Effective: 1 August 2026 · Developer: Xhale
WatchVault is a personal movie and TV tracking app. This policy explains how the app handles information.
Your library, watch progress, notes, custom lists, language setting, selected streaming services, and notification preferences are stored locally on your device. The app works without an account. Local data remains on the device until you remove it in the app, clear the app's data, or uninstall the app.
If you create a cloud profile, WatchVault uses Firebase Authentication for email sign-in and Cloud Firestore to store your library, episode progress, custom lists, language, selected streaming services, and notification preferences. Cloud data is stored below your Firebase user identifier, and Firestore access rules restrict it to the signed-in user. WatchVault does not store your password inside the app.
Firebase is operated by Google and processes account and cloud data as a service provider. More information is available in Firebase Privacy and Security and the Google Privacy Policy.
For signed-in users, reviews are public by default. Before saving, you can select “Private only” to keep a movie, TV show, or episode review out of Community. Before a first public review, users must accept the WatchVault Community Rules. The rules prohibit harassment, hate, sexual or illegal content, personal information, spam, and unmarked spoilers. Public reviews contain your chosen public name, the title, rating, comment, spoiler flag, and relevant season or episode number. Your email address, private library, watch progress, and other profile data are not included. You can make a review private again at any time.
You can block another Community user locally or report a public review for spam, harassment, hate, an unmarked spoiler, or another violation. Reports contain the review identifier, the reporting and reported account identifiers, the selected reason, optional details, status, and timestamp. Reports are not public and are restricted to moderation access.
When you browse, search for, or open a movie or TV show, WatchVault requests public catalogue information through a secure WatchVault proxy and TMDB. These requests can include the title or genre you search for, public TMDB title identifiers, language, region, and page number. Your local library, notes, ratings, and watch progress are not sent with catalogue requests.
The proxy temporarily uses an IP address in memory for up to 60 seconds to limit abusive traffic. WatchVault does not store this IP address in its own database. Cloudflare processes connection information while operating the proxy, and TMDB processes the catalogue request it receives. Their policies are available at Cloudflare and TMDB.
The automatic local backup remains private inside the app's storage area. If you export a portable profile file, that file is not password-protected. You decide where to share or store it and should treat it as private.
Episode notifications are optional and can be turned off at any time in the Profile section. They are used only for TV shows you choose to follow.
WatchVault does not contain advertising SDKs or analytics SDKs. Firebase is used for optional sign-in, cloud storage, and reviews you actively choose to publish in Community.
Local data remains on your device until you remove it in the app, clear the app's storage, or uninstall the app. From Cloud profile in the app, you can permanently delete your cloud data, public reviews, and sign-in account. Deleting the cloud profile does not delete the local library. Exported files remain under your control until you delete them from the location where you stored or shared them.
Catalogue and cloud requests use HTTPS, and the app prevents cleartext network traffic. Firestore security rules require authentication and restrict each cloud profile to its signed-in user. Portable exported profile files are not encrypted by WatchVault.
This policy may be updated when WatchVault changes how it handles data. For privacy questions, contact xhale4life@gmail.com.