Privacy Policy
Quadrate (“Quadrate”, “we”, “us”, “our”) is a social app for tracking and reviewing films, TV, books and music. This policy explains what personal information we collect, how we use it, who we share it with, and the rights you have over it. It covers the Quadrate mobile app and the accounts behind it.
We are committed to handling your data carefully and to giving you real control over what is public. If anything here is unclear, contact us — details are at the end.
The short version
- We collect the account details you give us (email, username, display name) and the content you create (your ratings, reviews, notes, quotes, lists, watchlists, favourites and who you follow).
- Quadrate is a social, public-by-default app. Most of what you log is visible to others — but you can make your account private or any list private at any time.
- We don’t sell your data, run ads, or use advertising trackers.
- We use a small number of trusted services to run the app and to fetch catalogue information (listed below).
- You can export your data or permanently delete your account from inside the app at any time.
- Quadrate is for users aged 13 and over.
1. Who we are (data controller)
Quadrate is operated by Liam Darrington, an individual based in the United Kingdom, who is the “data controller” responsible for your personal information under UK data protection law (the UK GDPR and the Data Protection Act 2018).
Contact: mailliamapp@gmail.com
2. The information we collect
a) Information you give us
- Account information — you sign in with Sign in with Apple: Apple provides your email address (or a private “Hide My Email” relay address) and, on first sign-in only and if you allow it, your name, which seeds your display name; you then choose a username and display name. We also keep the Apple sign-in token needed to revoke Quadrate’s access to your Apple ID when you delete your account. (A legacy email-and-password sign-in exists only in development builds; if it is ever used, the password is stored in hashed form by our authentication provider — we never see it in plain text.)
- Profile information — an optional profile banner (chosen from film artwork), an avatar that is either a colour gradient we generate for you or an image you choose from the app’s catalogue (film/TV artwork, a cast photo, a book cover or an artist photo) — stored as a link to the catalogue image, no photo is uploaded — and your “favourites” picks.
- Your media activity and content — films, TV, books and albums you log, with your star ratings, written reviews and notes, book quotes/highlights, tags, favourites, rewatch/re-read counts and the dates you logged them; your watchlists, custom lists (and any collaborators); per-episode and per-track ratings and reading/listening goals; your book-cover picks (the cover you choose a book to show — anonymous vote counts decide the community default); and your social graph — who you follow, your likes/reactions, and content you recommend.
- Moderation information — if you report content or a user, or block a user, we store that action so we can act on it and keep the block in effect.
- Support messages — if you email us, we keep that correspondence to help you.
b) Information collected automatically
- Technical/log data — like any internet service, our backend and the catalogue services we call receive standard request information such as your IP address, device/app version and timestamps. This is used to operate the service, keep it secure and prevent abuse. We do not build advertising profiles from it.
- Crash reports. Quadrate does not embed any third-party crash-reporting or analytics SDK. If you have chosen to share diagnostics with app developers at the operating-system level, Apple may provide us with anonymised crash reports through Apple’s standard developer tools — you control this in your device’s privacy settings. Quadrate does not include advertising trackers or behavioural-analytics SDKs.
- Activity timestamp. We store a “last active” date on your own profile (recorded at most about once a day) to power recent-activity features and understand retention. It stays on your record and is never shared.
- Browsing activity. To power community “popular” and “trending” features, we record which catalogue titles you open in the app (the item, and when). This is stored privately on your own record — other users never see your browsing history. Only anonymous aggregate counts — how many people opened a title, never who — are used to rank what’s currently popular. It is not used for advertising and is not sold.
- Push token (if you enable notifications). If you turn on push notifications we store a device push token — an identifier for your device, issued by Apple and routed via Expo — so we can deliver the alerts you’ve enabled. See the Expo entry in section 5.
c) Information from connected services
- Plex (optional). If you connect Plex, you authorise Quadrate through Plex’s own sign-in flow. We handle a Plex access token so the app can read your own Plex library (titles, editions, watched history). We don’t receive your Plex password, and you can disconnect at any time.
- File imports (optional). If you import your own Letterboxd, Goodreads, IMDb, Spotify or Plex export, we process the contents of that file (your own data) to create the corresponding logs in your account.
3. Public vs private — what others can see
- Public by default: your profile (username, display name, avatar, favourites) and your activity — logs, ratings, reviews, notes, quotes, tags, lists, watchlists, follows, reactions, comments and your weekly-challenge entries and votes — can be seen by other users and appear in feeds, search and on your profile.
- Private account: if you switch your account to private, your logs and reactions are hidden from everyone except the people who follow you.
- Private lists: any list you mark private is visible only to you and its collaborators.
- Always private to you: your email address, your “owned”/Plex library shelf, your browsing history, your blocked-users list, and the reports you file are not shown to other users.
