CT

CineTally

Community Film Stats

Privacy Notice

Effective date: February 25, 2026

This Privacy Notice explains how CineTally ("we", "us", "our") collects, uses, stores, and deletes personal data when you use this Service.

Independent Service; No Letterboxd Affiliation

This Service is independent and is not affiliated with, endorsed by, or sponsored by Letterboxd.

We process only user-submitted data and user-authorized RSS refresh data under your consent choices.

Data We Collect

We may collect and store:

1. Account data: account username, linked Letterboxd username, password hash, role, and consent timestamps.

2. Film data: uploaded export content, normalized film logs, and derived analytics for community statistics.

3. Preferences: RSS refresh opt-in/opt-out status and update timestamps.

4. Security and operations data: rate-limit events, auth events, and basic request metadata used for abuse prevention and troubleshooting.

How We Collect Data

We collect data when you register, upload your export file, change account settings, and use account-related endpoints.

Weekly RSS refresh runs only for members who explicitly opt in.

No scraping fallback is used for account ingestion.

How We Use Data

We use your data to:

1. Operate your account and authentication session.

2. Build member-level and community-level film analytics.

3. Run optional weekly RSS refresh for opted-in members.

4. Maintain security, prevent abuse, and monitor service health.

Data Sharing

We do not sell personal data.

We may share limited data only with service infrastructure providers needed to run this site (for example hosting/monitoring), or when required by law.

Data Retention and Deletion

Active accounts: Account credentials, uploaded film logs, derived analytics, and preference settings are retained while your account is active.

Weekly sync snapshots: Rolling snapshots of RSS-sourced viewing data are kept for 12 weeks, then automatically purged.

Upload history: Up to 16 upload snapshots per member are retained for rollback purposes; older snapshots are automatically removed.

Security logs: Auth events and rate-limit logs are retained for up to 90 days for abuse prevention and then deleted.

Account deletion: You can delete your account and all associated data from the Account page at any time. Deletion removes your uploaded logs, graph data, viewing records, and disables RSS refresh. Account credentials are permanently erased. Deletion is processed immediately and is irreversible.

Data export: You can request a copy of your stored data by contacting the site administrator.

Your Choices and Rights

You can access and update your account information, disable RSS refresh, and request deletion of your account data.

Security

We apply technical and organizational safeguards including access controls, rate limiting, request validation, and security event monitoring.

Changes to This Notice

We may update this Privacy Notice. The latest version is posted here with an updated effective date.

Contact

For privacy requests or questions, contact the site administrator.