Privacy Policy

Last updated: 14 March 2025

1. Who We Are

Reeluma ("we", "us") is a video-on-demand streaming platform operated by a sole trader established in the Czech Republic, European Union. You can reach us at support@reeluma.com.

We act as the data controller for personal data collected through reeluma.com.

2. Data We Collect

Account data

Email address used to create your account, whether registered directly or via Google Sign-In.

Usage data

Watch history and time spent watching individual films. This is stored locally in your browser (localStorage) and periodically synchronised to our database to enforce the free preview limit and to restore your watch progress across devices.

Subscription data

Subscription status, plan type, and expiry date obtained from our payment processor Cleeng. We do not store any payment card details — all payment data is handled exclusively by Cleeng.

Technical data

Standard server logs including IP address, browser type, operating system, and referring URLs, collected automatically when you visit our site. We use Vercel Speed Insights for aggregated performance monitoring; no personally identifiable information is associated with these metrics.

Analytics data (with consent)

If you accept analytics cookies, we use Vercel Analytics and Google Firebase Analytics to collect anonymised data about page views and user behaviour. This data helps us understand how the Service is used and improve it. Analytics are only activated after you give explicit consent via the cookie banner.

3. Legal Bases for Processing (GDPR)

  • Contract performance — processing your account and subscription data is necessary to provide the Service you have signed up for.
  • Legitimate interests — technical logs and aggregated usage analytics are processed to maintain security and improve the Service.
  • Legal obligation — we may process data as required by Czech or EU law.

4. How We Use Your Data

  • Create and manage your account
  • Verify subscription status and enforce access controls
  • Restore your watch progress across sessions and devices
  • Respond to support inquiries
  • Send transactional emails (account creation, subscription confirmation)
  • Comply with legal obligations

We do not sell your personal data and do not use it for behavioural advertising.

5. Third-Party Services

Firebase / Google (Authentication & Database)

We use Google Firebase for authentication and Firestore to store user and subscription records. Google processes data in accordance with its Privacy Policy. A Data Processing Agreement is in place through Firebase's standard terms.

Cleeng (Payment Processing & Subscriptions)

Subscription payments are handled by Cleeng. Cleeng processes billing and payment data under their own Privacy Policy. We share your email address with Cleeng solely to verify subscription status.

Vercel (Hosting)

Our website is hosted on Vercel infrastructure in the United States. Vercel processes standard web traffic data under its Privacy Policy.

6. International Transfers

Some of our third-party providers (Google, Vercel) process data in the United States. These transfers are covered by Standard Contractual Clauses adopted by the European Commission, or equivalent data transfer mechanisms under GDPR Chapter V.

7. Data Retention

We retain your account data for as long as your account is active, plus a reasonable period thereafter to comply with legal obligations. Watch history stored in your browser (localStorage) is managed by your own browser and can be cleared at any time. Server-side watch progress records are deleted when your account is deleted.

8. Your Rights (GDPR)

As a data subject under GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate data
  • Erasure — request deletion of your account and associated data
  • Restriction — ask us to limit how we process your data
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interests

To exercise any of these rights, email us at support@reeluma.com. We will respond within 30 days.

9. Cookies and Local Storage

We use browser localStorage to store your watch progress and authentication session tokens. Essential session cookies may be set by Firebase for authentication purposes. If you accept analytics cookies via our cookie banner, Google Firebase Analytics and Vercel Analytics may set additional cookies to measure site usage. You can decline analytics cookies and the Service will continue to work normally.

10. Children

The Service is not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users by email and post the updated policy on this page with a revised "Last updated" date. We encourage you to review this page periodically.

12. Contact

For any privacy-related questions or requests, please contact us at support@reeluma.com.