Privacy policy
This policy explains how Ciak processes your personal data when you use ciakapp.com, join the beta or use the app. It describes what we collect, why we use it, how long we keep it and the rights available to you.
Data controller
The data controller is IMPROBABILItea S.R.L., with registered office at Corso Galileo Ferraris 162, 10134 Turin (TO), Italy, VAT number 13409210013. For privacy requests, email [email protected].
Data we process
When you join the waiting list, we process your email address, selected language, the form location you used (hero or final CTA), and the signup date and time. A Cloudflare Pages Function handles the form and stores this data in the Cloudflare D1 database dedicated to the waiting list. Cloudflare Pages also processes technical data needed to deliver and protect pages, such as IP address, request date and time, requested page, outcome and essential device or browser information.
To measure use of the site, we process events such as page views, source, language, date and time, interactions with links, buttons, the demo and beta form, plus technical information about the browser, device and viewport. Your email address and anything you type into fields are not sent to PostHog; session recording is disabled.
In the app, we may process your email, display name, avatar, account and session identifiers, device token and notification preferences. If you use Sign in with Apple, we receive an identifier and any information you choose to share from Apple.
We also measure use of the app with PostHog. Anonymously, we process an identifier generated for the installation, the names of the screens you open and a closed list of product events — access started and completed, onboarding finished or postponed, an evening shared and decided, a recommendation declined, a rating given, a take published, a friendship accepted, an invitation created and redeemed — together with technical information about the device, operating system, language and app version: they are numbers about an installation, not about you. Only if you turn it on under “Account e dati” do those events also carry your opaque account identifier. We do not send PostHog your email, your name, the text of your takes or which titles you open: screens travel as fixed labels, for example “title detail”. Session recording and automatic tap capture are disabled.
To provide Ciak's features, we process what you choose to record: streaming services, films and shows watched or saved, episode progress, ▲/▼ ratings and reasons, preferences and limits, taste profile, searches, recommendations received and choices made.
If you use social features, we process friendships, invitations, sharing settings, evening participants, published takes, chosen visibility, reports and helpful marks.
Why we process your data
We use your waiting-list email to send you a beta invitation on the basis of your consent under Article 6(1)(a) GDPR. You can withdraw consent at any time.
We process account and app data to create and protect your profile, sync your library, generate recommendations, run shared evenings, manage friends and content, and send notifications you have enabled. The legal basis is providing the service you request under Article 6(1)(b) GDPR.
We process technical data, logs, rate limits and reports to prevent abuse, protect users and infrastructure, diagnose faults and defend our rights. The legal basis is our legitimate interest in security and proper operation under Article 6(1)(f) GDPR.
Before you choose and after “Reject”, we measure the site with PostHog in cookieless mode, without writing PostHog identifiers to your device or creating a person profile. The legal basis is our legitimate interest in aggregate statistics and improving the site under Article 6(1)(f) GDPR; you may object using browser privacy signals or by contacting us.
Only if you select “Accept cookies” does PostHog use cookies and localStorage to recognise the same browser across pages and visits. The legal basis is your consent under Article 6(1)(a) GDPR and applicable ePrivacy law. You may withdraw it at any time through “Manage cookies” in the footer.
We measure use of the app anonymously, to understand which parts work and where people stop. The legal basis is our legitimate interest in improving the product under Article 6(1)(f) GDPR; you can object by writing to [email protected] and we will stop collecting.
Linking those numbers to your account happens only if you turn it on under “Account e dati”. The legal basis is your consent under Article 6(1)(a) GDPR; the same switch withdraws it at any time, and withdrawal does not affect processing already carried out. When you turn it on we start from a new identifier, so the preceding anonymous period is not attributed to you.
We may also process data where necessary to comply with a legal obligation or a lawful authority request under Article 6(1)(c) GDPR.
How personalised recommendations work
Ciak automatically analyses the services you use, titles you track, ratings, reasons, preferences and the context of an evening. When you watch with others, it combines these elements with those of authorised participants to rank compatible titles and explain each recommendation.
This personalisation does not produce legal or similarly significant effects. The final choice is yours. You can influence recommendations by changing or deleting ratings, preferences, services and viewing history.
Ratings, takes and sharing
Your ▲/▼ ratings are not public. Connected friends may only see them according to the sharing settings available in the app.
