CinemaCC — Privacy Policy
Last updated: September 12, 2026
Overview
CinemaCC is a bilingual subtitle companion for films on any screen. Its core subtitle import, playback, history, Apple Watch transfer, microphone capture, and speech recognition work on your devices. The native app can also search third-party movie and subtitle services when you explicitly use Find subtitles online, and can offer an optional paid OpenSubtitles AI translation when a requested subtitle language is unavailable. Other limited network requests support product analytics, crash diagnostics, software updates, purchases, and the authenticated subtitle gateways described below.
CinemaCC does not require a visible account or signup and has no ads or advertising tracking. When movie requests need gateway fallback or you select a movie for online subtitle search, CinemaCC creates or restores a persistent anonymous Supabase identity for authenticated gateway warmup, fallback, quota, and abuse controls. You may also choose to connect your own OpenSubtitles account. We do not sell personal data.
Data That Stays on Your Devices
The subtitle files you import or download, file names, screening history, resumable playback state, and app settings are stored locally and are not uploaded for subtitle playback or synchronization. The product analytics described below can include playback duration and progress measurements and, for online screenings, the numeric movie catalog ID. They do not include movie titles or subtitle text; selected subtitle file IDs are limited to the paid-translation and manual-offset events described below. A completed OpenSubtitles download is cached on the device for up to 24 hours to avoid consuming the same daily download allowance twice; a selected pair is added to local history when you start playback.
To let you report the exact OpenSubtitles result you selected, the native app keeps up to 20 recent download records on your device. A record contains the provider file ID, movie title and year, language, release name, file name, and download time, but not the subtitle text. Choosing one in Settings > Support & Legal > Subtitle issue opens an email draft addressed to CinemaCC Support. Those identifiers leave your device only if you choose to send the email, and you can review or edit the draft first.
If you use the Apple Watch companion, subtitle files and playback position travel directly between your paired iPhone and Apple Watch through Apple's WatchConnectivity framework. They are stored only on your devices — up to five recent screenings on the watch.
On iPhone and Android, the optional Spoken Subtitles feature uses system voices to read locally stored subtitle text through connected private audio. Spoken Subtitles does not upload the subtitle text or generated speech. The Web player does not offer this feature.
Online Movie and Subtitle Search — TMDB & OpenSubtitles
Find subtitles online is available in the native iOS and Android apps. When you open it, CinemaCC sends the app locale and region directly to The Movie Database (TMDB) to load a popular-movie list. If you search, it also sends the movie-title query. After you choose a movie, the native app sends its TMDB movie ID to TMDB to load movie details and sends the same ID with the requested subtitle languages to OpenSubtitles. Choosing a matching release pair sends each selected file ID to OpenSubtitles and normally requests the temporary download links directly.
If a direct TMDB request fails to connect or times out, CinemaCC can send the movie-title query, movie ID, locale and region through its authenticated CinemaCC gateway to TMDB. A successful gateway route may be preferred for subsequent movie requests for five minutes, renewed after each success. This fallback can create or restore an anonymous Supabase identity before a movie is selected. The gateway receives that anonymous ID and ordinary request and network metadata. Movie queries and results may be held in a bounded in-memory cache for up to one minute; they are not written to search-rate records or application logs. Search-rate records contain the anonymous ID and a timestamp. Movie posters remain direct requests to TMDB's image service.
When you select a movie, CinemaCC also creates or restores a persistent anonymous Supabase Auth identity and sends authenticated warmup requests to the CinemaCC search and download Edge Functions. A warmup receives the anonymous CinemaCC user ID and ordinary request and network metadata, but no movie title, movie ID, language, file ID, subtitle text, playback position, microphone data, or theater activity.
If a direct OpenSubtitles search times out or has a transport failure, the search fallback receives the anonymous CinemaCC user ID, TMDB movie ID, one or two requested language codes, ordinary request and network metadata, and the OpenSubtitles result metadata it returns to the app. It does not receive the movie-title query or subtitle file contents. Search rate records associate the anonymous ID with a timestamp and are removed after the rolling rate-limit window.
If OpenSubtitles definitively reports that its direct anonymous download quota is exhausted, the separate download gateway receives the anonymous CinemaCC user ID, a request ID, one or two selected OpenSubtitles file IDs, quota and request timestamps, response status, and ordinary request and network metadata. It uses a server-only OpenSubtitles Consumer to obtain temporary links. Subtitle bytes still download directly from OpenSubtitles to your device and are never proxied or stored by CinemaCC or Supabase. Direct download timeouts and transport failures do not use this gateway; the app instead asks you to switch between Wi-Fi and mobile data or try another network before retrying.
