Bingr

Last updated October 5, 2026

Privacy

What Bingr keeps about you, why it keeps it, and what it never does with it. Written from the database rather than from a template — every claim here is one you could check.

The unusual part, first

Where you are in a show is the most personal thing Bingr holds, and it is also how Bingr works. It decides what the server sends you: an episode past your point is not hidden in your browser — its title, its summary and its image never leave the machine. And it decides what other people are allowed to see of you.

So your reading position is not a by-product of using this app. It is the thing the app is built out of. That is worth knowing before the list below, because it is the reason the list is as long as it is.

Your account

You sign in with an email address. There is no password to choose and none to lose — we email you a code, you type it, and that is the whole of it.

Your address is held by Supabase, who authenticate you. None of our own tables has a column for it: your profile row carries a handle, a display name, a photo, a time zone and your visibility settings, and that is all. The first time you sign in, the handle and the name are made up for you from your address — you can change both, and most people do.

Your address is used for one thing: sending you a sign-in code. There is no newsletter, no product announcement, no digest, and no code in this application that could send one. If you continue with Apple or Google instead, we receive the name and profile picture they hand over, and nothing else.

Your browser tells the server which time zone it is in, and we keep it, because “watched last night” has to mean your night rather than the server's. It also tells us which region to check streaming availability for; that one is used and thrown away.

What sits on your device

  • A cookie that says whether you are probably signed in. It holds a single character and no token — it exists so the server can render the app instead of the sales pitch.
  • A cookie of about forty bytes — a date and a number — that helps diagnose sign-in trouble. The server never reads it.
  • Your session token, your theme choice, and a small sign-in log, all in your browser's storage. The log records the names of storage keys and never their contents, and nothing sends it anywhere.
  • Scroll positions, for the length of the tab, so going back lands where you left.

What you watch

Every episode you tick, and every one you untick, is kept as an event — with the date and the hour where you were, and how far that was from UTC. That is more than it sounds like: it is a record of when you watch, which is a record of your evenings. It is kept because your own statistics are built from it, and a plain UTC timestamp stops being yours the moment you travel.

From those events we keep a running picture per show — how far you are, how many episodes, how many minutes — plus your ratings, your rewatch passes and which shows you are following.

Who sees any of it is yours to set, in Settings. Out of the box your profile page can be opened by anyone, while your numbers and your shows are limited to people who follow you. How far you are in a show is never shown to anyone, at any setting. The leaderboard is the one thing you have to switch on yourself: nobody is on it by default.

What you publish

Messages you write live in a room anchored to one episode, and they are readable by the people who have reached it. Your handle, your display name and your photo travel with them. Photos are served from a public address that contains your account identifier — anyone holding the link to your picture can open it without signing in.

We also keep who you follow and who you have blocked. When you pick a show with someone, your yes and your no are kept after the room closes, so the same show is not put in front of you twice.

Someone without an account can retrieve exactly two things about you, and only if your profile is open: your display name and your handle. That is what makes a shared link show a name rather than a blank card. No numbers, no shows, no progress.

History you bring with you

If you import a history file, the file itself is not stored. It is read, and the rows we recognised are kept — so that an import can be replayed when the catalogue improves, and so that you can export those rows back out. Rows we failed to match are kept too, with the reason, because that is the only way to fix a file by hand.

Nothing expires them. They stay until you delete that import from your history, or delete your account.

Notifications

Only if you turn them on. Doing so stores one address per device — the one your browser gives us — along with the two keys used to encrypt what we send there. Delivery goes through your browser vendor's push service, which learns that a message is on its way to that device, though not what it says.

Notifications are anchored like everything else: “someone finished Severance” is a spoiler if you have not, so it does not reach you.

Reports

A report keeps the reason, what was reported, and who reported it. It is never public and is never shown to the person reported — nobody is told who reported them. What happens next is in the community guidelines.

A report outlives your account. If you leave, the report stays with moderation and your identifier is removed from it — otherwise closing an account would erase the evidence against it.

What we count

Two counters, and they are worth describing exactly, because “we collect analytics” usually means something much larger than this.

The first counts how far people get through the welcome tour: which panel, reached or skipped, on which day. The second counts arrivals on a show page by where they came from — one of five words: search, social, direct, internal, other.

Between them they are five columns and an integer. There is no identifier, no session, no IP address, no user agent and no referring URL in either table — the page you came from is reduced to one of those five words before anything is written, and the words are all that exist to write. Nothing is placed on your device to make this work, and no script runs in your browser for it. We count arrivals, not people: reloading counts twice, and we would rather have that than know who reloaded.

Crawlers and link previews are left out, since counting them would make the numbers flattering and wrong on day one. Beyond those two counters there is no analytics in this application at all — no third-party tag, no session recording, no error-reporting service. Our server writes the path of a request and any error message to its own log; addresses and identifiers are not part of it.

Where your data goes

Bingr is one small application, so most of this list is infrastructure rather than partners. Nothing here buys data from us, and nothing here is paid in data.

