WatchesOpen the web app

Privacy policy

Last updated September 29, 2026

This policy explains what personal data Watches collects when you use the website and the iPhone app, why we collect it, who processes it for us, how long we keep it and what rights you have. It applies to everyone who uses Watches, with or without an account.

The controller of your personal data is ⁨{{CONTROLLER_NAME}}⁩, ⁨{{CONTROLLER_ADDRESS}}⁩. You can reach us about anything in this policy at ⁨{{SUPPORT_EMAIL}}⁩.

We collect only what the service needs:

  • Account data: your name, email address and profile picture, a hash of your password if you sign up with email, and, if you sign in with Apple, Google or Facebook, the identifier that provider gives your account and the sign-in tokens it issues.
  • Guest data: when you save a watch without an account, we create a guest account with a random identifier. It holds your saved watches until you sign up, when they move into your account.
  • Your collection: the watches you save, their status (wanted, owned or sold), your notes and your ratings.
  • Votes and opinions: your choices between pairs of watches, and the opinions you write. Opinions are public and shown with your name.
  • Shares: the links you send us and what we extract from them: the post's caption, description or transcript, the article's text, the creator's public name and the watches mentioned.
  • Subscription data: whether you have Pro, its status and renewal date, and the customer and subscription identifiers of our payment providers. We never see your card details.
  • Technical data: your IP address and browser or device type, recorded with each session and in our server logs; and, in the iPhone app only, crash and performance reports.
  • To provide the service you asked for (performance of a contract, Article 6(1)(b) GDPR): your account, sign-in, your collection, votes, opinions, shares and the Pro subscription.
  • To keep Watches secure and working (our legitimate interest, Article 6(1)(f)): server logs, rate limits, crash reports and fraud prevention.
  • To meet legal obligations (Article 6(1)(c)): tax and accounting records of payments, which our merchant of record keeps.

We do not sell your data, show you advertising or build advertising profiles.

These companies process personal data on our behalf, under data processing agreements:

  • Hetzner Online (Germany): hosts our servers and database in the EU.
  • Cloudflare: stores our database backups in the EU (R2 object storage, EU jurisdiction).
  • Axiom: stores our server logs, including account and session details.
  • Sentry: receives crash and performance reports from the iPhone app, without your email address.
  • Polar: sells the Pro subscription on the web as merchant of record and processes your payment under its own privacy policy.
  • RevenueCat: tells the iPhone app whether you have Pro, keyed by your account identifier.
  • Apple, Google and Facebook: only when you choose to sign in with them.
  • Anthropic and OpenAI: read the text of the links you share to find the watches mentioned.
  • Firecrawl: fetches the articles you share.
  • Perplexity and Exa: search the web for facts about watches in our catalog. They receive watch names, never data about you.

To read a shared post, our servers also request it from Instagram, TikTok or YouTube; those requests carry no information about you.

Our servers are in the EU. Some processors above are in the United States: Axiom, Sentry, RevenueCat, Anthropic, OpenAI, Firecrawl, Cloudflare (whose EU storage keeps our backups) and the sign-in providers. We transfer data to them under the EU–US Data Privacy Framework where the company is certified, and otherwise under the European Commission's Standard Contractual Clauses.

  • Account data, your collection, votes, opinions and shares: until you delete your account. Deletion is immediate.
  • Guest accounts: deleted automatically 30 days after their last use.
  • Sessions: 30 days from your last visit, or until you sign out.
  • Server logs: 30 days.
  • Crash reports: at most 90 days.
  • Database backups: at most 15 days, after which a deleted account is gone from them too.
  • Payment records: kept by Polar for as long as tax and accounting law requires.

The text we extracted from a shared link describes a public post, not you. It stays in our catalog after the share is deleted, with no link to your account.

Under the GDPR you have the right to access your data, to have it corrected, to have it deleted, to restrict or object to its processing, and to receive a copy in a portable format. To use any of these rights, write to ⁨{{SUPPORT_EMAIL}}⁩; we answer within one month.

You can delete your account and all its data yourself at any time, in the app or on the web: see how.

We use no advertising or tracking cookies. We store only what the service needs:

  • a session cookie that keeps you signed in, for 30 days;
  • the NEXT_LOCALE cookie, which remembers the language of the last page you visited, for one year;
  • your light or dark theme choice, in your browser's local storage;
  • the filters you last used on Explore, in your browser's local storage;
  • in the iPhone app, your session in the iOS keychain, and your settings and a copy of recently viewed pages in encrypted storage on the device.

Watches is not meant for children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, write to ⁨{{SUPPORT_EMAIL}}⁩ and we will delete it.

If you think we handle your data unlawfully, please tell us first at ⁨{{SUPPORT_EMAIL}}⁩. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live, work or where the infringement took place.

We will update this policy when what we collect or who processes it changes. The date at the top shows the latest version. If a change affects you significantly, we will tell you in the app or by email before it takes effect.