MovieCal

Privacy policy

Version: 1 (draft) · Effective: pending launch · Last updated: 2026-06-07

Short version: MovieCal collects only the data needed to give you a calendar of the movies you care about. Nothing is opted-in by default. You can export everything, delete everything, with one click. Servers are in the United States. We don't sell, share, or use your data to personalize ads.

This is the privacy policy for MovieCal (moviecal.app), operated by Vixen Labs LLC (a US limited liability company). It explains exactly what data we collect, why, and what control you have over it.

Status: v1 draft. The site is not yet accepting signups. A US tech lawyer will review this policy before MovieCal launches.


What we collect

The only data we keep about you is the data needed to deliver the features you sign up for.

When you create an account:

  • Email address — for sign-in, account recovery, and (if you opt in) the weekly digest. Stored case-insensitively.
  • Password hash — argon2id; we never store the plaintext password.
  • WebAuthn passkeys (if you choose to add one) — public key, credential ID, sign counter, transports (USB / NFC / BLE / internal), and a friendly label you pick ("YubiKey 5", "iPhone").
  • Country — used to filter your calendar to releases in your region. Stored as a two-letter ISO code (e.g. US).
  • Locale — your preferred language tag (e.g. en-US).
  • Account timestamps — when you created the account and when you verified your email.

When you opt in to a feature, we record the moment you opted in:

  • Weekly digestdigest_opt_in_at timestamp.
  • Marketing announcementsmarketing_opt_in_at timestamp.
  • (Future opt-in categories will follow the same pattern.)

When you build a watchlist:

  • The titles you add — either directly on MovieCal or synced from Letterboxd / TMDb / Trakt (when those integrations land).
  • Connected-watchlist usernames — your Letterboxd / TMDb / Trakt username + last-synced timestamp, if you choose to sync.

When you subscribe to a calendar feed:

  • A per-user feed URL with a random token, and the filters you applied to it (e.g. "US theatrical only").

When you visit any page:

  • Aggregate, cookieless analytics — page-view and event counts (which pages are popular, where visitors arrived from) via our own self-hosted analytics (Umami). No cookies, no user IDs, no cross-site tracking, no personal profiles — the data can't be tied back to you. It honors your browser's Do-Not-Track / Global Privacy Control signal.

When advertisers serve impressions on the site or in the newsletter:

  • Aggregate impression counts per ad — not per user. We do not log which user saw which ad beyond a short anti-fraud window (≤7 days) that is not used for any other purpose.
  • Sponsor banner counts are first-party + cookieless — a sponsor's per-week banner impression and click totals are simple aggregate counters in our own database (a 1×1 pixel for impressions, a click-through redirect for clicks), bot-filtered and never tied to an individual visitor.

That's it.

What we don't collect

Stated plainly so you can hold us to it:

  • No browsing history beyond what's needed to render the page you're looking at right now.
  • No inferred taste profiles — we don't build a model of "what kinds of movies you like" or sell one to anyone.
  • No cross-site tracking — we don't embed third-party trackers, ad-network pixels, or "social share" scripts that report back.
  • No third-party analytics — our analytics is first-party, self-hosted, and cookieless (Umami); we run no Google Analytics, Facebook Pixel, or any tool that shares data with ad networks.
  • No location beyond the country you set in your account.
  • No device fingerprinting.
  • No data about people who haven't signed up — public calendar feeds are anonymous; we don't try to identify the subscriber from the request.

How we use what we collect

  • Email address — sending the magic-link recovery email, the weekly digest (if opted in), and material policy / security notices.
  • Password hash + passkeys — authenticating you.
  • Country + locale — filtering your calendar and rendering it in your preferred language.
  • Watchlist + connected-watchlist state — populating your personal calendar feed.
  • Calendar feed URLs + filters — generating the iCal output your calendar app requests.
  • Aggregate ad impressions — showing advertisers how their sponsored placement performed.
  • Aggregate, cookieless analytics — understanding which pages and releases are popular to guide editorial + product decisions, and showing advertisers/sponsors aggregate traffic and click counts. Never tied to an individual.

We do not use any of this data for any purpose other than the ones listed above.