When you publish a take, you choose who can read it: friends only, friends and people with a similar taste, or everyone using Ciak. You can edit it, delete it or change its visibility. Takes marked as spoilers are covered, and users can report abusive content or unmarked spoilers.
Shared evenings
Only people with a Ciak account can join an evening: there is no guest profile. Whoever watches with you is a registered person, with their own taste and their own vetoes, and their ratings stay theirs from one evening to the next. We therefore process the data of registered participants only, according to the sharing settings each of them has chosen.
Recipients and service providers
Data may be processed by suppliers acting for us and under our instructions: Amazon Web Services for authentication, computing, storage, email, notifications and logs; Supabase for the app database; Apple for Sign in with Apple and push notifications; Cloudflare for Cloudflare Pages and Pages Functions, the waiting-list D1 database, CDN, DNS, security and the analytics proxy; and PostHog, on its European instance, for both cookieless site analytics and, after consent, persistent analytics — and for app analytics. Events reach PostHog through a subdomain of ours acting as a proxy, so requests stay on our own domain. The waiting-list email address is not sent to PostHog. We limit access to data needed for each service.
TMDB and JustWatch provide title and availability information. They don't receive your history, ratings or taste profile. OpenAI processes title metadata only to create mathematical catalogue representations; we don't send account identifiers, takes or personal viewing history.
We may disclose data to professional advisers, authorities or other parties where needed to meet legal obligations, protect rights or complete a corporate transaction, subject to the safeguards required by law.
Transfers outside the European Economic Area
PostHog is configured in the European region, and the Cloudflare D1 waiting-list database is configured with EU jurisdiction, which restricts database execution and storage to the European Union. The app database on Supabase is hosted in the European Union. Cloudflare distributes the site through a global network and may process other technical data outside the European Economic Area. Where a supplier processes data in a third country, the transfer relies on a European Commission adequacy decision or appropriate safeguards under Articles 45 and 46 GDPR, such as Standard Contractual Clauses. You can ask about applicable safeguards at [email protected].
How long we keep data
We delete the waiting-list data stored in Cloudflare D1 when you withdraw consent, within 30 days after sending the beta invitation, or within 12 months of signup, whichever happens first. After deletion, an isolated copy may remain in D1's Time Travel recovery history for up to 30 days, depending on the applicable Cloudflare plan; it is not used for other purposes and expires automatically.
Account and app data remain available while your account is active. When you request deletion, we delete or anonymise linked data within 30 days, except where needed for a legal obligation, security or the establishment of a legal claim. Isolated backup copies are overwritten according to each supplier's normal cycle and are not reused for other purposes.
Access codes expire within minutes, sessions within a maximum of 30 days and technical logs after 30 days. Pseudonymous events used to analyse and improve the recommendation system are kept for no more than 24 months, then deleted or aggregated anonymously.
Website analytics events held in PostHog remain available for no more than 12 months and are then deleted or aggregated. Your “Accept cookies” or “Reject” choice is remembered for six months. Persistent PostHog identifiers on your device expire after no more than 12 months unless you withdraw consent or delete them earlier.
App analytics events follow the same 12-month limit. The installation identifier is replaced with a new one each time you turn the link to your account on or off, so the periods before and after are not linked to each other.
Takes and other content you publish remain until you delete them or close your account. Reports may be retained for longer where needed to document abuse or protect a right, but no longer than the applicable limitation period.
Security
We use technical and organisational measures proportionate to risk, including encryption in transit and at rest, access controls, environment separation, least privilege, security logging and backup procedures. No system is risk-free; if a breach may create a risk to your rights, we will act as required by the GDPR.
Children
Ciak is intended for people aged 14 or over. If you are under 18, you must use the service with permission from a parent or legal guardian where the law requires it. We don't knowingly collect data from children under 14; if you believe this has happened, email [email protected].
Your rights
You may request access, rectification, erasure, restriction and portability, object to processing based on legitimate interests and withdraw consent without affecting earlier lawful processing. You may also ask about personalisation and complain to your local data protection authority.
To exercise your rights or close your account, email [email protected]. We will respond within one month, subject to extensions allowed by the GDPR. We may ask for information needed to verify your identity.
Changes to this policy
We will update this page when the service, suppliers or applicable law changes. If a change materially affects your rights, we will notify you in the app or through available contact details before it takes effect.