Privacy Policy
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Seenfy application (the "Application") on mobile devices and on the web. The Application is provided by Color Hub, operated by Luka Katsadze, a sole proprietor based in Tbilisi, Georgia ("we", "us", or "our"). Please read this Policy carefully. If you do not agree, please do not use the Application.
1. Data Controller
For the purposes of the EU General Data Protection Regulation (EU) 2016/679 ("EU GDPR"), the UK GDPR, and similar data protection laws, the data controller for personal data processed in connection with the Application is Luka Katsadze (Color Hub), Tbilisi, Georgia. You can contact us about this Policy or to exercise your rights at support@colorhub.online.
2. Information We Collect
2.1 Information You Provide
When you create an account or use the Application, we collect the following personal data:
- Email address — to create your account, authenticate sign-in, and send service communications.
- User ID — a unique identifier (e.g. Firebase Authentication UID) generated for your account. You may also use the Application anonymously, in which case only this identifier exists until you link a sign-in method.
- Display name and username — the name received from a third-party sign-in provider (e.g. Sign in with Apple, Google Sign-In) or set by you, and the public username (handle) you claim if you use the social features.
- Profile image — if you upload one or if it is received from a third-party sign-in provider.
- Your library — the movies and TV shows you track, their status, ratings, progress and watched episodes with their watch dates, favorites, rewatch counts, personal notes, custom titles and custom cover images, and lists (see Section 3).
- Imported data — if you import from another service (for example a TV Time GDPR export), the watch history, ratings, reactions, and lists contained in the file you choose to import. The file is read on your device; only the resulting library entries are stored.
- Social graph — friend requests and accepted friendships, and any reports or blocks you submit.
- Support correspondence — the contents of any messages you send to us by email.
2.2 Information Collected Automatically
When you use the Application, we and our service providers automatically collect:
- Internet Protocol (IP) address;
- Device information: operating system, OS version, device model, language, time zone;
- Usage information: screens visited, features used, time and duration of visits, referring URL;
- Crash and diagnostic data (e.g. stack traces, device state at the moment of a crash);
- Push notification tokens, if you enable notifications about new episodes of the shows you track;
- Subscription and purchase status (entitlement information, not full payment card data).
The Application does not collect precise (GPS-level) location data.
3. Your Library and Social Features
The Application is a personal watch tracker. The content you save — what you watched, when, how you rated it, and any notes you attach — is stored so that we can deliver it back to you across your devices. We never sell your library, we never share it in a form that identifies you, and we never use your notes, custom titles, or custom covers for anything other than operating the Application for you.
We do compile anonymous statistics from watch activity across our entire user base — for example, what share of viewers who start a series reach its finale — and we may license those statistics to third parties. These are counts and percentages about titles, never records about people: they are produced only after your data has been irreversibly aggregated with that of many other users. Section 9.1 sets out exactly what this covers and the limits we commit to.
Certain information becomes visible to other users when you choose to use the social features. Your username, display name, and profile image are visible to any signed-in user who looks you up by username. Your activity events (for example "watched an episode" or "rated a title") are visible only to people whose friend request you accepted, and only for the categories of activity you leave enabled in the sharing settings. Turning a category off deletes the corresponding events. Your notes, custom titles, and custom covers are never shared. Social features are unavailable to anonymous accounts.
Metadata about titles (posters, cast, episode lists, air dates) is not part of your personal data — it is fetched from external catalog providers and is not stored in your library, except for the title and cover snapshot attached to an activity event so that your friends can read the event.
4. How We Use Your Information & Legal Bases
We process your personal data only where we have a lawful basis to do so under Article 6 GDPR. The list below summarises the purpose and legal basis for each processing activity.
- To create and maintain your account — performance of a contract (Art. 6(1)(b) GDPR).
- To store, sync, and deliver your library to your devices — performance of a contract.
- To operate the social features you opt into (profile, friends, activity feed) — performance of a contract, and your consent through the per-category sharing settings.
- To send notifications about new episodes — your consent, given through the system permission prompt and the in-app notifications setting, which you may withdraw at any time.
- To process payments and manage subscriptions — performance of a contract; legal obligation (tax, accounting).
- To provide customer support — performance of a contract; legitimate interest in responding to user requests (Art. 6(1)(f)).
- To review reports of objectionable content or behaviour and to enforce our Terms — legitimate interest in keeping the Application safe for its users; legal obligation where applicable.
- To detect, prevent, and address fraud, abuse, or security incidents — legitimate interest in keeping the Application safe and reliable.
- To analyse usage and improve the Application — legitimate interest, where analytics are aggregated; otherwise, your consent.
- To compile anonymous statistics about viewing patterns, which we may license to third parties (Section 9.1) — legitimate interest in funding and sustaining the Application (Art. 6(1)(f) GDPR), read together with the safeguards for statistical purposes in Art. 89(1) GDPR. Only the aggregation step involves your personal data; the resulting statistics are anonymous and fall outside the scope of the GDPR (Recital 26). You may object to this processing at any time under Art. 21 GDPR by contacting us.