Several of these companies are outside the European Union, and European law lets personal data leave it only with a safeguard. Three are used below: a country the European Commission has found to protect it adequately, an American company certified under the EU–US Data Privacy Framework, and contractual clauses the Commission has approved. For each company, here is where it handles your data, and which of those applies.

  • Fly.io · United Kingdom (London)

    Fly.io, Inc., United States

    Runs the server that renders every page and answers the app, and the nightly jobs — backups included.

    What reaches it: Everything the app sends you or receives from you passes through it, along with your network address while a request is in flight.

    Adequacy decision · EU–US Data Privacy Framework

    The server is in London, and the United Kingdom has an EU adequacy decision, renewed in December 2025. Fly.io, Inc. is American, and is listed as an active participant in the EU–US Data Privacy Framework.

    Your device talks to it directly.

  • Supabase · Ireland (AWS eu-west-1)

    Supabase Pte. Ltd, Singapore

    Holds the database, your sign-in identity, and uploaded profile photos.

    What reaches it: Everything this page describes, including your email address.

    Kept in the EU · Standard contractual clauses

    The data is stored in Ireland. The company is registered in Singapore, which has no EU adequacy decision, so any access from outside the Union is covered by the European Commission’s standard contractual clauses, which its data processing addendum incorporates.

    Your device talks to it directly.

  • Resend · United States — the email itself leaves from Ireland

    Plus Five Five, Inc., United States

    Delivers the sign-in email, and nothing else.

    What reaches it: Your email address, the message carrying your code, and the record of its delivery.

    EU–US Data Privacy Framework · Standard contractual clauses

    Mail is sent from Ireland, but Resend keeps logs and delivery records in the United States whatever the sending region. It is listed on the EU–US Data Privacy Framework — its renewal was under review on the day we checked — and its data processing addendum incorporates the standard contractual clauses.

    Your device never talks to it; our server does.

  • Cloudflare · European Union (backups)

    Cloudflare, Inc., United States

    Answers for the bingr.watch name, passes on mail sent to our address, and stores the backups.

    What reaches it: The backups, encrypted on our server with a key Cloudflare does not hold, and any email you send us. Browsing Bingr does not go through it.

    Kept in the EU · EU–US Data Privacy Framework · Standard contractual clauses

    The backups sit in a storage bucket restricted to the EU jurisdiction. For the rest, Cloudflare, Inc. is listed on the EU–US Data Privacy Framework — its renewal was under review on the day we checked — and its data processing addendum incorporates the standard contractual clauses.

    Your device never talks to it; our server does.

  • TMDB · United States

    Xperi Inc., United States

    Show data, fetched by our server — and every poster and still your browser loads.

    What reaches it: Your network address, the description your browser gives of itself, which images it asked for, and that it asked from bingr.watch.

    EU–US Data Privacy Framework

    TMDB does not work for us, and we have no agreement with it about your data: your browser contacts it because we put its images on the page. Xperi Inc., which runs TMDB, is listed on the EU–US Data Privacy Framework — its renewal was under review on the day we checked — but TMDB’s own privacy policy does not rely on it.

    Your device talks to it directly.

  • TheTVDB · United States

    Whip Networks, Inc., United States

    Episode ordering, when TMDB gets a series wrong.

    What reaches it: Nothing about you.

    No personal data

    Our server asks it for episode lists and sends nothing about you, so there is nothing to transfer.

    Your device never talks to it; our server does.

  • Your browser’s push service · Wherever your browser’s maker runs it

    Google for Chrome, Mozilla for Firefox, Apple for Safari

    Delivers push notifications, only if you turn them on.

    What reaches it: The address of your device, and messages encrypted so that the service cannot read them.

    EU–US Data Privacy Framework · Not fully verified

    Your browser picks the service, not us. Google LLC, which runs Chrome’s, is listed on the EU–US Data Privacy Framework. We have not been able to confirm a transfer mechanism for Mozilla’s or Apple’s, and we would rather say so than guess.

    Your device talks to it directly.

Posters, and why your browser asks TMDB for them

Posters and episode stills are loaded straight from TMDB’s image server, image.tmdb.org, by your browser — we do not put them behind our own address. Each time, TMDB receives your device’s network address, the description your browser gives of itself, the image it asked for, and the fact that the request came from bingr.watch. That happens whether or not you are signed in. Nothing from your account goes with it.

We do this on the ground of our legitimate interest: showing the catalogue with its pictures without hosting every one of them ourselves. Weighed against it: TMDB does not work for us, and we have no agreement with it about your data; it is run in the United States by Xperi Inc., which is listed on the EU–US Data Privacy Framework for data from the EU — a certification that was under review for renewal when we checked, on October 5, 2026. And an image address can tell which show it belongs to. We think the interest holds because nothing that identifies you inside Bingr travels with the request, but you may see it differently.

If you object, write to hello@bingr.watch. There is no setting in Bingr that turns the images off today, so we will not pretend one exists: we will look at your objection and answer within one month, as the law requires.

Each line above was checked on October 5, 2026, against the provider’s own legal pages and the official Data Privacy Framework list. A certification can lapse, so if one of them has changed, the page is wrong and we want to know.

