← Back to Zappiness

Privacy Policy

Beta 1 Version · Last updated: 26/09/2026

1. DATA CONTROLLER

Data controller: Sergi Montesinos Tarres

Contact: contact@zappiness.app

2. SCOPE OF THIS POLICY

This Privacy Policy explains how Zappiness processes personal data necessary to provide and improve the service during the Beta phase.

For functional purposes, Zappiness distinguishes between:

  • Account: identity information necessary for authentication, access and session management.
  • Personal Profile: age or age range, gender and postcode, all optional.
  • Taste Profile: audiovisual preferences, filters, platforms, history, title states and signals used to personalise recommendations.
  • Technical and usage data: information necessary for operation, security, analysis and product improvement.
  • B2B data: statistics generated from use of the service under minimisation, generalisation and aggregation rules.

3. PERSONAL DATA ZAPPINESS PROCESSES

Depending on how each user uses the service, Zappiness may process:

a) Account and authentication data

  • account identifier;
  • email address and name provided through Google OAuth, where applicable;
  • technical information necessary to maintain the session.

Zappiness does not receive or store the user's Google password.

b) Optional Personal Profile

  • age or age range;
  • gender;
  • postcode.

c) Taste Profile and product usage

  • selected streaming platforms;
  • filters and preferences;
  • Favourites;
  • Watched titles;
  • Likes;
  • Dislikes;
  • Watch Later items;
  • lists;
  • history and signals from Train Zappiness;
  • signals from TurboZap and Suggest;
  • information needed to avoid repetitions and maintain consistency between sessions.

d) Technical data and telemetry

  • sessions;
  • screens and features used;
  • interactions;
  • internal conversions;
  • usage duration;
  • technical and performance events;
  • metrics necessary to validate the Beta;
  • simulated advertising metrics (banners and interstitials), where applicable.

Zappiness does not use IP addresses or user-agent strings as product data. However, the server infrastructure may temporarily log certain request information, including IP address, user-agent, date and time, requested resource, response code and, when present, referrer information, for operation, security and diagnostic purposes. These technical logs are rotated daily and retained for an approximate period of up to 14 days, after which they are deleted in accordance with the configured log-rotation policy.

4. PURPOSES OF PROCESSING

Zappiness uses personal data to:

  • create and maintain the account and session;
  • provide the service's features;
  • personalise recommendations through the Taste Profile;
  • retain preferences, title states and history necessary for operation;
  • measure the use, performance and quality of Zappiness;
  • detect errors, abuse and security issues;
  • analyse the Beta and improve the product;
  • measure simulated advertising during the Beta;
  • generate aggregated B2B statistics under the rules described in this Policy;
  • comply with legal obligations where necessary.

5. LAWFUL BASES

Because the Zappiness controller is established in Spain, the EU GDPR continues to apply to processing carried out in the context of that establishment. Where Zappiness offers services to individuals in the United Kingdom, the UK GDPR may also apply. The relevant lawful basis depends on the purpose:

  • Account, authentication, service operation and necessary personalisation: performance of the service requested by the user.
  • Metrics strictly necessary for operation, security and product improvement: legitimate interests, limited to what is necessary and subject to an appropriate balancing assessment.
  • Personal Profile — age/age range, gender and postcode —: specific, optional and revocable consent.
  • Compliance with legal obligations: compliance with a legal obligation where applicable.

The advertising used during the Beta is simulated. Any future real advertising and any consent or preference mechanisms required under applicable data protection or electronic communications law will be evaluated and implemented before activation.

6. PERSONAL PROFILE: CONSENT

The Personal Profile includes:

  • age or age range;
  • gender;
  • postcode.

It is optional and disabled by default.

Zappiness works even if the user does not provide this consent.

If the user enables the Personal Profile, Zappiness may use this information to generate B2B statistics in anonymised or aggregated form according to the system's rules.