- To send service-related communications (e.g. account, security, billing, policy changes) — performance of a contract; legal obligation.
- To send marketing communications — your consent, which you may withdraw at any time.
- To comply with legal obligations and respond to lawful requests — legal obligation (Art. 6(1)(c)).
We do not engage in automated decision-making producing legal or similarly significant effects on you.
5. Cookies and Similar Technologies
Our website and web app use cookies and similar technologies (e.g. local storage, SDK identifiers). Strictly necessary technologies — including the local storage entry that remembers your theme and accent choice — operate without consent; analytics and other non-essential technologies are loaded only after you give consent via our cookie banner. You can change or withdraw your consent at any time by reopening the cookie settings from the banner.
6. Third-Party Service Providers
We use trusted third parties to operate the Application. Each provider acts as our processor (or, where they determine their own purposes, as an independent controller) and is contractually bound to handle your data appropriately. The data each provider receives is limited to what is necessary for the stated purpose.
- Google Firebase (Authentication, Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, Analytics, App Check) — account identifiers, library storage, uploaded images, push tokens, device and usage analytics.
- Google Play Services — required platform services on Android devices.
- RevenueCat — subscription state, purchase events, your account identifier.
- Sentry — error and crash reporting (stack traces, limited device context).
- TheTVDB — the catalog of movies, series, episodes, and people shown in the Application. Catalog requests are made by our servers, not by your device, so this provider does not receive your identity or your library.
- Apple App Store and Google Play — payment processing and entitlement delivery for in-app purchases. We do not receive your full payment card number from these providers.
7. International Data Transfers
We are based in Georgia. Several of the service providers listed above are established in the United States or other countries outside the European Economic Area (EEA), United Kingdom, or Switzerland. When personal data is transferred outside the EEA/UK, we rely on appropriate safeguards under Articles 44–49 GDPR, including:
- the European Commission's adequacy decisions where they apply (including the EU–US Data Privacy Framework for certified US providers);
- the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum;
- additional technical and organisational measures where required by our risk assessment.
You can request a copy of the relevant safeguard documentation by contacting us at support@colorhub.online.
8. Payments and Subscriptions
The Application offers optional auto-renewing subscriptions that unlock premium features. Billing is processed by the Apple App Store or Google Play, and subscription state is managed through RevenueCat. We do not collect or store your full payment card number; we receive only the purchase and subscription status information needed to deliver your entitlements.
Subscriptions renew automatically at the end of each billing period unless cancelled at least 24 hours before the period ends. Cancellations, refunds, and trial terms are governed by the policies of the respective store.
9. Disclosure of Information
We may disclose personal data:
- To other users, to the extent you enable the social features, as described in Section 3;
- To our service providers (listed in Section 6) acting on our behalf under appropriate contracts;
- To comply with law, including subpoenas, court orders, or other valid legal process, and to respond to lawful requests from public authorities;
- To protect rights and safety, where we believe in good faith that disclosure is necessary to investigate fraud or abuse, prevent harm, or protect our rights, property, or the safety of our users or the public;
- In the context of a corporate transaction, such as a merger, acquisition, asset sale, or insolvency, in which case we will require the recipient to honour the terms of this Policy;
- With your consent, or at your direction.
9.1 Aggregated and Anonymised Insights
We compile statistics about viewing patterns across our user base and may license them to third parties such as studios, streaming services, and market researchers. This is a source of revenue that helps keep the Application running. We consider it important that you understand precisely what it does and does not involve.
What may be included: counts, percentages, averages, and time-series about titles and episodes — for example how many users tracked a series, what proportion of them finished a season, how long after broadcast an episode is typically watched, average ratings, and how these figures differ by country or over time.
What is never included: your name, username, email address, user ID, profile image, IP address, device identifiers, or any other identifier; your notes, custom titles, or custom covers; your friends or social graph; and any per-user record, watch history, or event log, whether or not identifiers have been stripped from it. We do not license row-level data about individuals in any form.
The limits we commit to. We publish these as binding commitments, not intentions:
- No figure we release is derived from fewer than 500 users, and no combination of released figures is permitted where it could be used to single out an individual;
- Aggregation is irreversible — the statistics we release cannot be resolved back to the records they were computed from, and we retain no key that would allow it;
- We maintain and use this information in aggregated, anonymised form only, and we will not attempt to re-identify any individual from it;
- Every recipient is contractually prohibited from attempting to re-identify any individual, from combining the statistics with other datasets for that purpose, and from onward transfer except under the same restrictions;
- These statistics are compiled from watch activity only. Enabling or disabling the social sharing settings has no effect on them, and no part of your profile is used.
Because this information is aggregated and anonymised, it is not personal data under the GDPR and not personal information under the CCPA/CPRA. We do not sell or share your personal information, as those terms are defined under California law, and we have never done so.
