Last updated: August 11, 2026
CharaScroll ("we", "us", or "our") operates the CharaScroll mobile and web application (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have.
By creating an account or using CharaScroll, you agree to the practices described in this policy.
1. WHAT CHARASCROLL IS
CharaScroll is a movie and TV tracking platform that lets you discover, track, and share the latest movies and series. You can build watchlists, rate content, track episode progress, and manage your viewing history.
2. ACCOUNT INFORMATION
When you create an account, we store your email address and a password (hashed by our authentication provider, Supabase). We also store your display name, username (handle), and an optional avatar and cover image that you choose to upload.
3. PROFILE INFORMATION
Your profile includes your display name, @handle, avatar, cover image, and bio. Your profile is visible to other users. You can edit your profile at any time from the Settings menu.
4. AUTHENTICATION PROVIDERS
CharaScroll supports authentication via:
- Email and password
- Google
When you sign in with a third-party provider, we receive your email and basic profile information (name and avatar) from that provider. We do not store your third-party passwords.
5. WATCHED MOVIES AND SHOWS
When you mark a movie or episode as watched, we store that record along with the date you watched it. This builds your watch history, which powers your Watch Next, Been A While, and Calendar features. Your watch history is private to you.
6. WATCHLIST AND FAVORITES
Items you add to your Watchlist or Favorites are stored as records linked to your profile. These help you track content you want to watch and content you enjoyed.
7. RATINGS, REVIEWS, AND REPLIES
When you rate or review content, your rating, review text, and display name are stored and may be visible to other users on the content detail page. You can delete your reviews at any time.
8. PREFERENCES AND SETTINGS
Your notification preferences, appearance settings (theme, text size), language and region settings, and other preferences are stored in two places: a local cache on your device for instant access, and in your account record in our Supabase database so they sync across your devices when you are signed in. These do not contain sensitive personal data.
9. TECHNICAL, CACHE, AND OFFLINE INFORMATION
CharaScroll uses local storage and cache on your device to:
- Persist your session so you stay logged in
- Cache content data (movie/TV metadata) for faster loading and offline use
- Queue actions you take while offline so they sync when you reconnect
- Store your preferences and settings
PUSH NOTIFICATIONS: If you enable push notifications, CharaScroll uses Firebase Cloud Messaging (FCM) to deliver notifications to your device. A device-specific FCM registration token is generated and stored in our database linked to your profile so we can send notifications to the correct device. You can disable push notifications at any time from Settings, and the token is deactivated when you log out. You can also revoke notification permission in your browser or device settings at any time.
Your offline actions are queued locally and synced to our servers when your connection is restored. Actions that fail permanently (for example, because the content no longer exists) are removed from the queue and you may be notified; actions that fail temporarily (network or server errors) are retried automatically.
10. TMDB AND EXTERNAL SERVICE INTERACTIONS
CharaScroll fetches movie and TV metadata (titles, posters, cast, crew, trailers, ratings) from The Movie Database (TMDB). When you browse or search content, requests are sent to TMDB's API. TMDB has its own privacy policy that governs how they handle data. We do not share your personal data with TMDB beyond what is necessary to retrieve content.
11. PURPOSES FOR PROCESSING DATA
We process your data to:
- Provide and maintain the Service
- Authenticate you and secure your account
- Display your watch history, watchlist, favorites, and ratings
- Power discovery, search, and calendar features
- Send you push notifications you have opted into via Firebase Cloud Messaging
- Improve the Service and fix issues
- Comply with legal obligations
12. DATA STORAGE
Your data is stored in our Supabase database, which is hosted on secure cloud infrastructure. Authentication data is managed by Supabase Auth. Content metadata is cached from TMDB. Your preferences are stored both on your device (local cache) and in your account record in the Supabase database so they sync across devices when you are signed in.
13. ACCOUNT DELETION
You can permanently delete your account from Settings > Account > Delete Account. This action is irreversible. When you delete your account:
- Your profile record is removed from our database
- Your Supabase authentication user is deleted, so you can no longer sign in
- Other records linked to your account (watch history, watchlist, favorites, ratings, reviews, episode progress, and push device registrations) are no longer accessible through the app because they require a valid authenticated account to read. These records may remain in our database for a limited period before being cleaned up
- Uploaded avatar and cover images associated with your profile are removed from storage
- Moderation records related to your submissions are retained for moderation history purposes
Because your authentication user is deleted, no one can sign in to your account or access your data through CharaScroll after deletion.
14. USER DATA DOWNLOAD AND EXPORT
You can download a copy of your CharaScroll data from Settings > Data & Storage > Download My Data. The export includes your basic account/profile data, preferences, watch history, episode and playback progress, watchlist, favorites, ratings and reviews, review interactions, social activity, notifications, and the current derived statistics snapshot. You can export as JSON or as a ZIP containing separate CSV files.
15. COOKIES, LOCAL STORAGE, AND CACHE TECHNOLOGIES
CharaScroll uses the following local storage technologies on your device:
- Authentication session: Required to keep you logged in. Without this, you would need to sign in on every page load.
- Content cache: Stores movie/TV metadata so the app loads faster and works offline. This is disposable and can be cleared without losing your data.
- Offline mutation queue: Stores actions you take while offline so they sync when you reconnect. Clearing the cache does not delete this queue.
- User preferences: Stores your settings (theme, language, notifications, date/time format) in a local cache on your device and syncs them to your account record in the Supabase database so they are available across devices when you are signed in.
CharaScroll does not use third-party advertising cookies, tracking pixels, or analytics cookies.
16. YOUR PRIVACY RIGHTS
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request a copy of your data (available via the Download My Data feature)
- Request correction of inaccurate data
- Request deletion of your data (available via the Delete Account feature)
- Object to or restrict certain processing
- Withdraw consent for optional processing
To exercise these rights, contact us at info@charascroll.com.
17. GDPR
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR). CharaScroll acts as a data controller for your personal data. We process your data based on:
- Performance of a contract (providing the Service you requested)
- Our legitimate interests in operating and improving the Service
- Your consent (for optional features like notifications)
You have the right to lodge a complaint with your local data protection authority if you believe we have not handled your data appropriately.
18. SECURITY
We take reasonable measures to protect your data:
- Passwords are hashed by Supabase Auth using industry-standard algorithms
- The service-role database key is never exposed to the client application
- All communication with our servers uses HTTPS encryption
- Authentication sessions are managed by the Supabase client, which stores session data (including the refresh token) in your browser's local storage so you stay logged in between visits; the current access token is also held in memory for the duration of each session
However, no system is perfectly secure. We cannot guarantee absolute security of your data.
19. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy in the app. The "Last updated" date at the top of this policy indicates when it was last revised.
20. CONTACT
If you have questions about this Privacy Policy or your personal data, please contact us at:
Email: info@charascroll.com