Skip to content
Kinopal
FeaturesScreenshotsDownloadTermsPrivacyGet Kinopal
FeaturesScreenshotsDownloadTermsPrivacyGet Kinopal
← Back to home

Kinopal legal

Privacy Policy

Effective: September 11, 2026Applies to the Kinopal mobile app and kinopal.app

This Privacy Policy explains how Kinopal processes personal data when you use the Kinopal mobile application, visit this website, create an account, save or track titles, share a collection, submit a report, or contact us.

1. Data controller

The controller responsible for your personal data is Dmitrii Galla, an individual operator established in Italy, VAT number IT01882570094.

Dmitrii Galla
Via Erbosa 15, 52100 Arezzo (AR), Italy
Email: info@kinopal.app

2. Data we process

Account and authentication data

Depending on the sign-in method you choose, we process a Firebase user identifier and your name, email address, phone number, profile image URL, authentication provider, account creation date, last sign-in date, and verification status. Google, Apple, or your mobile carrier may process additional data under their own terms when you use their services.

Library, viewing activity, and collections

We store titles you save, watch, or are currently watching; episode and season progress; title identifiers and cached metadata; collection names, contents, poster references, and related timestamps. This information is linked to your account so it can be synchronized across devices.

Shared collections

When you choose to publish a collection, its title, included titles, poster references, optional display name, publication date, and an internal owner identifier become accessible to anyone with the sharing link. Do not include personal or confidential information in a collection title or display name that you do not want others to see.

Content reports and communications

If you report a title, we process the selected reason, your explanation, the relevant title identifier, status, timestamp, and your account identifier. If you contact us, we process the contact details and message content needed to answer your request.

Notifications and device information

If you allow notifications, Firebase Cloud Messaging processes a push token, app-instance or device identifier, notification permission status, and message delivery information. Standard network data such as IP address, user agent, operating-system information, and request timestamps may be processed by Firebase, our hosting infrastructure, and requested content providers for security and service delivery.

Local data

Language, theme, selected country, pending phone verification state, recently handled deep links, recognition consent preferences, and cached genre data may be stored locally on your device. You can remove local data through your device settings or by uninstalling the app.

Search and content requests

Search terms and title requests are sent from your device to The Movie Database (TMDB) to return the content you request. Kinopal does not use these requests for advertising or behavioral profiling and does not keep a server-side search-history profile.

Optional photo and video recognition

Selecting a photo or video in the app does not itself upload it. When you confirm recognition, the selected media is sent to our recognition server. For a public Instagram link, the link is sent to Apify to retrieve the clip. The image or a video excerpt, including audio, is then sent to Google Gemini to identify a movie or series. Suggestions are checked against TMDB and may be incorrect. A matching cached result may be returned without repeating third-party recognition.

Video analysis starts with the first 15 seconds and may extend to 30 seconds if the first attempt is inconclusive. Our server may receive a longer source video before preparing these excerpts. We do not provide these uploads as a public video-hosting or streaming service. Do not submit sensitive personal information or media that you are not entitled to share and have processed.

Recognition consent and your choices

Transfer of selected media to recognition providers is based on your consent under Article 6(1)(a) GDPR. The Instagram Share Extension asks on first use and remembers your choice on the device; later shares can start recognition automatically. Declining recognition does not remove access to ordinary title search or your library. To withdraw a recorded consent or request help removing related data, contactinfo@kinopal.app. Withdrawal does not undo earlier processing or automatically cancel a request already sent to a provider. Stop submitting media if you no longer want it processed.

Recognition providers

  • Google Gemini API: processes images and video excerpts with audio. See the Gemini API termsand Google Privacy Policy. Provider-side safety processing and retention are separate from deletion of temporary files on our server.
  • Apify: retrieves clips from public Instagram links and may retain run metadata or datasets according to its service settings and retention rules. See theApify Privacy Policy. We do not request your Instagram password or access to private accounts.
  • Firebase and Google Cloud: run the recognition server, protect access, store cached results and usage records, and provide operational logging. These services process standard network and service data in addition to the data needed for recognition.

Recognition usage and reliability records

We record request counts, source type, timestamps, duration, success or no-match outcomes, error codes, cache use and model usage. A restricted usage record also contains your account identifier and a user-specific hashed source identifier to distinguish repeat requests from different submissions. These usage records do not contain uploaded media, raw Instagram URLs, phone numbers, email addresses or transcripts. They are not public and are available only to authorized administration.

We use these records for quotas, reliability and abuse prevention based on our legitimate interests under Article 6(1)(f) GDPR, with restricted access and limited retention. A low match rate can flag activity for human review; it does not by itself prove misuse or automatically ban an account. Short-lived result receipts link a proposed title to your account so that you can explicitly save it to your library.

Recognition retention

  • Media is processed in temporary server storage and removed during request cleanup. Saving a match stores title metadata, not the submitted photo or video.
  • Successful results may be reused from a source-hash cache for up to 30 days. No-match results normally remain valid for 15 minutes and error results for one minute. Result receipts expire after one hour; daily quota records have a three-day expiry.
  • Detailed recognition metric and account-linked usage records are scheduled to expire 30 days after the event. Expiry is not immediate physical deletion: database cleanup is asynchronous. Operational logs and provider-held copies follow separate retention cycles.

