Privacy Policy — Duetly
Last updated: 22 September 2026
Applies to: the mobile app Duetly (iOS and Android) with the features described here
This is a translation of the German original. In case of doubt, the German version prevails.
Contents
- Controller
- What the app does
- What personal data we process
- Legal bases
- Whether you have to provide data
- Recipients, processors and third-party services
- Transfers to third countries
- Storage periods and deletion
- Your rights
- Objection and withdrawal
- Security
- No profiling or ad-tracking suite
- Device features and permissions
- Minors
- Automated decision-making
- Distribution through app stores
- Changes to this policy
- What Duetly currently does not do
- Summary
1. Controller
The controller for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
Tom Merklinghaus
In der Bitz 14
56567 Neuwied, Germany
Email: [email protected]
No data protection officer has been appointed at present (to the extent not legally required).
Please send any privacy questions to [email protected].
2. What the app does
Duetly is an app for two people (a "couple") to find movies and shows together. The typical flow:
- Each person creates an account (email and password, "Sign in with Apple" or "Sign in with Google").
- One person creates an invite code; the other joins with it.
- Both swipe through titles (like / skip). Once a month each person can play a joker, which turns the top title into a match without the partner's consent.
- Whatever you both like appears in a shared match list.
- Optionally, you can set a status for each match (watched with stars and place, started, gave up with a reason).
Without an account, a couple assignment and stored swipes/matches, the core function (sync between two devices) cannot be provided.
Duetly is not a streaming player and not a purchase or subscription platform. Film data and streaming availability come largely from third parties (in particular TMDB) and may be incomplete or vary by region.
3. What personal data we process
Personal data is any information relating to an identified or identifiable natural person (Art. 4(1) GDPR).
3.1 Account and authentication
| Data | Examples / details | Purpose |
|---|---|---|
| Email address | at registration / sign-in; with Apple or Google sign-in provided by that provider (with Apple possibly a "Hide My Email" relay address) | create an account, sign in, assign data, confirmation code and password reset by email, replies to support requests |
| Password | only with email registration; not stored in plain text in the app | authentication; stored hashed at the auth provider |
| Sign-in providers | email, Apple and/or Google — which of them are linked to the account | shown under "Account", sign-in |
| Display name | a profile name you choose | shown in your profile and in the app |
| Internal user ID | UUID of the auth account | links profile, couple, votes and feedback |
| Session / auth tokens | handled by the auth client | keeping you signed in on the device |
Source: provided by you or generated by the auth system.
3.2 Profile
| Data | Purpose |
|---|---|
| Display name in the profile table | shown in your own profile |
| Partner's display name | visible in a connected couple on the home screen and under "Couple" (e.g. "Tom and Alex") |
Last activity (last_active_at) | time of last app use (e.g. after sign-in or a swipe); shown to your partner as a hint ("was active today") |
3.3 Couple connection
| Data | Purpose |
|---|---|
| Six-character invite code | inviting a partner / joining |
| Couple ID | shared data areas (votes, matches, status, dismissals) |
| Link between the two user accounts (host / partner) | sync and access control |
| Timestamps of the connection and updates | operation and traceability |
Note: Whoever holds the current code can join the couple as long as the second slot is free. Only pass the code to the person you intend. When you copy it, the code may briefly sit in your device's clipboard.
3.4 Swipes, likes and skips (votes)
Stored server-side (in the cloud), in particular:
- your decision (like or skip)
- the time of the rating
- whether and when you played the joker for this title (
joker_at; at most once per calendar month) - the link to your user ID and — when connected — to the couple ID
- title metadata for lists and sync, for example:
- title
- movie or show
- TMDB ID
- short description / overview
- poster URL
- year / release date (where available)
- rating (e.g. TMDB score)
Not stored in the cloud vote table (current state): genre lists and streaming provider rows for the title. They may, however, sit locally in the device cache of the vote/like store and be re-fetched from TMDB when needed.
Additionally on the device: vote caches (among other things for offline use and before syncing), so that likes are not lost and the deck can be controlled — including extended title info to the extent the app stores it locally.
