Seasons
Privacy Policy
This policy explains how MYV Studios LTD (“MYV Studios”, “we”, “us”) collects, uses, shares, and protects personal information when you use Seasons. That covers:
- the Seasons apps for iPhone, iPad, and Android;
- Seasons Web at app.getseasons.app;
- the Seasons MCP server that AI assistants connect to (
api.getseasons.app); - the website at getseasons.app.
Together these are “Seasons”. MYV Studios is the controller of your personal information for Seasons.
1. Information we collect
Your account
- Your username (your public handle) and your contact email address, which we verify and keep private.
- Your password, stored only as a salted one-way hash, if you sign in with a password.
- If you sign in with Apple or Google: the account identifier they give us and the email address you choose to share. See Google user data for exactly what we receive from Google.
Devices and sign-in sessions
For each app installation or browser you sign in with, we keep:
- an installation identifier, the platform, and the app version;
- your notification settings and, for the apps, the push notification token;
- a record of the sign-in session, so you can stay signed in and sign out of one device or all of them.
What you add to Seasons
The movies and shows on your watchlist, your viewing progress and ratings, and the streaming services you have or would consider. Your region, budget, and planning preferences. The plans Seasons calculates for you, and your alert preferences.
Families
If you create or join a Family, we keep:
- your membership and role;
- invitations, including the email address of the person invited;
- the shared Family plan.
Other members of your Family can see your username and the Family plan, which includes titles members contribute to it.
Trakt (optional)
If you connect Trakt, we store your Trakt credentials encrypted. We import your watched history, watchlist, and ratings from Trakt.
Seasons Pro purchases
Seasons Pro is sold through the App Store and Google Play and managed by RevenueCat. We receive the status of your subscription, such as active, in a trial, or expired. We never receive your payment card details.
AI assistant connections (Seasons Pro, optional)
For each AI assistant you connect, we keep:
- the name you or the app gave the connection, and its access level;
- when it was created and last used;
- for assistants that sign in, the name and return address the app registered;
- any address an assistant registers to be notified when your plan changes.
Access keys and tokens are stored only as one-way digests.
Account emails
We send emails needed to run your account: address verification, account recovery, security notices, and Family invitations. We keep delivery results and bounce or unsubscribe records so we don't send mail that shouldn't be sent.
Searches
Title searches are processed by our servers. Search terms may be passed to catalogue providers without your account details.
Diagnostics and usage in the apps
The apps use Google Firebase for:
- crash reports (Crashlytics) and performance data (Performance Monitoring);
- usage analytics (Google Analytics for Firebase);
- settings we can change remotely (Remote Config).
This can include:
- your device model, operating system, and app version;
- approximate location derived from your IP address;
- app instance identifiers;
- which screens and features are used.
Server logs
When your device, browser, or AI assistant contacts our servers, we log technical information such as the IP address, time, and the address requested. We use these logs for security and troubleshooting.
The getseasons.app website
The website uses:
- HubSpot, for its sign-up and contact forms and to understand visits;
- Ahrefs Web Analytics, for aggregated visit statistics;
- Google Fonts.
If you submit a form, we receive what you enter, such as your email address.
2. How we use it
| Purpose | Legal basis (UK and EU GDPR) |
|---|---|
| Running Seasons: your account, keeping your data in sync across devices, calculating plans, Families, Trakt import, alerts, and AI assistant access you set up | Performing our contract with you |
| Sending account emails and the notifications you turn on | Performing our contract with you; your consent for notifications, given through your device's notification permission |
| Keeping Seasons and your account secure, preventing abuse, and enforcing limits | Our legitimate interest in protecting our users and the service |
| Fixing crashes and understanding how Seasons is used, so we can improve it | Our legitimate interest in running a reliable, useful product |
| Managing Seasons Pro subscriptions | Performing our contract with you |
| Meeting legal obligations and responding to lawful requests | Legal obligation |
We do not sell your personal information.
