Skip to content
FeelSame
Terms of ServicePrivacy PolicyCommunity GuidelinesSafety Center

FEELSAME · COMMUNITY & TRUST

Privacy Policy

What FeelSame processes, what other people can see, and the controls currently available to you.

Version
1.2
Effective date
October 4, 2026
Last updated
October 4, 2026

On this page

  1. Voluntary third-party data imports
  2. Information you provide
  3. Technical data and cookies
  4. Why we use information
  5. Public community information and private account data
  6. Messages and reported material
  7. Children, teens and different kinds of interaction
  8. Infrastructure and external resources
  9. Retention and deletion limitations
  10. Security safeguards
  11. Your controls and requests
  12. Policy updates
  13. Contact and operator

Voluntary third-party data imports #

You may voluntarily upload the original ZIP containing CSV account data from Letterboxd’s official export. FeelSame processes it to transfer your own film ratings, reviews, diary entries, watch history and watchlist into your authenticated account, after you review and confirm the import. Imported activity becomes account data and follows the same profile visibility rules as activity you enter directly.

The original ZIP and CSV files are processed in temporary memory, are not publicly displayed and are not retained as uploaded files. Temporary previews last 30 minutes; this lifetime applies only to the preview, not to activity you confirm and import. Completed previews are removed. Import history retains safe status/count metadata and fingerprints to prevent duplicates. FeelSame does not ask for or store third-party service credentials, and does not scrape Letterboxd pages. Letterboxd is an independent third-party service and is not affiliated with FeelSame.

Information you provide #

For an account we collect email, username, display name, a password stored as a hash, date of birth and gender selection. You may provide city, pronouns, a bio, profile photos and optional MBTI or Enneagram preferences. Some existing records may contain a private name; it is not a public profile field.

We store Top 5 selections, ratings, reviews and spoiler choices, likes, watched and watchlist states, log dates, rewatch flags, episode watches and notes, and TV progress. We also store follows and follow requests, connection/pass choices, mutual connections, conversation membership, messages and read timestamps, blocks, and reports you submit.

Your language choice and privacy preferences affect how the application is presented and how your profile is shown.

Technical data and cookies #

Account and content records include creation and update timestamps. Requests involve an IP address, browser/request information and security-relevant server logs processed by the hosting, proxy and application infrastructure. Staff actions are recorded with the acting account, reason and timestamp; there is no claim of comprehensive user IP tracking.

The samewave_session cookie keeps you signed in for up to 14 days and is marked HttpOnly, SameSite=Lax and Secure in production. The samewave-locale cookie remembers English or Turkish; the same choice is written to browser local storage. The application also recognizes an existing NEXT_LOCALE cookie. Signing out clears the session cookie; clearing browser storage may reset preferences.

We have not integrated an advertising or analytics tracker into the current application. Infrastructure and third-party resources may have their own logging or cookie behavior. This policy does not claim that a proxy or external image provider never uses cookies.

Why we use information #

We use account data to create and secure your account, authenticate sessions, and apply age and moderation rules. Profile and entertainment data let us display your profile and activity, calculate shared-taste suggestions, search People, and provide Discover, connections and messaging.

We use reports, blocks and moderation records to investigate abuse, enforce restrictions, maintain a record of decisions and operate the service safely. Technical information helps deliver requests, diagnose failures and protect infrastructure. Processing and any legal rights that apply depend on the applicable law; this page is not a certification of GDPR or CCPA compliance.

Public community information and private account data #

Within the signed-in community, a public profile can display username, display name, photos, bio, pronouns, age derived from your birthday, city when city visibility is enabled, Top 5, reviews, ratings and recent activity. People search can display permitted public profiles and shared taste. Private profiles restrict profile content and reviews to approved followers, but the basic name/username can still appear on a restricted profile screen.

Email, password hash, exact birthday and any retained private/legal name are not public profile fields. Private does not mean inaccessible to authorized service operations: account contact and moderation context are available to staff where needed. Reports, staff notes and moderation audit records are not shown publicly.

Profile-photo files are served by direct image URLs. Making a profile private or hiding a photo in the interface does not make a previously shared image URL access-controlled. Avoid uploading sensitive images; others may save or share material they can see.

Messages and reported material #

Messages are stored on the service and shown through conversation membership and current interaction eligibility checks. They are not end-to-end encrypted. Blocking, account restrictions or an ineligible age pairing can stop access to a conversation without automatically erasing its stored history.