Consent is recorded with:

  • consent type;
  • status;
  • policy version;
  • date granted;
  • date withdrawn, where applicable.

The initial consent version is personal_profile_v1.

7. WITHDRAWAL OF PERSONAL PROFILE CONSENT

Users may withdraw this consent at any time from the User screen.

When consent is withdrawn:

  • Zappiness stops using age, gender and postcode for new B2B operations;
  • the demographic-data row associated with the user is immediately deleted;
  • only the record necessary to document the withdrawal of consent and the relevant dates is retained;
  • the account remains active;
  • the Taste Profile remains intact;
  • lists, Favourites, Watched titles, Likes, Dislikes, Watch Later items, platforms, filters and other B2C data remain intact.

Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

8. TASTE PROFILE

The Taste Profile is separate from the Personal Profile.

It may contain preferences, filters, platforms, history, lists, title states and signals used to adapt how Zappiness operates and improve the relevance of recommendations.

Users do not need to provide age, gender or postcode in order to use the Taste Profile or Zappiness's main features.

9. TELEMETRY AND BETA METRICS

During the Beta, Zappiness records metrics needed to understand real product usage, evaluate internal conversions, detect issues and improve the service.

Telemetry that can be linked to an account may be retained for a maximum of 12 months. After that period, any retained historical information must be anonymised so that it is no longer linked to an identified or identifiable person.

Beta advertising is simulated. These metrics do not represent real advertising impressions and do not, by themselves, involve third-party advertising tracking.

10. B2B STATISTICS

Zappiness may generate B2B statistics from use of the service.

The B2B layer is designed not to export direct identifiers such as email address, name, account id, userKey or sessionId.

Before usable B2B information is stored, minimisation and generalisation measures are applied, including:

  • postcode: the full postcode remains private in the B2C profile; for B2B purposes it is first reduced to its first three characters;
  • age: grouped into age ranges;
  • event date and time: reduced to time blocks;
  • removal of direct identifiers.

Aggregates intended for B2B use apply an internal minimum threshold of n >= 20.

This threshold is an internal risk-reduction measure and is not a numerical requirement imposed by the EU GDPR or UK GDPR.

Groups that have not yet reached the threshold may be accumulated temporarily for up to 90 days. If they do not reach the threshold within that period, they are purged under the current system logic.

Before B2B reports are commercialised, Zappiness will conduct a specific legal review of the processing and re-identification risk under the EU GDPR, UK GDPR and other applicable data protection law.

11. RECIPIENTS AND SERVICE PROVIDERS

During the Beta, the main providers that may be involved in processing personal data are:

Google

Google is used for OAuth authentication. Google receives the information necessary to provide the authentication process and may process technical information associated with that access under its own policies.

AWS Lightsail

AWS Lightsail is used as the technical infrastructure and execution environment for the service.

Neon PostgreSQL

Neon PostgreSQL is used as the service's database infrastructure and may be involved in storing and technically processing data necessary for Zappiness to operate.

TMDB

TMDB is used as a provider of audiovisual data and metadata. Zappiness sends catalogue requests through its server and does not send TMDB personal identifiers of the user. Text entered into a search may form part of a catalogue request without being associated with a userKey, email address or other personal identifier.

JustWatch

JustWatch is a source of information about streaming-platform availability supplied through TMDb. Zappiness does not maintain a direct integration with JustWatch and does not send it personal identifiers of users.

Zappiness does not sell users' personal data.

12. INTERNATIONAL DATA TRANSFERS

Some technology providers may process personal data from countries outside the European Economic Area or the United Kingdom.

Where EU transfer rules apply, transfers must use a legally recognised mechanism such as an adequacy decision, Standard Contractual Clauses or another valid safeguard. Where UK transfer rules apply, restricted transfers must be covered by UK adequacy regulations, appropriate safeguards or another lawful transfer mechanism.

The providers and applicable transfer arrangements must remain aligned with the services actually used by Zappiness.

