MovieMatch

PRIVACY & DATA

Your data, by system.

MovieMatch 4.7.9 separates device preferences, MovieMatch social data and the Trakt library.

On this device

Ignored and unfinished title IDs, display preferences and a cached catalogue are stored locally. Trakt access and refresh tokens are not stored in JavaScript-readable browser storage.

MovieMatch Worker and D1

MovieMatch stores a stable internal identity, invite code, approved social relationships, blocks, compact Trakt-ID snapshots, matching signals, public-share grants and revocable server sessions. Trakt access and refresh tokens exist only encrypted inside those server sessions. API responses are marked no-store.

Trakt

Catalogue and library actions use Trakt. OAuth authorization occurs on Trakt. MovieMatch encrypts Trakt tokens server-side and sends only the actions required by the app.

Controls

Settings can export local and server-side MovieMatch data, revoke a public link, reset one device, disconnect Trakt from MovieMatch, or delete the MovieMatch account and its D1 data. Deleting MovieMatch does not delete the separate Trakt account.

Public and private

Private profiles are excluded from fuzzy username search and public follows. Exact invitation codes can still be used to request a private connection. Public recommendation links expire after 30 days and can be revoked sooner.

Bot protection

Security-sensitive actions use Cloudflare Turnstile. The browser obtains a short-lived, single-use verification token and the MovieMatch Worker validates it with Cloudflare together with the connecting IP address. The Turnstile secret remains only in the Worker secret store.

Retention and security

Sessions expire after inactivity and have an absolute lifetime. Declined requests receive a cooldown. Public links and sessions can be revoked. Operational logs use request IDs and safe error codes rather than tokens or request bodies.

For questions about this independent Studio Sampersand project, use the contact details on studiosampersand.be.