Privacy Policy
Effective August 30, 2026. Version 2026-08-30.
On this page
1. What we collect
Togged collects the following information when you use the service.
- Account: your email address, username, display name, bio, avatar image, discovery setting, and email preferences.
- What you log: the shows, seasons and episodes you log, your watch status, ratings, reactions, tags, favourites, rewatch count, whether you are currently bingeing a show, a favourite character, dates, and free-text reviews.
- Social: who you follow, who follows you, accounts you block, comments you write, reviews and clips you like, clips and captions you share, and show requests you submit.
- Safety: reports you file, plus text and matched terms our automated filter withholds for a moderator to review (section 4).
- Consent records: which version of the Terms you accepted and when, so we can show what you agreed to.
- Product research: if you answer the optional “would you want a phone app?” question in Settings, we keep your latest answer.
- Favorite shows: the five shows you choose during onboarding, any changes you make later, and the My Shows entries created for newly added favorites you had not already logged.
How Togged uses it
- We use account and session information to sign you in, keep that browser signed in, and provide your profile and settings.
- We use logs and social activity to provide watch tracking, reviews, feeds, follows, shared clips and discussions, plus show and people suggestions where those features are available.
- We use your favorite-show selection to start and personalise your show recommendations. The selection itself is not shown to other users, and you can change it anytime from your profile. When you add a new favorite, a show that is not already in My Shows is added as Watched with no rating and creates the same activity as another show log. Existing log details stay unchanged. Removing a favorite does not delete its My Shows entry, and deleting that entry does not remove the favorite or recreate it while the show remains selected.
- We use safety information to screen submissions, route reports and support moderator decisions about held or reported content.
- We use consent, product-research and usage records to show which Terms you accepted and evaluate phone and Home Screen use.
2. Usage measurement, browser storage and abuse prevention
In Togged’s own daily-activity table, we record one row per account per day per kind of screen: your account, the date, and whether you were on a phone or a computer. That is the entire row in that table. It does not contain your IP address, browser user-agent, page path, or a time more precise than the date. It exists so we can tell how many people use Togged on a phone.
These rows are deleted after 180 days. Deleting your account removes them immediately.
When you sign in, Firebase Authentication handles the sign-in request and Togged sets a first-party, HTTP-only session cookie containing your account identifier, username, display name, avatar URL and bio. The cookie can keep that browser signed in for up to 30 days.
The Togged mobile app signs in with a bearer token instead of this browser cookie. That token lasts up to 24 hours and is re-checked against your account on every request, so signing out in the app stops it working right away.
Firebase Authentication’s browser SDK also keeps its own sign-in state in browser storage so it can restore your provider sign-in between visits. This client state is separate from Togged’s HTTP-only session cookie.
If you dismiss the first-steps guide on Home, Togged sets a separate account-specific, HTTP-only cookie for up to one year. Its value records only that the guide was dismissed. Replaying first steps from Settings deletes this cookie sooner.
When browser local storage is available, dismissing the optional Add to Home Screen prompt stores that choice in that browser. It is not tied to your Togged account and has no automatic expiry; clearing the site’s browser data removes it.
For signed-out requests to public or security-sensitive routes, Togged may use the request IP address as the key for an in-memory rate-limit counter. These counters are kept on the Vercel instance handling the request, not in Togged’s database.
3. Visibility within Togged
Togged is a social platform. Signed-in Togged members can view your profile, including your username, display name, bio, avatar, watch logs, reviews and comments. Your profile page, and watch activity tied to you as an individual such as your logs and the list of who watched a show, require sign-in.
One rating figure is public: the community average. Once at least three people have rated a show or episode, its average rating and the number of ratings show on show pages, episode lists and search results, including to signed-out visitors. The average is rounded to the nearest half star and no individual rating is listed, so a single reading of the figure does not tell you what any one person rated. It is still an average of real ratings. Someone who already knows how most of a small group rated, or who watches the figure change as new ratings come in, can narrow down an individual rating from it. If you would rather that not be possible for a show, do not rate it.
Clips you share are public. Signed-out visitors can view the clip, its caption and comments, plus the author’s username, display name and avatar. Clips can also appear on public show pages. Do not share anything you would not want people outside Togged to see.
Blocking someone limits what the two accounts can find and interact with while signed in. It does not make your profile private to other signed-in members, remove a public clip from signed-out visitors, or invalidate an avatar URL that someone already has. Uploaded avatars use public object-storage URLs.
