This policy explains how NOTJUST.DEV, SL (“DramaSip”, “we”, “us”) handles personal data when you use the DramaSip app for iPhone and Android, or visit https://dramasip.com. We are the data controller for that data. You can reach our privacy team at support@notjust.app.
1. The short version
- You can watch without telling us who you are. Tapping “Get started” creates a guest account identified only by a random ID. Adding an email, Apple or Google login is optional.
- Every onboarding question is skippable. Genres, first name, gender, age bracket and how you found us are all optional, and we explain below exactly what each one is used for.
- We never see your card. Apple and Google process every payment. We receive the purchase and its status, not your payment details.
- No precise location, contacts, photos, camera or microphone. The app does not ask for them and cannot access them.
- Ads are videos you choose to watch for coins. Nothing plays unless you tap “Watch ad”. On iPhone the advertising identifier is only used if you allow tracking; in the EEA, UK and Switzerland you are asked for consent before the first ad.
- Delete your account in three taps from Settings → Account. It takes effect immediately.
- We do not sell your personal data. We use a small number of service providers, all named in section 7.
2. What this policy covers
DramaSip is a short-drama streaming app: vertical episodes you watch in a feed, a library of series you save, an optional Pro subscription, and coins that unlock single episodes. This policy covers the app on iOS and Android and the website at https://dramasip.com. It does not cover Apple, Google or other companies whose own products you use alongside ours (for example the App Store, Google Play, or the account you sign in with); their own privacy policies apply to what they do with your data.
3. Information we collect
3.1 Information you give us
- Guest account. When you tap “Get started” we create an account for you with a random identifier. It carries no name, email or password. Every like, saved series and resume point is attached to that identifier so they follow you through the app.
- Email and password, if you connect an email to your account. The password is stored as a one-way hash by our authentication provider; we cannot read it. Confirming the address sends a six-digit code to it.
- Sign in with Apple. Apple gives us a stable Apple user identifier and, if you choose to share them, your name and either your real email address or an Apple “Hide My Email” relay address. Apple only shares your name the first time you sign in, and we store it then.
- Sign in with Google. Google gives us your Google account identifier, email address and basic profile (name and profile picture). We use the identifier and email to sign you in.
- Onboarding answers, all optional: the genres you like, a first name for greetings, your gender (including “prefer not to say”), an age bracket, how you heard about DramaSip, and whether you want notifications. They are stored on your profile. See section 4 for what each is used for.
- Feedback. If you send feedback from Settings (or by shaking the phone, which opens the same form), we receive the message you type plus your email address, if your account has one or you enter one so we can reply. The shake gesture reads the motion sensor on the device only; no motion data is stored or sent anywhere.
- Website forms. The early-access form collects your email address and, optionally, a favourite genre and platform, plus the campaign or referrer that brought you to the page. The account deletion form collects the email on your account and an optional reason.
- Emails you send us at any of our addresses, and the correspondence that follows.
3.2 Information collected as you use the app
- Viewing and library activity. Which episodes you start, how far you got in each one, which you finished, episodes you like, series you save to your list or follow for a release alert, and episodes you have unlocked. This is what makes “continue watching” and your list work.
- Purchases and coins. Which subscription or coin pack you bought, the price and currency shown, purchase and renewal dates, whether the subscription is active, a store transaction identifier, your coin balance and what you spent coins on, and coins earned from ads. We receive this through RevenueCat from Apple and Google. We do not receive card numbers, billing addresses or your Apple ID or Google account password.
- Usage analytics. Which screens you open (including the ID of the series or episode on screen), which buttons you tap, which onboarding steps you complete and the answer you chose (your name is never sent), how you signed in, when you saw or purchased from a paywall, and how you answered the iOS tracking prompt. Alongside each event: device model, operating system version, app version, language, time zone, your IP address and an approximate location derived from it (country or city level). Events are keyed to your account identifier, and start from the moment the app opens. We do not record your screen or replay your session.
- Crash and performance reports. When the app crashes or something fails in the background, we receive the error, a stack trace, the screens you visited just before it, performance timings, device model, operating system version, app version and your IP address. Feedback you send from the app travels through the same tool.