3. AI assistants you connect
With Seasons Pro you can connect an AI assistant that supports the Model Context Protocol (MCP). You connect one either by creating an access key or by approving the assistant in the Seasons app or on Seasons Web.
A connected assistant can read:
- your username;
- your plan, subscriptions, and watchlist;
- your planning preferences;
- your Family plan, if you are in a Family.
With “read and make changes” access, it can also update your watchlist and planning preferences.
What you share with an assistant, and what it receives from Seasons, is then handled by that assistant's provider under its own privacy policy. We are not responsible for it. An assistant can register a web address to be told when your plan changes; those notices name the plan version but never include your plan's contents.
You can see and revoke connections at any time in the Seasons app (Settings → AI Agents) or on Seasons Web. Revoking one ends its access immediately.
4. Google user data
You can sign in to Seasons with your Google Account in the apps and on Seasons Web. This section explains how Seasons accesses, uses, stores, shares, and deletes the information it receives from Google (“Google user data”). Seasons uses Google only for sign-in: it does not request access to Gmail, Google Drive, Google Calendar, Google Contacts, or any other Google service.
What we access
When you choose Sign in with Google, Google asks you to share your name, email address, and profile picture with Seasons. Of that, Seasons uses and stores only:
- your Google account identifier, which tells Seasons it is the same Google Account each time you sign in;
- your email address, and whether Google has verified it.
Seasons ignores your name and profile picture and does not store them.
How we use it
- We use your Google account identifier to sign you in, and to link Google to your existing Seasons account when you ask us to.
- If you create your account with Google, your verified Google email address becomes your Seasons contact email. We use it only for the account emails described in section 1, such as address verification, account recovery, and security notices. You can change your contact email at any time.
We use Google user data only to provide and secure sign-in and your account. We do not use it for advertising, we do not sell it, and we do not use it to develop, improve, or train artificial intelligence or machine learning models.
Who we share it with
We do not share, transfer, or disclose Google user data to anyone, except:
- the service providers that run Seasons for us, under contracts that limit their use of it: Fly.io (application hosting), Neon (database), and Mailjet, which delivers account emails to your contact email address;
- when the law requires it, or to protect the rights, safety, and security of our users, the public, or MYV Studios;
- a successor, if MYV Studios is involved in a merger, acquisition, or sale of assets, in which case this policy would continue to apply.
AI assistants you connect, other members of your Family, and the analytics and crash-reporting tools in the apps never receive your Google account identifier or your Google email address.
How we protect it
- Google user data travels only over encrypted HTTPS connections.
- We accept a Google sign-in only after checking it against Google's published signing keys, confirming it was issued for Seasons, and matching it to a one-time value we issued for that sign-in.
- Our servers do not keep Google sign-in tokens: each one is checked and then discarded.
- Access to the database that holds your Google account identifier and email address is restricted to the MYV Studios staff who need it to run Seasons.
How long we keep it, and how to delete it
- We keep your Google account identifier and email address while Google is linked to your Seasons account.
- When you delete your Seasons account, we delete them together with the rest of your account data.
- To remove Google from your account without deleting the account, email [email protected].
- You can stop Google from sharing your information with Seasons at any time from your Google Account at myaccount.google.com/connections. That does not delete what we already hold; email us if you want that deleted too.
Limited Use
Seasons' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Who we share it with
We share personal information only as described here:
- Service providers that run Seasons on our behalf, under contracts that limit their use of your information:
- Fly.io (application hosting)
- Neon (database)
- Mailjet (email delivery)
- Google Firebase (push notifications, crash reporting, performance, analytics, and remote settings)
- RevenueCat (subscriptions)
- HubSpot and Ahrefs (website forms and statistics)
- Apple and Google, when you sign in with them, buy through their stores, or receive push notifications.
- Services you connect, such as Trakt and the AI assistants you approve.
- Content providers:
- The apps load posters and images directly from The Movie Database (TMDB), and may play trailers from YouTube. These providers receive your IP address and technical request information when this happens.
- Catalogue and availability providers receive searches and title requests from our servers, without your account details.
- Other members of your Family, as described above.
