StaseraSign in

Privacy Policy

Last updated 18 August 2026

This policy explains what personal data Stasera collects, why, and the rights you have over it. Stasera is a free, personal project and takes a data-minimal approach: it collects only what is needed to run the service.

Data controller

The data controller responsible for your personal data is Augum Holding AS (organisation number 918 952 128), a company registered in Norway. For any privacy request, email hi@stasera.app.

What data we process

  • Account credentials — your email address and a hash of your password (never the password itself), managed by Convex Auth.
  • Sign-in identifiers — if you sign in with Google, the OAuth subject identifier and email returned by Google.
  • Watch history — the shows and films you follow and the episodes you mark as watched.
  • Imported data — if you choose to import from another tracking service, the viewing history contained in the file you upload, along with any ratings and reviews it includes.
  • Settings — the preferences you set, such as your region and the language you read titles in. If you have not chosen a title language, we record one guess from the language your browser reports, so notifications and emails can name titles the way the app does. It is stored once, never updated behind your back, and you can override it at any time under Settings.
  • Usage analytics — anonymous, aggregated product usage and anonymous session replays measured in a cookieless way (see “Product analytics and session replay” below).
  • Diagnostic logs — to keep the service working we log the metadata lookups it makes on your behalf, including the endpoint, the search text you typed, and whether the call succeeded. These logs are used for troubleshooting only and are deleted automatically after 30 days.
  • Error reports — when the application encounters an unexpected error, a report is sent to Sentry that includes the error details, your IP address, the page and action that triggered it, and, if you are signed in, your internal account identifier. These reports are used solely to diagnose and fix bugs and are never used for profiling or advertising.

Why we process it and our legal basis

  • To provide the service — creating your account, authenticating you, and storing your watch history. Legal basis: performance of a contract with you.
  • To improve the product — understanding aggregate usage patterns and diagnosing problems. Legal basis: legitimate interest in maintaining and improving the service, balanced against your privacy.

Processors and third parties

  • Convex — database and backend hosting (United States, under EU Standard Contractual Clauses).
  • Vercel — application hosting and content delivery.
  • TMDB — show and film metadata. Lookups happen server-side; your personal data is never shared with TMDB.
  • PostHog (EU) — cookieless usage analytics and session replay, hosted in the European Union.
  • Sentry (EU) — application error monitoring, hosted in the European Union (de.sentry.io). Receives the error reports described above.
  • OpenAI — writes the short texts described under “AI-generated text” below (United States, under EU Standard Contractual Clauses).

What we never do

  • We do not sell or license your personal data to any third party.
  • We do not serve advertisements or build advertising profiles.
  • We do not send marketing emails.
  • We do not share your watch history with other users.
  • We do not use your personal data to train AI models, and the AI provider we use does not train on it either.
  • We only disclose personal data to public authorities when required to do so by law. Where we are legally permitted to do so, we will notify you before complying.

Product analytics and session replay

Stasera uses PostHog (EU Cloud, hosted in the European Union) to understand how the service is used — which features people use and where they run into problems — including anonymous replays of how the interface is operated.

  • Analytics is fully anonymous: usage data and replays are never linked to your account, email, or watch history, and no identified analytics profiles are created.
  • PostHog sets no cookies; identifiers live only in your browser’s memory and are discarded when you close the page.
  • Session replays mask all visible text and all form inputs, so usernames, watchlists, and other personal details are not readable in recordings.
  • Legal basis: our legitimate interest in understanding and improving the service.

AI-generated text

Some of the text you see in Stasera — short highlights about your own viewing history — is written by a language model provided by OpenAI. The text is generated in the background on our servers and stored on your account; nothing is sent to a model while you use the app, and no AI feature reads what you type.

  • What is sent — a small, structured set of facts taken from your watch history: show and film titles, dates, and counts, together with the language the text should be written in.
  • What is never sent — no email address, no name, and no account identifier. OpenAI receives nothing that identifies you. This is enforced by the code that builds the request, not by policy alone.
  • Retention at OpenAI — OpenAI does not train its models on data submitted through its API. It may keep the input for up to 30 days for abuse monitoring, after which it is deleted.
  • Retention at Stasera — the generated text is stored with the rest of your account data and is removed when you delete your account.
  • Legal basis: our legitimate interest in making the service more useful, balanced against your privacy.

Cookies and local storage

Stasera uses only what is necessary to work. Authentication tokens keep you signed in, and your theme preference is stored in your browser’s local storage. Analytics are cookieless: PostHog EU runs in memory-only mode and sets no tracking cookies, and Vercel Analytics and Speed Insights are cookieless by design. Because no tracking cookies are set, there is no consent banner.

Retention and deletion

Your data is kept for as long as your account exists. Diagnostic logs are deleted automatically after 30 days. You can delete your account at any time from the app’s settings; doing so permanently removes all of your data, including your authentication record and your entire watch history.

Your rights

Under the GDPR you have the right to access, correct, and delete your personal data, to object to or restrict processing, and to data portability. You can download a copy of your data at any time from Profile → Data → Export my data, which produces a machine-readable export of your watch history. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet). To exercise any of these rights, email hi@stasera.app.

Business transfers

If Augum Holding AS is acquired by or merged with another company, your personal data may be transferred as part of that transaction. Any successor entity will be required to honour this Privacy Policy or notify you before applying materially different terms.

Changes to this policy

This policy may be updated from time to time. Any changes will be posted on this page with an updated date above.