Privacy Policy
Curator Co. is a place to log what you watch, read, hear, and play, and to read your own taste back. This policy says what we collect, why, who sees it, and what you can do about it. It is written to meet the EU and UK General Data Protection Regulation (GDPR); if you live elsewhere, the same rights are offered to you.
1. Who is responsible
The controller of your personal data is Justin Chuan. For anything in this policy, write to [contact email]. We answer requests within one month.
2. What we collect
Only what the service needs to work:
- Account. Username, email address, a hashed password (we never store the password itself), display name, bio, links you add, and a profile picture if you upload one. When you accepted the Terms.
- What you log. Titles, ratings, dates, reviews, tags, reactions, photos and video links you attach, lists, favorites, collections, likes, comments, votes on questions and content notes, and who you follow.
- Your taste profile. Numbers we compute from your ratings: leans on fourteen dimensions, an archetype, and predictions of how you would rate titles. See section 5.
- Connected services, only if you connect them. Letterboxd (a public RSS feed and, if you upload it, your export), Bluesky (public posts), Spotify (recently played albums, through Spotify's consent screen), Steam (recent playtime, through the official API), Netflix (a CSV you upload). We store what is needed to turn these into suggestions and the tokens or identifiers needed to check again.
- Technical. A session cookie, request logs kept by our hosting provider for a short period (address, time, page), and counts of how many judgments we asked our AI provider for on your behalf. We do not run advertising or analytics trackers.
3. Why, and on what legal basis
- To run the service you signed up for (contract, Art. 6(1)(b)): your account, logs, lists, profile, predictions, and the social features you use.
- Connected services (consent, Art. 6(1)(a)): each one is off until you turn it on, and you can disconnect at any time from Import and sources. Disconnecting stops the reading and deletes the tokens.
- Keeping the service safe and working (legitimate interest, Art. 6(1)(f)): rate limits, abuse prevention, error logs, and holding back comments our moderation reads as hostile.
- Email (contract): only password resets. We send no marketing.
4. Who can see what
Your profile, public logs, reviews, lists, collections, favorites, and follows are visible to anyone, including people who are not signed in, and can be linked to. A log marked private is visible only to you, counts toward your own profile, and is left out of every aggregate other people see. Private collections are visible only to you. Your email address is never shown.
Comments that our moderation reads as hostile are held: only the author and the owner of the page see them.
5. Profiling and automated judgments
The taste profile is profiling in the GDPR sense: software builds a picture of your preferences from your ratings and reviews and uses it to predict how you would rate things, to pick an archetype, and to choose what to show you. No decision with legal or similarly significant effect is made this way; it only orders and describes entertainment. Predictions are estimates, are shown with their probability, and you can see the evidence behind them on each title page.
To make these judgments we send excerpts of your data, such as a summary of your leans, the titles you rated, and the text of a review you are writing, to our AI provider (TypeSafe, see section 6). The provider processes them on our instructions and does not use them to train models. Deleting your account deletes the profile.
6. Processors and third parties
We use these companies to run the service. Each handles data only under contract and on our instructions:
- Neon (database hosting) and Netlify (web hosting and request logs).
- TypeSafe (the AI judgments described in section 5).
- Resend (password reset email), when configured.
- Catalogue data comes from TMDB, Open Library, MusicBrainz, and IGDB. When you search or open a title we request that title from them; your account details are not sent. Title images are loaded from their servers, which see your browser's address as any image host would.
- Spotify, Steam, Bluesky, and Letterboxd, only for the connections you choose to make, under their own privacy policies.
Some of these providers operate in the United States. Transfers rely on the providers' standard contractual clauses or an adequacy decision. We do not sell personal data.
7. Cookies and local storage
We set one cookie: a session identifier that keeps you signed in for thirty days, marked HttpOnly and Secure. During a Spotify connection a second, ten-minute cookie protects the sign-in handshake. Both are strictly necessary, so no consent banner is shown. The dark or light choice is kept in your browser's local storage and never sent to us. There are no advertising, analytics, or third-party cookies.
8. How long we keep things
- Account and everything you logged: until you delete your account, then removed at once. Backups roll off within thirty days.
- Sessions: thirty days, or until you sign out. Changing or resetting your password ends every other session.
- Password reset links: one hour, single use.
- Connected-service tokens: until you disconnect.
- Hosting request logs: a short rolling window set by the host, typically under thirty days.
9. Your rights and how to use them
You can, at any time and free of charge:
- See and take your data. Download your data in Settings gives you a machine-readable file of everything tied to your account (access and portability, Art. 15 and 20).
- Correct it. Edit any log, review, list, or profile field yourself; ask us for anything you cannot reach (Art. 16).
- Delete it. Delete account in Settings removes the account and everything tied to it, immediately (Art. 17).
- Object or restrict. Disconnect any source, mark logs private, or write to us to object to a processing based on legitimate interest (Art. 18 and 21).
- Complain. You may lodge a complaint with your data protection authority. We would rather hear from you first at [contact email].
10. Children
Curator Co. is for people aged 16 and over. We do not knowingly keep an account for anyone younger; tell us and we will remove it.
11. Security
Passwords are hashed with bcrypt. Connections are encrypted in transit. Sessions are random tokens in HttpOnly cookies. Sign-in attempts are rate limited. Uploaded images are re-encoded before storage. If a breach ever affects your data, we will tell you and the authority as the law requires.
12. Changes
When this policy changes in a way that matters, we say so on the site before it takes effect and update the date above. Continued use after that date means the new version applies.