13. RETENTION

Personal data is retained for as long as necessary for its purpose:

  • account and session: for as long as necessary to provide the service and manage access, subject to applicable technical and legal retention requirements;
  • Personal Profile: while consent remains active; when consent is withdrawn, age, gender and postcode are deleted;
  • Taste Profile: while necessary to provide account-related features, unless the user requests a reset or deletion;
  • account-linkable telemetry: up to 12 months; after that, only effectively anonymised historical information may be retained where appropriate;
  • B2B data below the threshold: up to 90 days under the current rules;
  • B2B aggregates that have ceased to be personal data through effective anonymisation may be retained as statistical information that is not linked to an individual.

14. PROFILE RESET AND ACCOUNT DELETION

The Reset Profile feature deletes the personal data and preferences defined for that reset while keeping the access account.

The Delete Account feature deletes or disassociates associated personal data according to the functionality actually implemented and applicable legal obligations.

Information previously anonymised in an irreversible manner and no longer capable of identifying an individual is no longer treated as personal data associated with the account.

15. COOKIES, LOCALSTORAGE AND SESSIONSTORAGE

The Beta technical audit identified only cookies that are strictly necessary for authentication and security:

  • zappiness_session: authentication session cookie;
  • zappiness_oauth_state: temporary security/CSRF cookie used during OAuth sign-in.

Zappiness also uses localStorage and sessionStorage for device preferences and technical functions, including PWA state, viewed help content, local Train Zappiness history, preferences, backgrounds and the technical telemetry session.

Zappiness currently does not use third-party analytics cookies, real advertising cookies or third-party advertising-tracking mechanisms.

Under the current Beta configuration, the storage and access technologies used are limited to those considered strictly necessary for the online service requested by the user, authentication and security. Zappiness therefore does not currently deploy a cookie-consent banner or consent management platform for these technologies.

If Zappiness later activates real advertising, third-party analytics or any other storage or access technology requiring consent under the Privacy and Electronic Communications Regulations (PECR) or other applicable law, the required mechanisms will be implemented before activation.

16. SECURITY

Zappiness applies reasonable technical and organisational measures designed to protect information against unauthorised access, loss, alteration or misuse.

Measures reviewed during the Beta include authentication, session management, access controls, persistence controls, permission separation, endpoint protection, B2B minimisation, secret management and maintenance and recovery procedures.

17. YOUR DATA PROTECTION RIGHTS

Where the relevant law applies and the applicable conditions are met, users may exercise rights including:

  • the right to be informed;
  • the right of access;
  • the right to rectification;
  • the right to erasure;
  • the right to restriction of processing;
  • the right to object;
  • the right to data portability;
  • the right to withdraw consent.

Requests and data protection complaints may be sent to:

contact@zappiness.app

Users in the United Kingdom may also raise a complaint with the Information Commissioner's Office (ICO) where UK data protection law applies. Users whose processing is subject to the EU GDPR may also lodge a complaint with the Spanish Data Protection Agency (AEPD) or another competent European supervisory authority.

18. ADULT USERS

Zappiness Beta is intended for users aged 18 or over.

Zappiness does not intend to knowingly collect personal data from persons under 18 during this phase.

19. CHANGES TO THIS PRIVACY POLICY

Zappiness may update this Policy to reflect changes in the service, processing activities, providers, infrastructure or applicable law.

When changes are material, the date will be updated and, if a change affects an existing consent, the relevant consent version will also be updated where required.

20. PERMANENT ACCESSIBILITY

The Legal Notice and this Privacy Policy must remain permanently accessible from:

  • the Login screen;
  • the Zappiness User screen.

21. EFFECTIVE VERSION AND CONTACT

This Privacy Policy applies to Beta 1 in the version identified at the beginning of this document.

For privacy questions, data protection complaints or to exercise your rights:

contact@zappiness.app