Seenit Privacy Policy
Last updated: 8 July 2026
Introduction
Seenit is operated by MSSD Ltd (trading as Mydus) (“we”, “our”, or “us”), a company registered in England and Wales whose registered office is at Flat 9 Dawson Building, 52 Prospect Row, London, E15 1GU, and whose registered number is 13278742. We are committed to protecting and respecting your privacy and to providing clear information about the use of your data. We are the data controller for the personal data we collect through the Seenit mobile application and any related services (together, the “Service”). We are registered with the Information Commissioner’s Office (the ICO) with registration number ZB326033.
If you have any questions or concerns about this Policy, or if you wish to exercise any of the rights set out below, please contact us at help@mydus.co.uk.
How we collect your data
When you use the Service, we collect personal data that you submit to us and personal data generated automatically when you interact with Seenit. We may collect, use, store and transfer the following different kinds of personal data about you: account data, social-graph data, activity data, device data, and communications data.
Personal information you disclose to us
- Account data — information you provide to create and use your Seenit account, including your email address, username, display name, and (optionally) an avatar image.
- Social-graph data — the follow requests you send, the follow requests you accept, and the resulting list of accounts you follow and accounts that follow you.
- Activity data — the films and TV titles you log on Seenit (each log records a reference to the title, whether you marked it as watched or as one you recommend, and the time it was logged), and the titles you add to your watchlist.
- Information you provide when you interact with us — including free-text information you include in support queries, feedback, or any other direct interaction with us.
All personal information that you provide to us must be true, complete and accurate, and you must notify us of any changes to such personal information so that we hold the most up-to-date information about you.
Information automatically collected
- Push-notification data — when you grant push permission, we store an Expo push token associated with your account so we can deliver notifications to your device. You can revoke push permission at any time in your device settings.
- Server request metadata — when the Seenit app talks to our backend (Supabase), the network request necessarily carries your IP address, your user-agent string, and the time of the request. Our backend retains this in operational logs for a limited period to operate the Service securely (abuse prevention, rate limiting, and diagnostics). We do not use this data to build a behavioural profile of you.
- Product-analytics data — to understand how the Service is used and to make informed product decisions, the app sends a defined set of behavioural events to PostHog (our analytics processor). Examples include: signing up, opening a title’s detail page, adding to your watchlist, logging a watch, following another user, and tapping through to a streaming provider. Each event is associated with your Seenit user id and a small set of context fields (the surface the action was taken from, the type of media, your app version, your device platform). We deliberately do not send free-text content (such as your search queries, your username, or your email address), and titles are referenced by catalogue id rather than by name — only identifiers and enums. PostHog session-replay is disabled. We process this data on the basis of our legitimate interest in operating, securing, and improving the Service; you have the right to object to this processing at any time by contacting help@mydus.co.uk.
- Crash and error reports — when the app crashes or encounters a runtime error, we send a crash report to Sentry containing a stack trace and limited contextual information (device model, operating-system version, app version). We have disabled Sentry’s IP-address and session-replay features so these reports do not include screen recordings or your network address. Sentry only receives data when something goes wrong; in normal use, nothing is sent.
Finding friends from your contacts
Seenit offers two optional features to help you connect with people you already know. Both are off by default, are never part of signing up, and run only when you actively choose them. Our legal basis for this processing is your consent, which you give by choosing to use each feature.
- Matching your contacts. If you tap “Find friends from your contacts” and grant contacts permission, the app reads the email addresses and phone numbers in your device address book on your device and converts each one into an irreversible cryptographic code (a SHA-256 hash). Only these anonymous codes are sent to our server, where they are compared against the codes of existing members. The names, raw email addresses, and raw phone numbers of your contacts never leave your device and are never stored by us. Codes that do not match a member are discarded immediately — we do not create records for, or build profiles of, people who are not Seenit users.
- Letting friends find you. If you choose “Let friends find you” and verify your mobile number with an SMS one-time code, we store an irreversible code (a SHA-256 hash) derived from your number, so that a friend using the matching feature above can find you. Your verified number is held as part of your account authentication data (with Supabase), and the matching code is held in a record that only you can read. Your number is never shown to other users, never used for advertising or marketing, and never shared with third parties for their own purposes.
These matching codes are one-way: we cannot recover your original email address or phone number from them. In the interest of transparency, a code derived from a phone number could in principle be tested against a guessed number; the real protection is that the code records are access-restricted so they cannot be read in bulk, and every matching request is authenticated and rate-limited. Providing a phone number to be findable is entirely optional — Seenit never requires one to create an account. You can ask us to stop making you discoverable at any time by emailing help@mydus.co.uk, and your matching codes are deleted when you delete your account.
How we use your data
We use the information we collect or receive for the following purposes:
- To create and manage your account. We use your account data to create your unique Seenit account, to authenticate you, and to operate the core social features (follows, feed, logs, notifications). This is necessary to perform our contract with you.
- To operate the social graph. When you send a follow request, we make the existence of that request visible to the recipient. When the recipient accepts, your subsequent logs become visible to them in their feed, and theirs to you. We process this data to perform our contract with you.
- To deliver notifications. When someone you follow logs a title, or when someone you follow logs a title you have also logged, we send a push notification and create an in-app notification record. This is necessary to perform our contract with you. We rely on Expo Application Services to deliver push messages to Apple Push Notification Service (APNs) and Firebase Cloud Messaging (FCM).
- To respond to your inquiries and offer support. We use your account data and any related context to respond to support requests and resolve issues.
- To protect our business and our users. We may use your information as part of our efforts to keep the Service safe and secure, including for abuse prevention, rate limiting, and content moderation. We are legally and contractually obliged to ensure the security of the Service.
