Privacy Policy
- We show no ads, don't sell your data and use no tracking cookies.
- Automatic detection sends only what is needed to record a watch (the title, address and length of what is playing).
- You can delete your account and all your data yourself at any time.
- Our servers are in Germany (Oracle Cloud, Frankfurt).
What is Skrobla?
Skrobla is a free app that lets you record, list and rate the series, movies and anime you watch. It is available on the web, Android, Windows and as a browser extension (Chrome, Edge and other Chromium browsers, and Firefox). It shows no ads and does not sell your data. Skrobla is developed by Mert Karabulut (developer name: Karahalo; Ankara, Türkiye), who is the controller of your personal data. For any privacy matter you can reach us at privacy@skrobla.com.
What data do we collect?
- Account: username, email address, your password (stored only as an irreversible bcrypt hash) and an optional profile photo. If you sign in with Google, we receive the email address and name verified by Google; your Google password never reaches us.
- Your library: your watch history (with dates), watchlist, lists, ratings and in-app notifications.
- App version: which client (web, Android, Windows, extension) and which version you use, to help fix problems.
- Security logs: events such as sign-ins, failed sign-in attempts, password resets and account deletion, together with the username and IP address. At most the latest 5,000 entries are kept; older ones are deleted automatically.
- Feedback: the message and category you send through "Report a bug", the app version and your device model / operating system or browser information.
- Ideas: the ideas you post on the in-app ideas board and the votes you give. Your ideas are shown to other users without your name; who voted for what is never shown to anyone. When you delete your account, your ideas and votes are deleted too.
- Beta signup: if you ask to join the Google Play test on skrobla.com/beta, the email address you enter, your phone model (optional) and your chosen language. They are used only to add you to the test and to tell you when it opens, and are deleted when the test ends.
- Unrecognized titles: if the name of a detected video can't be found in the movie/TV database, the title is recorded to improve detection (without showing who watched it; only the number of users is counted). Deleting your account removes your contribution to that count. A correction you make with "Fix" is used only for your account at first; if several different users make the same correction, it applies to everyone.
- Error reports: if an app crashes or hits an error, the error message, where in the code it happened, the app version and your device model / browser information are sent automatically. Your watch history and personal details are not included; reports are used only to fix bugs and are deleted shortly afterwards.
- Detection diagnostics: when you watch in a streaming app on Android (e.g. Netflix, Disney+), the app's name, whether it shares media information, the detected title and whether the player screen could be read are written to the server logs so we can tell whether detection works. This is used only to fix detection problems and is deleted with the server logs shortly afterwards. If you turn on "Detailed diagnostics" yourself in Settings > Detection, the texts on the streaming app's player screen are also sent for 5 minutes; it then switches off by itself. If a show isn't recognised and you pick which one it is, the texts of the last few pages open in that streaming app (show/movie name, year, episode lines) are sent once so we can fix the reading; messages, anything you type and other apps are never included.
- Preferences on your device: settings such as theme, language and font size are stored on your device (in the browser's local storage or the app's settings). Your language and country are sent with requests so titles appear in your language and prices in your currency; they are not stored.
Automatic detection
To record what you watch automatically, Skrobla reads and sends the following, only on the platforms you install and keep enabled. This information is used only to work out which series or movie you watched and to show it in your "Recent events" list.
- Browser extension: while automatic detection is on, the title and address of the tab where a video is playing and the length of the video. No request at all is sent to the server from sites you have blocked.
- Notification access (Android): if you grant it, the title and length of the media playing in allowed apps (by default browsers, streaming apps and video players; music apps are excluded) and, in browsers, the name of the website the video plays on (e.g. example.com). Only active media sessions and the playing app's media notification are used; the content of your other notifications is neither read nor sent.
- Address Bar Access (Android, optional accessibility permission): it only works after you read and accept the explanation in the app and turn it on yourself; nothing is read without that consent. In supported browsers (e.g. Chrome, Samsung Internet, Firefox, Edge, Opera, Brave, Vivaldi, DuckDuckGo and Kiwi) only the address in the address bar is read; in video apps such as Netflix, Disney+, Prime Video and Max only the name, year and number of episodes or runtime on the show/movie page you open before playing, and the non-button text on the player screen (the episode line), and the name and runtime on the show cover or episode you tap on the home screen, in search or in the episode list, and the show and movie names visible on that app's screen (the covers) right before you press play, are read, because these apps don't tell the phone the show's name. This is kept only in memory on your device and is sent only while a video is playing, to record the watch. Messages, passwords, anything you type, subtitles, other apps and other content on your screen are not read, and no screenshots are taken. You can turn this permission off at any time.
