Datenschutzerklärung für FlickCue
FlickCue von Manish Pundir
Datenschutzerklärung für FlickCue
Last updated: 16 September 2026
FlickCue saves films and shows you want to watch and reminds you about them.
This document describes exactly what the extension does with data, written
against what the code actually does rather than in general terms.
There is no analytics, no telemetry, no advertising, and no account with
the developer. Everything below is either kept on your own device, sent
directly from your browser to a service you can identify by name, or relayed
to one through FlickCue's small proxy server, which keeps no log of what passes
through it (see "Routed via FlickCue's proxy" below).
Held in the browser's extension storage, readable only by FlickCue:
- The titles you save, with the media type, year, rating and poster image URL
that a film database returned for them. - Your reminder times, and whether you have marked something watched.
- The page a title was saved from, a saved note, viewing status, and episode
checkmarks - plus anything the FlickCue Android app keeps on the same title
(such as Interested, your rating, like and review), which the extension
stores and syncs unchanged. - Your excluded scanning sites and whether on-page cards are quiet.
- A record of titles you deleted, kept for 90 days so a deletion is not undone
the next time your devices sync. - Your settings, including your selected streaming region. The streaming region is a country code used only to show availability
for the region you choose; FlickCue does not determine your physical or
precise location. - If you connect Google sync, the connection state needed to keep the feature
working. This may include OAuth access and refresh tokens, the identifier of
FlickCue's private Drive file, and the email address of the connected Google
account.
Removing the extension deletes all of this.
The extension reads the page you are on to work out whether it is about a film
or a show. It looks at the page title, headings, image labels, structured
metadata, and the address. This reading happens entirely on your device. The
full page contents and address are not sent to film databases. A discovery
address is stored when you save a title; it follows that title into your own
Drive account if sync is enabled, or into a backup you explicitly export.
If online matching is
enabled, only a candidate title or identifier derived from the page may be sent
to the services listed below.
When online matching is on, a short candidate title — for example
The Odyssey (2026) — is sent so the extension can confirm the title is realand fetch its poster, synopsis, rating and streaming availability. Where that
request goes:
| Service | What is sent | Routed via |
| --- | --- | --- |
| TMDB | Candidate title, or an IMDb/TMDB id read from the page | FlickCue's proxy |
| AniList | Candidate title | Directly from your browser |
| TVmaze | Candidate title | Directly from your browser |
| Wikidata | Candidate title | Directly from your browser |
| MDBList | Confirmed TMDB id | FlickCue's proxy |
| OMDb | The confirmed IMDb id when known, otherwise the confirmed title and year | FlickCue's proxy |
| Fanart.tv | Confirmed TMDB/TheTVDB id | Always via FlickCue's proxy |
Only the candidate title or an identifier is sent to any of these. The page's
address and your private notes are not.
Directly from your browser means exactly that: no FlickCue server sits in
the middle, and each request carries your IP address to that service under
its own privacy policy, linked above.
Routed via FlickCue's proxy applies to services that need a shared API
key: rather than bundling that key inside the extension (readable by anyone
who inspects it), FlickCue operates a small proxy server that holds those
keys and forwards your request to the real service, unmodified. That proxy
does not log or store request contents — it relays the request and forwards
the response, nothing more. To prevent abuse of the shared keys it applies a
per-minute rate limit keyed by your IP address, using Cloudflare's built-in
rate limiting, which holds only a short-lived request count and is never
linked to your saved titles or account. If you'd rather nothing pass through
any FlickCue-operated server, turn online matching off.
MDBList ratings come through the proxy. FlickCue reads the
tomatoes critic scoreand the
popcorn audience score from the response. It does not scrape orconnect directly to Rotten Tomatoes.
OMDb ratings work out of the box via the shared proxy key (1,000 requests/day
across all FlickCue users, not per person). FlickCue reads the
imdbRating, imdbVotesand
imdbID fields from the response to show an IMDb score. It does notscrape or connect directly to IMDb.
