Privacy Policy
Effective date: March 12, 2026 · Last updated: March 12, 2026
SyncCouch ("we," "us," or "our") operates the website at synccouch.com, the SyncCouch Chrome extension, and the SyncCouch mobile application (collectively, the "Service"). This Privacy Policy explains what data we collect, why we collect it, and your rights regarding that data.
1. Data We Collect
1.1 Information You Provide
- Email address — collected when you join the waitlist. Stored alongside the timestamp of signup and any UTM campaign parameters present in the URL.
- Google profile data — when you sign in with Google, we receive your name, email address, and profile picture from Google OAuth. We do not receive or store your Google password.
- Phone number (mobile app) — if you sign in via Phone OTP on the mobile app, we collect your phone number for authentication purposes only.
- Display name & avatar — set by you during profile creation. Visible to your watch-room partner.
1.2 Information Collected Automatically
- Usage analytics — page views, button clicks, and feature usage events collected via PostHog (or Google Analytics). These are anonymized and used solely to improve the product.
- Error reports — crash and error data collected via Sentry to diagnose bugs. These may include device type, browser version, and stack traces. No personal content is included.
2. Data We Do NOT Collect
- Video or audio streams — SyncCouch does not access, record, or store any video or audio content from streaming platforms. Each user streams directly from their own subscription.
- Chat messages — text chat messages are ephemeral and exist only for the duration of a watch room session. They are not persisted to any database after the room ends.
- Voice and video calls — voice and video calls are peer-to-peer (WebRTC) or relayed via Agora. We do not record or store call content.
- Browsing history — the Chrome extension does not track which websites you visit outside of supported streaming platforms.
3. How We Use Your Data
- To create and manage your account
- To send you a launch notification email if you joined the waitlist
- To display your profile to your watch-room partner
- To generate AI-powered movie recommendations based on your mood input
- To improve the Service through aggregated, anonymized analytics
- To enforce our Terms of Service and moderate content
We do not sell, rent, or share your personal data with advertisers.
4. Data Storage and Security
Your data is stored in Supabase (hosted on AWS), which provides PostgreSQL database hosting with row-level security (RLS) policies. All data is encrypted in transit (TLS) and at rest.
Temporary room state (active rooms, rate limits, recommendation cache) is stored in Upstash Redis with automatic expiration (6-hour TTL for rooms). This data is not personally identifiable.
5. Third-Party Services
We use the following third-party services, each with their own privacy policies:
- Supabase — authentication, database, and file storage
- Google OAuth — sign-in authentication
- PostHog / Google Analytics — anonymized usage analytics
- Agora — video and voice chat relay (used only when peer-to-peer connection fails)
- Sentry — error monitoring and crash reporting
- TMDB — movie and show metadata for recommendations (no user data is sent to TMDB)
- Anthropic (Claude) — AI-powered recommendation generation (mood prompts are sent; no personal identifiers are included)
- Perspective API (Google) — chat message moderation for safety
6. Cookies
We use essential cookies to maintain your authentication session (httpOnly, secure, SameSite=Lax). We may also use analytics cookies via PostHog or Google Analytics. No advertising or tracking cookies are used.
7. Your Rights
You have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — update or correct inaccurate data via your profile settings
- Deletion — request deletion of your account and all associated data
- Data portability — request your data in a machine-readable format
To exercise any of these rights, email us at privacy@synccouch.com. We will respond within 30 days.
8. Children's Privacy
SyncCouch is not intended for children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us at privacy@synccouch.com and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via the email associated with your account or by posting a notice on the Service. Your continued use of the Service after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: