Privacy Policy
Last updated August 2, 2026
Who we are
ShowReco (“we,” “us”) is operated by [OWNER: legal entity / operator name]. Questions about your privacy? Send us a message.
Account & sign-in
We use Clerk to handle sign-up and sign-in. You can create an account with an email verification code or by continuing with Google. Clerk stores your email address and a unique account id, and manages your login session (via an essential session cookie). The email code flow doesn't use a password at all. If sign-up does ask you for one, it goes to Clerk, who stores it; we never store it ourselves.
Clerk also runs a bot-protection check (a CAPTCHA) during sign-up to keep automated abuse out. That check is provided through Clerk.
What we store, and where
There's no traditional database. Your data lives as private JSON documents in a private Amazon S3 bucket, filed under your Clerk account id. There is no public access, and no other user's account can read it: the only people who can see your data are you, through the app, and the operator (see “Operator access” below). What we keep:
- Your taste profile: the AI-maintained model of your taste: what makes you different from the crowd (your “differentiators”), your lanes, anti-preferences, hard dealbreakers, eliminated genres, and confidence level.
- Profile history: a snapshot of your profile is saved before each time the AI re-distills it, so changes are traceable.
- Your ratings and verdicts: every title you rate, mark not-interested, haven't-seen, or “don't remember,” including the notes you write about why.
- Your queue: the current computed list of what to watch or read next.
- Divergences: the places where your rating disagreed with the mainstream, and the insight you gave when we asked why.
- Your full chat history: your ongoing conversation with ShowReco is retained so the assistant has context next time.
- Snoozes and muted services: titles you've pushed off, and streaming services you've hidden.
- Onboarding progress: your calibration deck state while you're getting set up.
- Billing record: your prepaid month balance, which months you've activated, a record of each purchase (Stripe session id and amount paid), and, for monthly supporters, opaque Stripe customer and payment method identifiers used for auto-renew. No card numbers: those never touch our servers (see Payments).
- Usage counters: per-day, per-feature tallies of AI calls and token counts (and your daily chat message count) so we can meter usage and enforce free-tier limits. These are aggregate counters, not a log of what you said.
- Product and reliability measurements: account-id keyed milestones such as onboarding completion, queue builds, recommendation ratings, shares, purchases, authenticated sessions, and browser performance. When an error occurs, we store a sanitized message, stack trace, route, release, and account id when available. We do not put chat content, taste profiles, request bodies, request headers, email addresses, or full URLs into these records.
- Messages you send us: if you use the contact form, we keep what you wrote along with your name, your account email, whether you support ShowReco, and the page you sent it from, so we can read it and reply. These are kept until the conversation is done with.
Operator access
ShowReco is run by one person, and that person can access stored account data, including your chat history, taste profile, ratings, and notes, through an operator-only admin area tied to the operator's own account. That access exists to run the service: answering your support messages, debugging when something breaks, preventing abuse, and reviewing how well the recommendations work so they can be improved. There is no support team or review staff reading conversations; the only person who can see your data is the same person who answers the contact inbox.
How AI processing works
ShowReco's recommendations and taste analysis are generated by large language models. To do that, we send relevant parts of your data (your ratings, your notes, your taste profile, and your chat messages) to our AI provider. Today that provider is Anthropic (the makers of Claude); the app can also be configured to use OpenAI. They process this data to return recommendations and taste insights; we don't use it to train any model of our own.
AI content disclaimer:recommendations, predicted ratings, and taste analyses are AI-generated and can be wrong. They're suggestions, not facts about you.
Title metadata (and what we don't send)
To show posters, availability, and ratings, we look titles up with the Movie of the Night Streaming Availability API, OMDb (IMDb / Rotten Tomatoes ratings), and Google Books (for books). These lookups send only the title being looked up, never your identity, and never which user is asking. Responses are cached so we don't re-ask for the same title.
Payments
Supporter purchases are handled by Stripe through Stripe Checkout. Your card details go straight to Stripe and never touch our servers. All we receive back is a confirmation (the Stripe session id, the amount, and which pack you bought) plus, for monthly supporters, the opaque identifiers Stripe uses to charge your saved card when a month auto-renews. See the Terms for how months and auto-renew work.
Outbound links & affiliates
Some “where to watch” and book links may earn ShowReco a commission. These outbound links route through a redirect that only allows known provider domains. When you click one, we count it, but only as an aggregate, per-service tally(“X clicks to Netflix this month”). We do not record who clicked, and we put no identifying information into the outbound URL. Commissions never influence what we recommend or how it's ranked. More detail is in the Terms.
Third parties we rely on
These are the services that help run ShowReco:
- Clerk: accounts, sign-in, and bot protection.
- Amazon S3: private storage of your data.
- Vercel: hosting.
- Stripe: payments (card data stays with Stripe).
- Anthropic (and, if configured, OpenAI): AI inference.
- Movie of the Night and OMDb: title, availability, and ratings data. Google Books: book data.
What we don't do
- We don't sell or rent your personal data.
- We don't run third-party ad networks, analytics pixels, or cross-site trackers. The only cookie is Clerk's essential login-session cookie.
- We don't attach any identifier to you in outbound affiliate links, and we don't put personal data in URLs.
Your choices & rights
Whatever privacy laws apply where you live (such as GDPR or CCPA), we aim to honor the basics for everyone:
- Access: ask for a copy of the data we hold about you.
- Correction: much of your profile is editable in the app; you can also ask us to fix something.
- Deletion: ask us to delete your account and data. There is currently no self-serve delete button, so send us a messageand we'll remove your account and wipe your stored files.
We don't sell data, so there's nothing to opt out of on that front.
Children
ShowReco isn't directed at children. You must be at least 13 to use it. If you believe a child under 13 has given us data, contact us and we'll delete it.
Changes to this policy
If we make a meaningful change, we'll update this page and the “last updated” date, and note it in the app. Continuing to use ShowReco after a change means you accept the updated policy.
Contact
Privacy questions or requests: send us a message. You'll need to be signed in, which is also how we know the request is yours.