Legal
Privacy policy.
CinemaBin is a log of what you watch, which means almost everything in it is personal by definition. This page says exactly what we hold, why we hold it, who else ever sees it, and how to make it all go away.
Last updated 7 September 2026
1. Who we are
CinemaBin is built and operated by Redtekk, the controller of the personal data described here. You can reach a person at hello@redtekk.com, or in the app under Settings, then Support.
Redtekk is the trading name of David Ranđelović PR računarsko programiranje Redtekk Barajevo, a sole trader registered in the Republic of Serbia, registration number 68681111, tax number 115841704, at Barajevska 11/2, 11460 Barajevo, Serbia.
We have not appointed a data protection officer, and we are not required to. That duty falls on public authorities, and on organisations whose core work is monitoring people on a large scale or handling sensitive categories of data on a large scale. None of that describes CinemaBin. Anything about your data goes to the contact above and reaches a person who can answer it.
2. What this covers
This policy covers the CinemaBin mobile app on Android and iOS, the account system behind it, and this website. It does not cover anything you reach by leaving here.
3. What we collect
3.1 What you give us to create an account
- Email address. Used to sign you in, to confirm the account with a six digit code, and to reset a forgotten password. It is never shown to other users.
- Display name and username. Both are visible to anyone who can see your profile. The username is how people find you.
- Password. Stored only as a scrypt hash with a per-account salt. We cannot read it, and neither can anyone who obtains the database.
- Country. Optional, and only what you pick yourself: we never derive it from your address, your device or your connection. We hold it for one reason, which is to see which countries people are finding CinemaBin from, and it appears on your profile. Nothing else in the app reads it. Leave it empty and everything works the same.
- Profile photo. Optional. Picked from your photos, or taken with the camera if you choose that instead. It is cropped on your device and stored on our server, as WebP, or as JPEG on a device that cannot write WebP. Removing it deletes the stored image.
3.2 What you create while using it
- Log entries. The film or episode, the date you watched it, whether it was a rewatch, and whether you abandoned it and at which minute.
- Ratings and notes. A score out of five and any text you write about a title.
- Your shelves. Which titles are on your watchlist and which are in your library.
- Social activity. Who you follow, who follows you, pending follow requests, the entries you like and the comments you write.
- The numbers we work out from all this. How many films, series and episodes you have logged, how much time that adds up to, and how it falls across the months. These are calculated from the entries above rather than collected separately, they are shown to you on your own screens, and the totals appear on your profile to anyone who is allowed to see it.
Whether any of this is visible to other people is your decision, and there are three separate switches for it. A new account starts open: your log is visible, anyone may follow you without asking, and your library, everything you have finished, can be browsed from your profile.
Two of those three switches, library sharing and hiding a single title, arrived in the version of the app released on 7 September 2026. Before that they did not exist: there was one setting, the one that made an account private, and it covered the diary alone. If you are reading this because you remember it working differently, you are remembering correctly.
Accounts made before that release were not changed. Until then a new account started private, and we changed only what happens when an account is created from now on. Not a single existing account was switched from private to open: doing that would have published diaries on behalf of people who never agreed to it. If your account was private, it still is, and it stays that way until you change it yourself.
You can close any of it at any time, and the switches are independent rather than ranked. Making your account private hides your log from everyone except the followers you approve, one request at a time. Library sharing, on your own library screen, decides whether your shelf can be browsed at all; if your account is also private, that means your approved followers and nobody else. Turning library sharing off closes the shelf to everybody, followers included, while leaving the rest as it was. And any single title can be hidden on its own, in which case other people see that you watched something on that day but are never told what it was, and it does not appear in your library to anyone but you.
3.3 What we record so the app works
- Sessions. When you sign in we store a hashed session token, the time it was created, the time it was last used, its expiry, and the browser or app identifier string your device sends. The token itself lives in a cookie that JavaScript cannot read.
- Which version you are running. Every request from the app says which build of it and which platform, so we can tell you when an update is needed and stop serving a version that no longer works. It is not kept against your account; what we keep is the newest build we have seen anywhere, so the release notes can be written for it.
