WatchCat
// privacy policy · 2026-08-29

WatchCat Privacy Policy

Material update: Paid web billing has moved to Paddle, which is now the merchant of record for WatchCat subscriptions and the recipient of your billing details. Paddle has no way to delete a customer record — its API can only archive one — and as merchant of record it must keep transaction, tax, and invoice records, so a WatchCat account deletion removes the WatchCat-side billing rows and archives the record held at Paddle. WatchCat also publishes one contact address, hello@getwatchcat.com, for privacy requests as well as commercial, billing, refund, and legal questions. It replaces the previous privacy-request address; mail sent to the old address is no longer monitored, so please resend anything outstanding. This version also records that the Max plan and its optional AI features — daily digests, summaries, and goal-aware reflection — have been withdrawn: WatchCat no longer sends any data to an AI provider, and the AI results and quota counters that existed have been deleted.

1. Scope and plain-language summary

This policy explains how WatchCat handles information in the browser extension, public website, waitlist, account dashboard, and optional cloud sync. The Free extension is local-only. Cloud history and settings sync are available only to eligible Pro accounts and begin only after you connect the extension and affirmatively consent.

2. Who is responsible

WatchCat is operated under the WatchCat name by the developer who publishes the WatchCat extension and services. For privacy questions or requests, email hello@getwatchcat.com. If a separate legal entity becomes the operator, this policy will be updated before that entity takes control of personal data.

3. Data kept locally by the extension

WatchCat uses browser extension storage to keep:

Detailed history is kept in a local extension IndexedDB as bounded UTC activity segments. Local-only use enforces limits from the current browser summary. After an eligible account enables detailed sync, the extension also keeps a current-day cache of other-device Today totals, including their hourly breakdown and view counts, and adds it to the current browser summary so the same daily allowance applies across linked devices and the same numbers appear everywhere it is shown. Local data remains in the browser profile unless you explicitly enable cloud sync. You can delete it by clearing WatchCat extension storage or uninstalling the extension. WatchCat does not run in private/incognito windows.

4. Browser permissions and supported sites

The extension uses storage to keep local data and alarms for local schedules and resets. It requests access to supported YouTube, Netflix, X/Twitter, and TikTok pages so it can detect active viewing, calculate watch time, show stats, and apply the limits you configure. Account-enabled Chrome and Safari builds open sign-in in a normal WatchCat dashboard tab and request access only to the configured WatchCat API origin when you start account connection. The dashboard callback relays only the backend-issued one-time authorization code and state to the allowlisted extension. Firefox uses its browser identity flow and a fixed extension-derived callback. It asks separately for authentication, account, technical, browsing-activity, website-content, and website-activity data permissions; detailed browsing categories are requested only before detailed cloud history is enabled. Revoking those Firefox permissions stops future transfer on that device. WatchCat does not use these permissions for advertising profiles or unrelated browsing analysis.

5. Accounts and authentication

In the backend-owned dashboard release, your browser sends registration, sign-in, confirmation, recovery, and account requests only to the WatchCat API. Supabase processes your email, account identifier, password-authentication state, confirmation/recovery state, and provider session credentials as internal backend infrastructure. The dashboard receives a host-only HttpOnly WatchCat session cookie and a session-bound CSRF value, never a Supabase key or token. The backend stores a hash of the browser handle and encrypted provider credentials needed to maintain or revoke the session.

Account-enabled Chrome, Firefox, and Safari releases connect through WatchCat OAuth Authorization Code with PKCE. The backend records the registered browser client, authorization request and decision, scopes, grant, revocation state, and hashes of one-time codes and rotating opaque tokens. The extension stores the short-lived access token in trusted extension session storage and its rotating refresh token in extension IndexedDB. Google and GitHub sign-in are not active.

During the migration and rollback window, an already-released dashboard or extension may still authenticate directly with Supabase. New client releases contain no fallback to that legacy path; WatchCat will retire it only after supported-client adoption and traffic checks are complete.