You can switch this off. With online matching disabled, no title ever leaves
your device, and the extension only suggests on pages that identify themselves
as a film or show in their own metadata.
On a page the pattern-based scan above cannot make sense of, FlickCue sends
the page's
<title> and a short excerpt of its visible text (up to 2,000characters) to an AI model, asking only "which single film or show, if any,
is this page about" — nothing else is asked, and the reply is discarded if
the page isn't about one specific title. This step only runs when every
regular database lookup above has already come back empty for that page.
One of four providers handles this, tried in order and stopped at the first
one that answers, so a busy or exhausted quota on one doesn't stop the
feature working. All four are called through FlickCue's own proxy (see the
film database lookups section above for what that means and does not mean —
no logging of what's sent, only a per-minute rate limit), never
directly from your browser, since this step relies on shared keys with no
personal-key alternative:
| Service | What is sent |
| --- | --- |
| Google (Gemini) | Page title and a text excerpt |
| Mistral | Page title and a text excerpt |
| Groq | Page title and a text excerpt |
| OpenRouter | Page title and a text excerpt, and OpenRouter may itself route the request to one of several underlying model providers |
This is a wider excerpt of the page than the film-database lookups above
receive (which only ever get a short candidate title), so private notes
still never leave your device, but this
step can send more of the page's own visible text than the rest of online
matching does. It is covered by the same online matching toggle: turning
that off stops this along with everything else in this section.
Google sync is off until you turn it on and is optional.
When enabled, your saved list—including attached notes, the pages titles
were saved from and episode progress—is written to your own Google Drive, in the hidden
application-data folder reserved for this extension. The extension requests one
scope,
drive.appdata, which grants access to that folder alone. It cannotread, list or modify any other file in your Drive, and it never requests one
that could.
FlickCue also reads the email address reported by Google Drive for the connected
account. It uses that address only to label the active account in the popup, so
you can tell which account is being synchronized. The address is stored locally
in the extension, is not written into the synchronized watchlist, and is never
sent to the developer.
Google supplies OAuth tokens that authorize this limited Drive access. FlickCue
or the browser keeps those tokens locally as needed to maintain the connection.
On Chrome, sign-in and token refresh happen entirely through the browser's own
Google integration and never pass through any FlickCue server. On Edge,
Firefox and Brave, completing sign-in and refreshing an expired token both
require a step Google's OAuth process calls a client secret; rather than
storing that secret inside the extension, FlickCue's proxy holds it and
performs that one step on the extension's behalf — the proxy sees only the
one-time authorization code (or refresh token) needed to complete that step,
forwards it to Google, and returns the resulting access token; it does not
log or retain it. Once obtained, all ongoing Drive reads and writes (the
appdata folder itself) go directly from your browser to Google, on every
browser, same as always.
The list is stored in your Google account, under your control, governed by
Google's privacy policy. Signing out
removes the stored token; the copy in your Drive stays until you delete it.
Nothing is read from Letterboxd until you add a profile in Settings →
Letterboxd, and adding one is optional. You can add up to ten public
profiles: one marked as yours, and others you follow — a friend's, say, or a
critic's. For each one you choose what comes across, and you can change or
remove it at any time.
FlickCue requests only the pages a profile's choices need, directly from
letterboxd.com — the same pages anyone can already see by visiting that profile
in a browser, signed out. It does so when you look a profile up while adding
it, once an hour after that, and whenever you press "Sync" on it:
| Page | What FlickCue reads from it | Read for |
| --- | --- | --- |
|
/watchlist/ | Title and year of each film on the watchlist | Any profile that brings in its watchlist ||
/films/ | Title, year, star rating and whether it was liked | Your profile, if it brings in watched films; a followed profile, if it brings in the films they loved ||
/reviews/ | The same, plus the text of published reviews | Your profile only, if it brings in reviews ||
/films/diary/ | The date each viewing was logged | Your profile only, if it brings in diary dates || The profile page (
/<username>/) | Display name, avatar image and the number of films logged | Every profile, so Settings can show whose it is |Looking a profile up while adding it reads its profile, watchlist and films
pages whatever you go on to choose, to show whose it is and how many films it
has.