Sharing

We do not sell, rent, or trade your personal data. Period.

We share data with a third party only in these specific, named cases:

  • Stripe — when an advertiser purchases a sponsorship via the self-service portal, billing details flow to Stripe for payment processing. Stripe is the merchant of record and handles its own privacy obligations; see Stripe's privacy policy.
  • Email delivery provider — Postmark (postmarkapp.com). All MovieCal email (account verification, password recovery, email-change confirmations, contact-form replies, the weekly digest) goes through Postmark. The provider handles delivery, bounce handling, and — for the weekly digest only — open and click tracking (see Email tracking). Postmark does not retain message content beyond what is needed for those purposes.
  • Pushover / Home Assistant — only for operational notifications about MovieCal itself (worker-job completion, error alerts) sent to Vixen Labs' own infrastructure. Your data is not part of these notifications.

We never share your data with advertisers, ad networks, data brokers, or marketing platforms.

Email tracking

MovieCal sends two kinds of email, and treats them differently for tracking:

Transactional email — not tracked

Account-related email — verification links at signup, password recovery, email-change confirmations, replies to your contact-form messages — has open tracking and link tracking disabled. The links in those emails go directly to the destination; no Postmark redirector sits in the middle. No invisible pixel is loaded when you open the message. We don't know whether or when you opened a verification email.

The control is enforced at the Postmark server level (Open Tracking + Link Tracking both off) and reaffirmed at every API call site in our code (each transactional send explicitly passes TrackOpens: false, TrackLinks: 'None').

Weekly digest — opens and clicks tracked, in aggregate

If you've opted into the weekly digest, those emails do include open tracking (a 1×1 pixel hosted by Postmark) and link tracking (the HTML links route through a Postmark redirector before reaching the destination URL). The plain-text fallback always carries the real, unrewritten links — screen readers and forwarding pipelines see the destinations directly.

Newsletter links also carry campaign parameters (e.g. utm_campaign=weekly_digest) so our cookieless analytics can attribute site visits back to the digest in aggregate — the attribution is bound to the campaign, never to you.

What we use this data for:

Use What it looks like
Editorial improvement "This week's open rate: 38% vs 31% last week" — informs subject-line + send-time decisions
Sponsor reporting "Your sponsored slot was clicked N times across M sends" — the aggregate counts are bound to the ad, not to individual users
Featured-title signal "The Brutalist outperformed the runner-up 12-to-1 in click-throughs" — informs next week's editorial picks
List hygiene If you haven't opened any digest in 6 months, we'll stop sending — implicit unsubscribe, saves you and us bandwidth
Bot-prefetch filtering Detect inflations from services like Apple Mail Privacy Protection so sponsor metrics stay honest

What we will never do with it:

  • Build a per-user "engagement score" that affects what content you see
  • Tie open or click behavior to your watchlist for any personalization purpose
  • Sell, share, license, or transfer this data to anyone
  • Send "you haven't opened our email in 30 days, here's a special offer"-style retargeting
  • Correlate Postmark engagement events with MovieCal session cookies for device fingerprinting

How to opt out:

  • Unsubscribe link in every digest (one-click — RFC 8058 honoured by Gmail / Yahoo / iCloud / Apple Mail)
  • Email preferences toggle on your Account page — disables the digest immediately
  • Delete your account — removes you from every list and deletes all stored engagement data

Disabling the digest is the only way to opt out of digest tracking. There is no separate "send me the digest but without tracking" option — the engagement data is what powers the editorial decisions and the sponsor model that make the digest viable. If you want a tracking-free read on what's coming out this week, every release calendar and the title detail pages are public and unauthenticated.

Affiliate links

Some outbound "buy / own" links on title and release pages are affiliate links — we're a participant in the Amazon Associates program (and may add other retail affiliate programs, e.g. via CJ Affiliate). If you follow one and make a qualifying purchase, we may earn a commission at no extra cost to you. As an Amazon Associate we earn from qualifying purchases.

  • What we see: only an aggregate, cookieless count of affiliate-link clicks per retailer (via our first-party Umami analytics) — never tied to you as an individual, and never your purchases.
  • What the retailer sees: once you follow an affiliate link you're on the retailer's site (e.g. Amazon), and their privacy policy and cookies apply — not ours.