You may optionally connect your own OpenSubtitles account after the available download routes are exhausted. Your OpenSubtitles username and password go directly from the native app to the official OpenSubtitles login endpoint and are not sent to CinemaCC-operated servers or Supabase. The returned OpenSubtitles username and session token are stored in native secure storage and sent only to official OpenSubtitles hosts.
CinemaCC does not send its PostHog or EAS installation identifier to TMDB or OpenSubtitles. TMDB, OpenSubtitles, and Supabase receive ordinary network information such as a source IP address and request headers and may retain request records under their own terms. See TMDB's Privacy Policy, OpenSubtitles' Privacy Policy, and Supabase's Privacy Policy. The public Web player does not offer online subtitle search or use the gateway or provider credentials.
Optional Coffee Support and Contact Details
Apple App Store or Google Play processes optional developer coffee tips. RevenueCat records the store, product, transaction, purchase date and status under your purchase profile. Tips do not grant translation credits or additional features. You can support CinemaCC without providing a name or email address.
After supporting, you may explicitly save a name or nickname, an email address, or both. RevenueCat stores these optional details with the consent version and update time, linked to the same purchase profile. We use them only for thank-you messages or contact about possible supporter rewards, not public supporter lists or marketing subscriptions. Rewards are not promised, and email ownership is not verified. The app does not send these fields to PostHog or Sentry.
These are profile-level contact preferences, not a separate identity for each tip. Saving replaces previous details, including clearing fields you leave empty; skipping does not change existing details. The contact form is offered only after a successful purchase in the current visit; reopening the coffee page does not offer contact management. For corrections or removal without another purchase, email haiyimei@gmail.com using the privacy-request process. The native purchase SDK stores pending changes on the device and synchronizes when connected; a saved message is not confirmation that the server has received the change. Contact details are retained until replaced, withdrawn, or removed following a verified privacy request. Removal clears the contact attributes and consent metadata, not store purchase records. If you no longer have access to the original purchase profile, email haiyimei@gmail.com to request removal.
Optional Paid AI Subtitle Translation
When the requested subtitle language has no available result, the native iOS or Android app may offer one paid translation of an existing OpenSubtitles subtitle. Apple App Store or Google Play processes the purchase. RevenueCat receives the store, product, transaction, and purchase-status information needed to validate the purchase and associates one translation credit with the existing anonymous CinemaCC Supabase user ID. CinemaCC and RevenueCat do not receive your payment-card number from Apple or Google.
After a verified purchase, CinemaCC sends its Edge Function the anonymous CinemaCC user ID, an idempotency key, the selected OpenSubtitles file ID, and the source and target language codes. The Edge Function deducts one RevenueCat translation credit, sends only the OpenSubtitles file ID and language codes to OpenSubtitles AI, and polls the job by its provider correlation ID. CinemaCC stores job and billing state for up to 30 days, but does not persist subtitle text on its servers or cache a translation for another user. The completed SRT is returned with a no-store response, validated by the native app, and saved only in the device library.
OpenSubtitles states that translation files are cached and isolated between users, but has not specified the cache-retention period or offered CinemaCC a data-processing agreement. Its published translation-model list includes AWS, DeepL, and Gemini; the configured model may change. OpenSubtitles and its selected model provider control their own processing and retention. See OpenSubtitles AI's Privacy Policy and AI service FAQ. The Web player does not offer paid translation.
Optional Subtitle Availability Alerts
If you ask to be notified when a movie's subtitles become available, Supabase stores your anonymous CinemaCC user ID, the TMDB movie ID, selected subtitle language, notification language, Expo push token, subscription expiry, and delivery status. CinemaCC periodically checks OpenSubtitles for that movie and language. It does not download subtitle text for these checks. When a matching listing is found, Expo Push receives your push token, a subscription identifier, and a localized notification message. The push payload does not contain the movie ID or subtitle language. Expo, Apple, and Google deliver notifications to your device.
Alerts are optional and separate from bookmarks and AI translation completion alerts. You can cancel in the movie page or notification settings; cancellation deletes the subscription but cannot recall a notification already accepted for delivery. Subscriptions expire after 90 days and are removed by the scheduled cleanup, along with movie/language watches that have no remaining subscribers. You may also disable notifications in system settings; this does not itself cancel the server subscription. No subtitle text or microphone data is stored for alerts.
Microphone & Speech Recognition ("Find My Place")
On supported iPhones and Android 13 or newer, CinemaCC can use a short microphone sample after you explicitly tap "Find My Place." The app does not listen in the background. Microphone audio is processed with the platform's on-device speech recognizer, is never uploaded, and is discarded after the match attempt.
The resulting transcript and matched subtitle snippets also stay on-device by default. If you enable Improve Find My Place sharing in Settings, CinemaCC sends transcript text, matched subtitle snippets, and match-analysis data to PostHog for troubleshooting and product improvement. The choice explains this behavior before it is enabled, can be turned off at any time, and does not upload microphone audio.