No Letterboxd account, password or sign-in is involved; FlickCue never
authenticates with Letterboxd, and reads nothing that is not already public on
the profile.
Your own profile. Titles from it are saved to your FlickCue library so you
can browse them under its Letterboxd tab. Watchlist titles arrive in your
queue; if you choose to bring in watched films, titles you have already logged
arrive marked watched — dated by when your diary says you watched them, if you
bring in diary dates — so they do not appear in your queue. Adding it can
therefore add several hundred titles at once, depending on the size of your
Letterboxd history; when Letterboxd shows the number, the add button says it
before you confirm.
If you bring them in, your rating, like and the first 600 characters of your
published review for a title are stored alongside that title on your device, so
the Letterboxd tab can show them. Like the rest of your saved list, that travels
to your own Google Drive if you have sync enabled, and to any backup you export
yourself. Resolving a title also sends its candidate title to TMDB, under the
same terms as the film database lookups above; review text is never sent to
TMDB or anywhere else.
Profiles you follow. Their titles are not added to your library. They go on
a separate shelf in the Letterboxd tab — the film's title, year, poster, and
that person's rating and like — which stays on this device: it is not part of
Drive sync or exported backups. A title reaches your library only when you add
it from the shelf yourself, and then it is saved like any title you save,
filed under a "From @username" collection.
The list of profiles you have added, and each profile's display name, avatar
image and counts, are also kept only on this device, outside Drive sync and
backups.
Removing a profile stops all requests for it and deletes its shelf and
cached details. Removing your own profile asks whether to keep the titles it
brought in or to delete the ones you haven't changed since (no notes, tags,
collections, progress, reminders or corrections); either way, nothing you have
changed is deleted.
A profile set to private shows nothing. Removing every profile stops all
requests to letterboxd.com.
- Your browsing history.
- The full contents of pages you visit. Page scanning is local; online matching
sends a candidate title or identifier and, only when nothing else identifies
a page, its title and up to 2,000 characters of its visible text to an AI
provider, as described above. - Contacts, payment information, health information, personal communications,
or precise location. - Anything sold, shared or transferred to a third party for advertising.
Exported backups contain your private title data and no settings. Imports add
missing titles without overwriting current entries. Excluded sites turn off
scanning there; the extension still retains its installed host permissions,
which you can manage separately in your browser settings.
- Access to websites — to read the page you are on and detect a title. Used
on the page only; nothing is sent to the developer. - Access to letterboxd.com — to read the public pages of the Letterboxd
profiles you add in Settings, only once you add one. - Access to FlickCue's own proxy server — to reach the shared TMDB,
MDBList, OMDb, Fanart.tv and AI-provider keys described above, and to
complete Google sign-in on Edge, Firefox and Brave, without those keys or
that one-time authorization step being embedded in the extension itself. - Storage — to keep your list, settings, reminders, cached metadata and, if
you enable Google sync, its connection state on your device. - Alarms — to fire your reminders, and to run Drive sync and Letterboxd
sync on their own schedule. - Identity — to sign in to Google, only if you enable sync.
FlickCue does not request the browsing-history permission.
Local extension data remains on your device until you remove it. Deleting a
title removes it immediately, leaving only a dated marker for 90 days so the
deletion propagates to your other browsers.
If Google sync is enabled, a copy of the watchlist remains in your private
Google Drive application-data folder. Signing out clears FlickCue's locally
stored connection information, including the connected email address and OAuth
tokens, but does not delete that Drive copy. Uninstalling the extension removes
its local data but does not delete the Drive copy either.
To remove everything: uninstall the extension, and if you used Google sync,
revoke its access at
myaccount.google.com/permissions and
delete the app data from your Drive.
Questions about this policy: manishpundir29@gmail.com