TotalShort Privacy Policy
The Italian version (
privacy.it.md) is the reference text.
Last updated: 30 September 2026
1. Who handles your data
Controller: Agape Group GmbH, Clarahofweg 25, 4058 Basel, Switzerland, UID CHE-184.481.924 ("TotalShort", "we"). Privacy contact: privacy@totalshort.com. EU representative (Art. 27 GDPR): [NAME AND ADDRESS], needed because the controller is established outside the EU.
2. In short
- You can use TotalShort without signing up: we give you an anonymous guest account.
- Email is optional: it only lets you get your coins and subscription back on another phone.
- You pay through Apple or Google: we never see your card details.
- Personalised ads and campaign measurement with Apple and Meta start only if you accept. You can change your mind anytime in My stuff → Privacy & ads.
- You can delete your account in the app (My stuff → Account → Delete account): we erase your data.
- We don't sell your data.
3. What we process, why, and on what legal basis
| Data | Why | Legal basis |
|---|---|---|
| Account ID (random code), language, subtitles, favourite genres | Run the app and personalise Home and For you | Performance of contract (Art. 6(1)(b)) |
| Email (only if you link it) | Sign-in on other devices, sign-in codes, renewal reminders | Performance of contract (Art. 6(1)(b)) |
| Coin balance, unlocks, subscription, purchase history | Provide purchased content, handle refunds and disputes | Contract (6(1)(b)) and legal obligations (6(1)(c)) |
| Invites (when active): personal code, who invited whom, date, whether the friend saved their account or made a purchase (yes/no, no amounts) | Give the friend and the inviter their coins, prevent abuse | Contract (6(1)(b)) and legitimate interest (6(1)(f)); deleted after 24 months or with the account (the link to the deleted account is removed) |
| App usage (episodes watched, screens, unlocks, poll answers, series opened or swiped past in the feed; if you arrive from one of our links, the campaign and source name, e.g. "meta · launch") | Improve the service and catalogue, recommend series on Home and in the feed, security, abuse prevention. Recommendations only use what you watch in the app, never data from other apps or sites; recommendation signals are deleted after 12 months without updates | Legitimate interest (6(1)(f)), without advertising identifiers |
| Notifications (if you turn them on): device token, time zone, preferences, which notifications we sent you and whether you opened them | Tell you about the series you watch at the right time, at most one a day, and check they are useful; a small share of users does not receive them, to measure their effect | Your consent to notifications (phone permission and switches in Mine → Notifications) and legitimate interest (6(1)(f)) for measurement; log deleted after 12 months |
| Device advertising identifiers; install and purchase events shared with Apple and Meta | Measure ad campaigns and show relevant ads | Consent (6(1)(a); Art. 122 Italian Privacy Code) |
| Your consent choice and its date | Prove consent | Legal obligation (Art. 7(1) GDPR) |
We do not process special categories of data (Art. 9) and we make no automated decisions with legal effects on you.
4. Who we share data with
Only with vendors processing it on our behalf (processors), or as independent controllers where stated:
- Supabase (database and authentication), servers in Frankfurt (EU).
- RevenueCat (in-app purchase management), USA.
- Apple and Google: handle payments and refunds as independent controllers, under their own policies.
- Meta Platforms and Apple Ads: only with your consent, to measure campaigns.
- Cloudflare: the totalshort.com website, abuse protection (Turnstile, an invisible check when a guest account is created and when an email code is sent, using technical signals from the device and browser) and, when enabled, video storage (R2).
- Expo (650 Industries): push notification delivery, only if you turn notifications on; receives the device token.
- Resend (Resend, Inc., USA): sends sign-in codes.
Transfers outside the EU: where a vendor processes data in the US we rely on the EU-US Data Privacy Framework, where the vendor is certified, or on the European Commission's Standard Contractual Clauses.
Business transfer: if TotalShort, or the part of the business running it, is sold or merged, the data passes to the buyer, who stays bound by this policy. We will notify you beforehand (Art. 6(1)(f)).
5. How long we keep data
- Account and preferences: while you use the service. Guest accounts with no purchases that have been inactive for 24 months are deleted with all their data, free coins included. Accounts with purchases are kept, because they hold paid coins. If you ask us to recover an old guest account, we use the order ID you give us only to find it, and we keep a record of the move.
- Purchase data: while you have an account. If you delete it, we also erase our coin and unlock records. Receipts for in-app purchases are kept by Apple or Google, who are the sellers, under their own rules.
- Usage events: 24 months, then deleted (automatic weekly job).
- Ad consent: until you withdraw it, plus proof of consent for the limitation period.
6. Your rights
You can request access, rectification, erasure, restriction and portability, and object to processing based on legitimate interest (Arts. 15–21 GDPR). You can withdraw consent at any time, with no effect on how the app works for you.
- In the app: account deletion, consent withdrawal, email and preference changes.
- By email: privacy@totalshort.com. We reply within 30 days.
- Complaints: to the Italian Data Protection Authority (garanteprivacy.it) or the authority in your country.
7. Children
TotalShort is intended for people aged at least 16. If we learn we collected data from a child under the minimum age, we delete it.
8. AI-generated content
TotalShort series are made with artificial intelligence tools and labelled as such (AI Act, Art. 50). We do not use your data to train AI models.
9. Security
- Data encrypted in transit.
- Access to data restricted per user, with row-level rules in the database.
- No payment data on our servers.
10. Changes
If we change this policy in a meaningful way, we tell you in the app before the changes apply.