Legal
Privacy
What we collect, why, and how to get rid of it.
Last updated 26 July 2026
The short version
Vescene stores the things you rate, log, write, and share, plus the email address your sign-in provider gives us. We do not sell it, we do not track you across other apps or sites, and there are no advertising identifiers anywhere in the product. You can export everything as JSON or delete your account from inside the app at any time.
Who is responsible
The data controller is Jonas Blendstrup Rasmussen. For anything in this policy — including access, correction, and deletion requests — write to support@vescene.com.
What we collect
Account identity
The email address released by Apple or Google when you sign in, and the given/family name if your provider includes one. Sign in with Apple lets you hide your real address behind a private relay — if you do, that relay address is all we ever see. We never receive your password from either provider.
Sign-in linkage
Which provider you used and the account identifier it issued, so the same person lands on the same account next time. Provider tokens are stored to complete the sign-in exchange.
Profile
The handle you claim, your display name, and your avatar — either a built-in preset or a photo you upload.
What you watch and think
Ratings on both axes, watch logs, reviews, lists and playlists, episode progress, the streaming services you tell us you have, and your friend connections. This is the substance of the product.
Taste profile
A profile derived from your own ratings, used to compute recommendations and the taste-match score against friends. It is computed from data already listed above, not from anything new.
Messages
Direct messages between you and friends, retained until either participant deletes them. They are not end-to-end encrypted: treat them as private-but-readable-by-the-service, not as secret.
Sessions and devices
For each active sign-in: when it started, when it expires, when it was last used, and a device label. On phones that is the device name you already gave your phone; in a browser it is a coarse label derived from your User-Agent header, like “Safari on macOS”. Push notification tokens are stored per device so notifications can reach you.
Moderation records
Reports, blocks, and mutes you create, so the action sticks and abuse can be reviewed.
We do not store your IP address against your account, and there is no advertising or cross-site tracking identifier in the app or on the site.
Why we are allowed to hold it
Under the GDPR our legal bases are: performance of a contract for everything needed to run the account and the features you use; legitimate interests for keeping the service secure and dealing with abuse; and consent for push notifications, which iOS asks you for separately and which you can withdraw in your device settings or per-channel in the app.
What other people can see
Some of Vescene is deliberately public: a profile set to public, the lists you mark public, published reviews, and share links you create for a list or a recap can be viewed by anyone with the URL and may be indexed by search engines. Your privacy setting controls this, and you can change it in Settings. Watch history, ratings you have not published, messages, and your email address are never public.
Who else processes it
We keep the list short on purpose. None of these receive your data for their own marketing.
- Hetzner — hosting for the API and database, inside the EU.
- Apple — Sign in with Apple, and the Apple Push Notification service for delivering notifications to iPhones.
- Google — Sign in with Google, and Firebase Cloud Messaging for notifications on Android.
- TMDB, OMDb and JustWatch — the film and series catalog, aggregate critic scores, and streaming availability. We query them for titles; we do not send them your identity or your activity.
When error reporting and analytics are enabled, we also use Sentry for crash and error diagnostics and Plausible for aggregate, cookie-free visit counts that cannot identify you. Neither sets a tracking cookie.
How long we keep it
Your content stays until you remove it or delete your account. Deleting your account starts a 30-day grace period during which signing in again restores everything — this exists because account deletion is easy to do by accident. After 30 days the account and its content are permanently removed. Expired sessions are cleaned up automatically, and signing out of a device deletes its push token immediately.
Your rights
You can access, correct, export, restrict, or erase your data, object to processing based on legitimate interests, and withdraw consent for notifications. Two of these are self-service in the app, with no waiting on us: Settings → Account exports your data as JSON and deletes your account.
For anything else, email support@vescene.com and we will respond within 30 days. If you are in the EU/EEA and think we have handled your data badly, you can complain to your national data protection authority — in Denmark that is Datatilsynet.
Children
Vescene is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, email us and we will remove it.
Changes
If this policy changes in a way that affects you, we will say so in the app before the change takes effect rather than quietly editing this page. See also our terms of service.