Privacy Policy

Version v1.3 — Last updated: May 6, 2026 · View changelog & older versions

This Privacy Policy for FriendRex ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:

Questions or concerns? Reading this Privacy Policy will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services.

Summary of Key Points

1. What Information Do We Collect?

Personal Information You Provide

We collect personal information that you voluntarily provide when you register, use our Services, or contact us:

Information Automatically Collected

When you use our Services (with your consent), we may automatically collect:

2. How Do We Use Your Information?

We process your information to:

3. AI Features & Data Disclosure

Rex AI Companion: Rex is an AI-powered chatbot that provides personalized movie and TV recommendations. When you interact with Rex:

No AI Training Without Consent. We do not use your User Content, Rex conversations, ratings, reviews, or other personal data to train artificial-intelligence models without your explicit, prior, opt-in consent. A toggle in Settings → Privacy & Security → AI Training lets you opt in to having your public content contribute to AI model training; the toggle is OFF by default and may be reversed at any time. Our AI provider does not use your data to train its general-purpose models under our service agreement with them.

4. Third-Party Services

We use the following third-party services to operate FriendRex:

ServicePurposeData Shared
Firebase (Google)Authentication, database, storage, cloud messagingAccount data, content, device tokens
TMDBMovie and TV show dataSearch queries (no personal data)
AI ProviderRex AI chatbot responsesWatch history, ratings, profile info, messages
StripePayment processingPayment information (processed directly by Stripe)
NetlifyWeb hostingStandard web traffic data

Movie and TV data is provided by TMDB. This product uses the TMDB API but is not endorsed or certified by TMDB.

5. When Do We Share Your Information? (Recipients of personal data)

We may share your information in the following situations:

We do NOT sell your personal information to third parties. See our Do Not Sell or Share My Personal Information page for California-specific opt-out rights.

6. Cookies & Tracking

FriendRex uses the following local storage technologies:

You can manage cookie preferences through our consent banner. Declining analytics cookies does not affect core app functionality.

7. How Long Do We Keep Your Information?

We keep your information for as long as necessary to provide our Services. When you delete your account:

8. How Do We Keep Your Information Safe?

We implement appropriate security measures including encrypted connections (HTTPS), Firebase Security Rules, server-side API key protection, and access controls. However, no electronic transmission over the Internet is guaranteed to be 100% secure.

9. Children & Minors

FriendRex is intended for users 13 years of age or older. In compliance with the Children's Online Privacy Protection Act (COPPA, 16 CFR Part 312) and the UK Age-Appropriate Design Code, we do not knowingly collect personal information from children under 13.

How we enforce this: During account creation, every user is required to provide their date of birth. We perform two independent age checks:

  1. A client-side check during onboarding that blocks anyone who reports an age under 13.
  2. A server-side Cloud Function that re-computes the user's age from the date of birth they submitted. If the user is under 13, the system automatically deletes the account, all associated data (profile, preferences, watch history, social graph), and the underlying authentication record. An immutable audit row is retained solely to evidence that the under-13 attempt was blocked, and contains no information that could identify the child.

If you believe a child under 13 has created an account: Please contact us at privacy@friend-flix-4daa6.web.app. We will investigate, delete any child's data within 30 days of confirmation, and terminate the account.

Users aged 13-17 receive enhanced protections:

10. Your Privacy Rights

All Users

California Residents (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

Categories of personal information collected in the last 12 months:

CategoryExamplesCollected
IdentifiersName, email, usernameYes
Personal Information (Cal. Civ. Code § 1798.80)Name, emailYes
Protected ClassificationsAge/date of birthYes
Commercial InformationSubscription historyYes
Internet ActivityApp usage, feature interactionYes (with consent)
GeolocationApproximate location via IPYes
Audio/VisualAvatar imagesYes
InferencesContent preferences, taste profileYes

To exercise your CCPA rights, email us at privacy@friendrex.app or use the in-app tools. We will verify your identity before processing requests.

European Economic Area / UK Residents (GDPR)

If you are in the EEA or UK, you have rights under the General Data Protection Regulation (GDPR) including:

Our legal bases for processing are: contract performance (providing Services), consent (analytics, marketing), and legitimate interests (security, fraud prevention).

11. Video Processing & Watermarks

When you post a video reel to FriendRex, we transcode it for delivery and store both the source file and generated renditions in Firebase Storage on Google Cloud.

When another signed-in user requests to download or save one of your videos, FriendRex generates a branded export on our servers by compositing a FriendRex watermark and a short (≤2 second) FriendRex end-card animation onto a copy of the source video using ffmpeg. The branded export is then delivered to the requesting user. In-app playback of your video is not modified. Basic metadata about each download event (requesting user ID, owner user ID, reel ID, timestamp, success/error status) is logged to enable abuse detection, rate limiting, and product analytics.

Your controls. You can disable downloads of your videos by other users at any time under Settings → Privacy & Security → "Allow others to save my videos." This setting is enforced server-side.

Legal basis (EEA / UK users). We process video content to deliver the Services you have requested (GDPR Article 6(1)(b) — performance of a contract) and to pursue our legitimate interests in operating, securing, and promoting the Services (GDPR Article 6(1)(f)). You can object to legitimate-interest processing by contacting us at privacy@friendrex.app.

Retention. Branded export copies are cached for up to 24 hours to reduce regeneration cost and then regenerated on demand. Download event logs are retained for up to 90 days for abuse monitoring.

12. Do Not Track

Some browsers transmit "Do Not Track" (DNT) signals. We honor DNT signals by not loading analytics for users who have not consented via our consent banner.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via in-app notification or email. Continued use of the Services after changes constitutes acceptance of the updated policy.

14. Response Times to Legal & Privacy Inquiries

We monitor the following dedicated email addresses and respond within the stated timeframes (business days):

We send an automated acknowledgment to confirm receipt. If you have not received an acknowledgment within 12 hours of sending a DMCA notice, please re-send to legal@friendrex.app as a backup.

Contact Us

If you have questions or concerns about this Privacy Policy or your data, contact us at:

Email: privacy@friendrex.app

General Support: support@friendrex.app

Parent/Guardian Inquiries: support@friendrex.app

FriendRex LLC
California, United States