Nxtory← Back to Nxtory

Privacy Policy

Last updated: August 12, 2026

Welcome to Nxtory. This mobile application (the “App”) and the website located at nxtory.app (the “Website”) are owned and operated by Puri Consulting LLC (“we,” “our,” “us,” or the “Company”).

Nxtory is a personal media tracker. You use it to log the shows, movies, and books you consume, and — if you choose to — to share some of that activity with people you approve. This policy explains exactly what we collect, where it goes, who else touches it, and how to get it back or delete it.

We have tried to write this in plain language rather than boilerplate. Where we do something you might not expect, we say so directly rather than burying it.

1. Information We Collect

A. Account & Authentication Data

  • Email Address. Your unique account identifier and the channel for critical account communications (password resets, email-change confirmations, security notices).
  • Username. A permanent, unique, public handle. Please choose carefully: usernames cannot be changed after they are set. Your username is visible to other users, is how people find and follow you, and is checked against a moderation blocklist when you create it. We reserve the right to reclaim usernames that violate our Terms.
  • Sign-In Method. Whether you registered with email/password, Google Sign-In, or Apple Sign-In.
  • Profile Details. Your first and last name and your country and state/region, where you provide them. These are used to personalize the App and are not sold, shared with advertisers, or used to build a marketing profile.
  • Authentication Metadata. Account registration date, sign-in timestamps, and security logs maintained by our authentication provider.

B. Application Tracking Data

This is the substance of what Nxtory stores, and it exists because you asked the App to remember it:

  • Catalog Entries. The TV shows, movies, and books in your library, together with the public metadata attached to them.
  • Watch & Read Progress. Episodes marked watched with timestamps, movie viewings and rewatches, book reading progress and page counts.
  • Ratings & Diary Entries. Your 1–5 star ratings, your dated diary activity, and any note or detail line you write.
  • List States. Where each title sits — Tracking, Want to Watch, Watched, Reading, and so on.
  • People You Follow. Actors and authors you follow for release reminders.

C. Device & Technical Data

  • Push Notification Token. If you enable notifications, we store a device registration token issued by Firebase Cloud Messaging so that our servers can deliver notifications to your device. See Section 7.
  • Platform. Whether a registered device is iOS or Android, so notifications are formatted correctly.
  • Last Opened Date. A single timestamp recording the last date you opened the App, updated at most once per day. It exists solely to operate the inactive-account policy in Section 11 — so that we delete abandoned accounts without ever deleting one that is still in use. We do not log individual sessions, session length, or in-app behavior.
  • Platform-Level Diagnostics. Aggregated, anonymized crash and performance data that your operating system may share with us according to your own device settings. You control this in iOS or Android settings.
  • Web Server Logs. When you visit the Website, our hosting provider records standard server logs including IP address, browser type, referring pages, and timestamps.

D. What We Do Not Collect

  • No analytics or behavioral telemetry. The App embeds no analytics SDK, no advertising SDK, and no third-party crash-reporting SDK. We do not track how you move through the App, we do not build an advertising profile, and we do not sell data.
  • No advertising identifiers. We do not read the iOS IDFA or the Android Advertising ID.
  • No payment details. See Section 10.
  • No location data. We do not request or collect device location. The country/region on your profile is a value you typed, not a coordinate we measured.

Firebase Cloud Messaging, described in Section 7, is a message-delivery service. It is not an analytics or crash-reporting product and we do not use it as one.

2. How Your Data is Stored and Processed

Nxtory keeps two copies of your library:

  • On your device. A local database is the App’s primary source of truth, which is why the App works offline. This file lives in the App’s private storage and remains on your device until you clear the App’s data or uninstall it.
  • In the cloud. Your data is synchronized to our Supabase project so it survives losing a phone and follows you to a new one. Access is enforced by row-level security policies, meaning a signed-in user can read and write their own rows and no one else’s.

Data is transmitted over encrypted connections (TLS) and encrypted at rest by our infrastructure providers.

3. Third-Party Service Providers

We keep this list short deliberately. Every company below is a processor acting on our instructions, not a partner we sell data to.

