, or later choose to sign in and sync.
If you create an account, WatchWatch stores your email address, username and display name, saved titles and queue state, sender attribution, notes, reactions, verdicts, movie and season status and ratings, Up Next organization, and notification registration. This supports backup, cross-device sync, personalization, recommendations, and closing recommendation loops.
Movie and season history, ratings, and personalization
WatchWatch stores movie-level and season-level status, ratings, timestamps, and how an item was added. Unwatched items have no progress record, and a personal rating is separate from any verdict sent to a recommender. WatchWatch does not keep episode-by-episode viewing history for the 2.1 model. Show status, personal statistics, and an Entertainment Fingerprint™ may be derived from the history you provide. The Entertainment Fingerprint is a private visualization of the movies and shows you mark as finished. It is not biometric data and is not used to identify or track you.
For signed-in use, these derived show-status, taste, Entertainment Fingerprint, and personal-stat projections are stored with your account and are treated separately from the history and ratings you supplied.
You do not need an account to see an Entertainment Fingerprint. For local-only use, WatchWatch derives it on your device from unique finished movies and shows; multiple finished seasons of one show count once. It keeps only a protected, versioned aggregate render cache in the app container. This local calculation does not upload your history or Entertainment Fingerprint data or make a vendor request triggered by the Entertainment Fingerprint. If you later create an account, the current render moves into the account's protected cache so the screen remains stable while sync completes; the synced account projection replaces it after a successful refresh.
If you choose to share your Entertainment Fingerprint or a personal-stat screen, WatchWatch creates a branded image in memory on your device and gives only that image to the iOS share sheet. An Entertainment Fingerprint share image contains the visualization, genre labels, WatchWatch branding, and a subdued shared poster mosaic made from currently popular artwork licensed through TMDB; the mosaic is the same for every person and is not based on your history. It does not contain your name, username, email address, account or installation identifier, title history, ratings, or contacts. WatchWatch does not upload or retain the shared image and does not receive the app, recipient, or message you choose.
Taste outputs are private by default. WatchWatch stores only the versioned projection and derived facts needed for your private experience. Removing source history invalidates affected outputs; signing out removes that account's cached projection from the device, and deleting your account removes its synced and cached outputs.
Contacts and title search
If you choose someone with the Contacts picker while signed in, WatchWatch syncs only that selected contact's display name and Contacts identifier—an opaque identifier—so the sender can be recognized on your devices. WatchWatch does not upload your address book, phone number, or email address.
Text you enter in title search is sent to TMDB to return matching results. WatchWatch does not store search text in its database or product analytics. Shared catalog metadata may be cached within applicable license limits.
Legacy profile and group images
WatchWatch 2.1 does not offer a photo picker, camera flow, avatar editor, group editor, or new image upload. Production storage nevertheless retains a limited set of profile and group images selected through an earlier version of WatchWatch. These legacy images are linked to the account or group for which they were supplied, are retained only for the earlier app functionality, and are not used for tracking, advertising, analytics, or the 2.1 taste experience.
The legacy image buckets were configured for public delivery, so stored objects are not protected like private account records. WatchWatch 2.1 does not fetch or display them. They remain until you request deletion at support@watchwatch.tv or WatchWatch completes a verified legacy cleanup. Deleting a WatchWatch account removes current synced 2.1 records but may not automatically locate these older Storage objects; contact support if you previously uploaded an avatar or group image and want it removed.
Optional product analytics
Product analytics are off by default. The app creates a random installation identifier and local first-use date so that, if you later opt in, measurements can use an installation cohort. Creating those local values does not record, queue, or upload an analytics event.
After opt-in, events contain only typed actions, closed categories, booleans, bounded counts and timings, and installation-secret pseudonyms for workflow identifiers. They do not include your Apple ID, WatchWatch account ID, email, contacts, titles, TMDB identifiers, season numbers, rating values, notes, search text, taste vectors or traits, prices, products, transactions, receipts, entitlements, recipients, or share text. WatchWatch does not join the analytics identifier to your account or purchase record and does not use analytics for advertising, tracking, or sale to data brokers.
