Binge.

Privacy Policy — Last updated September 9, 2026

Binge is an Android app for browsing, discovering, and tracking movies and TV shows. This policy explains what information is collected when you use Binge, how it is used, and your choices regarding that information.

Information we collect

What you do in the app

Your search queries, ratings, watchlist additions, favorites, and any custom lists you create are sent to The Movie Database (TMDB) so they can be saved to your TMDB account and synced across devices. Binge does not operate its own backend server — all account data lives with TMDB.

Stored locally on your device
DataPurpose
TMDB session & account IDKeeps you signed in between sessions
Recent searches (up to 10)Powers the search history suggestions
Content & UI preferencesYour chosen start tab, adult-content filter, analytics opt-in
Cached media dataSpeeds up browsing by avoiding repeated network calls; auto-expires
Connected server details (optional)If you connect Binge to your own media-request server: your access key or login session, stored encrypted, and the server's address, stored as you entered it. Only present if you set one up

All local data is stored in Android DataStore and a Room database on your device. Uninstalling the app removes all of it, with one exception — the sign-in backup described below. Images you chose to save to your Pictures folder are yours and stay where you put them.

Restoring sign-in on a new device Google Block Store

So you don't have to sign in again after switching phones, your TMDB sign-in can be restored on a new device. Only the TMDB session token and account ID are backed up — through Google Block Store, part of Google Play services — so Binge can sign you back into your own TMDB account when you set up a new device or restore from a backup.

Your password is never involved — Binge never sees it. Google encrypts the backup, and the session token is one you can revoke at any time from your TMDB settings. Signing out of Binge deletes this backup.

Crash reports on by default Firebase Crashlytics

When the app crashes — and when it hits an error it recovers from, such as a failed network request — a report is sent to Google Firebase Crashlytics so the bug can be found and fixed. It contains the stack trace, your device model, Android version and app version, plus recent diagnostic log entries — which can include the name of the screen you were on and the address of a request that failed.

Reports are not linked to your TMDB account. Like usage analytics they carry a randomly generated identifier for your app installation, so repeated crashes on one device can be recognised as the same device — making them pseudonymous rather than anonymous. Unlike analytics, crash reporting is on by default; you can turn it off in Account → Preferences → Send crash reports.

Usage analytics opt-in — off by default Firebase Analytics PostHog

Analytics is off until you turn it on. During setup Binge asks whether you want to share usage data (screens viewed, features used). Nothing is collected unless you actively agree — declining, or closing the app without choosing, leaves it off.

If you do agree, the same events are sent to two analytics providers. PostHog processes them on servers in the European Union. Google Firebase Analytics is operated by Google, which processes data on its own infrastructure outside the EEA under Google's privacy policy and terms.

These events record that something happened, not what it was. For example, a search is recorded as "a search was performed" — your search terms are never included. The point is aggregate: we log how the app is used — which features and actions people reach for — but no event tells us who you are or the specific titles you were looking at.

They are not fully anonymous, and we would rather say so than overstate it. Each provider attaches a randomly generated identifier for your app installation, and it is that identifier — not your IP address — that links events from the same device together. Your device's IP address does reach each provider with the request, and is used to infer your approximate location, which is stored alongside each event — typically your country and region, and in some cases down to a city or approximate coordinates. PostHog is configured to discard the IP address itself once that location has been derived. This is an estimate derived from the IP address, not your device's GPS: Binge never requests location permission and never sends your precise location. That identifier is not linked to your TMDB account and is discarded when you uninstall the app, but it does mean the data is pseudonymous rather than anonymous.

You can disable analytics at any time in Account → Preferences → Share analytics data. Turning it off stops all future collection by both providers. Previously collected data is governed by Google's privacy policy and PostHog's privacy policy.

Third-party services

Binge relies on the following third-party services. Each has its own privacy policy.

Permissions

Binge requests only the permissions it needs:

Binge does not request access to your camera, microphone, location, contacts, or any other sensitive data.

Account sign-in

Binge does not have its own account system. Signing in means authorising Binge to access your existing TMDB account via TMDB's OAuth flow. Your TMDB credentials are entered directly on the TMDB website — Binge never sees your password. The resulting session token is stored locally on your device and sent only to the TMDB API. It is also backed up through Google Block Store so your sign-in can be restored on a new device, as described under “Restoring sign-in on a new device” above. You can revoke access at any time from your TMDB connected applications settings, or by signing out inside the app.

Connecting a media-request server is separate, and works differently: that server has its own accounts, so you may enter its username or email and password directly in Binge. Those are sent only to the server address you supplied — never to us, and never to any third party — and only the resulting access key or login session is kept on your device, encrypted.

Who is responsible for your data

Binge is an independent app published by Scott Cooper, based in the United Kingdom, who is the data controller for the information described in this policy. There is no company behind it and no data protection officer. For anything about this policy, or to exercise any of the rights below, email scottalancooper@gmail.com.

Why we are allowed to use your data

Under UK and EU data protection law, every use of personal data needs a legal basis. Binge relies on three, one per purpose.

WhatWhyLegal basis
Showing you content, and syncing your ratings, watchlist and lists It is the app you asked for Performance of a contract (Art. 6(1)(b))
Keeping you signed in, including restoring sign-in on a new device You asked to be signed in and to stay that way Performance of a contract (Art. 6(1)(b))
Usage analytics To see which parts of the app get used Your consent (Art. 6(1)(a)) — off until you turn it on, and you can withdraw it at any time
Crash reports To find and fix the bugs that break the app Legitimate interests (Art. 6(1)(f)) — ours in shipping an app that works, weighed against a report that carries no account identity. You can object at any time by turning it off in Account → Preferences → Send crash reports

Where your data is processed

WhoWhereTransfer safeguard
PostHog — usage analytics European Union (PostHog Cloud EU, Frankfurt) Stored in the EEA; no transfer out for storage
Google — Firebase Analytics, Crashlytics, Remote Config, Play services United States and other countries Google operates in Google's Firebase Data Processing and Security Terms: transfers to a certified Google entity in the US rely on the EU–US Data Privacy Framework (§10.6), and transfers those do not cover — including from the UK — rely on the European Commission's Standard Contractual Clauses with the UK Addendum (§10.2(b))
TMDB — your account data and all content United States Governed by your own account with TMDB and their privacy policy
Gravatar (Automattic) — your profile picture, if you have one United States Automattic's privacy policy; only your IP address and the image request reach them

Ask us at the address above if you want more detail on any of these transfers.

Data retention and deletion

Your rights

You have the rights below over your personal data. Binge is unusual in holding almost none of it itself — your account data lives with TMDB, and your usage and crash data with the analytics providers — so each right names the fastest route. We will help with any of them if you email us.

We will answer any of these within one month, free of charge.

Complaints

If you think your data has been mishandled, please email us first — but you also have the right to complain to a data protection regulator. As a UK-based controller, ours is the Information Commissioner's Office (0303 123 1113). If you are in the EU or EEA you may complain to your own country's supervisory authority instead.

Children's privacy

Binge is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information through the app, please contact us and we will take steps to remove it.

Changes to this policy

If this policy changes materially, the updated version will be published at this URL with a revised "last updated" date. Continued use of the app after a change constitutes acceptance of the updated policy.

Contact

Questions about this policy? Email scottalancooper@gmail.com.