← Back to FilmerQuiz

Privacy Policy

Last updated: April 1, 2026

1. Data controller

The data controller responsible for your personal data is:

ALMACAS 1987 SL

Tax ID: B-XXXXXXXX

Contact: hola@filmerquiz.com

FilmerQuiz is an educational quiz application about movies and TV shows for the whole family.

2. Data we collect

When you create an account or use FilmerQuiz, we collect the following data:

  • Email: provided when you sign up via magic link, Google Sign In, or Apple Sign In. We use it to authenticate you and contact you if necessary.
  • Payment customer ID: if you purchase FilmerQuiz Plus, we create a Stripe Customer ID (web) or RevenueCat ID (mobile app) to manage your purchase.
  • Quiz history: movies played, scores, and dates. Stored on our servers linked to your account so you can track your progress.
  • Daily usage: count of quizzes taken each day to manage the limits of your plan (Guest, Free, or Plus).
  • Push notification tokens: if you enable notifications, we store your device token to send you alerts.
  • Anonymized IP address: hash of your IP in request logs for abuse control and rate limiting. We do not store your full IP address.
  • Preferences: visual theme, sound, local history, and daily limit are saved locally in your browser (localStorage). This data is not transmitted to our servers.

Data we do NOT collect:

  • Location or GPS
  • Phone contacts
  • Photos or device files
  • Browsing data outside FilmerQuiz
  • Advertising identifiers

3. Legal basis for processing (Art. 6 GDPR)

Each processing of personal data is based on a specific legal basis:

  • Authentication (email, account): contractual performance — necessary to provide you with the service.
  • Payments (Stripe, RevenueCat): contractual performance — necessary to process your purchase of FilmerQuiz Plus.
  • Request logs (hashed IP): legitimate interest — necessary for service security and abuse prevention.
  • Audience measurement (Umami): legitimate interest — necessary to improve the service. Data is aggregated and anonymous.

4. Cookies and local storage

FilmerQuiz does not use advertising, marketing, or retargeting cookies. Below is a complete list of all cookies and storage mechanisms we use:

Session cookies (exempt from consent)

  • filmerquiz-auth: authentication cookie that keeps your session active. Deleted when you log out.
  • NEXT_LOCALE: stores your language preference (es/en). Required for the app to function.

Persistent cookie (explicit consent)

  • "Keep me logged in": if you check the "Keep me logged in for 30 days" checkbox when logging in, the authentication cookie is extended to 30 days. This consent is explicit via checkbox. To withdraw consent, log out.

Payment cookies (necessary)

  • __stripe_sid: Stripe technical cookie, only present during the payment process. Stripe acts as a data processor.

Stripe cookie settings

Local storage (localStorage)

We store in your browser's localStorage: visual theme, sound preference, local quiz history, and daily limit counter. These are functional data that are not transmitted to our servers.

Audience measurement

We use Umami, a self-hosted analytics tool at analytics.filmerquiz.com. Umami does not use cookies, does not identify individual users, does not store IP addresses, and only generates aggregated data. This data is not shared with third parties.

We do not use advertising, marketing, or retargeting cookies of any kind.

5. Third-party services and international transfers

FilmerQuiz uses the following external services. Some involve international data transfers:

  • Stripe (USA) — web payment processor. Receives your email and transaction data to process FilmerQuiz Plus payments. Acts as a data processor. Safeguard: Data Privacy Framework. Privacy policy: https://stripe.com/privacy
  • RevenueCat (USA) — mobile payment processor. Acts as a data processor for in-app purchases (App Store / Google Play). Safeguard: Data Privacy Framework.
  • Google (USA) — OAuth authentication and AI. Receives your email when you sign in with Google Sign In. We also use Google Gemini to generate quiz questions, but we only send movie information, never personal data. Safeguard: Data Privacy Framework.
  • Apple (authentication) — receives your email when you sign in with Apple Sign In (may be an Apple relay email).
  • Resend (USA) — email delivery. Receives your email to send you the magic login link. Safeguard: Data Privacy Framework.
  • TMDB (USA) — movie and TV show data. We use their API to obtain titles, synopses, and posters. We do not send them any personal user data, only movie searches.

6. Data retention periods

We retain your data for the following periods:

  • User account (email, history, purchases): until the user deletes it.
  • Request logs (hashed IP, request metadata): 90 days. Automatically purged.
  • localStorage data (theme, sound, local history): until the user manually clears it from their browser.

7. Protection of minors

FilmerQuiz includes content adapted for different ages (3-5, 6-8, 9-12, 13+). The 3-5, 6-8, and 9-12 age bands are aimed at children under 13.

  • Age verification (parental gate) is required for the under-13 age bands.
  • We do not collect additional personal data from minors beyond what is strictly necessary for the service to function.
  • Minors cannot create an account without parental supervision.
  • If we detect that a child under 13 has created an account without parental consent, we will delete it along with their data.
  • We do not display advertising of any kind, neither targeted at minors nor adults.
  • Parents or guardians can contact us at hola@filmerquiz.com to request information about their children's data or request its deletion.

8. Data deletion

You can delete your account and all your data from the profile section of the app. This will permanently delete: your email, quiz history, purchase data, and notification tokens. This action is irreversible. You can also request deletion by contacting us at hola@filmerquiz.com.

9. Storage and security

Your data is stored on protected servers. All communication between your device and our servers is encrypted via HTTPS/TLS. Passwords are not stored: we exclusively use passwordless authentication (magic link, Google, or Apple).

10. Your rights (GDPR)

If you reside in the European Union, you have the following rights over your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: request correction of inaccurate data.
  • Erasure: request deletion of your personal data.
  • Portability: receive your data in a structured, commonly used format.
  • Objection: object to the processing of your personal data.
  • Restriction: request restriction of the processing of your data.

To exercise these rights, contact us at hola@filmerquiz.com.

You also have the right to lodge a complaint with the supervisory authority: Spanish Data Protection Agency (AEPD) — www.aepd.es.

11. Changes to this policy

We may update this privacy policy from time to time. Any significant changes will be communicated through a visible notice in the application.

12. Contact

If you have questions about this privacy policy or how your data is handled, write to us at hola@filmerquiz.com.

TMDB Attribution

This product uses the TMDB API but is not endorsed or certified by TMDB. Movie and TV show data is provided by themoviedb.org.