Your rights

These apply to everyone, not just EU/UK residents:

  • See your data. Your account page shows everything we store about you.
  • Export your data. One click on your account page produces a synchronous download containing your profile, full watchlist (internal + last-synced state of external sources), calendar feed URLs, email-subscription preferences, and any ad-impression history. Format: JSON for structured data, iCal for calendar feeds. No waiting period.
  • Correct your data. Edit your country, locale, email, watchlist, and connected accounts directly from your account page.
  • Delete your account. One click. Cascades through all your data: watchlists, calendar feeds, email subscriptions, passkeys, and (anonymized) ad-impression counts. You'll receive a confirmation email after deletion, not before. If you sign up again with the same email later, it's a new account — no soft-delete restoration.
  • Opt out of any data use. Every non-essential data use is a separate toggle. You can disable the weekly digest, marketing announcements, etc. from your account page at any time. Each toggle disables in one click.
  • Lodge a complaint. Email privacy@vixenlabs.info. If you're an EU/UK resident, you can also lodge a complaint with your data protection authority (see list of EU DPAs).

EU/UK users

MovieCal is operated from the United States. Servers and personnel are in the US. If you live in the EU, EEA, or UK and sign up, your personal data is transferred to and processed in the US.

We rely on the EU Standard Contractual Clauses (2021) (with the UK addendum for UK residents) as the legal basis for that transfer.

Our processing posture is designed to meet GDPR / UK-GDPR from day one regardless of where you live:

  • Lawful basis: consent (for opt-in features) and contract (for account services).
  • Data subject rights (access, rectification, erasure, portability, restriction, objection) are all available from your account page.
  • Children's data is not knowingly collected — see "Children" below.
  • We do not engage in automated decision-making with legal or similarly significant effects.

If MovieCal grows beyond the threshold for "occasional / low-risk processing," we will appoint an Article 27 EU Representative. As of the effective date, we believe MovieCal qualifies for the occasional-processing carve-out; a lawyer will confirm.

Cookies

MovieCal sets only first-party, essential or functional cookies:

  • A session cookie so you stay signed in.
  • A CSRF token cookie to protect form submissions.
  • A preference cookie (home_watchlist) that remembers whether your home page is filtered to your watchlist or showing everything.

We do not set advertising or tracking cookies. Our analytics is cookieless — the self-hosted Umami instance sets no cookies and stores no personal data (see What we collect). We do not run third-party scripts that set cookies. The preference cookie above is a functional first-party cookie that does not require consent, so there is no consent banner.

If we ever introduce a non-essential cookie that does require consent, we will ask first.

Security

  • Passwords are hashed with argon2id (memory-hard, current best practice). We never store plaintext passwords.
  • All connections to MovieCal use HTTPS with a valid Let's Encrypt certificate.
  • Passkeys (WebAuthn / FIDO2) are available as a stronger alternative to passwords.
  • The production database (PostgreSQL 16) is reachable only from the same Opalstack host that runs the app — no external DB connections.
  • We use rate limiting on login attempts to slow down credential-stuffing attempts.

No security posture is perfect. If you find a vulnerability, please email privacy@vixenlabs.info — we will respond promptly.

Children

MovieCal is not directed to children under 13 and we do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has provided personal data, email privacy@vixenlabs.info and we will delete it.

Changes to this policy

We will email all account holders about any material change to this policy before it takes effect, at least 14 days in advance, so you can decide whether to keep your account.

Non-material changes (typo fixes, clarifications, structural reorganizations that don't change what's collected, how it's used, or who it's shared with) will be reflected here with a version bump but without an email.

The change history is at the bottom of this document.

Contact

Email privacy@vixenlabs.info for any privacy question, complaint, or data request.

Postal mail: Vixen Labs LLC, [address to be added before launch].


Change history

Version Date Notes
1 2026-05-31 (pre-launch draft) Initial draft. Not yet in effect — the site is not accepting signups.
1.1 2026-06-07 (pre-launch draft) Named Postmark as the email delivery provider; added the Email tracking section spelling out the transactional-vs-digest two-tier policy.