Privacy Policy
Last updated 29 September 2026
This policy explains what Critic Shelf collects, why, and what control you have over it. Critic Shelf is a film and TV app built around a profile you can share — rate what you have seen, write reviews, keep a watchlist, build shelves, follow other people and compare your taste with theirs. This policy covers the account you create to do that.
Information we collect
Account information: your email address, username and a password. Your password is hashed before it is stored — we never keep it, or see it, in plain text.
Profile information: anything you choose to add to your profile, such as a display name, a short bio, an avatar image, your top-five picks and the taste tags you pick for yourself.
Content you create: ratings, reviews, watchlist entries, the episodes you mark watched, and who you follow — both other Critic Shelf accounts and the cast and crew you follow on title pages.
Technical information: standard request data (such as IP address and device/app version) used only to keep sign-in secure, enforce rate limits against abuse, and diagnose errors.
Crash and error diagnostics: if the app or our servers hit an unexpected error, technical details about it — such as a stack trace, the app version and device type — are sent to our crash-reporting processor, Sentry. Where you are signed in, this is tied to your internal account id, never your email or username. It never includes a review, a message, or anything else you have typed.
Product analytics: which screens you open and a small set of actions — rating or reviewing something, adding to your watchlist, following someone, creating a shelf, choosing your top fives, sharing a card or a link, finishing or skipping the onboarding tour, signing up (and whether with email, Apple or Google) — tied to a pseudonymous identifier, not your email or username, and sent to our analytics processor, PostHog. No review text, no messages, and nothing you type is included. We do not run any advertising trackers, and this data is never sold or shared with advertisers.
Push notification token: if you enable notifications, your device registers a token with Apple's or Google's push service. We use it only to deliver the notifications described below — who followed you, helpfulness votes on your reviews, and moderation notices — never for advertising.
How we use it
To run the features you are using it for: your shelf, your reviews, the profiles and reviews of people you follow, and the film/TV pages themselves.
To verify it is you: signing up and resetting a forgotten password both work by emailing a one-time code to the address on the account.
To keep the service secure and working: rate-limiting sign-in and code requests, and investigating abuse reports.
To email you account-relevant messages — verification codes and security notices. We do not send marketing email today, and if that changes it will be opt-in.
Who we share it with
This product uses TMDB and the TMDB APIs but is not endorsed, certified, or otherwise approved by TMDB. Film, TV and cast artwork and metadata shown in the app come from TMDB's API — browsing the catalogue does not send TMDB anything about your account.
Verification and password-reset emails are sent through a transactional email provider on our behalf, solely to deliver that one email.
An uploaded avatar image is stored with a cloud storage provider so it can be served back to the app; it is not shared with anyone beyond what is needed to host and display it. Before it is stored, the image is checked by an automated image-moderation service on our behalf, solely to keep explicit or violent images off public profiles.
If you enable notifications, your push token is passed to Expo's push service, which relays it to Apple or Google to deliver the notification to your device. They act as delivery processors only.
Product analytics (the screens and actions described above) is processed by PostHog, solely to help us understand how Critic Shelf is used and to fix what isn't working.
Crash and error diagnostics (described above) are processed by Sentry, solely to help us find and fix bugs.
We do not sell personal information, and we do not share it with advertisers or data brokers.
How long we keep it
Your account and everything attached to it — ratings, reviews, watchlist, follows — is kept for as long as the account exists.
Deleting your account (Settings → Account settings → Delete account) removes all of it permanently. That action cannot be undone, which is why the app asks you to confirm it explicitly before it happens.
A small moderation record outlives a deleted account: a note that the account (its username and internal id) was deleted, plus any reports other people filed about it and the moderator decisions on them. It is kept for up to 2 years, to deal with abuse and legal requests, and then removed.
Every step, and what is kept, is on our account deletion page: criticshelf.com/delete-account.
Your choices
You can view and change most of your profile at any time from Edit profile.
You can delete your account and everything on it at any time from Account settings — no one else needs to action that for you.
You can turn push notifications off at any time from Settings, or at the operating-system level. Either way, the in-app notifications list under the bell icon still shows the same activity — turning off push only stops the device alert.
A self-service data export is planned but not built yet. Until then, email support@criticshelf.com and we will get you a copy of your data.
Children's privacy
Critic Shelf is not directed at children, and we do not knowingly collect information from anyone under 13. If you believe a child has created an account, contact us and we will remove it.
Changes to this policy
If this policy changes in a way that matters, we will update the date at the top of this page. Continuing to use Critic Shelf after a change means you accept the updated policy.
Contact
Questions about this policy, or a request about your data: support@criticshelf.com.