Short-lived receipts, quota and usage records are managed separately and are not necessarily erased immediately by the in-app account deletion action. They follow the expiry periods above. For a verified request to remove related account-linked records sooner, contactinfo@kinopal.app, subject to applicable legal-retention requirements.

3. Why we process data and our legal bases

  • Provide the service and manage your account: account authentication, synchronization, watchlists, progress, collections, and sharing are necessary to perform our contract with you under Article 6(1)(b) GDPR.
  • Notifications: optional push notifications are based on your consent under Article 6(1)(a) GDPR. You may withdraw permission at any time in your device settings.
  • Safety and service integrity: authentication security, abuse prevention, content reports, troubleshooting, and protection of our service and users are based on our legitimate interests under Article 6(1)(f) GDPR.
  • Legal compliance: we may retain or disclose limited information where required by law under Article 6(1)(c) GDPR.

Kinopal does not sell personal data, show third-party advertising, use cross-app tracking, or use your data for automated decisions producing legal or similarly significant effects.

4. Service providers and recipients

We use the following third parties to operate Kinopal:

  • Google Firebase: Firebase Authentication, Cloud Firestore, and Firebase Cloud Messaging provide authentication, synchronized storage, and notifications. Firebase may process account, device, IP-address, and service-usage data.
  • Google Sign-In and Sign in with Apple: used only when you select that sign-in method.
  • TMDB: provides movie, series, cast, rating, image, and watch-provider metadata. Requests may expose standard network information to TMDB.
  • JustWatch: powers streaming-availability information displayed through TMDB data.
  • Apple App Store and Google Play: distribute the app and independently process store, download, and device information.
  • Website hosting providers: deliver kinopal.app and may process short-lived server logs for availability and security.

These providers process data under their own terms and privacy notices and, where they act on our behalf, are required to apply appropriate data protection safeguards.

5. International transfers

Some providers, including Firebase Authentication, Google Gemini and Apify, may process data in the United States or other countries outside the European Economic Area. Where required, transfers are protected by an adequacy decision, standard contractual clauses, or another lawful safeguard provided by the relevant service provider. You may contact us for information about the applicable safeguard.

6. Retention

Recognition media, receipts, caches, quota and usage records have the separate retention periods described inOptional photo and video recognition above.

  • Account, library, progress, and private collection data are kept while your account remains active and are deleted when the account is deleted, subject to the limited exceptions below.
  • Published collections remain available through their sharing links until the associated account is deleted or you request their removal.
  • Content reports are retained while they are reviewed and afterwards only for as long as reasonably necessary for safety, abuse prevention, dispute handling, or legal obligations.
  • Support and privacy correspondence is retained for as long as needed to answer the request and document our response.
  • Provider security logs and residual backups may remain for a limited period under the provider's documented retention cycle before being overwritten or deleted.

We may retain narrowly limited information where necessary to comply with law, resolve disputes, or establish, exercise, or defend legal claims. It will not be used for unrelated purposes.

7. Account and data deletion

You can delete your account in Kinopal from Profile → Account → Delete account. A recent sign-in may be required for security. This permanently deletes your authentication account, library, viewing progress, personal collections, content reports, and published copies of collections owned by you.

If you cannot access the app, follow the instructions on ourAccount Deletion page or emailinfo@kinopal.app. Never send a password, SMS verification code, or Apple/Google credential by email.

8. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection to processing. Where processing is based on consent, you may withdraw consent at any time without affecting earlier lawful processing. We may ask for proportionate information to verify that the request concerns your account.

Contact info@kinopal.app. We normally respond within one month. You also have the right to complain to the Italian Data Protection Authority,Garante per la protezione dei dati personali, or your local supervisory authority.

9. Security

We use access controls, encrypted network connections, platform security features, and service-provider safeguards intended to protect personal data. No system is completely secure, so we cannot guarantee absolute security.

10. Age requirement

Kinopal is intended only for people aged 18 or older because film and series metadata may include mature themes. We do not knowingly collect personal data from anyone under18. If you believe a person under that age has created an account, contact us so we can investigate and delete the data.

11. Changes to this policy

We may update this Policy when Kinopal, our providers, or applicable law changes. The effective date above identifies the current version. We will provide additional notice in the app where a change materially affects your rights or requires renewed consent.

12. Contact

Privacy questions and requests may be sent toinfo@kinopal.app or to the postal address in Section 1.

Kinopal

Your personal movie companion for discovering, saving, and tracking films and series.

ExploreFeaturesScreenshotsDownloadTermsPrivacyAccount deletion
Data sources

This product uses TMDB and the TMDB APIs but is not endorsed, certified, or otherwise approved by TMDB.

Streaming availability data powered by JustWatch.

© 2026 Kinopal · Dmitrii Galla · VAT IT01882570094· info@kinopal.app

Version 1.0