Leaving

Deleting your account happens immediately. There is no grace period and no way back.

The button is in Settings, behind typing your own handle. It removes your sign-in identity first, then your profile and everything attached to it: your events, your progress, your ratings, your messages, your follows, your blocks, your imports and any photo you uploaded. Removing the identity first is deliberate — if the second half failed, what would be left is an unreachable profile rather than a working login onto emptied data.

Two things survive on purpose. Reports you filed stay with moderation, without your identifier. And the two counters above keep their totals, since they never knew you were in them.

Backups are the one place where that isn't instant. Encrypted snapshots are kept for thirty days daily, then weekly for six months, then monthly for two years — after which they are deleted outright. So a deleted account can persist in an archive for up to two years before the last copy of it goes. Our hosting provider keeps no backups of its own: that two-year window is the whole of it.

Before you go: Download your data, in Settings, gives you everything we hold about you in a single download — your watch history included, as a CSV that Bingr and most trackers can import. The same button sits in the confirmation that deletes your account.

Why we are allowed to

European data protection law asks every use of personal data to rest on a legal ground, and asks us to say which. Most of Bingr rests on the plainest one: you asked for the service, and it cannot work without the data. Nothing on this page is used to advertise to you, and nothing rests on a consent you gave by signing up.

To provide the service you signed up for

GDPR Art. 6(1)(b)

  • Your account: sending sign-in codes to your address, your profile, your time zone, and what Apple or Google pass on if you continue with them.
  • Tracking: your ticks, progress, pauses, skips, rewatches and ratings, and the statistics built from them.
  • Rooms and friends: what you write, your reactions, who you follow and block, picking a show together, and the notifications you see inside the app.
  • Imports: the rows recognised in a history file you bring, kept so the import can be replayed and exported.

Because you said yes

GDPR Art. 6(1)(a)

  • Push notifications: one address per device and its two keys. Changing your mind: Turn them off on the Notifications page and the address is deleted at once. Revoking the permission in your browser works too: the address is deleted the first time the push service tells us it is gone.

Because we have a legitimate interest, and it does not override yours

GDPR Art. 6(1)(f)

  • Reports and moderation: the reports you file or receive, removed messages, and the record of a suspension — including a report kept after its author leaves. The interest: Keeping the rooms usable and safe, and being able to explain a sanction. A report that vanished with the account it concerns would erase the evidence against it.
  • The two counters: how far people get through the welcome tour, and where arrivals on a show page come from. The interest: Knowing whether the welcome tour and shared links work. Neither counter holds anything that identifies anyone.
  • Diagnosis and backups: the server’s error log, the small sign-in log and cookie on your device, and encrypted backups kept for up to two years. The interest: Keeping sign-in working, finding out why it broke when it does, and being able to restore the service after a failure.
  • Showing posters and episode stills: your browser loads them straight from TMDB’s image server, image.tmdb.org, which receives your network address, your browser’s description of itself, the image asked for, and that it was asked from bingr.watch. The interest: Showing the catalogue with its pictures without hosting every one of its images ourselves. Nothing from your account travels with the request: no name, no address, no identifier, and not the page you are on — only that it is bingr.watch.

Because the law requires it

GDPR Art. 6(1)(c)

  • Answering a court or an authority that has the legal power to require information from us — if one ever does.

Where a use rests on our legitimate interest, you can object to it, and we have to stop unless the reason is stronger than your objection — a report about you is the obvious case where it would be.

Age

Bingr is for people aged 16 and over, and creating an account means confirming you are. We do not ask for a date of birth — it would be one more thing to hold about everyone in order to learn one fact about a few. We do not knowingly keep data about anyone under 16. If we learn that an account belongs to someone younger, it is deleted, the same way as if they had deleted it themselves.

Your rights

You can ask for a copy of what Bingr holds about you, have it corrected, have it erased, have its use restricted while something is in dispute, receive it in a form a machine can read, and object to any use that rests on our legitimate interest. Where something rests on your consent, you can withdraw it at any time; that does not make what came before unlawful.

  • Correcting: your name, handle and photo are edited on your profile, and who sees what in Settings.
  • Erasing: deleting your account, in Settings, does it at once.
  • Withdrawing consent: push notifications are turned off on the Notifications page.
  • Everything else — a copy, a full export, a restriction, an objection — by writing to hello@bingr.watch from the address on your account. A full copy is also a button away: Download your data, in Settings, hands you all of it in a single download.

You get an answer within one month, as the law requires. If you think we have got something wrong, you can complain to the CNIL, the French data protection authority, at cnil.fr, or to the authority of the European country where you live. Writing to us first is not a condition of doing so.

Who answers for this

Bingr is run by Nicolas Negrier, a private individual in France. There is no company behind it. He decides what is collected and why, which makes him the data controller for everything on this page.

Questions about any of this, or about your own data, go to hello@bingr.watch. A postal address is given to anyone who asks for one there. If something on this page turns out not to match what the app does, that is a defect and it will be treated as one.