Purpose: controlling the deck, avoiding duplicate ratings, forming matches, showing your personal like list and the shared match list, syncing between both devices.
Partner and votes: In a connected couple, the couple's votes are loaded onto both devices for sync (so matches can be detected and the deck controlled). In the interface, "My likes" and the shared "Matches" list stay separate: your partner does not see a list called "Likes by …", but the sync logic knows the like/skip information of both sides. Shared matches and the shared match status are visible to both.
3.5 Matches and removals (dismissals)
- When a match occurs (you both like the same title), it appears in the shared list.
- Removed matches are stored per couple (dismissals) so they do not reappear in the shared list for either of you.
3.6 Match status (voluntary quiz)
For each match you may voluntarily state:
- still open, started (shows), watched or gave up
- for "watched": 1–5 stars and where you watched it (e.g. streaming service, cinema, somewhere else)
- for "gave up": optional reasons (a fixed selection such as "boring", "too long", or free text)
- the time at which the title was marked watched or given up
These entries apply to the couple, are synced, and are visible to the connected partner within the app; both can change them.
Evaluation by the operator: The operator can view this data in the backend administration and evaluate it manually or by database query (including in aggregate, e.g. how often "watched" is set). There is currently no automated evaluation pipeline in the app itself.
3.6a Personal archive after a couple is dissolved
When a couple is dissolved (via "Dissolve couple", "Create new code", or because one person deletes their account), the shared matches are lost. So that the titles you watched or gave up on together do not disappear, the server creates a separate copy for each of the two people at that moment ("Watched before"):
- title, poster, year, movie/show, TMDB ID
- stars, place, reasons for giving up and the watched date as of the dissolution
- the display name of the partner at that time (e.g. "with Alex")
This copy belongs to your own account only: the former partner can neither see nor change it, and any changes you make later (e.g. different stars) stay with you. Conversely, your former partner receives their own copy with your display name. The archive is deleted together with your account.
Legal basis: Art. 6(1)(b) GDPR (part of the app feature) and, regarding the partner's name, Art. 6(1)(f) GDPR (legitimate interest of both people in their own viewing history); for objection see section 10.
3.7 Feedback
When you send feedback or a support request ("Still got questions?") through the app, we store:
- subject and message text
- the kind (feedback or support)
- your user ID and email address
- the time it was sent
In addition, the message is delivered as an email to [email protected] (sent via Resend, see section 6.4) — with your email address as the reply-to address so that we can answer you.
Feedback is not visible to other users. It serves support and product improvement. Clients cannot read feedback in the app; it is accessed through the operator's backend credentials and the support mailbox.
Note on account deletion: When your account is deleted, the link between the feedback and your user ID is typically severed (SET NULL). The message text and any stored email address may remain with the operator until they are deleted or anonymised manually — if you wish, request deletion separately by email to [email protected].
3.8 Reason for leaving (asked when deleting an account)
Before you delete your account for good, the app asks for a main reason (from a list) and optionally for a short free-text note ("What could have been better?").
Stored in particular:
- the chosen reason code (e.g. bugs, partner does not use it, too few titles, privacy, just trying it out, found something else, other, rather not say)
- the optional free text
- where applicable, the email address and user ID at the time of sending
- the time
Purpose: product improvement and understanding why users leave. These entries are not visible to other users; evaluation happens through the operator's backend credentials (e.g. how often each reason is chosen).
After account deletion the user ID is typically decoupled (SET NULL); the reason and free text (and any email address) may remain with the operator for evaluation until they are deleted or anonymised.
Legal basis: legitimate interest in product improvement (Art. 6(1)(f) GDPR); choosing "Rather not say" or cancelling the deletion remains possible. The free text is voluntary.
3.9 Settings and usage state on the device
Stored locally (e.g. via shared preferences), among other things:
- display name (per account)
- the chosen streaming/watch region (country)
- filters (streaming services, cinema mode, movie/show, genres, minimum rating, minimum year, age ratings)
- local vote/like caches
- onboarding completed / certain hints dismissed (e.g. swipe hint, pick hint)
This data stays primarily on the device. Sync-relevant content is additionally processed server-side as soon as you are signed in and (for couple features) connected.
