SerieSensei · Public Beta · 18+
Privacy Policy
Effective and last updated: 5 September 2026
1. Controller and contact
The data controller is the private individual who operates SerieSensei under the project name MojaLab. The service is not operated by a company and has no VAT number. The controller can be contacted directly at dr@mojalab.com. Additional service information is available in the Legal Notice.
This document is a privacy notice. Using the service does not constitute consent to every processing activity; each purpose relies on the legal basis stated below.
2. Who may use the service
SerieSensei is intended only for people aged 18 or older. We do not knowingly offer it to, or seek data from, anyone under 18. If you believe a minor has used the service or provided personal information, contact us so that we can investigate and delete the data where appropriate.
3. Data we process
Account and Google sign-in data
When you choose Google sign-in, we receive your Google account identifier, email address, display name, and avatar URL. We request only the openid, email, and profile scopes. We do not request contacts, Drive files, or Google passwords. SerieSensei's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Conversation and personalization data
Messages and prompts, assistant replies, conversation summaries, inferred or stated tastes, mood and viewing constraints, remembered facts, recommendations and reasons, feedback, watchlist, watched/skipped items, episode progress, viewing briefs, notifications, and recommendation outcomes.
Technical and security data
Session and account identifiers, authentication status, timestamps, IP address, approximate country/region/city derived from the IP, request and WebSocket metadata, rate-limit events, browser/user-agent data present in server access logs, errors, latency, tool usage, and limited service telemetry.
Browser storage
Strictly necessary browser storage holds a random session identifier, the 18+ confirmation, theme preference, and—after sign-in—the account identifier and short-lived authentication credential. Google OAuth also uses a short-lived, secure session cookie on the backend during sign-in. We currently use no advertising or behavioural-analytics cookies.
Please do not enter health information, political or religious beliefs, sexual-life information, precise addresses, financial details, passwords, or other sensitive personal data in the chat. Free-form messages may otherwise reveal such information even though SerieSensei does not ask for it.
4. Purposes and legal bases
- Provide the requested service and account: conversation, recommendations, lists, progress, memory, synchronization, authentication, export, and deletion. Legal basis: performance of the service requested by you (GDPR Article 6(1)(b)).
- Secure and operate the beta: rate limiting, fraud/abuse prevention, diagnosis, availability, limited logs, and service-quality evaluation. Legal basis: our legitimate interest in safely operating and improving a free experimental service (Article 6(1)(f)).
- Comply with law and handle rights: responding to valid requests, disputes, or lawful authority demands. Legal basis: legal obligation (Article 6(1)(c)) or, where appropriate, establishment or defence of legal claims.
Providing chat content is necessary to generate a response. Google sign-in is optional: you can use SerieSensei as a guest, although cross-device persistence and account controls require an account.
5. Artificial intelligence and profiling
You are interacting with an artificial intelligence system, not a human. Your current message, relevant recent conversation, saved preferences, viewing context, and sometimes your Google display name may be included in prompts sent to the configured AI inference provider. Specialized AI agents may analyze the same request to produce a combined answer.
SerieSensei builds a taste profile and ranks entertainment recommendations. This profiling is limited to the service and does not produce legal or similarly significant effects. We do not use it for advertising, credit, employment, insurance, health, or eligibility decisions. AI answers may be inaccurate, biased, outdated, or inappropriate; verify anything important independently.
6. Service providers and external content
Data is not sold. It may be disclosed only as needed to operate the service, to the following providers or categories:
- Google: optional OAuth authentication and Google-hosted profile image. See Google's Privacy Policy.
- AWS Amplify: frontend hosting and delivery. See the AWS Privacy Notice.
- Backend infrastructure providers: VPS, network, database, cache, security, and backup infrastructure.
- OVHcloud AI Endpoints or another configured AI inference provider: prompts and relevant context required to generate, classify, summarize, or evaluate replies. The active provider can change during the beta; this notice will be updated before a material change.
- Tavily: search queries created when a question requires live web research. See the Tavily Privacy Policy.
- IPinfo: IP address used over HTTPS to infer coarse location for regional availability. The raw source IP is not stored in conversational state. See the IPinfo Privacy Policy.
- TMDB: catalogue data and images. Direct image requests disclose ordinary connection data such as IP address and user agent to TMDB infrastructure.
- YouTube or Vimeo: trailers loaded only after you request one; the provider receives ordinary connection and playback data.
Background catalogue sources such as TVMaze, Wikipedia, and news providers are used primarily with series titles rather than user identity. Links to independent websites are governed by those sites' own privacy notices.
7. International transfers
Some providers may process data outside Italy or the European Economic Area. Where GDPR transfer rules apply, a transfer must rely on an appropriate mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with supplementary safeguards where required. Provider regions and mechanisms are reviewed as part of the beta's release controls. You may request information about the mechanism relevant to your data by contacting us.
8. Retention
- Guest product data: automatically deleted after 30 days.
- Operational AI/search telemetry: automatically deleted after 30 days.
- Signed-in account data: kept while the account is used, then deleted on your request or after 24 months without a login.
- Authentication credentials: access tokens normally expire after 24 hours; OAuth exchange codes expire after about 60 seconds and can be used once.
- Browser storage: remains on your device until it expires, is replaced, you delete the account, or you clear site data.
- Security and application logs: size-rotated and retained only for the operational period needed to diagnose incidents and abuse.
- Backups: deleted account data may remain in access-restricted disaster-recovery copies until normal rotation. It is not returned to active use and will be removed again if a recovery temporarily restores it.
Retention may be extended only when required by law, a security investigation, or the establishment or defence of legal claims. Aggregate data that no longer identifies a person may be retained for service evaluation.
9. Your choices and rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may also complain to the Italian Data Protection Authority.
- Signed-in users can open Manage → Privacy & data to download a JSON export or delete their account.
- Any user can email dr@mojalab.com. We may request reasonable verification before acting.
- Requests are answered without undue delay and normally within one month, subject to the extensions permitted by GDPR.
- You can contact the Garante per la protezione dei dati personali.
10. Security
We use encrypted transport, restricted network exposure, authenticated administrative access, short-lived and revocable credentials, origin checks, rate limits, log redaction, service isolation, and account deletion controls. No online system is completely secure, so do not use SerieSensei to store secrets or sensitive records. Please report suspected security or privacy incidents to the contact email above.
11. Changes to this notice
We may update this notice as the beta changes. The effective date will be revised, and material changes will be presented in the service before they take effect where reasonably possible.