- Push notification data. If you allow notifications, a push token for the device, your account identifier, device and operating system details, language, time zone, app version, and whether a notification was delivered or opened.
- Advertising data, only when you choose to watch a rewarded ad. Google AdMob receives device and network information, your IP address and the approximate location it implies, and how you interacted with the ad. Where you have allowed it (see section 6), it also receives the advertising identifier of your device. We pass your account identifier to Google so that Google can confirm to us, server to server, that you watched the ad and should be paid the coins. Ad impressions and the revenue they earn are also reported to RevenueCat, keyed to your account.
- Install attribution. On iPhone, after you have answered the tracking prompt, the app lets RevenueCat collect Apple's Ad Services attribution token, which tells us whether an App Store ad campaign led to the install. It does not contain the advertising identifier.
- App update checks. On launch the app asks Expo's update servers whether a newer version of its code is available. That request carries your IP address, platform and app version, and no account information.
- Data stored on your device. Your session token, which account finished onboarding, your language choice, whether and when we asked you for an app store review, and how many episodes you have finished (to decide when to ask). None of this leaves the device except the session token, which is what authenticates you to our servers.
3.3 Information from other sources
- Apple and Google tell us, via RevenueCat, the status of your subscription and purchases: new, renewed, cancelled, refunded, or in a billing retry.
- Sign-in providers (Apple, Google) release the identifiers and profile fields described in 3.1.
- Google's consent platform tells us whether you have given or refused consent for ads in the regions where it is required, so that we know whether an ad may be requested at all.
3.4 What we do not collect
We do not collect payment card details, precise GPS location, contacts, photos, camera or microphone input, health data, or biometric data. The app cannot access any of these; there is no permission to grant. Our own code never reads your advertising identifier; only the ads SDK does, and only under the conditions in section 6. We do not buy data about you from data brokers.
4. How we use it, and our legal basis
Where the GDPR or UK GDPR applies, we need a legal basis for each thing we do with your data. This table lists every purpose and the basis we rely on.
| What we do | Data involved | Legal basis |
|---|---|---|
| Run your account, stream episodes, remember where you were, keep your list | Account and sign-in data, viewing and library activity, session token | Performance of our contract with you |
| Order the feed around what you like | Genres you picked, what you watch and save | Legitimate interest in showing you relevant series |
| Personalise recommendations with the optional profile questions | Gender, age bracket, first name | Consent. Every question can be skipped, and you can ask us to delete your answers at any time (section 10) |
| Sell and honour subscriptions, coin packs and episode unlocks; restore purchases | Purchase and coin data, account identifier | Performance of our contract; legal obligation for tax and accounting records |
| Show a rewarded ad when you ask for one, and pay the coins | Device and ad interaction data, advertising identifier, account identifier | Consent where the law requires it (Google's consent form in the EEA, UK and Switzerland; the iOS tracking permission for the advertising identifier). Otherwise our legitimate interest in funding the free tier with ads that are not personalised |
| Understand which campaigns bring viewers and which lead to purchases | Install attribution, how you said you found us, purchase events | Legitimate interest in marketing efficiently; iOS tracking permission where the advertising identifier is involved |
| Measure how the app is used and improve it | Usage analytics | Legitimate interest in understanding and improving the product |
| Find and fix crashes, keep the service secure, prevent fraud and abuse | Crash and performance reports, device data, IP address, purchase and coin data | Legitimate interest in a working, secure service; legal obligation where applicable |
| Send notifications about series you follow and your account | Push token, account identifier | Consent, given through the operating system permission |
| Send marketing messages by push or email | Push token, email address | Consent, which you can withdraw at any time (section 13) |
| Reply to your feedback and support requests | Your message, email address, and relevant account or crash data | Legitimate interest in answering you; performance of our contract |
| Comply with the law, respond to legal requests, defend claims | Whatever is relevant to the request | Legal obligation; legitimate interest in protecting our rights |
We do not use your personal data to train artificial intelligence models, and we do not make decisions about you by automated means that have legal or similarly significant effects.
