Privacy Policy

Effective date: September 3, 2026.

PopSesh answers one question — what to watch tonight — and is built so that it needs to know as little about you as possible. This page describes the whole of what PopSesh collects, in the app and on this website, in plain words.

Without an account, no profile is kept

PopSesh works without registration, and that is the default. Your taste — likes, ratings, skips, watchlist — is stored on your device. When the app asks our server for recommendations, it sends your recent signals with the request; the server ranks a response and forgets who asked. While you are not signed in, we keep no taste profile of you anywhere. The one thing that does reach us either way is the anonymous usage events described further down, and they are filed under a random identifier rather than under you.

If you sign in, we keep one copy for you

Signing in with Apple exists for exactly one reason: so your taste can follow you to your next phone. From that moment your app uploads a copy of its saved state to your account. That copy is everything the app remembers on the phone, which is:

We store all of it as one opaque record attached to your account and do not read inside it; the ranking still happens from what the app sends with each request.

The account itself is the second thing we keep, and it is what Apple hands us when you agree to share it: an email address and a name. The address is what the account is known by here, and the only way we could write to you about it — if you chose “Hide My Email”, what we hold is Apple’s relay address and not yours. Neither is used for marketing, and neither is shown to anyone else.

Deleting your account in Settings deletes the account and that copy of your taste together. Signing out leaves both untouched on the server and leaves your taste on the phone.

Anonymous usage analytics

To understand whether recommendations are getting better, the app reports product events — a swipe happened, a Match session found its film — under a random identifier created on your device. It is not your name, email, phone number, or advertising ID, and we cannot connect it to you. You can turn this off in Settings → “Share anonymous usage”, and the app keeps working exactly the same.

How long we keep them. An event is deleted 12 months after it reaches us. This happens on its own, on a schedule the server keeps — there is nothing to ask for and nothing for us to remember to do. Twelve months is what the only two questions we ask of these events need: whether recommendations got better after we changed how they are ranked, and how many evenings end in a decision. Both are read over a window, and the longest window either one wants is the same season a year earlier. Anything older describes a version of the app that no longer exists.

Those events are filed under that identifier and nothing beside it — no account, no name, no address — which is what keeps them anonymous. It also means we cannot find your rows from an email address, so turning the switch off is the reliable way to stop them; nothing already sent points back to you.

What we offered you, and what you said back. Beside those events the server keeps a record of the cards it dealt and the verdict you gave each one, together with the figures the ranking was made of. It is what lets us tell a recommendation that worked from one that got lucky. That record is filed under a one-time number for the deck — not for you, not for your device, not for an account: there is no such column in it, and nothing in a row that could be traced back to a person. After 30 days even the deck number is removed, so what is left describes single cards and no longer describes an evening; the rows themselves go after 12 months, like the events. The same switch stops it: Settings → “Share anonymous usage”, off.

Match sessions

A Match session is two devices and a short code. Sessions live in server memory for at most a day and then disappear; what you swiped in a session is never shown to your partner and never written into your taste. The film you both said yes to is remembered by your devices — and, if you are signed in, inside the account copy described above.

Notifications

Push exists here for one thing: a Match session already under way — your partner has joined, or the two of you have landed on the same film. The app asks permission at the moment a session starts, never at launch, and there are no marketing, promotional or reminder notifications.

To send one we have to store where to send it. The address Apple issues to your phone — the device token — sits in a row of three things: the token, the same random identifier the analytics events use, and when it was last refreshed. No account, no name, no session beside it. The row goes away when Apple tells us the token is dead, which is what happens when the app is deleted or reinstalled, and in any case after 90 days in which the app has not registered it again. Turning notifications off for PopSesh in iOS Settings removes it too: the next time you open the app it sees the switch is off and takes the row down.

The founders list

Separately from the app, our website has one page with a form on it: popsesh.com/founders. If you fill it in, we store your email address and the date you left it, and nothing else. There is no name beside it, no device, no account, and no link to anything you have done in the app: it is a list of addresses and nothing more.

What it is for. One message, sent once, on the day PopSesh reaches the App Store, containing a code for a free year of PopSesh Plus. It is not a newsletter, and no second message will come from it. We ask for it on the basis of your consent, which is the tick box on that page, and you can withdraw it at any time.

How long. The address is deleted as soon as the codes are sent, and in any case 12 months after you leave it, on the same kind of schedule the server keeps for everything else here. Write to support@popsesh.com and we will remove it sooner, on the day you ask. Encrypted backups of our database are kept for up to 30 days, so a deleted address can survive in those until they age out; they are never read except to restore the server.

The Android waiting list

There is a second form on this website, and it is not ours. A Match guest opening an invitation on an Android phone is offered “Save me a seat”, which opens a form hosted by Tally — a third party, under their privacy policy and not this one. What you type there reaches them first. The form asks for an email address and nothing else, and the address is the only thing we take out of it: it is a list of people to write to once, if and when PopSesh runs on Android. We read the answers in Tally and do not copy them anywhere else. To be taken off it, write to support@popsesh.com and we will remove you on the day you ask.

What we never do

Where the film data comes from

Film and series information is supplied by TMDB. This product uses the TMDB API but is not endorsed or certified by TMDB. Streaming availability data comes from JustWatch via TMDB.

Your choices

“Reset taste data” in Settings erases everything the app knows about your taste. “Delete account” removes your account and the copy of that state we hold for it. Deleting the app removes its data from your phone, with one deliberate exception: the random analytics identifier is kept in the system keychain, which outlives the app, so that a reinstall is not counted as a new person. That one string is the only thing that survives a delete-and-reinstall — your taste does not.

Your rights

The GDPR gives people in the EU and the UK a set of rights over their data. We answer these requests from anybody who writes in, wherever they are.

The taste on your device needs no request from anyone: it never left the phone, and deleting the app deletes it. For everything above, write to support@popsesh.com.

Contact

Questions about this policy: support@popsesh.com.