Privacy Policy
1. Summary (Plain English)
Zo2y ("we", "us", "our") is a personal media-tracking app. We let you build lists, write reviews, and save travel plans across movies, TV, books, games, music, sports, and travel. This policy explains what data we collect, why, who we share it with, and the rights you have over it.
- We collect account data (email, username, profile fields) to run your account.
- We collect content data (your lists, reviews, ratings, planner notes) to display it back to you.
- We collect operational telemetry (page loads, error reports, device type) to keep the app fast and safe.
- We never sell personal data. We share data only with infrastructure processors needed to run the service.
- You can export or delete your account at any time from your privacy dashboard.
2. Who We Are (Data Controller)
The data controller for Zo2y is:
Zo2y (operated by the Zo2y team)Email: privacy@zo2y.com
Support: darkpastadude@gmail.com
If you are in the EU/UK, you can also reach our EU representative at the same email with subject line starting with "EU Representative".
3. What We Collect
3.1 Account data
- Email address (used for login, password reset, and important service notices).
- Username, full name, and any profile fields you choose to fill in (bio, avatar URL).
- Authentication state (logged in / logged out) and OAuth provider metadata if you sign in with Google.
- Password hashes (we never see or store your plaintext password; Supabase handles hashing).
3.2 Content data
- Lists you create (title, description, cover image URL, icon, list type).
- Items you add to lists (movie/TV/game/book/track/team/country/brand/food/fashion/car IDs).
- Ratings (1+�G�Gǣ5 stars) and reviews (text you write, edit timestamps).
- Travel planner entries (cities, best months, budget tier, notes, country code).
- Custom list memberships and collaborator links.
3.3 Operational telemetry
- Page performance metrics (load time, render time) +�G�Gǥ only if you opt in via the cookie banner.
- Error reports (stack traces, request URLs, browser version) used solely to debug crashes.
- API request metadata (timestamp, endpoint, status code) for rate limiting and abuse prevention.
3.4 Device & connection data
- IP address (used for security, rate limiting, and approximate country detection; not stored in a user profile).
- User agent string, screen size, and language preference (for responsive UI).
3.5 Data we do not collect
- We do not collect biometric data, health data, financial data, government IDs, or precise geolocation.
- We do not read your Gmail, Google Drive, Calendar, Contacts, Photos, or YouTube watch history.
- We do not run advertising trackers or ad networks.
4. Sources of Data
- Directly from you when you sign up, fill in your profile, write a review, or save a list.
- From your device via cookies and local storage (see +�-�11).
- From third-party identity providers if you sign in with Google (basic profile fields only: name, email, profile image URL).
5. How We Use It (Purposes)
- Provide the core service: lists, reviews, planner, search, profile pages.
- Authenticate you and protect your account.
- Personalize content (e.g., "your lists", "your reviews").
- Prevent abuse, fraud, spam, and security incidents.
- Measure product health (only with your consent) and debug errors.
- Comply with legal obligations and respond to lawful requests.
We do not use your content for advertising. We do not profile you for automated decisions that produce legal or similarly significant effects (see +�-�14).
6. Lawful Basis (GDPR Art. 6)
If you are in the EU/UK, we rely on the following bases:
- Contract +�G�Gǥ to provide the service you signed up for.
- Legitimate interests +�G�Gǥ for security, fraud prevention, and product analytics that do not override your rights.
- Consent +�G�Gǥ for non-essential cookies, analytics, and any optional features you opt into.
- Legal obligation +�G�Gǥ to comply with applicable law.
8. International Data Transfers
Zo2y is operated from the United States. If you access the service from the EU, UK, Switzerland, or another region, your data will be transferred to and processed in the US and other countries where our subprocessors operate.
For transfers from the EU/UK/Switzerland we rely on:
- European Commission Standard Contractual Clauses (SCCs) with each subprocessor.
- UK International Data Transfer Addendum where applicable.
- Supplementary technical and organizational measures (encryption in transit and at rest, access controls, minimization).
You can request a copy of the SCCs we have executed by emailing privacy@zo2y.com.
9. Data Retention
We keep your data only as long as needed to provide the service or comply with legal obligations. Specifically:
- Account data +�G�Gǥ for the life of your account, plus up to 30 days after deletion to allow recovery and to comply with tax/legal retention.
- Content data (lists, reviews, planner) +�G�Gǥ for the life of your account. When you delete, it is removed within 30 days except where retention is legally required (e.g., financial records).
- Backups +�G�Gǥ encrypted daily backups are retained for up to 35 days, then overwritten.
