In short
SineO does not track you: no analytics, no ad network, no crash reporting. Your watchlist stays on your phone.
An account is needed for the watchlist only. Discover, search, title pages and "What should I watch?" all work without one, and if you never sign in, nothing goes to any server at all. The watchlist needs an account because carrying that list between your own phones is the one thing an account does.
Data kept on your device
The following is stored only in your device's own storage and is never sent anywhere:
- Your watchlist and the last known details of the titles in it
- Your "watched" marks and how you rated them
- Your region, additional regions and the streaming services you picked
- Appearance preference and recent searches
- The notification setting and which services a title was last seen on
- Your "what should I watch" filters and the backdrop theme you chose
Two more things stay inside your device, but deserve to be named:
- So that system search can find them: the names and artwork paths of the titles on your watchlist are written to your iPhone's own search index (Spotlight). That index is Apple's on-device index; it does not come to us or to anyone else. Removing a title from your list removes it from the index too.
- For the widget and the Control Center button: because the widget on your home screen needs to know what to show, a small summary of your list (title and artwork path) is written to a shared container inside your device. That container lives on the phone, is shared between the app and its widget, and never leaves.
The share card ("share my watchlist") renders the image on your device; you decide where it goes in the share sheet, and the app never sends it anywhere on its own.
There is no analytics, no crash reporting, no ad network and no "user experience measurement" inside SineO. The one third-party package is for signing in (Google Firebase Authentication), and it is never started until you press a sign-in button: for somebody using the app without an account it sits dormant and makes no request at all.
Deleting the app deletes all of it. It may appear in your device backups, which are under your own Apple account's control.
Account (for the watchlist)
Nothing in the app asks for an account. Signing in does exactly one thing: it carries your watchlist between your own phones. If you never sign in, the whole app works the same way.
If you do choose to sign in:
- What is stored: a user id and — unless you signed in with Apple and chose to hide it — your email address. And the synced list itself: the TMDB identifiers of the titles on your watchlist, with timestamps for adding, removing and reacting. No names, artwork or ratings are sent; a new phone fetches those from TMDB itself. No phone number, no contacts, no location: none of it is asked for and none of it is taken. One caveat, and it is Google's alone: Google's sign-in scopes are fixed, so its token hands Firebase Authentication the display name and avatar link on that account. SineO never asks for them, never shows them and never uses them; they sit in the Firebase account record and go when you delete the account. Sign in with Apple, or with the emailed link, and there is no name at all — of Apple, SineO asks for an e-mail address and nothing else.
- Who processes it: authentication is run by Google's Firebase Authentication; we do not operate a server of our own. Apple verifies your password if you sign in with Apple, Google if you sign in with Google — your password never reaches SineO.
- Sign in with Apple lets you hide your address; we then hold an Apple private relay address rather than your real one.
- When it starts: the sign-in software is never run until you press a sign-in button. So for anybody using the app without an account, this whole section does not apply.
- Deletion: Settings → Account → Delete account. The account and anything synced with it are removed; the list on your phone stays where it is. Signing out is on the same screen. If you cannot reach your phone, you can ask for the same deletion at mustafa@mustafaevleksiz.com; the detail is at mustafaevleksiz.com/sineo/delete-account.
Services the app talks to
SineO makes requests to three places in order to work; two more are added if you sign in. The first three carry no identity: no account, no device identifier, no advertising identifier. As with any internet request, your IP address and general device information are visible to the receiving service; we neither log this nor operate a server of our own.
- TMDB (api.themoviedb.org, image.tmdb.org) — film and TV metadata, artwork, availability
- OMDb (www.omdbapi.com) — IMDb, Rotten Tomatoes, Metacritic scores
- YouTube (when you play a trailer) — trailer playback
- Google Firebase Authentication (only if you sign in) — verifying who you are
- Google Cloud Firestore (only if you sign in) — where your list is carried between your phones
Streaming availability is provided by JustWatch through TMDB. Tapping a service logo opens that service's own site or app; from there their privacy policy applies.
Backup file
From Settings → Your data you can create a backup file: your watchlist, your "watched" marks, your recent searches and your preferences, in a single JSON file. You create that file and you decide where it goes; the app never sends it anywhere and never uploads it to a server. The file is plain text, so you can open it and read exactly what is in it. You can restore from it on the same screen.
Notifications
If you turn on "Tell me when it arrives", the availability of titles on your watchlist is checked and your device itself shows a notification when one of them reaches a service you subscribe to. Notifications are local: there is no remote server, no push service and no notification token.
Children
SineO is not directed at children and does not ask anyone's age.
Changes
If this policy changes, the date above is updated and the new text ships with the next version of the app.
Contact
mustafa@mustafaevleksiz.com