Privacy Policy
Last updated: 6 October 2026
moviio is a movie and TV recommendation app for iPhone and Android. This page explains what the app does with your data. The short version: there are no accounts, no ads, no tracking, and nothing is sold to anyone.
No account, almost no personal details
moviio does not ask for your e‑mail address, phone number or any identity documents. On first launch the app receives a random access token from our server; it identifies your device's profile and nothing else. During the optional welcome screen the app may ask for a display name, your year of birth and your gender — all three are optional and can be skipped. The name is used only when you share your taste with a friend (see below). The year of birth and gender, if provided, are stored with your profile and used solely to tune recommendations (for example, favouring films of your generation) and to keep age‑restricted content away from minors. They are never shown to anyone, never used for advertising, and you can ask us to delete them at any time.
On Android, the app also sends the Android ID — an identifier the system issues to this app on this device — when it registers. Our server stores only a one‑way hash of it and uses it for one purpose: to give you back your profile if you reinstall the app on the same phone, instead of creating a new empty one. It is not used for advertising or tracking and is not shared with anyone.
What the app stores on our server
- Your marks — titles you mark as seen, seen‑but‑not‑for‑me or planned, your star ratings, and the wishes you type (for example “a horror with some sci‑fi”). Recommendations are built from them, and they stay in sync if you reinstall the app.
- Imported lists — if you upload an export from Letterboxd or IMDb, or any list of films, we keep only the titles we matched to our catalogue as marks. The uploaded file itself is not stored. A free‑form list is parsed by an AI model (Anthropic) to extract titles; the model does not receive any identifier of you.
- Your recommendation feeds — the lists of titles generated for you, and a daily count of how many were served, kept so the app opens instantly and the daily limits work.
- Taste sharing — if you choose “Share my taste”, we create a short code linked to your profile and the display name you typed. Anyone who enters the code becomes a follower: they will occasionally see in their stack a title you have watched, labelled with your name and your rating. Your marks are never shown as a list. You can revoke the code at any time; followers can unfollow at any time. We store who follows whom and which titles were shown.
- Welcome details — the display name, year of birth and gender you optionally entered on the welcome screen (any of them can be left blank).
- Where I watch — the streaming services you starred in the app, so they show first and survive a reinstall. Only the list of services, nothing about your subscriptions or accounts there.
- App settings — kept only on your device.
None of this is linked to your e‑mail or any real‑world identity, because the app never collects one.
How recommendations are made
To pick titles and write the “why for you” note, our server sends an AI model (Anthropic API) a summary of your taste: favourite genres and directors, a few titles with your ratings, and the wish you typed. It never sends your name, token, device identifier or your full history. The same applies to the “facts” shown in reading mode: they are extracted by a model from the public Wikipedia article about the film and cached per title, not per person.
Third‑party services
- TMDB — posters, synopses, cast, trailers and “where to watch” data (powered by JustWatch) are loaded from The Movie Database. When the app fetches an image, TMDB's servers see your IP address, as with any website. This product uses the TMDB API but is not endorsed or certified by TMDB.
- YouTube — trailers play through YouTube's embedded player (privacy‑enhanced mode). While a trailer plays, Google's own privacy policy applies to that request.
- Wikipedia — film facts come from Wikipedia and are fetched by our server, not your device. Each fact links to its source.
- Home media servers — if you add your own Plex or Jellyfin server or your own player in the app, its address and access token are stored only on your phone, and the app talks to it directly. They never reach our server.
- My TV box — if you install the moviio receiver on an Android TV box and pair it by entering the code shown on the TV, our server keeps a record of that box: a random device token, the model name the box reports (for example “MiTV‑AFMU0”), its Android TV version, which profile it is paired with and when it was last online. When you tap “Open on the TV box”, the server passes the film’s title to the box (if the box doesn’t pick it up within two minutes, it isn’t sent) and keeps a log of the films sent to that box. Unpairing deletes the box record and this log; a box that is never paired is deleted after a day.
The app contains no advertising, no analytics SDKs and no third‑party trackers.
Where the data lives
Our server is located in the European Union. Data is transmitted over encrypted connections. Backups are kept for 14 days.
Deleting your data
Deleting the app removes everything stored on your device, including your access token; a reinstall starts a fresh, empty profile. To have your marks, imports and sharing links removed from our server, write to hello@alloroman.com and we will delete them.
Children
moviio is not directed at children under 13 and does not knowingly collect information from them.
Changes
If this policy changes, the new version will be published on this page with an updated date.