Product Analytics — PostHog
CinemaCC uses PostHog to understand whether the app and its features work as intended. PostHog receives randomized persistent app-installation identifiers; app, operating-system, device, locale, and time-zone information; app lifecycle and screen events; search and download attempt outcomes, requested subtitle-language codes, result-count, subtitle-cue-count, remaining-quota, content-duration, and latency ranges, technical routes, cache use, and typed failure codes; and screening entry source, active foreground playback duration, progress and completion measurements, and counts of playback or synchronization controls used.
When you select a catalog movie, search for its subtitles, or start, complete, cancel, or encounter a failure during subtitle preparation, PostHog can receive its numeric TMDB movie ID and the requested subtitle-language codes. For online screenings, this movie ID is also included when entering or resuming the player, when foreground playback actually starts for the first time in that session, and in playback checkpoints, endings, or entry failures. Playback events include the dialogue and reading language codes. The ID is retained with local online-screening history so later playback can be associated with the same movie. Local imports without a known catalog ID are left unidentified; CinemaCC does not infer an ID from their filenames. Catalog-linked events use the randomized installation identifier and can reveal the viewing interests of that installation; they are not fully anonymous.
When you manually adjust subtitle timing for an online-downloaded screening, PostHog also receives the TMDB movie ID, selected dialogue OpenSubtitles file ID, a five-minute movie-position range, the resulting offset, and the random screening session ID. These fields let CinemaCC attribute and aggregate timing observations for future synchronization improvements. The event does not include the movie title, subtitle filename, or subtitle text.
For optional paid translation, PostHog can receive fixed events for translation start, purchase completion, job submission, validated local completion, or typed failure, plus the numeric TMDB movie ID, the selected OpenSubtitles source file ID where available, source and target language codes, and coarse duration ranges. These events do not contain movie titles or title searches, OpenSubtitles release names or filenames, provider correlation IDs, prices, store receipts, RevenueCat balances, or subtitle text.
The first time you open CinemaCC on iPhone or Android, the app asks once how you heard about it. Answering is optional and there is a Skip button. If you answer, PostHog receives the choice you tapped from the fixed list shown on that page and the survey version; the page never accepts free-typed text. The app also records that the page was shown and whether it was answered or skipped. The Web player never shows this page.
After a qualifying screening, CinemaCC may also offer an optional experience survey. If you open, answer, skip, or permanently disable it, or change its preference in Settings, PostHog receives that interaction, the survey version where applicable, and a random screening session ID so a fixed-choice response can be compared with privacy-safe synchronization measurements from the same screening. An answer contains only the choices you tap for venue, subtitle synchronization, subtitle quality, and how helpful CinemaCC was. The survey has Not now and Don’t ask again controls, can be turned back on under Help & Support in Settings, and has no free-text field; it does not send a movie title or ID, subtitle file identity, or subtitle text.
The first-player tour records its version, automatic or manual entry, fixed step identifiers, completion or explicit skip, and whether Find My Place or Spoken Subtitles is available on that platform. The Improve Find My Place choice records whether sharing was accepted or declined. On iPhone only, CinemaCC may later call the system StoreKit review surface after a qualifying screening and record the API attempt and fixed outcome; CinemaCC cannot tell whether Apple displayed a prompt or whether you submitted a rating.
On supported physical native devices, CinemaCC may also measure the whole-device battery change during a screening. Measurement begins when playback first starts. PostHog receives a numeric battery drop only after at least 30 minutes of active foreground playback, when active playback covers at least 80% of the observation window, while the device remains unplugged and its charging and low-power states remain stable. The event can also include a coarse starting-level range, charging and low-power states, state-change flags, and a reason when the sample cannot be compared. This is an observed whole-device change, not energy use attributable only to CinemaCC; display brightness, other apps, system activity, battery health, temperature, and radio use can affect it.
Apart from the numeric TMDB movie ID on the controlled preparation and playback events and the selected OpenSubtitles file IDs on the paid-translation and manual-offset events described above, baseline product events do not include movie-title search text, movie titles, exact movie duration or subtitle cue counts, OpenSubtitles release names, subtitle file names or contents, download URLs, account credentials, microphone audio, transcript text, matched subtitle snippets, exact starting or ending battery levels, or freeform error messages. Transcript text and matched subtitle snippets are sent only through the separate Improve Find My Place sharing choice described above.
PostHog is configured with session replay, touch autocapture, person profiles, and GeoIP enrichment disabled. Baseline product analytics do not currently have an in-app opt-out. See PostHog's Privacy Policy.
