This policy is provided in German and English. The German version is legally binding; the English version is a convenience translation only.
Diese Datenschutzerklärung liegt auf Deutsch und Englisch vor. Die deutsche Fassung ist rechtsverbindlich; die englische Fassung dient lediglich der Information.
Preamble
With the following privacy policy, we would like to inform you which types of your personal data (hereinafter also referred to as "data") we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications, and within external online presences (hereinafter collectively referred to as the "online offering").
Last updated: 17 July 2026
Controller
Cuevie – Pascal Hofstäter
c/o Online-Impressum #3559
Europaring 90
53757 Sankt Augustin
Germany
Email: [email protected]
Legal notice (Impressum): https://cuevie.com/impressum
Overview of Processing Activities
The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of data processed
- Account data (e.g. names, addresses).
- Contact data (e.g. email addresses).
- Content data (e.g. watchlists, ratings).
- Usage data (e.g. interactions with content and features).
- Meta, communication, and procedural data (e.g. IP addresses, timestamps, identifiers).
- Log data.
Categories of data subjects
- Users (visitors and registered users of our online offering).
Purposes of processing
- Security measures.
- Provision of our online offering and its usability.
- IT infrastructure.
Relevant Legal Bases
Below is an overview of the GDPR legal bases on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection requirements in your or our country of residence or registered office may apply.
- Consent (Art. 6(1)(a) GDPR) – the data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract (Art. 6(1)(b) GDPR) – processing is necessary for the performance of a contract with the data subject or to take steps prior to entering into a contract.
- Legal obligation (Art. 6(1)(c) GDPR) – processing is necessary for compliance with a legal obligation to which we are subject.
- Legitimate interests (Art. 6(1)(f) GDPR) – processing is necessary for the purposes of our legitimate interests or those of a third party, provided those interests are not overridden by the data subject's interests or fundamental rights and freedoms.
In addition to the GDPR, national data protection provisions apply in Germany, in particular the Federal Data Protection Act (BDSG).
Security Measures
In accordance with legal requirements, and taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.
Securing online connections via TLS/SSL encryption (HTTPS): To protect user data transmitted through our online services from unauthorized access, we rely on TLS/SSL encryption technology. Where a website is secured by an SSL/TLS certificate, this is indicated by HTTPS being shown in the URL.
Disclosure of Personal Data
In the course of our processing of personal data, it may become necessary to transmit or disclose such data to other bodies, companies, legally independent organizational units, or persons. Recipients of this data include, in particular, the service providers named in the "Provision of the Online Offering and Web Hosting" and "Additional Services and Service Providers" sections below. In such cases we comply with legal requirements and, in particular, enter into appropriate contracts or agreements that serve to protect your data with the recipients of your data.
International Data Transfers
Where we transfer data to a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), for example in connection with the use of third-party services, this is always done in compliance with legal requirements.
For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognized as a safe legal framework by an adequacy decision of the EU Commission dated 10 July 2023. In addition, where available, we have entered into Standard Contractual Clauses with the respective providers, in accordance with EU Commission requirements, establishing contractual obligations to protect your data.
Further information on the DPF and a list of certified companies can be found at https://www.dataprivacyframework.gov/.
General Information on Data Retention and Deletion
We delete personal data we process in accordance with legal requirements as soon as the underlying consent is revoked or no further legal basis for processing exists. Exceptions apply where legal obligations require longer retention or archiving of data (in particular commercial and tax law retention periods of up to 10 years under German law, §§ 147 AO, 257 HGB).
Where a period does not expressly begin on a specific date and is at least one year, it automatically begins at the end of the calendar year in which the triggering event occurred.
Rights of Data Subjects
As a data subject, you have various rights under the GDPR, arising in particular from Art. 15 to 21 GDPR:
- Right to object: You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you carried out under Art. 6(1)(e) or (f) GDPR.
- Right to withdraw consent: You have the right to withdraw any consent you have given at any time.
- Right of access: You have the right to request confirmation of whether data concerning you is being processed, and to obtain information about that data.
- Right to rectification: You have the right to request that incomplete data concerning you be completed or that inaccurate data be corrected.
- Right to erasure and restriction of processing: You have the right to request that data concerning you be deleted without delay, or, alternatively, to request restriction of the processing of that data.
- Right to data portability: You have the right to receive data concerning you in a structured, commonly used, and machine-readable format.
- Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a supervisory authority if you believe that the processing of personal data concerning you violates the GDPR.
Provision of the Online Offering and Web Hosting
We process user data in order to provide our online services to them. For this purpose we process, in particular, the user's IP address, which is necessary to deliver the content and functions of our online services to the user's browser or device, as well as further log data (e.g. time of access, amount of data transferred, browser type, operating system).
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). Deletion: Logfile information is stored for a maximum of 30 days and then deleted or anonymized.
- Hetzner: Provision of IT infrastructure and related services (e.g. storage space and computing capacity); Service provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.hetzner.com; Privacy policy: Hetzner Privacy.
- Cloudflare: Content delivery network (CDN), connection security, and provision of a secure tunnel (Cloudflare Tunnel) between our servers and users' devices, including termination of TLS encryption, as well as cookieless, privacy-friendly website analytics (Cloudflare Web Analytics); Service provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.cloudflare.com; Privacy policy: Cloudflare Privacy Policy; Data processing agreement: Cloudflare DPA.
Additional Services and Service Providers
In addition to the hosting and CDN provider named above, we use further service providers who process personal data on our behalf to operate our online offering.
- Firebase Authentication (Google): Provides the registration and login functionality of our online offering, including via Google account sign-in ("Google Sign-In") and anonymous accounts; depending on the sign-in method chosen, we process e.g. email address, display name, and profile picture, or a device-generated identifier; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Performance of a contract (Art. 6(1)(b) GDPR); Website: https://firebase.google.com; Privacy policy: Firebase Privacy; Data processing terms: Firebase Data Processing Terms.
- MongoDB Atlas: Database service used to store all data required to operate our online offering (including user profiles, watchlists, lobby, and voting data); Service provider: MongoDB Limited, Building 2, Number 1 Ballsbridge, Shelbourne Road, Ballsbridge, Dublin 4, Ireland; Legal basis: Performance of a contract (Art. 6(1)(b) GDPR); Website: https://www.mongodb.com; Privacy policy: MongoDB Privacy Policy; Data processing agreement: MongoDB DPA.
- The Movie Database (TMDb): Retrieval of movie and TV metadata and poster artwork via the TMDb API to provide the core functionality of our online offering; requests are made server-side by us, and no personal data of users is transmitted to TMDb; Service provider: Xperi Inc., 2190 Gold Street, San Jose, CA 95002, USA; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.themoviedb.org; Privacy policy: TMDb Privacy Policy.
- Sentry: Collection and analysis of error reports (crash and error reports) from the frontend and backend to detect and fix technical issues; this may involve processing IP address, device and browser information, and other technical context data; Service provider: Functional Software, Inc. (d/b/a Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA (EU representative: Sentry Software Netherlands B.V., Schiphol Boulevard 359, 1118 BJ Amsterdam Schiphol, Netherlands); Legal basis: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://sentry.io; Privacy policy: Sentry Privacy Policy; Data processing agreement: Sentry DPA.
Use of Cookies
"Cookies" are functions that store and retrieve information on users' devices. We use exactly one strictly necessary cookie (sidebar_state), which stores the collapsed/expanded state of the sidebar for up to 7 days. This cookie serves solely the functionality and convenience of our online offering; we do not use cookies for tracking, analytics, or advertising. For traffic analysis we use Cloudflare Web Analytics, which operates without cookies and only collects aggregated, non-personally-identifiable usage statistics (see the Cloudflare entry above).
Legal basis: Because this cookie is technically necessary to provide an explicitly requested feature, we rely on our legitimate interests (Art. 6(1)(f) GDPR); consent is not required for this cookie.
Changes and Updates
We ask that you regularly review the content of our privacy policy. We will adjust the privacy policy as soon as changes to the data processing we carry out make this necessary.
Supervisory authority responsible for us:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Postfach 20 04 44
40102 Düsseldorf, Germany
This is an English translation of our German privacy policy provided for convenience only. In the event of any discrepancy or ambiguity between the German and English versions, the German version ("Datenschutzerklärung" tab) is legally binding. Parts of this document were created using the free Datenschutz-Generator.de by Dr. Thomas Schwenke; the sections on Firebase, MongoDB Atlas, TMDb, Sentry, and Cloudflare were compiled based on publicly available information from those providers and have not been individually reviewed by a lawyer. This document does not constitute legal advice.