5. Guest accounts and connected accounts
A guest account is a real account on our servers, held under a random identifier. Connecting an email, Apple or Google login upgrades the same account rather than creating a new one, so nothing you did as a guest is lost. Signing out of a guest account without connecting a login leaves its data on our servers with no way to get back to it: because there is no email or login attached, we cannot identify it from a request you send us. We delete guest accounts that have not been opened for 12 months, together with everything attached to them. If you want a guest account deleted sooner, delete it from Settings → Account before you sign out.
6. Advertising, tracking and your choices
The only ads in DramaSip are rewarded videos: you tap “Watch ad”, watch a short video, and receive coins. Nothing plays uninvited. Ads are served by Google AdMob.
- Personalised or not. An ad can be chosen for you based on your advertising identifier and inferred interests (personalised), or based only on context such as the app you are in and your approximate location (not personalised). Which one you get depends on the choices below. Either way, the reward is the same.
- EEA, UK and Switzerland: consent first. Before the first ad you see Google's consent form listing the purposes and partners involved. You can consent, refuse, or manage options individually. To change your answer later, open Settings → Legal → Your privacy choices, which appears wherever the form applies. Refusing keeps the ad button hidden until you change your mind; it does not affect anything else in the app.
- iPhone: App Tracking Transparency. During onboarding the app explains, and iOS then asks, whether DramaSip may track you across other companies' apps and websites. Allowing it lets Google use your advertising identifier (IDFA) for personalised ads and lets us measure which campaigns led to installs and purchases. Denying it means the identifier is never made available, and the app works exactly the same. You can change your answer at any time in iOS Settings → Privacy & Security → Tracking.
- Android. You can reset or delete your advertising ID, or opt out of ad personalisation, in Android Settings → Google → Ads.
- Google's role. Google acts as an independent controller for the data its ads SDK collects. How Google uses that data is described at policies.google.com/technologies/partner-sites, and the list of ad technology partners Google may share it with is at support.google.com/admob/answer/9012903.
- Our own measurement is not tracking. Usage analytics and crash reporting are collected for us alone, under our account identifier, and are not combined with data from other companies to target advertising. They run whether or not you allow tracking, and they are not affected by the ad consent form.
- US state privacy laws. Making your advertising identifier available to Google for personalised ads may count as “sharing” for cross-context behavioural advertising or “targeted advertising” under some US state laws. We do not sell personal data for money. The controls above are how you opt out; see also section 15.
7. Who we share it with
We do not sell your personal data. We share it with the following companies, which process it for us under contract and on our instructions, except where noted as independent.
| Provider | What it does for us | Privacy policy |
|---|---|---|
| Supabase | Authentication (including guest accounts and the sign-in code emails), the database that holds your profile, library and unlocks, and the storage and content delivery that streams episodes and artwork | supabase.com/privacy |
| RevenueCat | Subscription and coin purchases, entitlement checks, coin balances, restoring purchases, verifying rewarded-ad rewards, ad revenue reporting, and install attribution | revenuecat.com/privacy |
| Google AdMob (independent controller) | Serves rewarded video ads and runs the consent form in regions that require it | policies.google.com/privacy |
| PostHog | Usage analytics for the app, and cookieless page-view counting on the website | posthog.com/privacy |
| Sentry | Crash and performance reporting, and delivery of the feedback you send from the app | sentry.io/privacy |
| OneSignal | Push notifications | onesignal.com/privacy_policy |
| Expo | Builds the app and delivers over-the-air updates to its code | expo.dev/privacy |
| Apple (independent controller) | Sign in with Apple, App Store payments and subscriptions, Ad Services attribution | apple.com/legal/privacy |
| Google (independent controller) | Sign in with Google, Google Play payments and subscriptions | policies.google.com/privacy |
| Vercel | Hosts the website and its two forms | vercel.com/legal/privacy-policy |
Two links between these systems are worth knowing about. Your account identifier is the same customer ID in RevenueCat, the same user ID in our analytics, and the same external ID in our push provider, so that a purchase, a crash and a notification can all be traced to one account when you ask us for help. And your analytics ID is attached to your RevenueCat customer record, so we can see which parts of the app lead to purchases.
We may also disclose personal data:
- to comply with a law, regulation, court order or lawful request by a public authority;
- to protect the rights, property or safety of DramaSip, our users or the public, or to detect and prevent fraud and abuse;
- to a buyer or successor in a merger, acquisition, financing or sale of assets, in which case this policy continues to apply and we will tell you before your data is transferred under a different policy;
- with your consent, or at your direction.
