FindMyVideos

Privacy Policy

Effective date: May 11, 2026 · Last updated: May 11, 2026

1. About This Policy

This Privacy Policy explains how Gripul Inc., a Texas corporation ("Gripul", "we", "us", "our"), collects, uses, shares, and protects your personal information when you use FindMyVideos (the "Service") at findmyvideos.com, myowntitles.com, and any related services we operate.

This policy is designed to comply with:

  • EU General Data Protection Regulation (GDPR) for users in the European Economic Area, United Kingdom, and Switzerland
  • California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA) for California residents
  • Texas Data Privacy and Security Act (TDPSA) for Texas residents
  • Other U.S. state privacy laws (Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, and similar laws)
  • Personal Information Protection Act (PIPA) of the Republic of Korea (where applicable to Korean residents using the Service)
  • Other applicable data protection laws

If you have questions, contact us at [email protected].

2. Controller / Operator

The entity responsible for the personal information processed under this policy is:

Gripul Inc.
A Texas corporation
Email: [email protected]

For users in the EU/EEA, UK, or Switzerland, the same contact serves as the point of contact for data protection matters. We have not appointed a Data Protection Officer (DPO) at this time, as we do not meet the mandatory appointment threshold under GDPR Article 37.

For Republic of Korea users, the same contact serves as the personal information protection officer under PIPA Article 31.

3. Categories of Information We Collect

3.1 Information from OAuth Sign-In

When you sign in via Google or Apple, we receive the following:

DataSourcePurpose
Email address (verified or relayed)OAuth providerAccount identification, communication
Display nameOAuth providerProfile display (you may change this later)
Profile picture URLOAuth providerInitial avatar (downloaded once and stored in our infrastructure)
Locale / language codeOAuth providerDefault UI language preference
Unique account identifierOAuth providerLinking your sessions to a stable identity

3.2 Information You Provide While Using the Service

  • Ratings: numerical scores (1–10) you assign to titles
  • Reviews and notes: text you submit about titles
  • Comments: text you submit on other users' reviews
  • Likes: which reviews and comments you have liked
  • Watchlist: titles you save
  • Follows: other users you follow
  • Custom profile fields: username, display name, bio
  • Avatar uploads: profile pictures you upload to replace the OAuth-provided image
  • Settings: notification preferences, interest regions, language preferences
  • Feedback messages: when you contact us via the in-app feedback form

3.3 Information Collected Automatically

  • IP-derived country code: We obtain your country code from Cloudflare's edge network (the CF-IPCountry header) at sign-up ("signup region") and at the time you submit ratings ("watched region"). We do not store your IP address itself.
  • Session cookies / tokens: To keep you signed in
  • Browser and device information: User agent, screen size, and other standard request headers
  • Activity logs: Pages visited, features used, events triggered
  • Analytics events (if Google Analytics 4 or similar is active): Aggregated and pseudonymized usage data

3.4 Information We Do NOT Collect

  • Passwords — authentication is delegated to Google or Apple OAuth
  • Government identifiers (Social Security numbers, passport numbers, etc.)
  • Payment information (no purchases are processed on the Service)
  • Health, biometric, or genetic data
  • Children's data (the Service is not directed at users under 13; see Section 11)
  • Precise location (we only receive country-level codes from Cloudflare)
  • Contacts, microphone, or other device sensors

We do not purchase user data from third parties.

3.5 Categories of Personal Information (CCPA Notice at Collection)

Under the California Consumer Privacy Act, the categories of personal information we collect are:

  • Identifiers (email, OAuth account ID, username)
  • Customer records (profile information)
  • Internet or other electronic network activity (browsing history within the Service, interaction with reviews, follows)
  • Geolocation data (country-level only, from IP)
  • Inferences (e.g., taste profile, recommendations)

We do not collect: sensitive personal information (as defined by CPRA), biometric data, financial information, or precise geolocation.

4. How We Use Your Information and Legal Basis (GDPR Art. 6)

PurposeLegal basis
Authenticating you and maintaining your sessionContract (necessary to provide the Service)
Displaying your profile, reviews, ratings, public contentContract
Showing region-specific availability informationLegitimate interest (operating a region-aware catalog)
Computing taste-match scores and recommendationsLegitimate interest
In-app notificationsContract
Email notifications (when activated and opted in)Consent
Diagnosing technical issues and securityLegitimate interest
Detecting and preventing abuse, fraud, and spamLegitimate interest, legal obligation
Aggregated analytics for product improvementLegitimate interest
Responding to legal requestsLegal obligation
Identifying demand for unsupported features or regionsLegitimate interest

You may withdraw consent at any time where processing is based on consent (e.g., by toggling off email notifications). Withdrawal does not affect the lawfulness of processing before withdrawal.

5. Region Data — Important

We collect and store country-level information derived from your IP address ("signup region" and "watched region"). This region data is used internally only. It is never:

  • Displayed publicly on your profile, reviews, comments, or any user-facing surface
  • Included in API responses available to other users
  • Shared with third parties for marketing purposes

We use region data for:

  • Internal product analytics
  • Recommendations (e.g., "Returned to Netflix" notifications based on your interest regions)
  • Tracking demand for unsupported regions
  • Anti-abuse and security investigations

If you manually set "interest regions" in your settings, that data is also stored and used only as described above.

