Privacy Policy
Last updated: 2026-08-19
Fandex is a one-person hobby project, not a company. This policy is written to be plain and accurate about exactly what the app stores and why, rather than assembled from a template. It is not legal advice, and it is under review pending professional legal advice (see the note on the controller's address below).
Who controls your data
Nils Mlynarek, contactable at hello@fandex.org.
The controller's full postal address is published in the Imprint, which forms part of this notice.
What Fandex stores about you
Fandex does not ask for your name or email address. Your account is identified only by the provider account(s) you connect. Specifically, the app's database stores:
- Account: an internal account id, when the account was created, when you were last seen, your country setting (used to localize release dates and streaming availability), and a session-invalidation counter used when you sign out or disconnect a provider.
- Connected providers: which provider (Trakt, Steam, TMDB, RAWG; see "Providers we work with" below) you connected, that provider's own account id and display name for you, your avatar image URL if the provider supplies one, and an access token (and refresh token, where the provider issues one) so the app can act on your behalf. Tokens are encrypted at rest before they are stored. The database never holds them in plain text.
- Your library: which titles you've marked watched/played, your rating and any written review, and which of your connected providers each entry came from.
- Your wishlist: which titles you want, and which providers each came from.
- Per-provider item state: for items with more nuanced state across providers (e.g. "in progress" on one service), a record per provider of that title's status, rating and review.
- Sync history: a log of each sync run per provider (when it ran, how many items it touched, and whether it succeeded), used only for diagnosing sync problems.
What Fandex does NOT store
No email address, no real name (only whatever display name your connected provider gives us), no payment information (Fandex has no payment feature today), and no third-party analytics or advertising identifiers. Fandex does count pageviews, but it does so itself and without identifying anyone; see "Usage statistics" below.
Cookies
Fandex sets three cookies, all strictly necessary for the app to function and none used for tracking or advertising: a session cookie so you stay signed in, and two short-lived (10-minute) security cookies used only during the moment you connect a provider account, to prevent a cross-site forgery of that connection. Because every cookie is strictly necessary, German law (§25 TDDDG) doesn't require a consent banner for them. That conclusion, and the full list with exact names and lifetimes, is recorded separately for anyone who wants the detail.
If Fandex ever adds analytics, advertising, or affiliate-tracking cookies, a consent banner will be added before that happens, not after.
Usage statistics
Fandex counts how much the site is used, so the operator can tell whether it is worth continuing to run and pay for. That counting is done by Fandex itself, in its own database. There is no Google Analytics, no other third-party analytics service, no tracking script, no advertising identifier and no fingerprinting.
What a count records: the calendar day, what KIND of page was opened, whether the visitor was signed in, and a coarse category for where the visit came from (a search engine, a social site, a link inside Fandex, or no referrer at all). "Kind of page" means a route template, so opening a specific tag, person or item page is recorded only as "a tag page", "a person page" or "an item page" and never as the particular one you looked at.
What a count does not record: any identifier of any kind. No user id, no IP address, no session id, no device or browser details, and no time more precise than the day. Counts are stored only as running daily totals, so there is nothing in them that could be traced back to you, and no way to reconstruct what any one person did.
Because nothing is stored on or read from your device, this needs no consent banner under §25 TDDDG, and because no personal data is kept there is nothing here for the GDPR to attach to. Sending a count is an ordinary web request, and like every request to any website it briefly shows your IP address to the server; it is used only to apply a rate limit, exactly as it is on every other part of the app, and is never stored alongside the counts.
For signed-in accounts Fandex also records the date each account was last seen, at most once per day, so the operator can tell how many accounts are still in use. That date is stored on your account and is removed when you delete it.
These statistics are visible only to the operator.
Providers we work with, and what we send them
TMDB, RAWG and IGDB supply the movie/show/game metadata (titles, posters, descriptions, genres) Fandex displays. The app queries them with a title or id, and doesn't send them anything about you unless you connect your own account with that provider.
- TMDB (The Movie Database): metadata always; if you connect your TMDB account, the app also sends your own ratings and watchlist actions to your TMDB account, and reads them back.
- Trakt: if you connect your Trakt account, the app sends your ratings, watched status and watchlist actions to your Trakt account, and reads your existing Trakt library back.
- RAWG: game metadata always; if you connect your RAWG account, the app also sends your ratings and wishlist actions to it, and reads them back.
- Steam: if you connect your Steam account, the app reads your owned games and playtime. Steam's API does not support writing ratings or watchlist changes back, so nothing is sent to Steam beyond the read request itself.
- IGDB: game metadata only, via an app-level API key. It never sees anything about you individually.
Most of these providers are based in the United States. What that means for your data depends on which of them we are talking about, so rather than one blanket statement, here is each case:
- Metadata only: no personal data leaves Fandex. IGDB always, and TMDB and RAWG whenever you have not connected an account with them, receive a title or an id and nothing about you. There is no transfer of your personal data to base on anything.
- Accounts you connect yourself. If you link your TMDB, Trakt, RAWG or Steam account, data goes to an account you already hold with that provider, at your instruction, and only for as long as the connection exists. You can disconnect at any time in Settings. That transfer happens because you explicitly asked for it (Art. 49(1)(a) GDPR), and from the moment it arrives that provider handles it under its own privacy policy, not this one.
- Providers that process data on Fandex's behalf. These are Railway (hosting, including the database) and Cloudflare (DNS, and routing the hello@fandex.org mailbox). The database is stored in the Netherlands, in Railway's europe-west4 region. Both companies are based in the United States and their staff can reach what they host for us, which counts as a transfer, so both self-certify under the EU–US Data Privacy Framework, and both additionally commit to the European Commission's Standard Contractual Clauses as a fallback should that certification lapse. Checked August 2026. Certifications can be withdrawn, so this is re-checked rather than assumed.
Fandex is hosted on Railway, with DNS and the hello@fandex.org contact mailbox routed through Cloudflare. Both providers process data as part of running the service (hosting the database, delivering the app, and routing the one contact address) rather than receiving it for their own purposes.
How long we keep it
Your account data is kept for as long as your account exists. If you delete your account (Settings → Your data), every table that stores anything about you is erased in one transaction. See "Deleting your account" below for how that is actually implemented, not just promised.
The database is continuously backed up for disaster recovery. Backup snapshots are retained for 24 hours before being replaced by a fresh one, so after an account deletion, a small window (up to 24 hours) can exist where a backup snapshot still reflects the pre-deletion state, purely as a byproduct of that backup cycle rather than active retention of deleted data.
CSP violation reports (a security mechanism that logs when the browser blocks a resource the app didn't intend to load) are written to Railway's server logs, which are operational logs rather than a database table with its own separate retention setting.
Your rights
Under the GDPR you have the right to access the data held about you, correct it if it's wrong, have it erased, restrict or object to its processing, and receive it in a portable format. Two of these are already self-serve, not just promised on paper:
- Export your data: Settings → Your data → download a JSON file of everything the app holds about you, readable on its own without any knowledge of the app's internals.
- Delete your account: Settings → Your data → a type-to-confirm dialog that erases every table holding anything about you. This is irreversible; there is no undo.
For anything else, such as correction, restriction or objection, contact hello@fandex.org.
You also have the right to lodge a complaint with a data protection supervisory authority. Under Art. 77 GDPR you can do that with the authority in the EU or EEA country where you live, where you work, or where you believe the problem occurred. It does not have to be a German one, even though Fandex's controller is based in Germany.
Changes to this policy
This is a living document for a project that is itself still being built out, so check the "updated" date at the top of the page. Material changes (e.g. adding a new provider, adding analytics, or adding a payment flow) will update that date.