watchlog
Privacy Policy
Last updated: 21 August 2026
This policy covers watchlog for iPhone. It is written to comply with UK data protection law, including the UK GDPR and the Data Protection Act 2018.
The short version
- We collect nothing. No accounts, no sign-up, no analytics, no advertising, no tracking, no crash-reporting SDK. We run no server, so there is nowhere for your data to go.
- Your library — what you track, what you've watched, your ratings and stats — is stored on your iPhone, and we never see it.
- To show you titles, artwork and air dates, the app asks TMDB and TVmaze about specific titles. What you search for, and which titles are in your library, do reach those services. This page is specific about that.
- Notifications are scheduled on your phone. There is no push server and the app never obtains a push token.
- watchlog is free. There is nothing to buy, and no in-app purchases.
Who we are
watchlog is made by Sassy Pants, an independent app studio, and published on the Apple App Store. For anything in this policy, contact [email protected].
What we collect about you
Nothing. There is no account, no profile, no identifier assigned to you and no telemetry. We operate no server and run no analytics, so your library, your viewing history and your usage never reach us. The app does contain an internal device identifier used to order its own local records — it never leaves your phone.
What the app stores on your iPhone
Everything you build up in watchlog lives in a single database on your device: the shows and films you track, episode-by-episode watch history, ratings, and the statistics derived from them. There is no cloud account and no sync service — the app has no server to sync with.
Two honest caveats, because "it stays on your phone" deserves to be exact:
- Your own device backups. The database is not excluded from iOS backups, so if you use iCloud Backup or an encrypted computer backup, your library is included in your backup. That is between you and Apple, under your Apple Account; we have no access to it. (A planned update will let you control this more precisely.)
- Exports you create. When you export your library, the app writes a JSON file and hands it to the iOS share sheet so you can save it where you like. A copy of that file also stays in the app's temporary cache until the next export replaces it, or until you delete the app.
What reaches TMDB and TVmaze
watchlog has no database of its own for film and TV metadata, so it asks two public services. This is the only network traffic the app produces, and it is worth being precise about, because it is more than just search.
- Who: TMDB is the primary source for titles, artwork, air dates and where-to-watch availability. TVmaze is used as a fallback for TV when TMDB cannot answer. Posters load from their image services,
image.tmdb.organdstatic.tvmaze.com. - What you search for. The text you type into the add-title search is sent to TMDB — and to TVmaze if TMDB's answer fails. Searching is debounced, so a single search usually produces a few requests as you pause typing, not one per keystroke.
- Opening the add screen. The app loads popular titles as soon as that screen opens, so a request goes out before you type anything.
- Which titles are in your library. This is the important one. Your library rows stay on your phone, but the app periodically refreshes their details, which means sending each stored title's ID to TMDB. Over time, TMDB therefore receives a title-by-title picture of what you track — not as an account or a profile, but as a stream of requests from your IP address.
- What you are looking at. Opening a title's detail screen fetches recommendations for it, which tells TMDB which title you are viewing.
- Adding a show fetches its details plus one request per season, so a long-running series produces a burst of requests.
- Importing sends the IDs of the titles you import, the same way adding does.
- What is not sent: no account, no device identifier, no advertising identifier, no ratings, no watch history, and no region. Where-to-watch data covers every region and is filtered on your phone, so your location is never disclosed to get it. JustWatch availability arrives inside TMDB's response — the app never contacts JustWatch directly.
- Unavoidably: as with any app talking to any server, those services can see the IP address the request came from and roughly when. Your IP address is personal data under UK GDPR, so we would rather name it than pretend otherwise. We never receive it. Their handling is governed by TMDB's privacy policy and TVmaze's privacy policy. All traffic is encrypted over HTTPS.
Notifications
New-episode reminders are scheduled locally by your phone. The app never registers for remote push and never obtains a push token, so no notification server — ours, Apple's or anyone else's — is told what you watch. Notification permission is the only permission watchlog asks for; you can decline it and everything else still works.
Permissions
Other than notifications, the app requests no permissions at all: no location, no contacts, no photos, no camera, no microphone, no calendar. It does not use the App Tracking Transparency prompt because it does not track you across apps or websites and never touches your device's advertising identifier.
Crash reports and App Store statistics
We deliberately ship no crash-reporting SDK. However, because the app is distributed through Apple with debug symbols, Apple may share crash and performance diagnostics with us — but only from users who opted in to sharing analytics with developers, and only in Apple's aggregated, non-identifying form. Apple also gives every developer anonymous App Store statistics such as download counts and rough territory. We cannot identify anyone from any of it, or connect it to your library. We also see App Store ratings and reviews, which carry whatever name you chose to publish them under.
Paying for the app
watchlog is free. There are no in-app purchases, no subscriptions and no adverts, so we never see payment details of any kind — there are none to see.
If you email us for support
When you email us, we receive your email address and whatever you put in the message. We use it only to reply and to fix the problem, relying on our legitimate interests (Article 6(1)(f) UK GDPR) in supporting our apps. Support emails are kept for up to 24 months and then deleted. Your address is never added to a marketing list and never shared.
Children
watchlog is not directed at children. It collects no data from anyone of any age, contains no advertising and has no chat or user-generated content. Search results come from TMDB with adult content excluded.
Your rights
Under UK GDPR you have the right to access, correct, erase, port, restrict or object to the processing of your personal data, and to withdraw consent where consent is what we rely on.
For the app itself there is nothing to exercise these rights against: we hold no personal data about you, so there is nothing for us to hand over, correct or delete. Your library is on your phone under your control — the export feature is your right to portability in practice, and deleting the app erases everything. Where these rights do apply is any support email you have sent us: write to [email protected] and we will act within one month.
Complaints
If you are unhappy with how we have handled your data, please tell us first and we will try to put it right. You can also complain to the Information Commissioner's Office (ICO) at ico.org.uk.
International transfers
We hold no personal data, so we transfer none ourselves. TMDB and TVmaze are US-based services, so requests your phone makes to them leave the UK. Those requests carry no account or identifier — only the title or search term being looked up, and the IP address inherent in any internet connection.
App Store privacy label
Our App Store listing declares Data Not Collected. That is accurate in Apple's sense: neither we nor any embedded third-party SDK collects or retains data from the app. It is not a claim that the app never talks to the internet — the section on TMDB and TVmaze above sets out exactly what it does.
Changes to this policy
If the app's data behaviour ever changes — a new data source, a sync feature, anything at all — we will update this page and the date at the top before that version ships, and say so in the release notes.
Contact
Need help with the app? See watchlog support. Looking for our studio-wide policy, covering this website and our other apps? See the main privacy policy.