These rules are enforced at the database level (row-level security), not just in the app’s screens.
4. How we use your information, and our legal bases
Under UK GDPR we must have a “lawful basis” for each use of your data:
| What we do | Lawful basis |
|---|---|
| Create and run your account; show your logs/lists/profile; power the social features you use | Performance of a contract |
| Display your content publicly (when your account/list is public) | Performance of a contract / legitimate interests |
| Keep the service secure, prevent abuse, and operate reporting/blocking/moderation | Legitimate interests; legal obligation where applicable |
| Send essential service emails (sign-up confirmation, password reset) | Performance of a contract |
| Connect Plex / import your files when you choose to | Consent / performance of a contract |
| Respond to your support requests | Legitimate interests |
We do not use your data for advertising, and we do not sell it.
5. Third-party services we use
a) Service providers (process data on our behalf):
- Supabase — our backend platform: it hosts the database, handles authentication, stores your content and runs our server functions, as a data processor under our instructions.
- Expo — delivers push notifications: if you enable them, we send your device push token and the notification text to the Expo push service, which forwards it to Apple’s notification service (APNs). Used only to deliver notifications you’ve turned on.
- RevenueCat — manages the Quadrate Pro subscription. When you use the app we share your Quadrate user identifier with RevenueCat so it can check whether Pro is active on your account; if you subscribe, it also records your subscription status and purchase history. RevenueCat acts as a data processor on our behalf.
- Apple (App Store / in-app purchase) — processes the subscription payment itself. We never receive or store your card or full payment details; Apple handles billing and any refunds and shares only aggregate purchase information with us.
b) Catalogue and content sources (we fetch information from them): when you search for or open a title, we send the relevant query or item identifier to these services to retrieve catalogue information. We do not send them your account identity:
- The Movie Database (TMDB) — film and TV information and artwork. This product uses the TMDB API but is not endorsed or certified by TMDB. Some “where to watch” data comes from TMDB’s JustWatch data.
- Apple Music API — music (albums, tracks, artwork, audio previews). Requests carry an app-level Apple Music developer token that identifies Quadrate (not you) to Apple. Apple Music is a trademark of Apple Inc.
- ISBNdb and Open Library — book details and cover images.
- GIPHY — only if you open the GIF picker to attach a GIF to a review: we send your search term (not your account identity) to GIPHY to fetch matching GIFs.
- YouTube — only if you open a trailer: it plays in an embedded YouTube player, so YouTube (Google) receives the standard information any video load involves (such as your IP address). We do not send it your account identity.
- Plex — only if you connect it (see section 2c).
Each of these services has its own privacy practices, which apply when your device or our server contacts them.
6. Sharing and disclosure
We do not sell your personal data. We only share it: with other users (per the public/private rules in section 3); with our service providers (section 5a), under contract and only to run Quadrate; if required by law, or to protect the rights, safety and security of our users, the public or Quadrate; and in connection with a transfer of the app (e.g. if Quadrate is sold or merged), in which case we’ll let you know.
7. International transfers
Our providers may process data on servers outside the UK. Where personal data is transferred outside the UK, we rely on appropriate safeguards recognised under UK law (for example the UK International Data Transfer Agreement / Addendum, or transfers to countries with UK “adequacy” status) so your data keeps an equivalent level of protection.
8. How long we keep your data
- We keep your account and content for as long as your account exists.
- When you delete your account, we permanently delete your account and the content tied to it from our live database. Deletion is immediate and cascades across your data.
- Residual copies may persist briefly in routine encrypted backups before they expire, and we may retain limited records where we’re legally required to (for example, to evidence that we acted on an abuse report).
- You can also export a copy of your data at any time.
9. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict or object to processing of your data, to data portability, and to withdraw consent where we relied on it. To exercise any of these, contact us at mailliamapp@gmail.com. We’ll respond within the time UK law allows (normally one month). You can also complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk — though we’d appreciate the chance to help first.
10. Security
We protect your data with measures including encrypted connections (HTTPS/TLS), hashed passwords handled by our authentication provider, and database-level access controls (row-level security) that enforce who can read and write each piece of data. No system is perfectly secure, but we take reasonable steps to keep your information safe.
11. Children
Quadrate is intended for users aged 13 and over and is not directed at children under 13. The catalogue can surface mature titles. If you believe a child under 13 has created an account, contact us and we will remove it.
12. Changes to this policy
We may update this policy as Quadrate evolves. When we make a material change we’ll update the date at the top and, where appropriate, notify you in the app. Continuing to use Quadrate after a change means you accept the updated policy.
13. Contact us
Questions or requests about your privacy? Email mailliamapp@gmail.com.
Data controller: Liam Darrington, United Kingdom.