6. Optional cloud sync

When connecting an eligible account, the extension records a device identifier, device label, normalized browser name, browser family, coarse operating-system name, extension and storage versions, timezone, link and revocation state, its linked OAuth grant identifier, and last-sync timestamps. The device display excludes the full user-agent string, OS version, hardware model, and processor architecture. Eligible cloud history has one scope: detailed history. Before transfer, the extension shows the categories, purpose, destination, exclusions, and controls and requires an affirmative choice.

History and account settings go only to the WatchCat API. Paid cloud-history payloads, daily rollups, imports, and generated export artifacts are stored as encrypted objects with FIL.ONE in its European region. Supabase remains internal infrastructure for Auth, subscriptions, consent, device and settings state, and bounded synchronization metadata such as opaque object references, revisions, checksums, leases, and watermarks; this control metadata does not contain reconstructible history. The protocol does not upload URLs, full browsing history outside supported activity, PIN data, temporary unlocks, unlock counters, or current enforcement/block state. Synced settings configure each linked browser. For an eligible account with detailed sync enabled, consented other-device Today totals are cached locally and contribute to the same daily allowance; temporary unlocks and the local limit-event log are not uploaded. Free accounts cannot enable this transfer. Existing accounts must accept the current disclosure before settings leave a browser.

Once accepted, the versioned receipt applies account-wide. Signing back into the same device or linking another device inherits a current receipt, merges missing eligible local segments automatically, and loads account history in small pages. A new device initially requests a lightweight manifest and Today; 24-hour and seven-day history load when selected. Signing out stops history network work on that device. Revoking a connected device also revokes its linked WatchCat OAuth token family. On its next authenticated contact, the extension clears local account credentials and cloud cache; local history and enforcement remain available. Entitlement loss or consent withdrawal blocks future history and settings transfer without signing the device out. Withdrawal does not itself delete already stored cloud data; use account deletion for erasure. The product API includes authenticated export and staged account deletion.

7. Subscription billing

When paid web billing is enabled, the dashboard sends your selected Pro plan, billing period, an account reference, a checkout request identifier, and your account email when available to the WatchCat API. The backend reserves the checkout attempt, opens it in a Paddle overlay in your browser, and stores the resulting transaction, customer, price, and subscription identifiers, subscription status and current-period end, plus bounded webhook reconciliation metadata and a mutation idempotency/audit record containing the operation type, selected target when applicable, status, and bounded result or error code in service-role-only Supabase Postgres tables. These records support checkout, plan or billing-period changes, cancellation or resumption, entitlement projection, account export, and duplicate-safe provider callbacks.

Payment-card, tax, and invoice details are entered directly with Paddle, and your account email address is shared with Paddle as the billing identity. They are not received by the WatchCat dashboard or stored in WatchCat Postgres. Active billing must be canceled before account deletion can finish. Account-linked WatchCat billing rows are included in account export and removed during account deletion. Paddle provides no way to delete a customer record — the record is archived instead — and as merchant of record Paddle retains transaction, tax, invoice, and fraud records when required by its legal and provider obligations.

8. Website analytics

The public website uses limited anonymous analytics on the landing. This may include page views, campaign and referring source, browser and device information, web-performance measurements, approximate country, automatically captured interaction metadata and heatmaps, masked session replay and related console diagnostics, and which call-to-action placement was clicked.

Input values are masked in session replay by default. WatchCat does not intentionally send waitlist email addresses, support form values, extension history, or extension settings through website analytics. Analytics runs only on the public landing route and not on the support, privacy, or private unsubscribe routes. The analytics service is configured not to retain raw client IP addresses. Browser storage holds a random anonymous identifier, the cookie notice acknowledgement, and — if you play the landing mini-game — your best score and how many runs you finished, until you clear site data. The mini-game score stays in your browser; analytics receive only a coarse score band.