On account deletion, locally: the app typically removes the vote/like caches and the display name of the deleted account. Filters, region, onboarding flags and similar may remain on the device until you uninstall the app or clear its data.
3.10 Technical operating data
Technically necessary data may arise during operation, in particular:
- timestamps of write operations
- auth/session information
- error and connection information from the backend services
- usual connection data for network requests (e.g. the IP address that may arise at the respective server)
We currently operate no advertising or analytics SDK tracking suite in the app (no classic advertising or cross-app tracking). The app's typefaces are bundled with the app and are not fetched from external servers.
3.11 Film data from TMDB (not Duetly account content)
To show titles, posters, age ratings and streaming availability, the app calls the TMDB API. Hand-picked recommendations ("Duetly pick") are a list of TMDB IDs maintained by the operator without any personal reference. Search and filter parameters (e.g. region, providers, genres) and technical connection data are processed in the course of this. Duetly passwords and your private couple content are not transmitted to TMDB. The film metadata itself is publicly available catalogue data; your swipes and matches are stored in our backend (see above).
4. Legal bases
Where the GDPR applies, we base the processing in particular on:
| Processing | Legal basis |
|---|---|
| account, sign-in, couple connection, swipes, matches, sync, lists | Art. 6(1)(b) GDPR (contract / pre-contractual steps — using the app) |
| secure authentication, abuse prevention, technical operation | Art. 6(1)(b) and/or (f) GDPR (contract or legitimate interest in secure operation) |
| match status for the couple feature | Art. 6(1)(b) GDPR |
| aggregated / internal product evaluation (including match status, feedback) | Art. 6(1)(f) GDPR (legitimate interest in improving and stabilising the app); for objection see section 10 |
| sending feedback | Art. 6(1)(a) and/or (f) GDPR (consent by actively sending, or legitimate interest in support/improvement) |
| asking for a reason when deleting an account | Art. 6(1)(f) GDPR (legitimate interest in product improvement); free text voluntary |
| local storage of settings and caches | Art. 6(1)(b) and/or (f) GDPR |
| fetching film data from TMDB | Art. 6(1)(b) and/or (f) GDPR (providing the app's content) |
| sign-in via Apple or Google | Art. 6(1)(b) GDPR (the sign-in method you chose) |
| sending confirmation codes, password-reset and support emails (Resend) | Art. 6(1)(b) GDPR |
| personal archive after a couple is dissolved (incl. partner's name) | Art. 6(1)(b) and (f) GDPR (see section 3.6a) |
Legitimate interests (Art. 6(1)(f) GDPR) exist in particular in: secure operation, fixing errors, preventing abuse, product improvement and traceability of support requests. You may object where the conditions of Art. 21 GDPR are met (see section 10).
5. Whether you have to provide data
For the core features you need:
- a valid email address and a password or an Apple or Google account (account)
- at registration, your consent to the privacy policy and terms of use
- for couple sync: a successful connection via the invite code
- for matches: swipes from both people
Without these, you cannot use Duetly, or not to the intended extent. Optional entries (display name details, match status, feedback, many filters) are voluntary; omitting them only limits the respective extra feature.
6. Recipients, processors and third-party services
Personal data is only passed on where this is necessary for operation, legally permitted or required, or where you have consented.
6.1 Supabase (backend: auth, database, realtime)
Purpose: authentication, storage and sync of profiles, couples, votes, dismissals, match status and feedback; realtime updates between the couple's devices.
Provider / infrastructure: Supabase (Supabase Inc. and associated hosting partners).
Duetly project region (current): European Union, data centre region Frankfurt (eu-central-1).
The account and app content data listed in section 3 is processed there, to the extent it is stored server-side (including feedback and reasons for leaving).
Access control in the database uses Row Level Security (RLS), among other things: in the app you generally only see your own data and data belonging to your couple.
6.2 TMDB — The Movie Database
Purpose: fetching movies and shows, posters, metadata and streaming availability by region.
Provider: TMDB / associated services — see https://www.themoviedb.org (please note the provider's terms and privacy policy).
No Duetly account passwords are transmitted to TMDB. Technical connection data (including IP) may arise at the provider when the API is called.
