Premiere
Privacy Policy
Last updated: August 2, 2026
The short version
Premiere is a local-first app, and it stays that way whether or not you make an account. Your film library, watchlist, swipes, ratings, notes, and watch history live in a database on your device. There are no ads and no tracking, and we never sell or share your data with advertisers. We count anonymous usage — how often features are used, never what you watched — described below.
Two things are optional, and both are off until you choose them. Sharing a stack puts that stack’s films on our service so the people you invite can see them. Making a profile — signing in with Apple and claiming an @name — publishes your watch history and star ratings so people you approve can see them. Both are described in full below.
Your watch notes are never published, ever. Not to a profile, not to a shared stack, not to us. They are the one thing in Premiere with no way out of your phone, and that is deliberate: there is no column for them on our servers to store them in.
What stays on your device
Everything you do in the app: the films you import, swipe, save, rate, review, and watch, plus your settings. Deleting the app deletes this data. You can also wipe it yourself at any time in the app (Me → Start over).
If you never make a profile, this is all of it — your ratings, watch history, watched marks and notes never leave your device, and sharing a stack shares its films, not your viewing life. If you do make a profile, your history and ratings are published as described below, and your notes still never leave.
Sharing stacks (optional)
Sharing is off until you use it. If you never share or join a stack and never make a profile, Premiere stores nothing about you on any server. When you do share, here is exactly what our sharing service stores:
•
An anonymous identity. The first time you share or join, the app creates a random anonymous identifier for your install — no email, no password, no phone number, no sign-up. It exists so the service can tell stack members apart; the app never sends your name, contacts, or device identifiers alongside it.
•
Your display name. The name you type when sharing or joining (e.g. “Anna”). It can be anything. If you have no profile it is visible only to people who are on a stack with you; if you have one, it is shown beside your @name in search.
•
The shared stack itself. The stack’s name and its films (film titles and poster references), plus which member added each film and when members joined. Everyone on the stack sees this — that is what sharing means.
•
Invite codes. A stack is joined with its invite code (shown as text and QR). Anyone you give the code to can join the stack, so share it like you’d share the stack itself.
This data is stored with Supabase, hosted in the European Union (like any hosting provider, Supabase may process standard technical data such as IP addresses transiently to operate the service). Leaving a shared stack (“Remove for me”) removes your membership; when the last member leaves a stack, its data is deleted from the service entirely. Films you added to a shared stack stay on it for the remaining members, so their stack isn’t hollowed out, and add-attribution persists until you ask us to detach it. Your display name and anonymous identity also remain stored until wiped. For a complete wipe of your sharing data (display name, memberships, and your name off every film you added), email us — address below — and we’ll do it.
Profiles (optional)
You never need an account. Everything above works without one. A profile exists only so friends can find you and see what you have been watching — if you want that.
•
Signing in. Premiere offers Sign in with Apple and nothing else. Apple gives us an identifier for you and, usually, a private relay email address. We never read, display, or send anything to that address; it is stored by our authentication provider because the sign-in standard includes it.
•
Your @name, display name and avatar. Public in the sense that anyone can find them by searching your @name. Avatars are a fixed set we ship with the app — there are no photo uploads.
•
Your watch history and star ratings. Once you have a profile, the films you have watched — title, poster, the date, and your ★ if you gave one — are published to our service so approved people can see them. Your written notes are not, and cannot be.
•
Stacks you choose to show. Off for every stack until you switch it on, one stack at a time.
•
Who you follow, and who follows you. Plus any follow requests waiting on an answer.
•
Accounts you block, and reports you send. A block is visible only to you — the person blocked is never told. A report is visible only to us. If you delete your account, reports you sent are kept so a record of the complaint survives, but your identity is removed from them. Reports about you are deleted along with the rest of your account.
Who can see your profile is your choice. New accounts start private: people can find your @name and see your avatar and follower counts, and nothing else until you approve them. Making your profile public lets anyone who finds you see your films and the stacks you chose to show. Switching back to private hides it again straight away from everyone except the people you approved yourself — anyone who followed you while you were public goes back to being a request you can accept or ignore. Nothing is deleted by the switch.
Deleting your account is in the app (Me → Delete account). It removes your profile, your published history and stacks, your follows and your blocks, and it asks Apple to revoke Premiere’s access to your Apple ID. Your films, watchlist and history stay on your phone and the app keeps working — deleting the account is not deleting the app.
What leaves your device
•
Film data requests. When you search for a film, import a list, or the app fetches more films for a filter, the app requests film metadata from The Movie Database (TMDB) through a server we operate. These requests contain the search text or film identifiers needed to answer them — never your identity, because the app has no concept of one. Our server forwards the request to TMDB and returns the result; our own application logs record only aggregate counts (e.g. rejected requests), not who asked for what. Our hosting provider (Expo EAS Hosting, running on Cloudflare infrastructure) may process standard technical data such as IP addresses transiently to operate the service. Poster images load directly from TMDB’s image servers.
•
Crash reports. If the app crashes or hits an internal error, an anonymized diagnostic report (stack trace, device model, OS and app version) is sent to Sentry, hosted in the European Union. Reports are configured to exclude personal data and are used for one thing: fixing bugs.
•
Anonymous usage counts. The app reports which features are used — that a swipe happened, that a standoff finished, that a stack was created — to TelemetryDeck, a privacy-focused analytics service. No film titles, stack names, searches, notes, display names or ratings are ever included; the events carry nothing but a fixed name and, at most, a number or a fixed word like “left”. Each install is counted using a random identifier created on your device, unrelated to your sharing identity, and hashed before it is sent — so we can count how many people use a feature, and cannot tell who they are or connect it to anything else. It exists to answer questions like “does anyone use the Daily Reel?”, and for nothing else.
•
App updates. On launch the app checks our update service (Expo EAS Update) for a newer version of itself. The request carries standard technical metadata (app and update version, platform) — no personal identity.
•
Outbound links. If you open a trailer (YouTube) or a “where to watch” link (JustWatch), you leave the app, and those services’ own privacy policies apply from that point.
Third-party services
•
TMDB — film metadata and images. This product uses the TMDB API but is not endorsed or certified by TMDB. Streaming availability data is provided by JustWatch via TMDB.
•
Sentry — anonymized crash reporting (EU region).
•
TelemetryDeck — anonymous usage counts, as described above. It is built so that it cannot identify individual people.
•
Expo (EAS) — app hosting infrastructure and over-the-air app updates.
•
Supabase — the sharing and profiles service (EU region). Stores the sharing data described above if you share or join a stack, and the profile data described above if you create a profile. It also handles Sign in with Apple, which is why the private relay address Apple gives us is stored there. Standard technical data (such as IP addresses) may be processed transiently to operate the service.
What we don't do
•
We don’t sell your data or share it with anyone, and we store nothing about you beyond what the sharing and profile sections above describe.
•
We don’t profile you or build a taste model on a server.
•
We don’t use advertising SDKs, and the analytics we do use never receive your content — no titles, searches, notes or ratings — and cannot identify you.
•
We don’t require an account. Premiere works fully without one: the swipe deck, your watchlist, your history and your stats are all on your phone. Signing in is something you do only if you want a profile, and stack sharing still runs on an anonymous identity and a display name you choose.
•
We don’t upload your watch history unless you have a profile. Until you claim an @name, what you watch never leaves your phone.
Children
Premiere is not directed at children under 13. Without sharing or a profile, the app collects nothing about you at all. Stack sharing asks only for a display name. A profile adds an @name, an avatar from the set we ship, and — through Sign in with Apple — an identifier and usually a private relay email address, which we never read or use. We never ask for a real name, an age, a phone number, or a photo.
Changes
If this policy materially changes (as it did when stack sharing was added), we update this page and the date above before the change ships.
Contact
Questions about privacy: premiere.movienights@gmail.com