- Server logs. Our host records ordinary request logs, which include IP addresses, for the short period needed to keep the service running and to investigate abuse.
3.4 What you send us on purpose
- An imported history. If you bring a CSV export over from another tracker, we read the rows and turn them into log entries. The file itself is not stored: what is kept is the entries it produced, plus a short record of the run with the titles we could not identify, so the screen can show you what was missed.
- Support messages. What you write, the address you want a reply at, and the app version and platform, so nobody has to ask you for them.
- Reports. When you report a post, a comment or an account, we store who reported it, who it was about, the reason you picked, anything you typed, and a copy of the reported text as it read at that moment. The copy is the point: without it a complaint disappears the second somebody deletes what they wrote, and there is nothing left to judge. The person you report is not told that it was you.
- Blocks. If you block somebody we store that you did, so it can be applied and so you can undo it. They are not told, and they cannot see the list.
- Suspensions. If an account is suspended for breaking the terms, we store that it is, when, why, and who decided. The reason is shown to the account it concerns when they try to sign in, and to nobody else.
4. What we do not collect
The only counting we do is over our own database: how many accounts exist, how many were opened this week, how many entries have been logged, and the spread of countries people gave us. It is looked at in aggregate, on an internal screen, and it never leaves our server.
There is no analytics SDK in the app or on this website. No Google Analytics, no advertising identifier, no third party tracking pixel, no session recorder, no fingerprinting. We do not read your contacts, your photo library beyond the single image you pick, your location, or anything else on your device.
The camera is the one exception worth naming, because the app can ask for it. When you set a profile picture, the system offers to take a new photo as well as to pick an existing one. If you choose to take one, iOS or Android asks your permission first, and the picture goes where any profile picture goes and nowhere else. Choose the other option and the camera is never opened. We cannot see through it, and there is nothing in the app that turns it on by itself.
This website sets no cookies at all. The app sets exactly one, and it is the session cookie that keeps you signed in.
The app also keeps a few small things in your device's own storage, which never reach us: the language you picked, two version numbers that stop it showing you the same release notes or the same update prompt twice, and the title you left off on, so the sign-in screen can remind you. That last one is cleared the moment you sign out or your session ends. Nothing else is written there, and none of it is readable by anyone but the app.
The typefaces are served from our own domain rather than from a font service, so opening a page here does not hand your address to one.
We do not sell personal data, and we do not share it for advertising. There are no advertising partners to share it with.
5. Why we are allowed to hold it
Under the Serbian Law on the Protection of Personal Data, and under the GDPR where it reaches you, our lawful bases are:
- Performance of a contract. Your account, your log, your shelves and the feed are the service you asked for. Without this data there is nothing to provide.
- Legitimate interests. Session records, server logs and rate limiting exist to keep accounts secure and to stop abuse. Reports and blocks are here too: keeping a service usable for the people in it, and having a record of what was decided and why, is a legitimate interest of ours and of everyone else using it.
- Consent. The optional fields, meaning your country and your profile photo. You can withdraw either at any time by clearing the field.
6. Who else touches it
Us, first. A small number of people at Redtekk hold an administrator account, and it shows them a list of every account with its display name, profile photo, username, email address, country, the date it was opened, whether it is confirmed and whether it is private, and how many entries it has logged. It also shows the messages sent through the support form and the queue of reported content, with a copy of what was reported. It is used to answer support, to deal with reports, and to see how many people are here.
An administrator can also open your profile from that list, and doing so shows them what is on it even if your account is private, even if you are suspended, and even if you have blocked them. This exists for one reason: when somebody reports content, the person deciding what to do about it has to be able to read the thing that was reported. A moderator who has to act without seeing the content will either not act or act wrongly, and we think both are worse for you than the intrusion.
Two limits on that, so you know exactly how far it goes. A title you marked private stays private: hiding one title is a promise about that title, and the panel does not break it. And when an administrator opens a private profile this way, the profile itself says so on the page, every time, so it is never a silent thing even to the person doing it.
