Privacy Policy

Last updated: August 7, 2026 · Effective: August 7, 2026

The short version.

The rest of this page is the detail behind those points. It's long because it's specific.

1. Who we are

Vued is an iPhone app for ranking films and television and sharing those rankings with people you follow. This policy covers the Vued app and vuedapp.com.

In this policy, "Vued", "we", and "us" mean the operator of the Vued app, contactable at support@vuedapp.com. For data protection purposes we are the controller of the information described here.

2. What you give us

Everything in this section exists because you typed it, tapped it, or chose it. Nothing here is inferred or bought.

Account and sign-in

You can create an account three ways: email and password, Sign in with Apple, or Google.

Your signed-in session is stored in the iOS Keychain on your device, not in ordinary app storage.

Your profile

A username is required. Optionally: a display name, a bio, an avatar, a banner image, your favourite genres from onboarding, your per-notification-type preferences, and whether your profile is private.

Avatars and banners are the only images you upload to us. They're resized and compressed on your device first, then stored in our Supabase storage under a folder keyed to your user id, and served publicly from that URL.

What you watch and what you think of it

CategoryWhat's in it
Rankings Your ranked lists for films and for shows, the position and derived score of each title, and your overall sentiment for it (loved it / it was fine / didn't like it).
Comparisons Every head-to-head answer you give — which title you picked over which. This is how your list is built, so it's kept.
Logs and reviews The date you watched something, your written review, tags, friends you tagged as watch companions, and the film stills you chose to attach.
TV progress Which episodes and seasons you've marked watched, and when. See §5 — this one is private to you.
Lists Your watchlist, favourites, collections (and, for shared collections, their members and invites), and yearly goals.
Reactions Comments, likes on posts and on comments, and the release reminders you set for films, shows, and people.
Social graph Who you follow (users and cast/crew), who follows you, and anyone you block, mute, or whose comments you hide.

A note on "attach stills". The stills you add to a review aren't photos from your library — they're a reference to an image in TMDB's catalogue for that title. We store the reference, not an image, and nothing leaves your photo library.

Imports from other services

Vued can import a Letterboxd data export (a .zip you download from letterboxd.com) or an IMDb ratings export (a .csv). You export the file yourself and hand it to the app; both are parsed on your device. Vued never asks for, receives, or stores credentials for those services, and never connects to them on your behalf.

Reports and support

3. What's collected automatically

WhatDetail
Product analytics Which screens you visit and which features you use, so we know what's working. Events carry opaque identifiers, enums, and counts only — for example a TMDB title id, a sentiment bucket, or "search returned 12 results". We deliberately never send your email, your name, your review text, or your search terms. Events are tied to your user id so we can tell one person's session from another's.
Crash and error reports If the app crashes or hits an error, we receive a diagnostic report: device model, OS version, stack trace, and our own breadcrumb trail of recent screens and actions. That trail is redacted before it's recorded — session tokens, API keys, and email addresses are stripped on device.
Screen replay on errors When an error or a bug report fires, Sentry attaches a short masked replay of the moments leading up to it. Masked means exactly that: all text and all images are blocked out — what we get is layout shapes and where you tapped. We don't record random sessions, only ones with an error or a report attached.
Push token If you allow notifications, we store your device's Apple Push Notification token so we can deliver them. Turn notifications off, per type or entirely, in Settings.
Device attestation Vued can ask Apple's App Attest to vouch that requests come from a genuine, unmodified copy of the app, which is how we keep our backend from being abused by scripts. The token contains no personal information and identifies the app instance, not you.
Your region To show the right release dates and what's in cinemas near you, we read the country code from your device's Settings — for example US or GB. Nothing finer than a country, and no location permission is involved.
Server logs Our backend and hosting providers log requests, including IP address and timestamp, as any web service does — for security, abuse prevention, and rate limiting.

4. What stays on your device

AI review drafting. On iPhones that support Apple Intelligence, Vued can draft a review for you using Apple's on-device Foundation Models. That runs entirely on your device — there is no network call, so your prompt and the generated draft are never sent to us or to anyone else. On other devices the feature simply isn't offered.

Recommendations. The ranking maths and the "what to review next" prioritisation run locally against data already on your device.

Your photo library. Vued has no photo-library permission and never asks for one. Picking an avatar, banner, or bug report attachment uses Apple's system picker, which runs outside the app — Vued only ever receives the single image you chose.

