Privacy

Privacy Policy

Effective May 10, 2026

Not legal advice. This is a starting-point document for an indie horror catalog. Have a lawyer review before relying on it.

watchdarkly (“we”, “us”) operates a horror motion-picture catalog at watchdarkly.com. This policy explains what data we collect, why we collect it, and the choices you have.

What we collect

Account data

Authentication is handled by Clerk. When you create an account we receive your email address, a Clerk-issued user ID, and any profile info you choose to add. We do not store passwords — Clerk handles that. See Clerk's privacy policy for details.

Activity you create

  • Ratings and review text you submit on films.
  • Helpful / unhelpful votes you cast on other reviews.
  • Films you add to your watchlist or favorites, and your favorites ordering.
  • Films you submit for catalog inclusion.

Usage signals

  • Anonymous page-view events (which film pages you visit) used only to compute catalog-wide popularity. Not joined to your account for advertising.
  • Standard request logs (IP address, user agent, timestamp) retained for abuse-prevention and rate-limiting. These rotate out of our logs within 30 days.

What we do not collect

  • We do not run third-party advertising trackers.
  • We do not sell your data.
  • We do not collect precise location data, biometric identifiers, or contact lists.

How we use it

  • To operate the service: show your ratings, favorites, and watchlist back to you.
  • To compute personalized recommendations. We build a 4-dimensional taste vector from your ratings and compare it against unrated films. The computation stays on our servers; we never expose another user's ratings to you.
  • To rank reviews using a Bayesian helpfulness score (no profile data feeds this).
  • To prevent abuse via per-account and per-IP rate limiting.
  • To send transactional email (account changes, important service notices) via Resend. We do not send marketing email.

Who we share it with

We share data only with the subprocessors required to run the service:

  • Clerk — authentication and account management.
  • Vercel — frontend hosting and edge delivery.
  • Railway — backend and PostgreSQL hosting.
  • Resend — transactional email delivery.
  • Sentry — error reporting (request URL, stack trace, user ID).

Film metadata and poster art come from TMDB. Visiting watchdarkly does not send your personal data to TMDB; we fetch on the server and your browser only loads poster images from TMDB's CDN.

Your choices

Access & correction

You can edit your ratings, reviews, watchlist, and favorites from your account at any time. Reviews lock for 30 days after submission against score changes; review text remains editable.

Deletion

You may delete your account from the settings page or by emailing support@watchdarkly.com. Deletion removes your profile, ratings, reviews, watchlist, favorites, and vote history. We retain anonymized aggregate data (rating averages, helpfulness counts) so the catalog remains coherent.

GDPR / CCPA

If you are in the EEA, UK, or California, you have additional rights to access, port, correct, or delete the personal data we hold about you. Email support@watchdarkly.com and we will respond within 30 days.

Data retention

  • Active account data: held while your account exists.
  • Request logs: 30 days.
  • Backup snapshots: 30 days.
  • Sentry error data: 90 days.
  • Deleted accounts: purged within 30 days of deletion request.

Children

watchdarkly is not directed to children under 13. We do not knowingly collect data from children under 13. If you believe we have, email support@watchdarkly.com and we will delete the account.

Changes

We may update this policy. Material changes will be announced on the site for at least 14 days before they take effect.

Contact

Questions or requests: support@watchdarkly.com.