Beyond us, three companies are involved, each for one job:
- Railway hosts the server and the database. Everything described above is stored there.
- Resend sends the two emails the service sends: the confirmation code and the password reset code. They receive your email address and the contents of those messages, and nothing else.
- TMDB supplies titles, posters, episode lists and artwork. We send them the identifier of a title, never anything about you. Worth knowing: posters load straight from TMDB's image servers, so your device connects to them directly and TMDB sees that connection, including your IP address. That is true on this website too.
Beyond these, personal data is disclosed only if the law requires it of us, and we will tell you unless we are forbidden from doing so.
7. How long we keep it
- Your account and everything in it stays until you delete it.
- Sessions expire a year after they were last used, and are destroyed immediately when you sign out or delete your account.
- Confirmation codes expire thirty minutes after they are sent. Password reset codes expire after an hour. Both are stored hashed and are useless afterwards.
- Support messages are kept so a conversation can be finished. If you delete your account first, the message stays but its link to you is removed.
- Reports are kept after they are dealt with, so a decision can be looked up and so a pattern of behaviour is visible rather than being reset by each new complaint. If either account is deleted, the report loses its links to both, and to the post or comment it was about. What is left is the reason, the copy of the text, and the usernames as they were written down at the time. We keep those because a report with no name on either side cannot be checked against the one filed last month, which is most of the reason for keeping reports at all.
- Blocks last until you undo them, and are deleted with your account.
- The record of an import stays with your account, so the screen can still tell you which titles it could not match. It goes when the account goes.
8. Deleting your account
In the app, under Settings, then Delete account. You confirm with your password, and it happens on the spot. Your log, ratings, notes, shelves, follows, likes, comments, profile photo and sessions are removed with the account.
There is no recovery window and no soft delete, because the button says permanent. Copies may survive briefly in encrypted backups held by our host, which roll off on their own schedule and are never restored selectively.
One exception, and it is deliberate. While an account is suspended the button does not work. A suspension that the suspended account can erase for itself is not a suspension: it would let somebody remove the record of what they did and come straight back. Your right to have your data erased does not go away because of this, and the button is not the only way to use it. Write to hello@redtekk.com and we will deal with the request, weighed against the reason the account was suspended, and answer you either way.
9. Your rights
CinemaBin is run from Serbia, so Serbian data protection law applies to everybody using it, and the GDPR applies as well to anyone we are reaching in the UK or the EEA. Under either, you can ask us for a copy of your data, correct it, delete it, restrict or object to how we use it, or have it sent to somebody else. Most of this you can do yourself in the app; for anything you cannot, write to hello@redtekk.com and we will answer within thirty days.
If you think we have handled your data badly, you can complain to the Serbian Commissioner for Information of Public Importance and Personal Data Protection, and if you are in the UK or the EEA you can complain to your own national authority instead. We would rather you told us first.
10. How it is protected
- Everything travels over HTTPS.
- Passwords are scrypt hashes, never stored or logged in a readable form.
- Session tokens are stored hashed, so the database alone cannot be used to impersonate anyone.
- The session cookie is httpOnly and Secure, which keeps it out of reach of scripts.
- Deleting your account requires your password again, so a borrowed unlocked phone is not enough to erase your log.
No system is perfect. If a breach ever affects your data we will tell you and the relevant authority as the law requires.
11. Age
CinemaBin is for adults. You must be at least eighteen to have an account, and we do not knowingly collect anything from anybody younger. If you believe somebody under eighteen has an account, write to us and we will remove it.
12. Where the data lives
Redtekk is in Serbia. Our host and our email provider are United States companies, so your data may be processed outside Serbia, and outside the UK and the EEA. Where it is, the transfer relies on the standard contractual clauses those providers offer.
13. Changes to this policy
If we change it, the date at the top changes with it. For anything that meaningfully affects you, we will say so in the app rather than quietly editing this page.
14. Contact
hello@redtekk.com. A person replies.