6. Cookies and Similar Technologies

We use cookies and equivalent local storage for the following purposes:

PurposeDescriptionRequired?
Strictly necessaryAuthentication tokens, session cookies, security cookiesYes (cannot be disabled while logged in)
FunctionalRemembering your settingsNo
AnalyticsAggregated usage metrics (Google Analytics 4 or similar)No

We do not use cookies for advertising or cross-site tracking.

For users in the European Economic Area, the United Kingdom, or other jurisdictions requiring consent for non-essential cookies, we display a cookie consent banner on first visit. You can change your cookie preferences at any time through the in-app settings.

Global Privacy Control (GPC): For users in jurisdictions that recognize GPC (including California, Texas, Colorado), we honor GPC browser signals as opt-out of sale/sharing/targeted advertising. We do not engage in any of these practices, but the signal is acknowledged.

7. How We Share Information

7.1 Public Content

The following are public by default:

  • Reviews, ratings, comments, likes
  • Profile information (display name, username, avatar, bio, public statistics)
  • Lists of titles you have rated

Your personal watchlist (saved titles you have not rated) is private unless you explicitly make it public.

You may mark individual reviews as private through account settings.

7.2 Service Providers (Processors)

We share information with the following service providers, strictly to operate the Service. Each acts under contractual obligations to protect your data:

ProviderPurposeData shared
Google (OAuth)AuthenticationOAuth sign-in flow
Apple (OAuth)AuthenticationOAuth sign-in flow
Cloudflare (Workers, R2, KV, D1, Image Transformations, Access)Hosting, infrastructure, content deliveryAll Service data
Resend (when email is activated)Transactional email deliveryRecipient address, email content
OpenAI / Anthropic (when AI moderation is activated)Automated content moderationSubmitted comments and reviews
Google Analytics 4 (if active)Aggregated analyticsPseudonymized event data

These providers are bound by contracts limiting how they may use your data. We never share information with third parties for their own marketing or advertising purposes.

7.3 We Do NOT Sell or Share Your Personal Information

We do not "sell" your personal information as defined by U.S. state privacy laws (including CCPA/CPRA, TDPSA, Virginia CDPA, Colorado CPA, Connecticut CTDPA, and Utah UCPA).

We do not "share" your personal information for cross-context behavioral advertising as defined by CPRA.

We do not engage in targeted advertising, profiling for legal/significant effects, or processing of sensitive personal information for which opt-in consent is required by U.S. state laws.

7.4 Legal Disclosures

We may disclose information when:

  • Required by law, court order, subpoena, or governmental request
  • Necessary to enforce our Terms of Service
  • Necessary to protect the rights, safety, or property of Gripul Inc., our users, or the public
  • In response to verified DMCA takedown notices

7.5 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, user information may be transferred as part of that transaction. We will notify users in advance and provide options where required by law.

8. Data Retention

Data categoryRetention period
Active account profile (email, display name, OAuth identifier)While account is active
Public User Content (reviews, ratings, comments)While account is active or until you delete
Watchlist, likes, followsWhile account is active
Avatar files in R2 storageWhile account is active or until replaced
Region data (signup region, watched region)While account is active
Session data and authentication tokensUp to 30 days after last use, or until you sign out
Analytics event data (pseudonymized)Up to 14 months
Cookie consent recordsUp to 13 months from collection
Deleted account dataSoft-deleted for up to 30 days, then permanently deleted
Banned account record (for abuse prevention)Up to 2 years from ban date, then permanently deleted
Backup snapshotsUp to 30 days
Audit logs (admin actions, security events)Up to 1 year
Legal records (DMCA notices, regulatory requests)As required by law (typically 3–7 years)

Aggregated, anonymized data that cannot be linked to you may be retained indefinitely.

9. International Data Transfers

Gripul Inc. is based in the United States (Texas). Our primary infrastructure provider (Cloudflare) operates globally, and your data may be processed in countries other than your own.

For transfers from the European Economic Area, United Kingdom, or Switzerland to countries without an adequacy decision, we rely on:

  • Standard Contractual Clauses (SCCs) with our service providers
  • Cloudflare's published data residency commitments
  • Supplementary measures where appropriate

For transfers from the Republic of Korea, we comply with PIPA's cross-border transfer requirements.

You may request more information about specific transfer mechanisms by contacting us.

10. Your Rights

The rights below apply based on your jurisdiction. To exercise any right, use the in-app tools (where provided) or contact [email protected]. We will respond within the timeframes required by applicable law (typically 30–45 days). We may request identity verification before fulfilling certain requests.