8. International transfers
We are established in Spain. Several of the providers in section 7 process data in the United States, and some in the European Union. Where data leaves the European Economic Area, the United Kingdom or Switzerland, we rely on the EU–US Data Privacy Framework (and its UK and Swiss extensions) for providers certified under it, and otherwise on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, with additional safeguards where an assessment calls for them. You can ask us for a copy of the relevant safeguard at support@notjust.app.
9. How long we keep it
| Data | Kept for |
|---|---|
| Account, profile, onboarding answers, library, viewing and unlocks | Until you delete your account. In-app deletion removes them immediately; a request through the website form is completed within 30 days of verifying it is you |
| Guest accounts you never connected a login to | Deleted after 12 months without the app being opened |
| Purchase and coin transaction records | Up to 7 years, as Spanish tax and accounting law requires. After account deletion they are no longer linked to a profile |
| Usage analytics events | Up to 12 months, after which they are deleted or reduced to aggregate counts |
| Crash and performance reports; feedback sent from the app | 90 days |
| Push notification records | Until you delete your account, or you disable notifications and we prune the token |
| Support and privacy correspondence | 24 months after the conversation ends |
| Early-access waitlist emails | Until you unsubscribe, or 12 months after the app launches, whichever is first |
| Account deletion requests made through the website | 12 months, as a record that the request was handled |
| Website server logs | 30 days |
We keep data longer only where a law requires it or where it is needed to resolve a dispute or enforce our agreements, and then only the data that is needed.
10. Your rights
Depending on where you live, you have some or all of these rights over your personal data:
- to know whether we hold data about you, and to get a copy of it;
- to correct data that is wrong or incomplete;
- to have your data deleted;
- to restrict or object to how we use it, including objecting to direct marketing;
- to receive the data you gave us in a portable, machine-readable format;
- to withdraw consent at any time, without affecting what was done while consent stood;
- not to be discriminated against for exercising any of these rights.
How to exercise them. Delete your account from the app (Settings → Account → Delete account) or through the deletion form. For anything else, including a copy of your data or deleting your onboarding answers without deleting the whole account, email support@notjust.app. We reply within 30 days, and always within the time the law where you live allows. We will need to confirm the request comes from the holder of the account, usually by writing to the email on it. A guest account has no email, so a guest request is best made from inside the app.
EEA, UK and Swiss residents may also complain to a supervisory authority. Ours is the Spanish Agencia Española de Protección de Datos (aepd.es); you may instead contact the authority where you live or work. We have not appointed a data protection officer because the scale of our processing does not require one; the address above reaches the people responsible.
What deletion removes and what it does not. Deleting your account removes your profile, onboarding answers, library, viewing history, unlocked episodes, any coins on the account, and the link between your device and your account for push notifications. Transaction records are kept for the period in section 9 and are no longer linked to a profile. Deleting your account does not cancel a subscription, because Apple or Google bill it; cancel it in your store settings first, or the store will keep charging you. Coins on a deleted account are forfeited. If you also use another app of ours with the same Apple, Google or email login, the login itself stays so that the other app keeps working; everything belonging to DramaSip is still removed.
11. Children and age
DramaSip is for people aged 13 and over, or the minimum age of digital consent where you live if that is higher. It is not directed at children under 13 and we do not knowingly collect their personal data. If you believe a child under that age has an account, tell us at support@notjust.app and we will delete it. The age bracket asked during onboarding is optional and self-declared; it is not an age verification. Our child-safety reporting channels are in section 10 of the Terms of Service.
12. Security
Data travels between the app, the website and our providers over TLS, and is encrypted at rest by the providers that store it. Each account can only read and write its own rows: the database enforces this itself, not just the app. Passwords are hashed, coins are spent only by our server (the app cannot credit itself), and access to production systems is limited to the people who need it, protected by multi-factor authentication. No system is perfectly secure. If a breach affects your data we will notify you and, where required, the relevant regulator without undue delay.
