Effective date: April 19, 2026
RandomFlix (“we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use randomflix.ai (the “Service”).
By using the Service, you agree to the collection and use of information in accordance with this policy. This policy should be read alongside our Terms of Service.
Account information (provided by you via Clerk):
User-generated content:
Automatically collected information:
We use the information we collect to:
We use the following third-party services that may receive or process your data:
The following services are used server-side only and do not receive your personal data: TMDb (movie metadata), OpenAI (movie content embeddings), and Streaming Availability API (streaming data).
We do not sell, rent, or trade your personal information to third parties.
We share your data only with the third-party service providers listed above, solely for the purpose of operating the Service. We may also disclose your information if required by law, legal process, or governmental request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
We retain your personal data for as long as your account is active or as needed to provide the Service. When you delete your account (via the Account page, managed by Clerk), your personal data is removed from our systems via an automated webhook process.
Anonymized or aggregated data that cannot be used to identify you may be retained indefinitely for analytical purposes.
Guest data stored in browser cookies and local storage persists on your device until you clear it manually or it expires. We do not have access to guest data stored only in your browser.
Depending on your location, you may have the following rights regarding your personal data:
To exercise any of these rights, please contact us. We will respond to your request within 30 days.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):
Lawful basis for processing:
You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated. To contact us about GDPR-related matters, please use our contact form.
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
Categories of personal information collected: identifiers (email, username), internet activity (browsing history, interactions with the Service), and inferences (taste profiles derived from your movie preferences).
To exercise your CCPA rights, please contact us.
The Service is not directed to children under 13 years of age (or 16 in the EEA). We do not knowingly collect personal information from children under these ages. If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us.
We implement reasonable technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include:
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security.
Your data may be transferred to and processed in the United States, where our hosting infrastructure (Vercel), database (Neon), authentication provider (Clerk), and other service providers are located. If you are located outside the United States, your data will be transferred internationally.
For users in the EEA, UK, or Switzerland, such transfers are conducted in accordance with applicable data protection laws, including reliance on Standard Contractual Clauses or other approved transfer mechanisms where required.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the revised policy on this page with an updated effective date. For significant changes, we may also notify you via email (if you have an account) or through a notice on the Service.
Your continued use of the Service after a revised policy is posted constitutes your acceptance of the changes.
If you have questions or concerns about this Privacy Policy or our data practices, please contact us.