10.1 GDPR Rights (EU/EEA, UK, Switzerland)

You have the right to:

  • Access — receive a copy of your personal information
  • Rectification — correct inaccurate or incomplete data
  • Erasure ("right to be forgotten") — request deletion
  • Restriction — limit our processing of your data
  • Portability — receive your data in a structured, machine-readable format
  • Object — object to processing based on legitimate interest
  • Withdraw consent — for processing based on consent
  • Lodge a complaint with your supervisory authority

10.2 CCPA / CPRA Rights (California)

You have the right to:

  • Know what categories and specific pieces of personal information we collect, the sources, business purposes, and third parties with whom we share it
  • Delete your personal information (subject to legal exceptions)
  • Correct inaccurate personal information
  • Limit the use and disclosure of sensitive personal information (we do not collect sensitive PI as defined by CPRA)
  • Opt-out of sale or sharing (we do not sell or share personal information)
  • Non-discrimination — we will not deny service, charge different prices, or provide lower quality service for exercising your rights

We will respond within 45 days (with a possible 45-day extension if necessary, with notice).

You may designate an authorized agent to make requests on your behalf, with appropriate written authorization.

10.3 Texas Privacy Rights (TDPSA)

If you are a Texas resident, you have the right to:

  • Confirm whether we process your personal data
  • Access your personal data
  • Correct inaccuracies
  • Delete your personal data
  • Obtain a portable copy of your data
  • Opt out of sale of personal data, targeted advertising, and profiling for decisions producing legal or similarly significant effects (we do not engage in any of these)
  • Appeal any refusal to act on your request

10.4 Other U.S. State Rights

If you reside in a state with applicable privacy laws (Virginia, Colorado, Connecticut, Utah, Oregon, Montana, New Jersey, Delaware, Iowa, Indiana, Tennessee, and others), you have substantially similar rights as listed above. We honor these rights regardless of which state you reside in.

10.5 PIPA Rights (Republic of Korea)

You have the following rights as a data subject:

  • Right to access personal information (PIPA Article 35)
  • Right to correction and deletion (Article 36)
  • Right to suspend processing (Article 37)
  • Right to withdraw consent
  • Right to file a complaint with the Personal Information Protection Commission

For children under 14, a legal representative may exercise these rights on their behalf.

For disputes, you may contact:

  • Personal Information Dispute Mediation Committee (1833-6972)
  • Korea Internet & Security Agency Privacy Center (118)
  • Supreme Prosecutors' Office Cyber Investigation Division (1301)
  • National Police Agency Cyber Safety Bureau (182)

10.6 Other Jurisdictions

If you are not in the listed jurisdictions, you may still have rights under your local law. Contact us at [email protected].

11. Children's Privacy

The Service is not intended for users under the age of 13, in compliance with the U.S. Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will delete it promptly and terminate the associated account.

For jurisdictions requiring higher minimum ages for online services (e.g., 16 in some EU member states under GDPR Article 8), users must meet the locally applicable threshold.

If you are a parent or guardian and believe your child has provided personal information to us, please contact [email protected]. We will work with you to remove the information.

In the Republic of Korea, processing of personal information of children under 14 requires consent of a legal representative. By signing in via Google or Apple OAuth, users represent that they meet the applicable age requirements.

12. Automated Decision-Making and AI

We use automated systems for the following purposes:

  • Content moderation (when activated): AI classifiers may evaluate comments and reviews for spam, abuse, or policy violations. Flagged content may be hidden pending human review. You can request human review of any moderation decision affecting your content.
  • Taste-match scoring: Algorithms compute compatibility scores between user accounts based on common ratings.
  • Recommendation surfaces: Aggregated rating data informs which titles appear in discovery sections.

These systems do not produce legal or similarly significant effects on you within the meaning of GDPR Article 22 or U.S. state privacy laws. You have the right to request human review of any moderation decision by contacting [email protected].

13. Security

We implement reasonable technical and organizational measures to protect your personal information, including:

  • HTTPS encryption for all data in transit
  • Authentication via established OAuth providers (we do not handle passwords)
  • Access controls on infrastructure (Cloudflare Access for admin endpoints)
  • Rate limiting to prevent abuse
  • Server-side input validation
  • EXIF metadata stripping from uploaded images
  • Audit logs for administrative actions

No system is 100% secure. In the event of a personal data breach affecting your rights, we will notify you and applicable supervisory authorities within the timeframes required by law (within 72 hours of awareness under GDPR; without unreasonable delay under U.S. state laws).

14. Third-Party Services and Links

The Service may contain links to third-party websites (e.g., Netflix watch pages, IMDb pages). Once you leave our Service, this Privacy Policy no longer applies. We are not responsible for the privacy practices of other sites.

Gripul Inc. and FindMyVideos are not affiliated with Netflix, Inc. or IMDb.com, Inc. Trademarks and content remain the property of their respective owners.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes:

  • The "Last updated" date will be revised
  • Material changes will be announced through the Service (e.g., in-app banner) and, where required by law, by direct notification
  • We will not retroactively reduce your privacy rights without your explicit consent

16. Languages

This policy is published in English. Where translations are provided for user convenience, the English version controls in case of any inconsistency.

17. Contact

For all privacy-related questions, requests, or concerns:

Email: [email protected]
Operator: Gripul Inc., a Texas corporation
Personal Information Protection Officer: Gripul Inc.


This Privacy Policy is effective as of the date stated at the top of this document.

FindMyVideos · Netflix catalog discovery
Home · Browse · Terms · Privacy