OnTheList — Privacy Policy
Last updated: 11 July 2026
This privacy policy explains what information the OnTheList app (“OnTheList”, “we”, “us”) collects, how we use it, and the choices you have. OnTheList is a movie & TV bookmarking app.
Who we are
OnTheList is operated by Medland Solutions, the developer account that publishes the app on Google Play. For any privacy questions or requests, contact us at support@onthelist.watch.
Information we collect
We only collect what’s needed to run the app. We do not sell your personal information, and we do not collect your location, contacts, messages, files, or payment information.
- Account information (from Google Sign-In). When you sign in with Google we receive your email address, display name, and profile photo, and a unique account identifier. OnTheList uses Google as the only sign-in method.
- Region & language. The market (country) and device language associated with your account, so we can show the right streaming availability and wording.
- Your username. A username you choose so friends can find you to connect.
- Your lists (content you create). The movies and TV shows you bookmark — your watchlist, shortlist, and “seen” list — including the title, its identifiers, artwork reference, and the dates you added or marked them.
- Friends & sharing data. Friend requests you send or receive, and the friendships you accept, so you and your friends can see each other’s lists.
- Notification token. A device messaging token (Firebase Cloud Messaging) so we can send you notifications — for example when someone sends you a friend request, or, if you turn it on, when a TV show on your lists has a new series on the way.
- App activity & diagnostics. Aggregate, non-identifying usage and diagnostic data via Firebase Analytics (e.g. screens viewed, crashes, device model, app version) to help us improve the app.
- App integrity signals. To protect our backend from abuse we use Google Play Integrity / App Check, which verifies requests come from a genuine, unmodified copy of the app.
We do not knowingly collect data from children. OnTheList is intended for users aged 13 and over.
How we use your information
- To provide the core app: sign you in, store and sync your lists across your devices.
- To power friends: let you find people by username, send/accept friend requests, and show you and your friends each other’s lists.
- To send you notifications (a friend request, or — if you enable it — a new series for a show you follow).
- To look up movie/TV metadata, ratings, and streaming availability (see “Third-party services”).
- To keep the service secure and prevent abuse.
- To understand aggregate usage and fix problems.
How your information is stored and shared
- Hosting / processing. Your account and lists are stored using Google Firebase (Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Messaging, App Check, Analytics), acting as our data processor. Data is held on Google’s infrastructure.
- Friends. Your lists are private to you unless you add a friend. When you and another person become friends — one of you sends a request and the other accepts — you can each see the titles on the other’s lists, along with each other’s display name, photo, and username. Either of you can remove the friendship at any time to stop sharing.
- Your profile link and QR code. To let friends add you, the app gives you a personal link and QR code. They contain a long secret code unique to you, so your display name, photo, and username (never your lists) are visible only to someone you have given the complete link or QR code to. Your username alone reveals nothing — without the secret the page shows only a generic OnTheList banner — and profile pages are marked not-for-indexing by search engines. You can reset your link at any time from “My code” in the app: every previously shared link and QR code immediately stops working (allow a few minutes for web previews; a preview already delivered into another app, e.g. a messaging chat, may persist there until that app refreshes it). Adding a friend by typing their exact username sends them a request to accept or decline; it does not reveal their name or photo to you.
- Metadata providers. To show details, ratings, and streaming links we query TMDB, MDBList, and the Streaming Availability API from our backend. These requests contain only the title’s identifiers — never your personal information.
- We do not sell your data or share it with advertisers.
Data retention and deletion
We keep your information for as long as your account exists. You can:
- Sign out at any time from the Profile screen.
- Delete your account from the Profile screen (“Delete account”). This permanently removes your profile, your watchlist/shortlist/seen lists, your username reservation, and any friend requests/friendships involving you, and deletes your sign-in account. This cannot be undone.
- Alternatively, request deletion by emailing support@onthelist.watch or following the steps on our Delete Account & Data page.
Security
Data is encrypted in transit (HTTPS/TLS) and encrypted at rest by Google Firebase. Access requires authentication, and our backend enforces App Check and per-user rate limits.
Third-party services
OnTheList relies on these services, each with its own privacy policy:
- Google Firebase / Google Play services — firebase.google.com/support/privacy
- TMDB — this product uses the TMDB API but is not endorsed or certified by TMDB.
- JustWatch — “where to watch” streaming availability is sourced from JustWatch (via TMDB).
- MDBList, Streaming Availability API (Movie of the Night) — for ratings and streaming links.
Changes to this policy
We may update this policy; material changes will be reflected by updating the “Last updated” date.
Contact
Medland Solutions — support@onthelist.watch