You can turn analytics off again at any time in Account. Turning it off stops future recording and deletes pending on-device events. Raw events already received are automatically deleted within 90 days. A reinstall, second device, and staging app are separate installations.
Website advertising measurement
The public marketing, support, privacy, and terms pages use Google Ads conversion measurement to understand whether an ad led someone to choose the App Store link. Advertising storage and advertising user-data processing are denied by default. The Google tag may send limited, cookieless measurement signals while consent is denied. If you choose Allow measurement, Google may also store or read limited advertising identifiers and receive landing-page, browser and device, ad-click, consent, and App Store-link interaction data. Personalized advertising remains disabled.
This website measurement is separate from optional in-app product analytics. WatchWatch does not send Google your WatchWatch account ID, email, contacts, queue, titles, ratings, sender details, notes, viewing history, Entertainment Fingerprint, or app activity. You can decline through Not now and can remove a saved choice later by clearing WatchWatch site data in your browser.
Sharing and public artifacts
WatchWatch never sends a message on your behalf. Recommendation cards, Entertainment Fingerprints, and statistics are created or shared only after your explicit action. Entertainment Fingerprint and statistics sharing creates no public WatchWatch link.
When you continue to the system share sheet for a recommendation, WatchWatch creates a link first. The card contains the title, year, artwork and availability, plus the public sender name or initials, reaction, and note you chose. Anyone with a card link can view that information until the card is revoked or expires, even if you dismiss the share sheet without sending it. Anonymous cards expire after 7 days. Cards created from an account expire after 90 days by default and never later than 180 days.
Links are unguessable, have bounded expiration, can be revoked, and are revoked or deleted with an account when account-owned. Sharing an image or card does not make your viewing history or private taste data public. The system share sheet controls the selected app and recipient; WatchWatch does not receive the recipient or message body.
Email, notifications, and service providers
WatchWatch uses Supabase for accounts, database, storage, Edge Functions, and optional analytics; TMDB for catalog search and metadata; Resend for transactional email; Apple for push notifications; Vercel for WatchWatch web pages; and Google Ads for consent-controlled advertising measurement on the public website. Resend receives the recipient address, subject, message body, time-limited authentication action link, and delivery metadata required to send account email. WatchWatch does not use Resend for marketing or open/click tracking. YouTube may process a trailer or link request you choose to open. These providers may receive normal request and delivery metadata under their own service terms.
Staging uses separate accounts, endpoints, email controls, APNs sandbox topics, public-card hostnames, and analytics storage. Production customer data is not copied to staging.
Retention and security
Synced queue, movie and season history, ratings, account details, and derived taste data remain until you remove them or delete your account. Legacy profile and group images follow the separate retention and support-deletion process above. Mutation receipts contain only an account identifier, random operation identifier, payload hash, and time and are removed within 30 days. Raw optional analytics is kept for no more than 90 days. Public artifacts follow their displayed expiration and revocation controls. TMDB catalog caches are refreshed or purged within license limits.
WatchWatch uses account ownership rules, row-level security, environment isolation, and protected local storage. No security measure is perfect; contact support if you believe your account or a public link has been misused.
Your choices and account deletion
You can remain local-only, sign out, disable analytics, remove history, revoke public recommendation cards, or permanently delete your WatchWatch account and synced data from Account in the app.
Deleting the app removes its app-container data. Some Keychain material may follow Apple platform behavior until explicitly cleared; WatchWatch clears authentication credentials during sign-out and account-deletion flows. Previously received pseudonymous analytics remains only until its 90-day deletion deadline.
Contact
Questions or privacy requests: support@watchwatch.tv
Entertainment Fingerprint™ is a trademark of WatchWatch.
Last updated August 8, 2026. Effective August 8, 2026.