Infrastructure

Provider Role What it handles
Supabase, Inc. Database, authentication, serverless functions Your account and library data
Cloudflare, Inc. DNS, hosting, network security, email routing Website traffic and server logs
Google LLC (Firebase Cloud Messaging) Push notification delivery Your device push token and notification payloads
RevenueCat, Inc. Subscription management Purchase receipts and subscription status (see Section 10)
Resend, Inc. Transactional and contact-form email Messages you send us
Apple Inc. / Google LLC Sign-in services and app distribution Authentication and store transactions

Metadata Catalogs

The App queries these services for public information about titles — a poster, a synopsis, an air date, a content rating. These are anonymous lookups about titles, not about you: no account identifier, email, or personal data is attached to them.

  • The Movie Database (TMDb) — film and television metadata
  • OMDb — IMDb ratings, Rotten Tomatoes scores, and content certifications
  • Google Books and Open Library — book metadata
  • Trakt.tv — title and air-date lookups (distinct from a connected Trakt account, see Section 6)

4. Sharing With Other Users (Your Circle)

Nxtory includes optional social features. Nothing is shared with another user until you approve that person as a follower. Follow requests require your approval, and you can remove a follower at any time in Settings, which immediately revokes their access.

What an approved follower can see

  • Diary entries: the title you watched or read, your note or detail line, your star rating, and the date and time.
  • Stats: aggregate figures such as watch hours, counts by media type, and your Top Actors list (your ten most-watched actors with counts).
  • Your public profile: your username and the display name you have set.

To make stats load quickly and accurately for the people who follow you, the App periodically computes summary snapshots of your activity — totals and counts for fixed time windows — and stores them in your account for approved followers to read. These snapshots contain aggregate figures, not your raw history.

What an approved follower cannot see

  • Your email address, password, or any authentication data
  • Your profile’s legal name, country, or state
  • Your payment or subscription details
  • Your library beyond what appears in shared diary entries and stats
  • Who else follows you, or who you follow

Public by design

Your username is public. Other users can search for it in order to send you a follow request. If you would prefer not to be discoverable, do not accept follow requests — but understand that the username itself is visible.

5. Community Contributions

Some of what you contribute is pooled with other users’ contributions and shown to people outside your Circle. This is always aggregated and de-identified — your name and username are never attached to it — but we want to be explicit that it leaves your account.

  • Nxtory Score. Your 1–5 star ratings are included in a cross-user average score displayed on title pages to all users. Your individual rating is never shown as yours.
  • Catalog corrections. When you correct a book’s series membership or ordering, that correction is recorded as an anonymous vote. Where enough users agree, the majority result is applied to the shared catalog and may appear on other users’ devices. Your own local edits always take precedence on your own device.

If you delete your account, your contributions to these aggregates are removed along with the rest of your data.

6. Connected Accounts (Trakt)

You may optionally connect a Trakt.tv account to import and synchronize your watch history. If you do:

  • You authorize the connection through Trakt’s own login screen. We never see your Trakt password.
  • We store an access token so the App can sync on your behalf.
  • Data flows in both directions according to the sync settings you choose.
  • You can disconnect at any time in Settings, which discards the token.

Your use of Trakt is governed by Trakt’s own privacy policy and terms.

7. Notifications

Nxtory uses two different notification mechanisms, and they have meaningfully different privacy implications.

Local reminders (no data leaves your device)

Reminders for a tracked show’s next episode, and for new releases from actors and authors you follow, are scheduled locally on your device. They are computed from data already on your phone. No server is involved and no token is required for these.

Push notifications (server-delivered)

Notifications about Circle activity — such as someone requesting to follow you — are sent from our servers and require push infrastructure:

  • When you grant notification permission, the App registers with Firebase Cloud Messaging, a Google service, which issues a device registration token.
  • We store that token, along with whether the device is iOS or Android, in our database linked to your account. This is the address our servers deliver to; it is not a browsing history and it does not tell us what you do in the App.
  • The notification content is transmitted through Google’s infrastructure in order to reach your device.
  • Tokens are replaced when the operating system rotates them, and are deleted when you delete your account.

Your controls

Each notification type can be turned off individually in Settings, and notifications can be disabled entirely in your device’s OS settings. Turning notifications off in your OS stops delivery; to also remove the stored token, sign out or delete your account.

Note: A previous version of this policy stated that we did not operate a push-notification service and did not collect push tokens. That was accurate when written, when the App used only local reminders. It is no longer accurate, and this section replaces it.

8. Home Screen Widget (Android)

The Android home screen widget reads directly from the App’s local database on your device to display your Up Next titles and artwork. Widget rendering happens entirely on-device. No additional data is collected, and nothing is transmitted in order to draw the widget.