The app switcher. Vued covers its own interface as soon as it leaves the foreground, so the iOS app-switcher thumbnail shows a blank background instead of what you were ranking or reading.

5. What others can see

Vued is social by design, so a good deal of what you create is visible to other signed-in users. Here's the line, precisely.

Visible to othersNot visible to others
Username, display name, avatar, banner, bio Your email address
Your ranked lists, scores, and sentiments Your individual head-to-head comparison answers
Reviews, tags, watch dates, attached stills, comments, likes Your episode-by-episode TV watch history
Your watchlist and favourites Collections you've left private (new ones are private by default)
Who you follow and who follows you Who you've blocked or muted
Collections you've made public, and shared collections you're a member of Reports you file, and your bug reports

Controls you have

Moderation

When a post, review, or collection is reported by three or more people it's automatically hidden pending review. We review reports and can remove content or accounts under our Terms of Service. We deliberately do not auto-hide entire profiles on report count — that's a decision a person makes, not a threshold.

6. Service providers

These are every third party that touches your data, what they get, and why. They process it on our instructions; none of them are permitted to use it for their own purposes.

ProviderWhat they receiveWhy
Supabase Everything in §2 and §3 that we store: your account, profile, content, social graph, avatar and banner images, and server logs. Our database, authentication, file storage, and backend functions.
TMDB Search terms and title ids — but from our servers, not your device. TMDB doesn't see your IP address or who you are. Film and TV titles, artwork, cast, and metadata.
YouTube / Google Only when you press play on a trailer. The trailer plays in an embedded YouTube player, and at that point YouTube receives your IP address and standard playback telemetry, and may set cookies inside that player. Don't play a trailer and YouTube receives nothing. Trailer playback.
PostHog The analytics events in §3, tied to your user id. No emails, names, review text, or search terms. Product analytics.
Sentry Crash and error diagnostics, our redacted breadcrumb trail, masked screen replays, and your bug reports with any attachments you added. Crash reporting and user-submitted bug reports.
Apple Your push token and notification payloads (APNs); Sign in with Apple credentials if you use it; App Attest results. Notifications, sign-in, and app integrity.
Google Identity Only if you choose Google sign-in: the sign-in exchange itself. Authentication.
Cloudflare Standard web request logs for vuedapp.com. Hosting this website.

We may also disclose information if we're legally required to, or where it's necessary to investigate abuse, enforce our Terms, or protect someone's safety. If Vued is ever acquired or merged, information may transfer as part of that — you'd be told before it happened.

7. What we never do

8. Why we're allowed to (legal bases)

If you're in the EEA, the UK, or Switzerland, these are our lawful bases under the GDPR:

9. Children

Vued is not directed to children under 13, and you must be at least 13 to use it (or older, where your country sets a higher minimum age for consent to data processing). We don't knowingly collect information from children under 13. If you believe a child has created an account, email support@vuedapp.com and we'll delete it.

10. International transfers

Our providers operate internationally, so your information may be processed in countries other than your own, including the United States. Where we transfer personal data out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with the provider concerned.

11. How long we keep it

12. Your rights

Depending on where you live you may have the right to access, correct, export, delete, or restrict our use of your personal information, to object to processing based on legitimate interests, and not to be discriminated against for exercising any of it. Most of these you can exercise yourself, immediately, without asking us:

For anything not covered by a switch in the app, email support@vuedapp.com. We'll respond within 30 days. If you're in the EEA or UK and unhappy with our answer, you can complain to your local data protection authority.

13. Security

Access to your data is enforced in the database itself. Every table in Vued has row-level security enabled, with policies tied to the authenticated user id — so "only you can see your comparison history" is a rule the database enforces on every query, not a check the app is trusted to remember. Traffic is encrypted in transit, your session lives in the iOS Keychain, passwords are hashed by our authentication provider, our backend functions that hold paid API keys are rate limited, and requests can be attested with Apple's App Attest.

No system is perfect. If you find a security issue, please email support@vuedapp.com rather than posting it publicly, and we'll work with you on it.

14. Changes to this policy

If we change how Vued handles your information we'll update this page and move the date at the top. For a change that materially affects you, we'll tell you in the app or by email before it takes effect.

15. Contact

Questions, requests, or complaints: support@vuedapp.com.