Skip to main content

Privacy Policy

Effective date: March 12, 2026 · Last updated: October 6, 2026

SyncCouch ("we," "us," or "our") operates the website at synccouch.com, the SyncCouch Chrome extension, and the SyncCouch mobile application (collectively, the "Service"). This Privacy Policy explains what data we collect, why we collect it, and your rights regarding that data.

1. Data We Collect

1.1 Information You Provide

  • Google profile data — when you sign in with Google, we receive your name, email address, and profile picture from Google OAuth. We do not receive or store your Google password.
  • Phone number (mobile app) — if you sign in via Phone OTP on the mobile app, we collect your phone number for authentication purposes only.
  • Display name & avatar — set by you during profile creation. Visible to your watch-room partner.

1.2 Information Collected Automatically

  • Product usage statistics — only if you say yes. The extension (version 0.2.0 and later) asks you once, and nothing is recorded until you agree; you can turn it off at any time in the extension's popup. Earlier versions are never counted, and a room is counted only if everyone in it agreed. To learn which streaming sites and features people use, our server then records a few pseudonymous events about your watch rooms and sends them to PostHog. They are tied to a random code derived from your account with a secret key, not to your name, email or account ID, and we cannot read them back to a person without that key. We record: when a room is created and which streaming site it is for (YouTube, Netflix, Crunchyroll, Prime Video or JioHotstar); when someone joins a room and their country (your IP address is used once to look up the country and is not stored by PostHog); and, when a room ends, how many minutes were watched on each site, how long the room was open, whether a voice or video call was used, how many minutes of voice-only and video calls, and how many chat messages, reactions, speed changes and control locks happened. From the extension we also count how many times you open the sidebar or the popup, copy an invite link, and click the rename, control-lock and reaction buttons. A chat message is counted, never recorded. We never record what you type, names, emails, video titles, video links, which video you watch, or call audio or video. Usage events are kept for 12 months.
  • Error reports — crash and error data collected via Sentry to diagnose bugs. These may include device type, browser version, and stack traces. No personal content is included.

2. Data We Do NOT Collect

  • Video or audio streams — SyncCouch does not access, record, or store any video or audio content from streaming platforms. Each user streams directly from their own subscription.
  • Chat messages — text chat is temporary. The most recent 50 messages are kept only while your watch room exists, so a partner who joins or reconnects can see the recent conversation. They are deleted when the room ends and are never written to our permanent database. A room ends when the last person leaves, or 24 hours after you both disconnect; it is never kept longer than 7 days.
  • Voice and video calls — voice and video calls are peer-to-peer (WebRTC). When a direct connection isn't possible, the encrypted call traffic is relayed through a TURN server run by Cloudflare (or Metered, as a backup); the relay cannot see call content. We do not record or store call content.
  • Browsing history — the Chrome extension does not track which websites you visit outside of supported streaming platforms.
  • What you say or watch — chat text, display names, video titles, video links and call audio/video are never sent to our analytics.

3. How We Use Your Data

  • To create and manage your account
  • To display your profile to your watch-room partner
  • When AI Picks launches (coming soon), to generate AI-powered movie recommendations based on your mood input
  • To improve the Service through aggregated, pseudonymous analytics
  • To enforce our Terms of Service and review content reported to us

We do not sell, rent, or share your personal data with advertisers.

4. Data Storage and Security

Your data is stored in Supabase (hosted on AWS), which provides PostgreSQL database hosting with row-level security (RLS) policies. All data is encrypted in transit (TLS) and at rest.

Temporary room state (active rooms and rate limits, plus a recommendation cache once AI Picks launches) is stored in Redis (hosted on Railway in the US) with automatic expiration (rooms and their recent chat end 24 hours after the last person disconnects, and 7 days at most). Room state is keyed by a random room ID and is deleted automatically when the room ends.

5. Third-Party Services

We use the following third-party services, each with their own privacy policies:

  • Supabase — authentication, database, and file storage
  • Railway — hosts our server and the temporary room store (Redis), in the US
  • Vercel — hosts this website
  • Google OAuth — sign-in authentication
  • PostHog — usage statistics described in section 1.2, and only if you said yes in the extension. The website sends nothing to PostHog.
  • Cloudflare — relays encrypted call traffic (TURN) when a direct peer-to-peer connection isn't possible
  • Metered — backup call relay (TURN), used only when Cloudflare's relay is unavailable
  • Sentry — error monitoring and crash reporting
  • TMDB — movie and show metadata for AI Picks, once it launches (coming soon); no user data is sent to TMDB
  • Anthropic (Claude) — for AI Picks, once it launches (coming soon): recommendation generation, where mood prompts would be sent with no personal identifiers included
  • Perspective API (Google) — for chat moderation, once it launches (coming soon); chat messages are not sent to it today

6. Cookies

We use essential cookies to maintain your authentication session (httpOnly, secure, SameSite=Lax). The website does not use analytics cookies today. No advertising or tracking cookies are used.

7. Your Rights

You have the right to:

  • Access — request a copy of the personal data we hold about you
  • Correction — update or correct inaccurate data via your profile settings
  • Deletion — request deletion of your account and all associated data
  • Data portability — request your data in a machine-readable format

To exercise any of these rights, email us at privacy@synccouch.com. We will respond within 30 days.

8. Children's Privacy

SyncCouch is not intended for children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us at privacy@synccouch.com and we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you via the email associated with your account or by posting a notice on the Service. Your continued use of the Service after changes constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

privacy@synccouch.com