4. Moderation and content filtering
Reviews, review comments, clip captions, clip comments, bios and display names are checked against a word list when you post them. If something matches, that text is withheld and queued for a moderator rather than published. While it is awaiting review, replacing or clearing a held profile field or review can delete the earlier held record. A moderator’s decision does not currently erase the withheld text or matched terms; decided records remain while your account exists.
When you report content, we store the report, who filed it, and any details you added. Reports are visible to our moderators, not to the person reported.
5. Third-party services
We use a few third-party services to run Togged:
- Firebase Authentication (Google) for sign-in and account security. Every way of signing in to Togged, including Sign in with Apple, runs through Firebase Authentication. Google’s Firebase privacy documentation says Firebase Authentication processes email addresses, IP addresses and user-agent strings for authentication and abuse prevention.
- Apple for Sign in with Apple. If you sign in that way, Togged asks Apple for your name and email address, and Apple decides what to send. Apple only returns your name the first time you authorise Togged, so a later sign-in may carry no name at all. If you choose Hide My Email, Togged receives a private relay address ending in
@privaterelay.appleid.comand never sees your real one; that relay address is what we store and what any Togged email would be sent to. Togged does not receive your Apple ID password. When you delete your account we ask Apple to revoke the sign-in grant, so Togged stops appearing in your Apple ID settings; the code that authorises that revocation is used at deletion time and is not stored. Read Apple’s Sign in with Apple privacy notice. - Supabase for PostgreSQL database hosting, and for storing the profile picture you upload.
- Vercel for hosting, image delivery, and analytics. Web Analytics can receive page-view details such as a timestamp, URL, referrer, coarse location, device type, operating system and browser. Togged also sends install-prompt events and, for a Home Screen launch, a source value from the URL when one is present. Vercel’s Web Analytics privacy documentation says it does not use third-party cookies or associate these records with an individual or IP address.
- GitHub Actions for private database-backup artifacts created by successful backup runs. Those artifacts are configured to expire after 90 days.
- TVDB for television show metadata and artwork.
- TikTok and YouTube for clips members share and source links Togged may curate through a clearly identified Togged account. An Edit may load an image from the provider’s network. When you choose to play it, your browser loads the provider’s embedded player and contacts that provider directly. The provider can receive your IP address and may set or read cookies under its own privacy policy. We do not host the video. Read TikTok’s Privacy Policy, YouTube’s Terms of Service, and Google’s Privacy Policy.
6. Weekly email digests
Weekly email digests are currently disabled and deferred. Togged does not send weekly digest emails.
If digests are turned on later, sending them will involve a third-party email provider that receives your email address to deliver the message. Togged will record delivery outcomes such as bounces and spam complaints, and whether you click links in the email. This policy will name that provider before any digest is sent.
7. How long we keep things
- Your active content and account data: until you delete it, or until you delete your account, subject to the exceptions below.
- Daily usage rows: 180 days.
- Reports and content-filter records: reports you file and filter records tied to your account are deleted when account deletion succeeds. A report about your account or content can remain in the moderation record because its target is stored separately from your account row.
- Database backups: backup artifacts from successful runs can remain for up to 90 days before GitHub expires them.
- Firebase Authentication: Google’s current privacy documentation says authentication data is removed from its live and backup systems within 180 days after Togged asks it to delete the user.
8. Account deletion
You can request account deletion at any time from Settings > Danger Zone > Delete Account. On a successful request, Togged removes your Firebase sign-in credential and deletes or de-identifies the active database records tied to your account, including logs, reviews, comments, follows, blocks, likes, reports you filed, consent records, daily usage rows, profile information and clips.
The browser used for deletion is signed out. Session cookies on another browser or device are not centrally revoked today and may continue to be treated as signed in until they expire, up to 30 days. Backup artifacts from successful runs can remain for up to 90 days, and Firebase Authentication follows the provider timeline described above.
Account deletion does not clear the first-steps cookie or Add to Home Screen preference described in section 2. The cookie expires on its existing schedule, and the local-storage preference remains until that browser’s site data is cleared.
Togged attempts to delete the avatar file you uploaded, but storage cleanup can fail and a direct image URL may continue to work. Deletion crosses Firebase, PostgreSQL and object storage, so a failed step can leave part of a request incomplete. If deletion returns an error or an old avatar URL still works, contact us so we can investigate the remaining data.
9. Contact
Questions about your data, or a request for a copy of it: support@togged.tv. More ways to reach us are on the support page.