6.3 Apple and Google (sign-in)
Purpose: signing in with an existing Apple or Google account ("Sign in with Apple", "Google Sign-In") if you choose that route.
Providers: Apple Inc. or Apple Distribution International Ltd. (Ireland); Google LLC or Google Ireland Ltd.
When you sign in, the provider transmits an identifier, your email address (with Apple, optionally an anonymous relay address) and possibly your name for the display name to us. The provider learns that you are signing in to Duetly and processes that event under its own privacy policy. Your Duetly content (swipes, matches, couple) is not transmitted to Apple or Google.
6.4 Resend (email delivery)
Purpose: sending confirmation codes at registration, password-reset codes, and feedback/support messages to our mailbox.
Provider: Resend, Inc. (USA). Processed are the recipient address, subject and message body as well as delivery logs. The sender domain is tmapps.de. Resend is bound as a processor; see section 7 on transfers to third countries.
6.5 IONOS (support mailbox)
The mailbox [email protected], where feedback and support emails arrive, is operated by IONOS SE (Germany).
6.6 Connected partner
Within a connected couple:
- Interface: both partners' display names on the home screen and under "Couple" (e.g. "Tom and Alex"); a short activity hint ("was active today"); shared matches and the shared match status are visible to both; who played a joker is shown on the match; "My likes" stays a separate list.
- After dissolution: your display name remains in your former partner's personal archive next to the titles you watched together (see section 3.6a).
- Technology/sync: the couple's votes are synced to both devices for match detection and deck control (see section 3.4).
This is part of the app feature you have chosen.
6.7 Operator (admin)
The operator can access stored data through backend administration credentials — in particular for support, security and abuse prevention, and product evaluation (including feedback, reasons for leaving, match status). An automated analytics pipeline is currently not part of the app.
We do not sell your personal data.
6.8 Authorities
Disclosure to authorities only takes place where we are legally obliged to do so, or where it is necessary and permitted for legal defence.
7. Transfers to third countries
Duetly's Supabase project data is currently hosted in the EU (Frankfurt).
When fetching from TMDB, when sending email via Resend, when signing in via Apple or Google, and possibly during infrastructure or support processes at service providers, a transfer to third countries (in particular the USA) cannot be ruled out. Where the GDPR applies and no adequacy decision exists, such transfers take place — where applicable — on the basis of appropriate safeguards (e.g. the EU Commission's standard contractual clauses) or in line with the respective provider's information. For details, please also see the privacy information of TMDB, Resend, Apple, Google and Supabase.
8. Storage periods and deletion
We store personal data only for as long as it is necessary for the purposes stated, or as long as statutory retention obligations exist.
| Data | Period (current state) |
|---|---|
| account / profile | until the account is deleted |
| couple connection | until the couple is dissolved or the associated data is deleted |
| votes / matches / dismissals / match status | as long as needed for the feature; when a couple is dissolved, the couple's cloud data is deleted; local likes may remain on the device |
| personal archive ("Watched before") | until the account is deleted (see section 3.6a) |
| feedback | until handled / deleted by the operator; may remain after account deletion, with text and email address (the user ID is typically only decoupled) |
| reason for leaving | until evaluated / deleted by the operator; user ID typically decoupled after account deletion |
| local settings / caches | vote/like caches and the account's display name are cleaned up on account deletion; filters/region/onboarding may remain until the app is uninstalled or its data cleared |
| technical logs at service providers | according to the respective provider's deletion periods / briefly, as is technically usual |
Deleting your account yourself
In the app you can permanently remove your account under Couple → Account → Delete account. This removes in particular:
- the login / auth user
- the profile
- couple-related cloud data, where you are the host (the couple is dissolved) or the partner slot is freed — your partner first receives their personal archive of the titles you watched together (section 3.6a)
- your personal archive
- local vote/like caches and this account's display name on the device
Not automatically removed in full: previously sent feedback and the reason for leaving (text and any email address may remain with the operator — request deletion at [email protected]). Filter and region settings on the device may also remain.
After deletion, residual information may technically persist in backups for a short time until they are overwritten — without being actively used in the production database.