- Windows app: the name and progress of the file playing, from the local interface of VLC and MPC-HC and from the window title of supported players (e.g. PotPlayer). It also reads the title and length of what is playing from Windows media sessions (e.g. the Netflix app or a browser without the extension).
- To find out which title a detected text belongs to, the text (e.g. "Breaking Bad Season 1") is searched on TMDB; no account details are added to the search.
How do we use your data?
Your data is used only to run the app, record what you watch, protect your account (e.g. password reset, sign-in verification codes, rate limiting), debug problems and reply to your feedback. There is no marketing, profiling or advertising.
Third parties
- TMDB: series and movie information (posters, overviews, cast, episodes) comes from The Movie Database. Searches and detected titles are sent to TMDB through our server; your account details are not. Posters and images load directly from TMDB's image server, so your IP address is visible to TMDB. This product uses TMDB and the TMDB APIs but is not endorsed, certified, or otherwise approved by TMDB.
- Google (optional): if you use "Continue with Google", the identity token issued by Google is verified with Google to sign you in. To show this button, the web sign-in page loads Google's sign-in script, so your IP address is visible to Google.
- Trakt (optional): if you connect your own Trakt account in Settings, your watch history, watchlist, ratings and lists are imported once, and afterwards what you do is also sent to Trakt. If you don't connect it, no data goes to Trakt; you can disconnect at any time.
- Netflix file (optional): if you upload a viewing history file you downloaded from Netflix yourself, the watches in it are imported into your account. The file itself is not stored and nothing is sent to Netflix.
- Email delivery: verification-code and password-reset emails are sent through an email service provider, which sees your email address while doing so. Our provider is Brevo (Sendinblue SAS, France, EU). Emails you send us (support@ / privacy@skrobla.com) are forwarded through Cloudflare's email routing to the developer's Gmail inbox.
- Hosting: your data is hosted on servers in Germany (Oracle Cloud, Frankfurt region). Your data is not sold or shared with anyone for advertising.
How long do we keep it?
- Your account and library data are kept while your account is open and are deleted immediately when you delete your account.
- Daily database backups of the server are kept for 7 days; the records of a deleted account remain only in those backups during that time and are then removed automatically. To protect against data loss, a copy of the daily backup is also kept for the same 7 days on the developer's computer in Türkiye, in a folder only the developer can access.
- At most the latest 5,000 security log entries are kept.
- Your feedback messages may remain after you delete your account, unlinked from it (with your username removed).
- Sign-in verification and password-reset codes are valid for a short time and are stored only as hashes.
- Server logs (including error reports and detection diagnostics) are deleted after 14 days.
Cookies and device keys
On the web, a required session cookie keeps you signed in; the Android app, the Windows app and the extension use a device key (token). You can see and remove your connected devices under Settings → My Devices. There are no tracking or advertising cookies; our website also loads its fonts from our own server and makes no third-party requests.
Security
All connections are encrypted with HTTPS. Passwords are hashed with bcrypt, sign-in attempts are protected by rate limiting and, if your email address is on file, a verification code sent to your email may be required when signing in.
Your rights
- Deletion: you can permanently delete your account and all data linked to it under Settings → Profile → "Delete My Account". See the Account Deletion page for details.
- Portability: you can export your watch history as a CSV file at any time (Settings → Watch History / Data).
- Correction and access: you can change your username, email, password and profile photo in Settings.
- Other requests: write to us via Ideas & Feedback in the app (the light bulb at the top, or Settings) or at privacy@skrobla.com.
- Legal basis and your legal rights: we process your data because it is necessary to provide the service you signed up for (performance of a contract) and for our legitimate interest in keeping it secure; optional features (Google sign-in, Trakt, the accessibility permission, detailed diagnostics) run only with your consent, which you can withdraw at any time. Under the GDPR and Türkiye's KVKK (Art. 11) you have the right to access, correct or delete your data, to restrict or object to its processing and to data portability. Write to privacy@skrobla.com; we reply within 30 days. You can also complain to Türkiye's Personal Data Protection Authority (KVKK) or the data protection authority where you live. Because our servers are in Germany (EU), your data is processed outside Türkiye.
Children
Skrobla is not directed at children under 13.
Changes
This policy may be updated; the current version is always on this page, and we announce important changes inside the app.
This text is for information only and is not legal advice.
Skrobla