The CinemaCC Website
This section describes the cinemacc.net website rather than the app. When another site links you to cinemacc.net, the page sends PostHog the hostname of that site, such as chatgpt.com or a search engine, any utm_source value carried in the link, the path you landed on, and the page language. This is how CinemaCC can tell whether AI search and other sites bring readers to its guides. Your browser reduces the referring address to a bare hostname before sending it, so a full referring URL never leaves the page. The request is sent to cinemacc.net and forwarded from there, so PostHog does not receive your IP address, and the record is created with person profiles and GeoIP enrichment disabled. It carries no cookie and no visitor, session, or device identifier, so these records cannot be linked to you or to one another. Visits that arrive directly, and movement between pages of cinemacc.net, send nothing at all. The website carries no advertising or advertising tracking, and these records are separate from the app analytics described above.
The website also remembers two preferences in your own browser: the language you pick in the language selector, and your dismissal of the Google Play banner. Both stay in your browser, are never sent to CinemaCC or PostHog, and are cleared when you clear site data.
Crash and Diagnostic Data — Sentry
CinemaCC uses Sentry to diagnose crashes and technical failures. A report can include an app version, device model, operating-system version, stack trace, and limited technical diagnostic information. Sentry is configured not to send default personally identifying information, screenshots, view hierarchies, touch or console breadcrumbs, request data, or persistent user identities. It does not receive imported subtitle files or microphone audio through CinemaCC's crash-reporting configuration. See Sentry's Privacy Policy.
Software Updates — Expo / EAS Update
CinemaCC checks Expo's EAS Update service for compatible software updates. Update requests can include a randomized persistent installation token, operating system, app and runtime version, current update identifiers, source IP address, and technical request information. Expo uses update requests to deliver updates, monitor adoption, and provide aggregated app-usage information. See Expo's Privacy Policy.
Network and Location Information
Like most internet services, TMDB, OpenSubtitles, Supabase, Sentry, PostHog, and Expo may receive a source IP address and request headers when CinemaCC connects to them. CinemaCC does not request precise location permission or use precise location. Providers may use network information to deliver and secure their services and may derive an approximate region from an IP address, subject to their settings and policies.
Processors, Sharing, and International Transfers
Sentry, PostHog, Expo, Supabase, and RevenueCat process the data described above as service providers for CinemaCC. Apple and Google process store purchases under their own terms. TMDB and OpenSubtitles provide the user-requested search, download, and translation services under their own terms and privacy policies. We do not sell or rent this data, use it for advertising, or share it with data brokers. These providers may process data in countries outside your own and use their own subprocessors under their applicable terms and data-protection safeguards.
Retention, Choices, and Deletion
Analytics and diagnostics are retained in our service-provider accounts only as long as reasonably necessary to operate, secure, troubleshoot, and improve CinemaCC, according to the retention settings and contractual obligations of those services. Search rate-limit records are automatically deleted shortly after their one-hour window ends. Gateway download requests, file-ID grants, quota records, and completed or failed AI translation job metadata are deleted after 30 days. CinemaCC does not persist translated subtitle text on its servers. The anonymous Supabase identity remains until an operational cleanup or a verified deletion request removes it. TMDB and OpenSubtitles control the retention of their own API request records and translation caches; OpenSubtitles has not specified the AI translation cache period to CinemaCC. Apple, Google, and RevenueCat retain purchase records under their applicable terms. Aggregated or de-identified statistics may be retained longer.
You can turn off Improve Find My Place sharing in Settings and disconnect an optional OpenSubtitles account. Baseline analytics, crash reporting, and update checks are currently part of the app's operation. Online subtitle discovery begins when you explicitly open Find subtitles; the anonymous gateway identity and warmup begin only after you select a movie, search fallback occurs only after a qualifying direct-search failure, and download fallback occurs only after definitive direct-quota exhaustion. Paid translation occurs only after you choose the displayed store product and confirm the purchase with Apple or Google. You can delete locally stored subtitle data, AI-translated subtitles, and history from the app or by uninstalling it; the short-lived download cache is also removed when you uninstall the app.
To request access to or deletion of data held in our provider accounts, email haiyimei@gmail.com with the subject “CinemaCC Privacy Request.” Because CinemaCC has no visible account profile and most records use pseudonymous installation or gateway identifiers, we may need device, app version, event time, or diagnostic details to locate a record, and in some cases may be unable to associate a record with you.
Children's Privacy
CinemaCC is not directed at children under 13 and does not knowingly use its analytics or diagnostic systems to identify children.
Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal data. We do not sell personal data or use it for cross-context behavioral advertising. Contact us at the address below to exercise an applicable right.
Changes
We may update this policy as CinemaCC or its service providers change. Changes will be posted on this page with an updated date.
Contact
For privacy questions or requests, contact Haiyi Mei at haiyimei@gmail.com.