FT Family Tasker

Privacy Policy

Version 2026-08-03

1. Who is responsible for your data

The data controller is Toto Inc., [Your registered address]. For anything in this policy, contact odthinker@gmail.com.

2. What we collect

  • Account data — your name, email address and a hashed (never plain text) password.
  • Family data — the family name, who belongs to it and who owns it.
  • Content you create — watch list entries, their status and any notes.
  • Invitations — the email address of anyone you invite, plus the invitation's status and expiry.
  • Consent record — when you accepted these documents and which version.
  • Technical data — a session cookie, and server logs that may include your IP address.

We do not use advertising or analytics trackers, and we never sell your data.

3. Why we use it, and on what legal basis

  • To provide the service (accounts, families, watch lists) — performance of a contract, Art. 6(1)(b) GDPR.
  • To send invitation emails — our legitimate interest in letting members set up their family, Art. 6(1)(f).
  • To keep the service secure (logs, rate limiting) — legitimate interest, Art. 6(1)(f).
  • To meet legal obligations, including proving consent — Art. 6(1)(c).

4. Who sees it

Other members of your family see your name and everything you add to the shared lists. Beyond that, we share data only with the processors needed to run the service — our hosting provider and our email delivery provider — under contracts that restrict them to acting on our instructions.

Poster images are loaded directly from TMDB's servers, which means TMDB receives your IP address and browser details when a poster is displayed. We send them the titles you search for, but nothing that identifies you.

5. Where it is stored, and for how long

Data is stored in Frankfurt, Germany (DigitalOcean). We keep your account data for as long as your account exists. Unaccepted invitations expire after 7 days and can be revoked at any time from the Family screen. When you delete your account we remove your personal data, except where we must retain something to meet a legal obligation.

6. Cookies

We set one strictly necessary cookie to keep you logged in, and a CSRF token cookie to protect forms against cross-site request forgery. Neither is used for tracking or profiling, so no cookie consent banner is required.

7. Your rights

Under the GDPR you have the right to:

  • access a copy of your personal data;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to processing based on legitimate interests;
  • receive your data in a portable, machine-readable format;
  • withdraw consent, without affecting processing that already took place.

To exercise any of these, email odthinker@gmail.com. We respond within one month. You may also complain to [Your EU/EEA supervisory authority].

8. Children

The service is not intended for children under 16 without the consent of a parent or guardian. If you believe a child has given us data without it, contact us and we will delete it.

9. Changes

If we change this policy materially we will tell you and, where required, ask for fresh consent. The version you accepted is recorded against your account.

Back