In short: Nextsode exists so you can keep track of what you watch.
For that we store your email address, your watch records and (if you upload
one) your profile picture. We do not sell your data, we do not hand it to
ad networks, and we use no third-party analytics or tracking. You can
delete your account in one step from inside the app, and export everything you
have at any time.
1. Who collects it
The app and the service behind it are run by Nextsode. To reach the data
controller: iletisim@nextsode.app.
2. What we collect
Account information
Email address — for signing in, verifying your account and
resetting your password. Required. When you sign up we send a
verification link to that address; an unverified account can't use the
app. We do NOT send marketing email to this address.
Password — never stored in the clear; we keep only an
Argon2 hash of it.
Username and display name — shown on your profile and in your
friends' feed. You choose both.
Profile picture — only if you upload one. You don't have to; an
avatar is drawn from your initial instead.
Watch data
The shows and films on your shelf and their status (watching, on hold,
dropped, finished).
The episodes you mark and when you watched them — your diary,
stats and badges are built from these records.
Your ratings, reviews, lists, favourites and diary tags.
Your room messages, episode comments, predictions and emoji reactions.
Ideas and bug reports
When you use the in-app "share an idea / report a bug" box, we store the
text you wrote and the context of that moment: the minimum needed to
trace a problem or reproduce an idea on the right device/version.
Your message — the idea or the bug description.
App version (e.g. 1.0.0) — so we know which
release you were on.
Build number (e.g. 26) — so a TestFlight and a
store build can be told apart.
Platform (ios, android or
web) — so a bug can be tied to the right shell.
Operating system version (e.g. iOS 17.5.1) — for
compatibility questions.
Interface language (e.g. tr, en-US)
— to chase down a translation issue.
Name of the screen you were on (e.g.
settings.notifications) — to answer "where did this
happen?".
These fields are filled automatically; the box tells you so
on screen. We do not collect your address book, location or exact
device identifier. If you delete your account the report survives but no
longer carries your identity.
Technical data
Device push token — only if you allow notifications. It is deleted
when you turn notifications off or sign out.
Time zone — so notifications don't arrive in the middle of the night.
Anonymous daily counters — such as "how many comments were written
today". These counters are not tied to a person and are never
shown to any user.
Daily activity marker — to answer "how many people opened the app"
without counting the same person twice, a day + account pairing is kept
temporarily and deleted within 7 days at the latest. This is the
one metrics record tied to a person; it has no content, only "opened
that day".
3. What we do not collect
Location, contacts, photo library (only the single profile picture you
pick is read), calendar, health data.
Advertising identifier (IDFA) — there are no ads in the app.
Third-party analytics SDKs, crash reporters, social network pixels —
none of them.
Your data is not sent to any AI or language model; the recommendations in
the app are rule-based.
4. Why we process it
To provide the service: your shelf, diary, statistics and the
"next episode" calculation come straight from your watch records.
To perform our agreement: the app does not work without an account.
With your explicit consent: notifications and making your profile
public are separate switches that you turn on; you can turn either off at
any time.
5. Who it is shared with
We do not sell your data and we do not give it to anyone for marketing.
Sharing happens in three cases only:
Things you share yourself: the feed your followers see, your
messages in shared rooms, lists you make public and your web profile. All
of it is under your control; you can make your profile private.
Infrastructure providers: the server and database provider hosting
the app, the Apple Push Notification service (APNs) that delivers
notifications, and the email provider that sends the password-reset
message. They process data on our behalf and may not use it for their own
purposes.
Legal obligation: if a competent authority makes a lawful request.
Where show and film information comes from
Catalogue data (posters, synopses, episode lists) comes from TMDB.
This app uses the TMDB API but is not endorsed or certified by TMDB.
"Where to watch" information comes from JustWatch via TMDB. Your
watch data is not sent to these services — catalogue queries are made from
our server and carry no information about who asked.
6. How long it is kept
Your data is kept for as long as your account exists — your history is
the product itself.
When you delete your account, all of it goes: shelf, watch
records, ratings, reviews, lists, messages and your profile picture. This
cannot be undone.
The text of notification queue rows is deleted 30 days after
delivery; the only thing kept is which subject has already been
announced (so the same notification isn't sent twice).
7. Your rights
Under the GDPR (and, in Türkiye, Law no. 6698 / KVKK) you have the following
rights:
Access and portability: Settings → Export my data downloads your
whole watch history in a machine-readable format. You can also write to
us at any time.
Rectification: you can correct your name, username, watch dates
and ratings inside the app.
Erasure: Settings → Delete my account. It is one step and asks for
nothing beyond confirmation.
Objection and withdrawal of consent: you can turn notifications and
the public profile off whenever you like.