10. Data Retention
We retain personal data only for as long as needed for the purposes set out in this Policy:
- Account data and library content — for the duration of your account, plus up to 30 days after deletion to allow account recovery, after which it is permanently deleted from active systems. Encrypted backups are deleted within 90 days.
- Activity events — until you delete the underlying item, turn off the relevant sharing category, or delete your account, whichever is earliest.
- Reports of objectionable content or behaviour — up to 2 years, so that repeat reports can be assessed.
- Purchase and subscription records — up to 7 years where required by tax and accounting laws.
- Support correspondence — up to 3 years from the last interaction.
- Aggregated analytics and the anonymised statistics described in Section 9.1 — may be retained and licensed indefinitely, because they are anonymous and deleting your account cannot and does not remove your past contribution to a figure that says nothing about you.
- Crash and diagnostic logs — typically up to 90 days.
You can delete your account at any time from the Application's profile settings, or request earlier deletion by emailing support@colorhub.online, subject to legal obligations to retain certain records.
11. Your Rights
11.1 Rights under EU/UK GDPR
If you are in the EEA, the UK, or Switzerland, you have the right to:
- Access your personal data and obtain a copy (Art. 15);
- Rectify inaccurate or incomplete data (Art. 16);
- Erase your data (“right to be forgotten”) (Art. 17);
- Restrict processing in certain circumstances (Art. 18);
- Receive your data in a portable, machine-readable format (Art. 20) — the Application also lets you export your whole library as JSON or CSV at any time;
- Object to processing based on legitimate interests or for direct marketing (Art. 21);
- Withdraw consent at any time, where processing is based on consent (Art. 7(3));
- Lodge a complaint with your local supervisory authority (Art. 77).
11.2 Rights under California law (CCPA/CPRA)
If you are a California resident, you have the right to:
- know what personal information we have collected about you in the past 12 months, the sources, the purposes, and the categories of third parties with whom we share it;
- request deletion of your personal information, subject to legal exceptions;
- request correction of inaccurate personal information;
- opt out of the "sale" or "sharing" of personal information (we do not sell or share personal information as defined under the CCPA/CPRA);
- limit the use and disclosure of sensitive personal information;
- not receive discriminatory treatment for exercising any of these rights.
You may also designate an authorised agent to make a request on your behalf, subject to verification.
11.3 How to exercise your rights
To exercise any of the rights above, contact us at support@colorhub.online. We will respond within the timeframes required by applicable law (generally one month under GDPR, 45 days under CCPA, extendable where permitted). We may need to verify your identity before fulfilling a request.
12. Children's Privacy
The Application is not intended for children under the age of 13, and we do not knowingly collect personal data from children under 13. In jurisdictions where the minimum age of digital consent under GDPR is higher than 13 (for example, 14 in Italy and Spain, 15 in France, 16 in Germany and the Netherlands), users below that age may only use the Application with the consent of a parent or legal guardian.
If we learn that we have collected personal data from a child below the applicable minimum age without verified parental consent, we will delete it as soon as reasonably possible. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us at support@colorhub.online.
13. Security
We use reasonable technical and organisational measures designed to protect your information, including encryption of data in transit (TLS), encryption of data at rest by our cloud infrastructure providers, server-side access rules that restrict each document to its owner and to the friends you have accepted, and app attestation to reject requests that do not come from a genuine copy of the Application. No method of transmission or storage is fully secure, however, and we cannot guarantee absolute security.
14. Data Breach Notification
In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Article 33 GDPR. Where the breach is likely to result in a high risk, we will also notify affected users without undue delay, as required by Article 34 GDPR.
15. Consumer Right to Cancel
If you are a consumer in the EU or UK and unless an exception applies, you have a statutory right to cancel a purchase within 14 days without giving any reason. The cancellation period expires 14 days after the day of the transaction. To meet the deadline, it is sufficient to send your cancellation statement before the period expires.
To cancel, please contact us by email at support@colorhub.online with a clear, unambiguous statement of your decision to cancel. In respect of subscription services, the right to cancel applies following the initial subscription and not upon each automatic renewal. Refunds for in-app purchases are processed by Apple or Google in accordance with their policies.
16. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the "Last updated" date. For material changes, we will provide additional notice (for example, an email or an in-app notice) and, where required by law, obtain your renewed consent before the changes take effect.
17. Your Consent
By creating an account or otherwise using the Application, you acknowledge that you have read this Privacy Policy and that we will process your personal data in accordance with the legal bases set out in Section 4. Where processing is based on your consent (for example, for notifications, marketing emails, or non-essential cookies), separate consent will be requested and may be withdrawn at any time.
18. Contact Us
For any questions or requests relating to this Privacy Policy or our processing of your personal data, including to exercise any of the rights described in Section 11, please contact us at support@colorhub.online. See also our Terms of Use.