- Authorities or others, when the law requires it, or to protect the rights, safety, and security of our users, the public, or MYV Studios.
- A successor, if MYV Studios is involved in a merger, acquisition, or sale of assets. This policy would continue to apply to your information.
6. Where it is stored
Seasons account data is stored in the European Union, in Frankfurt, Germany. Some providers, such as Google, RevenueCat, HubSpot, Trakt, TMDB, and the AI assistants you connect, may process information in other countries, including the United States.
When information leaves the UK or the European Economic Area, we rely on safeguards the law recognises. These include adequacy decisions and data bridges, standard contractual clauses, or the UK International Data Transfer Addendum.
7. How long we keep it
- Account data and what you add to Seasons: while you have an account. It is deleted when you delete your account, as described below.
- Sign-in sessions: end after 30 days without use, or when you sign out.
- AI assistant connections: last until you revoke them.
- Access tokens for assistants that sign in expire after one hour, and their refresh tokens after 30 days without use.
- Unanswered connection requests are deleted within about a day.
- Email links: verification and recovery links expire after 15 minutes. Delivery records are kept for a limited period to prevent abuse.
- Server logs: kept for a short period for security and troubleshooting.
- Crash, performance, and analytics data: kept according to Google's retention settings for Firebase.
We may keep limited information for longer when the law requires it.
8. Security
We protect your information with technical and organisational measures:
- Connections are encrypted with HTTPS.
- Passwords are stored as salted hashes.
- Access keys and tokens are stored as digests, and Trakt credentials are encrypted.
- Seasons Web keeps your sign-in in cookies that page scripts cannot read.
- Access to production systems is restricted.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
9. Cookies and similar technologies
Seasons Web (app.getseasons.app) uses only cookies that are strictly necessary for signing in. It uses no advertising or analytics cookies:
| Cookie | Purpose | Duration |
|---|---|---|
__Host-seasons-session | Keeps you signed in | Up to 30 days |
__Host-seasons-installation | Identifies this browser as one of your devices, so you can sign it out separately | Up to 400 days |
__Host-seasons-flow | Remembers a sign-up or sign-in in progress | 30 minutes |
__Host-seasons-connect | Remembers the AI assistant connection you are reviewing | 10 minutes |
If you choose Sign in with Google or Sign in with Apple, Google or Apple may set their own cookies under their privacy policies.
The getseasons.app website uses HubSpot, which sets cookies to run forms and measure visits. You can block or delete cookies in your browser settings; forms may not work without them.
The apps don't use browser cookies. Firebase uses app instance identifiers as described above.
10. Your choices and rights
Depending on where you live, including under UK and EU data protection law, you may have the right to:
- access your personal information;
- correct it;
- delete it;
- receive a copy in a portable format;
- object to or restrict how we use it;
- withdraw consent where we rely on it.
You can also:
- turn off notifications in your device settings;
- disconnect Trakt or AI assistants at any time;
- sign out of individual devices.
To exercise a right, email [email protected]. We may need to confirm your identity first, and we will respond within the time the law requires.
If you are unhappy with how we handle your information, you can complain to a data protection authority. In the UK that is the Information Commissioner's Office; in the EU it is the authority where you live. We would appreciate the chance to help first.
11. Deleting your account
You can permanently delete your Seasons account in the app, from Settings > Manage Account > Delete Account, or request deletion without the app.
- Account-owned personal data is deleted, including your AI assistant connections and their credentials.
- Shared catalogue records and records belonging to other users remain.
- A shared contribution may remain, but only after its reference to your account has been removed.
Deleting your account does not cancel a Seasons Pro subscription. Manage that in the App Store or Google Play.
12. Children
Seasons is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has given us personal information, contact us and we will delete it.
13. Changes to this policy
We may update this policy as Seasons changes. We will post the new version here with a new effective date. If the changes are significant, including any change to how we use Google user data, we will tell you in the app or by email before they take effect.
14. Contact us
For questions about this policy or your personal information, email MYV Studios LTD at [email protected].