9. Importing Data From Other Services

Nxtory can import your history from other trackers via a file you export from them (for example a JSON or spreadsheet export). When you do this:

  • You select the file yourself using your device’s file picker. The App has no standing access to your files.
  • The file is parsed entirely on your device. We do not upload your import file to our servers.
  • The library entries produced by the import are then synced to your account like any other entry.

10. Subscriptions and Payments

Nxtory offers a free trial followed by a paid subscription.

We never receive, collect, or store your payment card number, billing address, or any financial details. When you purchase a subscription, the transaction is handled entirely by the Apple App Store or Google Play, who act as the merchant of record and process the payment.

To manage entitlements across your devices and platforms, we use RevenueCat, Inc. as our subscription-management provider. RevenueCat sits between the App and the app stores and does not process payments or handle card data either. RevenueCat receives:

  • The purchase receipt and transaction history issued by Apple or Google
  • An app user identifier, which is your Nxtory account identifier, so your subscription follows your account rather than a single device
  • Basic device, platform, and country information supplied by the store

We receive your subscription status — active, trialing, expired, or lifetime — and the dates associated with it. That status is stored on your profile and determines your access to paid features.

Subscription management, cancellation, and refunds are handled through your Apple or Google account settings and are governed by those stores’ policies.

11. Data Retention, Export & Account Deletion

  • Export (Data Portability). You can export your complete library at any time from Settings as a JSON or CSV file, directly on your device — no request to us required.

  • Account Deletion. You can permanently delete your account from within the App (Settings → Delete Account). This immediately and irreversibly purges your account, library, watch and read history, ratings, diary entries, social connections, and push tokens from our databases. You may also request deletion via the contact link below.

  • Automatic deletion of inactive accounts. So that we do not retain data for people who have stopped using Nxtory, we permanently delete an account when all of the following are true: the account has no active subscription and no lifetime access, it is not in an active free trial, and the App has not been opened for 90 days or more.

    We will always warn you first. At 75 days of inactivity we email the address on your account to tell you the date your account is scheduled for deletion and how to keep it. We will not delete an account that has not received that warning at least 14 days beforehand — if for any reason the warning cannot be delivered, the account is retained rather than deleted.

    Opening the App is all it takes. Simply launching Nxtory while signed in resets the clock completely and cancels any pending warning. You do not need to sign in again, make a purchase, or take any other action.

    To measure this we record a single timestamp — the last date you opened the App — which is updated at most once per day. We do not log individual sessions or how long you use the App.

    Deletion is permanent, irreversible, and cascades to all associated data. If you would like to keep a copy, export your library from Settings first.

  • Local Copies. The database file on your own device remains until you clear the App’s data or uninstall it. Deleting your account does not reach a device that is offline; clear the App’s data or uninstall it to remove the local copy.

  • General Retention. We retain your data only while your account is active, subject to the automatic deletion rule above.

12. Global Privacy Rights (GDPR & CCPA/CPRA)

Wherever you live, you can exercise the core rights below. Most are available immediately in the App without contacting us.

  • Access & Portability. Export your full library from Settings at any time.
  • Rectification. Edit your profile and correct your library entries directly in the App. (Usernames are the exception — see Section 1A.)
  • Erasure. Delete your account from Settings, which purges your data.
  • Objection & Restriction. Disable notifications, decline social features, or disconnect Trakt at any time.
  • Non-Discrimination. We will not degrade your service for exercising these rights.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have never done so.

If you are in the European Economic Area or the United Kingdom, our legal bases for processing are: performance of a contract (operating the account and syncing your library), consent (notifications, optional social features, connected accounts), and legitimate interests (security, abuse prevention, and keeping the service running). You may withdraw consent at any time, and you have the right to lodge a complaint with your local supervisory authority.

13. Children's Privacy

Nxtory does not knowingly target, solicit, or collect personal data from anyone under 13 (or under 16 in certain European jurisdictions). If we learn that a child has created an account without verifiable parental consent, we will terminate the account and purge the data.

14. Updates to This Privacy Policy

We will update this policy when the App changes in a way that affects your privacy, and we will revise the “Last Updated” date at the top. For material changes — new categories of data, a new processor, or a new way data is shared — we will provide notice in the App or by email before the change takes effect.

15. Contact Information

For questions, concerns, or to exercise your data rights, please contact us.

Puri Consulting LLC