- Server logs (IP, user agent, request URL) +�G�Gǥ retained for up to 90 days for security and abuse prevention, then deleted or anonymized.
- Email records +�G�Gǥ transactional emails we send are retained for up to 24 months for support and audit purposes.
Anonymized or aggregated data that can no longer be associated with you may be retained indefinitely.
10. Security
We use industry-standard measures to protect your data:
- HTTPS / TLS 1.2+ in transit.
- Encryption at rest in our database and storage.
- Row-level security (RLS) in Supabase so users can only read or write their own rows.
- Rate limiting on authentication, signup, and review endpoints.
- Spam and abuse heuristics on user-generated content.
- Access logging on admin endpoints; service-role keys restricted to serverless functions.
No system is 100% secure. If we discover a security incident affecting your data, we will notify you and applicable regulators in line with applicable law.
12. Your Rights
12.1 EEA / UK / Swiss residents (GDPR / UK GDPR)
You have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure ("right to be forgotten").
- Restriction of processing in certain cases.
- Data portability in a structured, commonly used, machine-readable format (JSON).
- Object to processing based on legitimate interests.
- Withdraw consent at any time, without affecting prior lawful processing.
- Lodge a complaint with your local data protection authority (e.g., CNIL, BfDI, ICO, AEPD, Garante).
Exercise any of these rights from your privacy dashboard, or by emailing privacy@zo2y.com. We respond within 30 days.
12.2 California residents (CCPA / CPRA)
You have the right to:
- Know what categories of personal information we collect and how we use them (covered above).
- Delete personal information we have collected from you.
- Correct inaccurate personal information.
- Opt out of sale or sharing +�G�Gǥ we do not sell or share personal information, so this is moot, but you can still submit a verifiable request.
- Limit use of sensitive personal information +�G�Gǥ we do not collect sensitive PI as defined under CPRA.
- Non-discrimination for exercising your rights.
Submit a verifiable consumer request via the privacy dashboard or by emailing privacy@zo2y.com. We respond within 45 days.
You may designate an authorized agent to act on your behalf in line with 11 CCR +�-�7063.
12.3 Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other US state residents
You have similar rights to access, correct, delete, port, and opt out of targeted advertising, profiling, or sale of personal data. Submit requests through the same channels above.
12.4 Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), and other regions
You have analogous rights to access, correct, delete, and port your data. Contact us to exercise them.
13. Children's Privacy
Zo2y is not directed to children under 13. We do not knowingly collect personal data from children under 13 (or under 16 in the EEA/UK, where the higher age applies).
If we learn that we have collected personal data from a child in violation of these rules, we will delete it as soon as possible.
Parents or guardians who believe their child has provided personal data to us may contact privacy@zo2y.com for deletion.
Users between 13 and 16 (or the local age of digital consent) may only use the service with verifiable parental consent.
14. Automated Processing
Zo2y does not perform automated decision-making that produces legal or similarly significant effects on you (no credit scoring, no automated denial of service, no profiling for such decisions under Art. 22 GDPR).
Recommendations and "people also saved" features are based on simple co-occurrence (titles saved by other users into similar lists) and do not constitute profiling under Art. 4(4) GDPR.
15. Do Not Track & Global Privacy Control
We honor Global Privacy Control (GPC) signals. If your browser sends a GPC: 1 header, we treat it as a request to opt out of any non-essential processing, including analytics cookies.
Legacy "Do Not Track" (DNT) browser signals are honored where technically feasible.
16. Changes to This Policy
We may update this policy from time to time. Material changes will be announced:
- On this page with a new "Last updated" date.
- Via an in-app banner on the home page for at least 30 days.
- By email for changes that affect your rights or how we process your data.
Continued use of Zo2y after a change becomes effective means you accept the updated policy. If you do not accept, you may delete your account from the privacy dashboard.
17. Contact & Complaints
Questions, requests, or complaints about this policy or our data practices can be sent to:
Zo2y Privacy TeamEmail: privacy@zo2y.com
Support: darkpastadude@gmail.com
If you are in the EEA and believe we have not handled your request adequately, you have the right to lodge a complaint with your local supervisory authority. A list of national Data Protection Authorities is maintained by the European Data Protection Board at edpb.europa.eu.
UK residents may complain to the Information Commissioner's Office (ICO) at ico.org.uk.
California residents may complain to the California Attorney General at oag.ca.gov/privacy/ccpa.
Plain-text version of this policy is available on request. Effective date: June 6, 2026.