Privacy Policy

Last updated: August 26, 2026

ReelShowster ("we", "us", or "our") is a short-form vertical video streaming service operated by [LEGAL ENTITY NAME]. This Privacy Policy explains what personal data we collect when you use reelshowster.com (the "Service"), why we collect it, how we use it, and the rights you have over your data. By creating an account or using the Service you agree to the practices described in this Policy.

1. Data We Collect

Account information

When you register with email and password we store your email address and a bcrypt hash of your password — never the password itself. When you sign in via Google or Apple we receive and store your display name, email address, the OAuth provider name (google or apple), the unique provider-issued user ID, and the avatar URL supplied by the provider — a link to an image hosted on the provider's own servers; no image bytes are copied to our systems at sign-in. Your email is only linked to an existing account when the provider has cryptographically confirmed you own it. If you later upload a custom profile avatar, the image is validated, resized to 100 × 100 px, and stored in Amazon S3 (see §3). Deleting your avatar removes the stored S3 object immediately.

Session and authentication tokens

After sign-in we issue a Sanctum bearer token stored server-side and set a web session cookie in your browser. The session cookie is HttpOnly and used solely to keep you authenticated across page loads.

Coin balance and purchase transactions

We store your current coin balance and a record of each coin-package purchase (package identifier, amount, and Stripe payment-intent ID). Card numbers and payment credentials are collected and processed exclusively by Stripe — they never pass through or are stored on our servers.

Watch history

For each episode you watch we store the episode identifier, your playback progress in seconds, and the timestamp of your last viewing. This lets us resume playback and populate your watch-history list.

Watchlist

We store which series you have saved to your watchlist so we can display them on your account.

Device type

We read the User-Agent header your browser sends on each request to determine whether you are on a mobile or desktop device so we can serve the appropriate layout. We hash the User-Agent string with MD5 and cache only the derived device-type label (mobile / desktop) for 24 hours — the raw User-Agent is never logged or stored in our database.

Video delivery cookies

When you start watching an episode we set three short-lived HttpOnly cookies (CloudFront-Policy, CloudFront-Signature, CloudFront-Key-Pair-Id) scoped to the path of that series. These authorise your browser to stream video directly from Amazon CloudFront and expire shortly after playback ends. No video bytes pass through our application servers.

Advertising

We use Google Ad Manager and the Google IMA SDK to serve rewarded and pre-roll video ads. Google's advertising systems may collect identifiers, cookie data, and interaction signals on our pages in accordance with Google's Privacy Policy.

2. How We Use Your Data

  • Authenticate you and maintain a secure session.
  • Display your account name and avatar.
  • Track and display your watch history and watchlist.
  • Manage your coin balance and record purchase transactions.
  • Authorise video streaming via CloudFront signed cookies.
  • Serve the layout appropriate for your device type.
  • Deliver in-stream advertising through Google Ad Manager.
  • Investigate abuse, enforce our Terms of Service, and comply with law.

3. Third Parties We Share Data With

We do not sell your personal data. We share data only as described below.

Google

OAuth sign-in (you choose to share your name, email, and avatar with us via Google) and advertising (Google Ad Manager / IMA SDK). Governed by Google's Privacy Policy.

Apple

OAuth sign-in (you choose to share your name and email, or an Apple-anonymised relay address). Governed by Apple's Privacy Policy.

Stripe

Payment processing for coin purchases. Card details go directly to Stripe and never pass through our servers. We receive only a payment reference to confirm the purchase. Governed by Stripe's Privacy Policy.

Amazon Web Services

Video content is stored in Amazon S3 and delivered via Amazon CloudFront. Avatars that you upload yourself are also stored in S3 (resized to 100 × 100 px); deleting your avatar removes that S3 object. OAuth sign-in avatars are external provider URLs and are not stored in S3. Governed by the AWS Privacy Notice.

4. Data Retention

We retain your account data, watch history, watchlist, and transaction records for as long as your account is active. If you request account deletion (see §6) we will delete or anonymise your personal data within 30 days, except where law requires longer retention. CloudFront signed cookies expire automatically and are not stored beyond the active session.

5. Security

We use industry-standard measures including bcrypt password hashing, HTTPS for all traffic, HttpOnly and SameSite=Lax cookie flags, CSRF protection, and server-side access controls. No method of internet transmission is completely secure, and we cannot guarantee absolute security.

6. Your Rights and Account Deletion

Depending on your location you may have the right to access, correct, or delete the personal data we hold, or to object to or restrict certain processing. To exercise any of these rights, or to request deletion of your account, please contact us at support@reelshowster.com. We will respond to verified requests within 30 days.

7. Governing Law

This Privacy Policy is governed by the laws of [JURISDICTION].

8. Changes to This Policy

We may update this Policy from time to time. Material changes will be signalled by updating the "Last updated" date at the top of this page. Continued use of the Service after changes are posted constitutes acceptance of the revised Policy.

9. Contact

Questions about this Privacy Policy? Email us at support@reelshowster.com.