13. Notifications and marketing
- Push notifications only reach you if you allow them when asked. We use them for new episodes of series you follow, release alerts for series you asked to be told about, and account matters. Where you have agreed, we may also send occasional promotional notifications. Turn all of them off at any time in your device's notification settings for DramaSip.
- Email. We send transactional emails you cannot opt out of while you have an account (sign-in codes, password resets, important changes to these terms). We send marketing emails, such as the early-access launch email or news and offers, only where you have agreed to receive them. Every marketing email has an unsubscribe link, and you can also write to support@notjust.app.
14. Cookies and data on your device
The website sets no cookies and stores nothing in your browser: no cookies, no local storage, no pixels, no fingerprinting, and no third-party scripts, embeds or advertising tags. That is why there is no cookie banner; the consent rule applies to storing or reading information on your device, and the site does neither. Fonts are served from our own domain, so your browser never contacts Google to load them.
We still count page views, using PostHog in its cookieless mode. Instead of tagging your browser with an identifier, PostHog derives a temporary, rotating value on its own servers from your IP address and browser user-agent. Nothing is written to your device, and the value cannot recognise you tomorrow or on another site. What we see is aggregate: which pages were viewed, in what order, and what referred you. The two forms on the site (early access and account deletion) send only what you type, and are rate-limited by IP address in server memory for a minute. A content blocker or private browsing stops the page-view count and changes nothing else.
If we ever add a tool that stores something on your device, this section changes first and a consent banner appears before the tool loads. The app has no cookies either; the small set of values it keeps on your device is listed in section 3.2, and the advertising identifier controls are in section 6.
15. Notice for California and other US states
This section supplements the rest of the policy for residents of California and of other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas and Oregon). The categories below use the terms in the California Consumer Privacy Act.
| Category | Examples we collect | Disclosed to (for a business purpose) | “Shared” for cross-context behavioural advertising? |
|---|---|---|---|
| Identifiers | Account ID, email, Apple or Google identifier, IP address, device identifiers, push token, advertising identifier | Supabase, RevenueCat, PostHog, Sentry, OneSignal, Google | Advertising identifier and device data with Google, only when you allow it |
| Customer records | Name (optional) | Supabase | No |
| Protected classifications | Gender and age bracket (optional, self-declared) | Supabase, PostHog | No |
| Commercial information | Subscriptions, coin packs, unlocks, coin balance | RevenueCat, Supabase | No |
| Internet or app activity | Screens viewed, taps, viewing history, ad interactions | PostHog, Sentry, Supabase, Google | Ad interaction data with Google when you watch an ad |
| Geolocation | Approximate location from IP address only | PostHog, Sentry, RevenueCat, Google | With Google, only when you allow it |
| Inferences | Genre preferences drawn from your picks and viewing | Supabase | No |
| Sensitive personal information | Account log-in credentials (password, stored hashed) | Supabase | No. We do not use sensitive information to infer characteristics about you |
We do not collect biometric, health, precise geolocation, professional, education, or audio or visual information. We have not sold personal information in the preceding 12 months and do not sell it. The sources of each category, our purposes, and retention periods are in sections 3, 4 and 9.
Your rights are to know, access, correct and delete your personal information, to opt out of sharing for cross-context behavioural advertising and targeted advertising, to limit the use of sensitive personal information (which we already do), and not to be discriminated against. Exercise them as described in section 10; an authorised agent may act for you if they show us your written permission. If we refuse a request you may appeal by replying to our decision, and we will answer the appeal within 45 days.
Do Not Sell or Share My Personal Information. To opt out of sharing for advertising, use Settings → Legal → Your privacy choices in the app where it appears, deny tracking on iOS, or disable ad personalisation on Android (section 6). The website sets no cookies and does not sell or share data, so a Global Privacy Control signal from your browser has nothing to switch off there; the app cannot receive browser signals. We do not knowingly sell or share the personal information of anyone under 16.
16. Changes to this policy
When we change this policy we post the new version here and update the date at the top. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect, and where the change needs your consent, we will ask for it.
17. Contact
NOTJUST.DEV, SLC/ Balmes 129bis, 4º 2ª, 08008 Barcelona, Spain
NIF B26785477
Email: support@notjust.app (one inbox for privacy, support and legal matters; put “Privacy” in the subject line to reach the right person quickly)