togged

Privacy Policy

Effective August 30, 2026. Version 2026-08-30.

On this page

1. What we collect

Togged collects the following information when you use the service.

How Togged uses it

2. Usage measurement, browser storage and abuse prevention

In Togged’s own daily-activity table, we record one row per account per day per kind of screen: your account, the date, and whether you were on a phone or a computer. That is the entire row in that table. It does not contain your IP address, browser user-agent, page path, or a time more precise than the date. It exists so we can tell how many people use Togged on a phone.

These rows are deleted after 180 days. Deleting your account removes them immediately.

When you sign in, Firebase Authentication handles the sign-in request and Togged sets a first-party, HTTP-only session cookie containing your account identifier, username, display name, avatar URL and bio. The cookie can keep that browser signed in for up to 30 days.

The Togged mobile app signs in with a bearer token instead of this browser cookie. That token lasts up to 24 hours and is re-checked against your account on every request, so signing out in the app stops it working right away.

Firebase Authentication’s browser SDK also keeps its own sign-in state in browser storage so it can restore your provider sign-in between visits. This client state is separate from Togged’s HTTP-only session cookie.

If you dismiss the first-steps guide on Home, Togged sets a separate account-specific, HTTP-only cookie for up to one year. Its value records only that the guide was dismissed. Replaying first steps from Settings deletes this cookie sooner.

When browser local storage is available, dismissing the optional Add to Home Screen prompt stores that choice in that browser. It is not tied to your Togged account and has no automatic expiry; clearing the site’s browser data removes it.

For signed-out requests to public or security-sensitive routes, Togged may use the request IP address as the key for an in-memory rate-limit counter. These counters are kept on the Vercel instance handling the request, not in Togged’s database.

3. Visibility within Togged

Togged is a social platform. Signed-in Togged members can view your profile, including your username, display name, bio, avatar, watch logs, reviews and comments. Your profile page, and watch activity tied to you as an individual such as your logs and the list of who watched a show, require sign-in.

One rating figure is public: the community average. Once at least three people have rated a show or episode, its average rating and the number of ratings show on show pages, episode lists and search results, including to signed-out visitors. The average is rounded to the nearest half star and no individual rating is listed, so a single reading of the figure does not tell you what any one person rated. It is still an average of real ratings. Someone who already knows how most of a small group rated, or who watches the figure change as new ratings come in, can narrow down an individual rating from it. If you would rather that not be possible for a show, do not rate it.

Clips you share are public. Signed-out visitors can view the clip, its caption and comments, plus the author’s username, display name and avatar. Clips can also appear on public show pages. Do not share anything you would not want people outside Togged to see.

Blocking someone limits what the two accounts can find and interact with while signed in. It does not make your profile private to other signed-in members, remove a public clip from signed-out visitors, or invalidate an avatar URL that someone already has. Uploaded avatars use public object-storage URLs.

4. Moderation and content filtering

Reviews, review comments, clip captions, clip comments, bios and display names are checked against a word list when you post them. If something matches, that text is withheld and queued for a moderator rather than published. While it is awaiting review, replacing or clearing a held profile field or review can delete the earlier held record. A moderator’s decision does not currently erase the withheld text or matched terms; decided records remain while your account exists.

When you report content, we store the report, who filed it, and any details you added. Reports are visible to our moderators, not to the person reported.

5. Third-party services

We use a few third-party services to run Togged:

6. Weekly email digests

Weekly email digests are currently disabled and deferred. Togged does not send weekly digest emails.

If digests are turned on later, sending them will involve a third-party email provider that receives your email address to deliver the message. Togged will record delivery outcomes such as bounces and spam complaints, and whether you click links in the email. This policy will name that provider before any digest is sent.

7. How long we keep things

8. Account deletion

You can request account deletion at any time from Settings > Danger Zone > Delete Account. On a successful request, Togged removes your Firebase sign-in credential and deletes or de-identifies the active database records tied to your account, including logs, reviews, comments, follows, blocks, likes, reports you filed, consent records, daily usage rows, profile information and clips.

The browser used for deletion is signed out. Session cookies on another browser or device are not centrally revoked today and may continue to be treated as signed in until they expire, up to 30 days. Backup artifacts from successful runs can remain for up to 90 days, and Firebase Authentication follows the provider timeline described above.

Account deletion does not clear the first-steps cookie or Add to Home Screen preference described in section 2. The cookie expires on its existing schedule, and the local-storage preference remains until that browser’s site data is cleared.

Togged attempts to delete the avatar file you uploaded, but storage cleanup can fail and a direct image URL may continue to work. Deletion crosses Firebase, PostgreSQL and object storage, so a failed step can leave part of a request incomplete. If deletion returns an error or an old avatar URL still works, contact us so we can investigate the remaining data.

9. Contact

Questions about your data, or a request for a copy of it: support@togged.tv. More ways to reach us are on the support page.