rekko.
English · Français · Deutsch · Español · Italiano · Português (Brasil) · 日本語 · 한국어
Privacy Policy
Last updated: June 8, 2026
Rekko is built around a simple promise: your data stays yours.
What you watch, what you rate, the friends you share with — none of it lives on
our servers. This page explains, in plain language, what data Rekko handles,
where it goes, and how you can control or delete it at any time.
1. Who is responsible for your data?
Rekko is developed and operated by Jean-Baptiste Meyer ("we", "us"),
acting as the data controller under the General Data Protection Regulation
(GDPR / RGPD).
Any question about this policy or your data can be sent to
jib@jibstudios.com.
2. What data Rekko handles
Rekko collects only what is strictly necessary to make the app work. Concretely:
-
Sign-in identifier. When you sign in with
Sign in with Apple, Apple gives Rekko a stable, opaque
userIdentifier. We do not store your real
Apple ID, your name, or your email address. The email Apple offers to
share is intentionally discarded.
-
Profile content you create: the display name you
choose, the avatar photo you upload, and the favourite genres you pick.
-
Journal content: the TV shows and films you follow,
their viewing status (to watch / in progress / watched / dropped),
ratings and optional review comments.
-
Circles and recommendations: the private circles you
create or join, their member list (limited to who you explicitly invite),
and the recommendations / ratings you share inside them.
-
Anonymous device attestation. Rekko uses Apple's
App Attest framework to prove that requests to its read-only
relay come from a legitimate copy of the app. App Attest does not expose
any personal information.
Rekko does not collect: your contacts, your location,
your microphone, your browsing history, your advertising identifier, or any
third-party analytics. There is no in-app tracking SDK.
3. Where your data is stored
Personal data is stored in your own private iCloud space,
via Apple's CloudKit framework. We do not have a server holding a copy.
Specifically:
-
Your profile, your journal, and your locally-created circles live in your
iCloud Private Database, accessible only by your Apple ID.
-
Shared circles use Apple's CKShare mechanism: the data is
replicated only to the iCloud accounts you have explicitly invited.
-
A read-only relay we operate is used to securely sign requests to TMDB
(see §4). It does not store any of your data and only logs short-lived
technical traces for abuse prevention.
4. Third parties involved
-
Apple Inc. processes your iCloud data on its servers,
under Apple's Privacy Policy.
The CloudKit infrastructure that hosts your circles, profile, and journal
is Apple's, not ours.
-
The Movie Database (TMDB). Rekko fetches TV show and
film metadata (titles, posters, synopses, cast) from
TMDB. The TMDB request includes
only the identifier of the show you are looking at; no personal Rekko
identifier is sent. TMDB is the source of the movie catalogue and is not
affiliated with Rekko.
5. Legal basis
All processing of personal data is based on your consent
(GDPR art. 6(1)(a)) — given when you sign in and create your profile — and
on the performance of a contract (art. 6(1)(b)) for the
functionality you actively request (creating a circle, sending a
recommendation, etc.).
6. How long we keep your data
For as long as your account exists. When you delete your account from the
Rekko settings, your local database is wiped, the App Attest key tied to
your installation is invalidated, your CloudKit zones (shared and private)
are torn down, and your sign-in identifier is cleared from the keychain.
Members of circles you owned are notified that the share is gone and the
bookmark disappears from their device.
Because Rekko never stores a Sign in with Apple token (we keep
only the opaque userIdentifier on your device, in your local
keychain), there is no token for us to revoke server-side. If you want to
additionally invalidate the Sign in with Apple authorisation on Apple's
side, you can do so at any time from iOS Settings → your name →
Password & Security → Apps Using Apple ID → Rekko → Stop using Apple
ID.
7. Your rights under GDPR
You can exercise the following rights at any time:
-
Right of access & portability. Rekko offers an
in-app "Export my data" action that produces a structured JSON file
containing your profile, journal, circles, and recommendations. You can
save it to Files, send it by mail, or open it in any tool.
-
Right to rectification. You can edit your display name,
avatar, favourite genres, and the content of any rating or recommendation
directly in the app.
-
Right to erasure. The "Delete my account" action in
Settings wipes every trace of your data on your device and in your
iCloud Rekko zones. See §6 for the details on the Sign in with Apple
authorisation.
-
Right to object & withdraw consent. Signing out of
the app stops every form of processing on our side; deleting the account
makes it definitive.
-
Right to lodge a complaint with a supervisory authority
(in France: the CNIL, cnil.fr).
To exercise any of these rights, including a manual data request when the
in-app flows are not enough, write to
jib@jibstudios.com. We will reply
within 30 days at most.
8. Permissions Rekko may ask for
-
Photos (read-only). Only when you tap the avatar to
pick a photo. The selected image is downscaled to a 300 pt thumbnail and
stored in your local profile.
-
Notifications. Used to tell you when a friend in one of
your circles sends you a recommendation. You can disable them in the iOS
Settings at any time.
-
iCloud. Required for circles to sync between members
and between your devices. Rekko cannot function without an iCloud account
signed in on the device.
9. Children
Rekko is not directed at children under 13. We do not knowingly collect data
from children. If you believe a child has signed up, please contact us and
we will delete the corresponding account.
10. Changes to this policy
We may update this policy when the app or applicable law change. We will
update the "Last updated" date at the top of this page, and a meaningful
change will be surfaced in-app the next time you open Settings.