The current moderation interface does not offer casual browsing of private conversations. Reports target accounts, reviews, media or episodes; there is no dedicated message-report attachment flow. If you describe harmful messages in a report, the context you submit may be reviewed by authorized staff for safety. Only include information relevant to the concern.

Children, teens and different kinds of interaction #

FeelSame requires an age of at least 13 and uses the date of birth you supply. There is no deployed biometric identity or age verification system. Users under 18 start with a private profile, and Discover starts off for new accounts. These defaults can be changed through the available settings; they are not a guarantee of identity or safety.

Entertainment discussions, visible profiles and following do not use the same eligibility rules as private contact. Following across age groups is possible, with approval required for private profiles. Discover and connection requests require the same 13–15, 16–17 or 18+ group and an eligible visible candidate. Private profiles do not appear in Discover. Messaging requires an active connection and the same age group; a follow alone never grants messaging access.

Blocking and account-level Discover/messaging restrictions apply separately. Do not evade these rules by entering a false birthday or moving inappropriate contact to another service.

Young user safety advice ↗

Infrastructure and external resources #

Neon PostgreSQL stores application records. The current deployment runs on a VDS; profile uploads are stored on that server, and local upload archives are kept for recovery. Cloudflare provides domain/proxy delivery in front of the application. These services process information needed for hosting, delivery and security.

TMDB supplies film/TV metadata and images; MusicBrainz supplies music metadata; Cover Art Archive supplies album images. Searches and item identifiers are sent to catalog services to retrieve results, rather than your password or private conversations. Images may load directly from these providers. The login artwork loads from Unsplash. The current theme loads fonts through Google Fonts (fonts.googleapis.com and fonts.gstatic.com). External image and font requests share ordinary network/request data, such as IP address and browser information, with the resource host.

Providers may process data in different countries under their own arrangements. This policy does not promise a particular storage country or a verified international-transfer safeguard. We have not added third-party advertising sharing to the current application. Information may also need to be disclosed where a valid legal obligation requires it, with applicable safeguards.

Retention and deletion limitations #

Account, activity and message records remain in the service while needed to provide it. Reports, restrictions and audit records may need to remain for safety investigations, repeat-abuse prevention or legal obligations. We do not have a single configured retention period for all database records.

The current local upload-backup task expires older archives after approximately 14 days. That does not promise the same deletion timetable for database records, provider backups or copies saved by others. Supported photo/review removal changes current application content; backups and moderation records can persist until their applicable retention process runs.

Security safeguards #

Safeguards include hashed passwords, signed session cookies, HTTPS delivery, server-side account and interaction checks, role-restricted moderation and validated image uploads. Uploaded photos are resized and converted to WebP. Operational credentials are excluded from browser-facing system metrics.

No service can guarantee perfect security. Keep your password private, use a unique password, and avoid putting sensitive information in public profiles, photos, reviews or reports.

Your controls and requests #

Settings lets you edit supported profile fields, manage photos, choose language, make your profile private, hide your city, and enable or disable Discover. You can manage reviews using their existing controls, and block or unblock accounts. A change in Discover visibility does not itself make your profile private.

There is currently no self-service account deletion or data export interface, no dedicated privacy-request form, and no published privacy contact in the application. Reports are for safety concerns and are not a general privacy-request or appeals channel. This page does not promise that a deletion/export request can currently be submitted through a feature that does not exist.

Depending on your location, law may give you rights to access, correction, deletion, restriction, objection or portability, and to complain to a relevant data-protection authority. These rights are subject to applicable rules and exceptions; this policy does not remove them. An operator contact and request-handling process still need to be published.

Privacy and profile settings (sign-in required) ↗Manage blocked accounts (sign-in required) ↗

Policy updates #

This page identifies its version, effective date and last updated date. Changes will be published here, with any further notice required by applicable law. Review it when choosing what to share.

Terms of Service ↗Safety Center ↗

Contact and operator

FeelSame is the product’s brand name. The legal person or entity responsible for the service has not yet been published.

A monitored contact channel for privacy and data requests has not yet been published.

A monitored contact channel for general support or account appeals has not yet been published.

For safety concerns, use the in-app Report and Block controls. Reporting is not an emergency hotline.

TermsPrivacyCommunity GuidelinesSafety

© 2026 FeelSame

Create an accountBack to top ↑