9. Your rights
Where the GDPR applies, you have the right to:
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR) — the "right to be forgotten"
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing based on legitimate interests (Art. 21 GDPR)
- withdraw consent you have given, with effect for the future (Art. 7(3) GDPR)
To exercise these rights, contact: [email protected].
You can also delete your account in the app yourself (see section 8).
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence, your place of work or the place of the alleged infringement.
In Germany this is usually the supervisory authority of your federal state; an overview is available, for example, through the pages of the Data Protection Conference (DSK).
10. Objection and withdrawal
Objection (Art. 21 GDPR)
Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you may object on grounds relating to your particular situation. We will then examine whether compelling grounds on our side override your interests.
Please address an objection to the contact details in section 1 and describe the processing concerned.
Withdrawing consent
If you have given consent (e.g. by actively sending feedback), you may withdraw it at any time with effect for the future. The lawfulness of processing carried out up to the withdrawal remains unaffected.
11. Security
We take appropriate technical and organisational measures to protect personal data against loss, manipulation and unauthorised access. These include in particular:
- authentication for access to account data
- encrypted transmission (HTTPS/TLS) between the app and the backend or APIs
- server-side access controls including Row Level Security
- separate roles for admin and service access
No online service can guarantee absolute security. Please protect your password and your invite code.
12. No profiling or ad-tracking suite
In the current state of the app we use no embedded advertising networks and no classic cross-app advertising tracking. We carry out no profiling for personalised advertising.
Technically necessary operating data (section 3.10) and internal product evaluation from app content (e.g. feedback, reasons for leaving, match status in the backend) are separate from this.
13. Device features and permissions
For core operation, Duetly mainly needs internet access.
Other typical device features in the current state:
- Clipboard: optional, when you copy the invite code
- Local storage: settings, caches, session
Currently no access to camera, microphone, contacts, location tracking for advertising or similar is required for the core function. Should permissions change later, we will update this policy and, where necessary, the store information.
Exactly how system permissions are displayed depends on iOS/Android and the store configuration.
14. Minors
Duetly is not aimed at children. Use requires your own account. Parents and guardians are responsible for use by minors, to the extent provided by law.
Age ratings in the filters are content filters for film titles and say nothing about a person's capacity to consent under data protection law.
15. Automated decision-making
There is no automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you (no scoring to your detriment or similar). Matches are formed by rule from the likes of both of you.
16. Distribution through app stores
If you obtain Duetly through the Apple App Store or Google Play, Apple or Google process data on their own responsibility as part of running their store (download, updates, payments if introduced later, device information, fraud prevention and so on). Apple's and Google's privacy information applies to that processing. We are not the controller for these store processes.
17. Changes to this policy
We may adapt this privacy policy when features, the services used or the legal situation change. The current date is stated at the top of this document. We will indicate material changes in a reasonable manner (e.g. in the app, on a publication page or in the store listing).
18. What Duetly currently does not do
For transparency — as of this document:
- privacy policy and terms of use can be viewed in the app (registration and Couple → Legal)
- consent is required at registration
- no push notifications
- no profile photos, no camera
- no public admin dashboard of our own in the app
- no embedded third-party ad trackers / no advertising ID evaluation by us
- no chat history, no photos from your gallery as a core feature
- no sale of personal data
19. Summary
| Topic | In short |
|---|---|
| What do we store? | account, couple, swipes (incl. joker), matches, optional match status, personal archive after a break-up, feedback, reasons for leaving, local filters/caches |
| What for? | sign-in, partner sync, shared watchlist, running and improving the app |
| Who sees what? | partner's name in the interface; matches + status; votes technically for sync · operator: backend including feedback/reasons · no sale to ad networks |
| Which services? | Supabase (auth/DB/sync, EU Frankfurt), TMDB (film data), Apple/Google (only with that sign-in), Resend (email), IONOS (support mailbox) |
| Deleting? | in the app: Couple → Account → Delete account; ask separately by email to have feedback deleted |
| Tracking? | no ad-tracking suite; no classic advertising tracking |
End of the privacy policy — Duetly
Back to Duetly