- To enforce our terms and policies in order to protect the Service and its users.
- To comply with legal and regulatory requirements, including responding to lawful requests from public authorities.
- To improve the Service generally, by reviewing crash and error reports and by analysing the product-analytics events described above. We use this to understand which features are being used, where users get stuck, and which parts of the experience need work. We do not use these events for advertising, profiling, automated decision-making, or any third-party sharing beyond the data processors named below. We rely on our legitimate interest as the lawful basis for this processing.
Consent
Where we rely on your consent (for example, push notifications and the contact-matching features described above), you may withdraw it at any time. You can disable push notifications in your device settings, or contact us at help@mydus.co.uk to withdraw consent for any other consent-based processing.
Deletion of personal data
You can delete your Seenit account at any time from the Profile → Delete account option within the app. When you do this we will permanently delete your profile, your follow relationships (in both directions), your logs, your notifications, your stored avatar image, and your contact-matching codes (including any code derived from your phone number). Backups containing residual personal data will be purged on our normal backup-retention cycle, and in any event within 30 days of your deletion request.
Product-analytics events are keyed to a random identifier rather than your name or email address, so once your account is deleted we can no longer connect them to you. If you would like those events erased outright, say so in your deletion request (or email us afterwards) and we will remove them from our analytics processor as well.
You can also request deletion by emailing help@mydus.co.uk.
Disclosure and data processors
We do not sell your personal data. We share personal data only with the third-party service providers we rely on to operate the Service. Each provider acts as a data processor and is only permitted to process your personal data on our instructions and for the purposes described below:
- Supabase, Inc. — hosts our database, authentication system, and file storage (for avatar images). All account, social-graph, activity, and notification data is stored with Supabase. Supabase’s privacy policy is available at supabase.com/privacy.
- Expo Application Services (650 Industries, Inc.) — we use Expo to deliver push notifications to your device via APNs and FCM. The Expo push token associated with your account is shared with Expo for this purpose. Expo’s privacy policy is available at expo.dev/privacy.
- PostHog (PostHog, Inc.) — receives the product-analytics events described above so we can measure how Seenit is used. We use PostHog’s EU-region hosting so that event data is stored in the European Union. PostHog’s privacy policy is available at posthog.com/privacy.
- Apple Push Notification Service (Apple Inc.) and Firebase Cloud Messaging (Google LLC) — receive push messages from Expo and deliver them to your device. Their handling of push data is governed by Apple’s and Google’s respective privacy policies.
- Sentry (Functional Software, Inc.) — receives crash reports and error logs to help us diagnose bugs. Sentry’s privacy policy is available at sentry.io/privacy.
- The Movie Database (TMDB) — when you search for a film or TV show in Seenit, your search query is sent to TMDB to return matching titles and poster images. We do not send TMDB any account-identifying information. TMDB’s privacy policy is available at themoviedb.org/privacy-policy. This product uses the TMDB API but is not endorsed or certified by TMDB.
We may also disclose your personal data where we are required to do so by law, by court order, or by a competent regulatory authority; or where disclosure is necessary to protect the safety, rights, or property of Mydus, our users, or others.
International transfers
Some of our data processors (notably Supabase, Expo, and Sentry) may process personal data outside the United Kingdom and the European Economic Area. PostHog stores our analytics data in its EU region, but its corporate operations and sub-processors may, in limited cases, involve transfers outside the EEA. Where any transfer outside the UK or EEA occurs, we rely on appropriate safeguards (such as the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or an adequacy decision) to ensure your personal data continues to receive an essentially equivalent level of protection.
Retention
We will only keep your personal information for as long as is necessary for the purposes set out in this Policy, unless a longer retention period is required or permitted by law. When you delete your account, your personal data is removed from our active systems as described above and from backups within 30 days.
Where we do derive aggregated, non-identifying information from operational logs or crash data, we may retain that aggregated information indefinitely for statistical and product-improvement purposes. Once aggregated in this way it is no longer personal data.
Keeping your personal information secure
We have implemented appropriate technical and organisational security measures designed to protect the security of any personal information we process, including encryption in transit (HTTPS / TLS), encryption at rest for our database and object storage, row-level security policies that restrict access to your personal data to you and to the people you have explicitly connected with on Seenit, and least-privilege access for our administrators.
However, no electronic transmission or storage technology can be guaranteed to be 100% secure, and we cannot guarantee that hackers or other unauthorised third parties will not be able to defeat our security measures. Transmission of personal information to and from the Service is at your own risk, and you should only access the Service within a secure environment.
Your rights
Under UK GDPR you have the following rights in respect of your personal data:
- the right of access (a “subject access request”);
- the right to rectification of inaccurate or incomplete personal data;
- the right to erasure (a “right to be forgotten”);
- the right to restrict processing;
- the right to data portability; and
- the right to object to processing, including for direct marketing.
To exercise any of these rights, please email us at help@mydus.co.uk including your name, the email address associated with your Seenit account, and a description of the request. We will respond within one month.
Making a complaint to a supervisory authority
If you are dissatisfied with how we have handled your personal data, you have the right to file a formal complaint with the Information Commissioner’s Office at ico.org.uk.
Children
Seenit is intended for users aged 17 and over and is not directed at children. We do not knowingly collect personal data from anyone under the age of 17. If you believe a child has provided us with personal data, please contact help@mydus.co.uk and we will delete it.
Changes to this policy
If we change this Policy, we will post the revised policy here with an updated effective date. If we make significant changes we will also notify you in-app or by email before the changes take effect.