9. Waitlist and email data

The pre-launch waitlist is closed and the public site no longer offers a join form. For addresses collected while it was open, WatchCat retains the email address, source, a limited referrer, subscription and confirmation timestamps, confirmation attempts, and unsubscribe state, and uses them only for the promised launch announcement and to honor unsubscribe requests. Resend delivers waitlist email. Unsubscribing stops waitlist messages and preserves the suppression state needed to honor that choice; you may also request deletion.

10. Support requests

The public support form accepts a category, the product area you choose, a subject and message, and an optional reply email. It also creates an opaque submission identifier and support reference. The page does not automatically attach your account identifier, active-tab URL, browsing history, extension settings, user agent, or installed version. Do not include passwords, session tokens, PINs, full browsing history, or other sensitive information.

The WatchCat API stores accepted tickets in service-role-only Supabase Postgres and uses Resend to notify the ordinary support inbox. If you provide an email, it is used as the reply address. The backend derives HMAC-protected abuse-limit keys from request metadata, and Cloudflare processes a one-time Turnstile token only when an additional challenge is required. Support form values are excluded from website analytics and privacy-limited application logs and metrics.

Support tickets are retained for 12 months and then deleted by a scheduled database cleanup. They are not linked to an account identifier and are not automatically included in account export or account deletion. To request access to or deletion of a support ticket, send a verified privacy request with the reply email or support reference. Privacy and legal requests must be sent separately to hello@getwatchcat.com with the subject “Privacy request,” not through the ordinary support form.

That address is also the general contact address published on the website and the legal pages, for commercial, billing, refund, and legal questions. Email you send there reaches an ordinary mailbox rather than the ticket database: we receive your address, the message, and anything you choose to attach, use it only to answer you and to keep a record of the request, and keep it no longer than needed for that purpose and any related legal or accounting obligation. Use the subject “Privacy request” so a data-protection request is recognized as one. Do not send passwords, session tokens, PINs, or payment-card details to it.

11. How we use data

We use data to:

Depending on the context, processing is necessary to provide the service you request, to meet legal obligations, for legitimate security and service-operation interests, or for aggregate website measurement where applicable, or based on consent for processing that WatchCat presents as optional. We do not use WatchCat data for advertising profiles, credit decisions, or data-broker activity.

12. Service providers and disclosure

WatchCat uses service providers for hosting and delivery, authentication and database infrastructure, cloud-history object storage, subscription billing and payment processing, product analytics, bot protection, and email delivery. These currently include Supabase, FIL.ONE, hosting and analytics infrastructure used by the WatchCat website and API, Paddle, Cloudflare Turnstile, and Resend. FIL.ONE receives paid cloud-history objects from the WatchCat backend, not credentials from the extension. Providers process data under their own contracts and security terms only for the relevant service.

We may also disclose information when required by law, to protect users and the service, or as part of a business transfer with appropriate notice and safeguards. We do not sell personal information or share it for cross-context behavioral advertising.

13. Retention

Account deletion removes user-owned data and authentication last. Records that must be retained for financial or audit law are de-identified and stripped of account linkage.

14. Security

Backend-owned releases use HTTPS, host-only HttpOnly cookies, exact-origin and CSRF checks, OAuth PKCE and rotating-token replay protection, scoped browser permissions, server-side token verification, access controls, row and tenant boundaries, input validation, and privacy-limited logs and metrics. No service can guarantee absolute security. Keep access to your browser profile and email account secure, and contact us if you believe your account or data has been compromised.

15. Your choices and rights

You can:

Depending on where you live, you may also have rights to access, correct, delete, restrict, port, or object to processing and to complain to a local data-protection authority. We will verify requests before disclosing or deleting account data. Privacy choices will not be used to discriminate against you.

16. Children

WatchCat is not directed to children under 13, and we do not knowingly collect account or sync data from a child under 13. Where local law requires a higher age or parental authorization for an online account, do not create or connect a WatchCat account without that authorization. Contact us if you believe a child provided personal data so we can review and delete it where required.

17. International transfers

WatchCat and its providers may process data in countries other than your own. Where required, transfers are handled through an adequacy decision, contractual safeguards, or another lawful transfer mechanism offered by the relevant provider.

18. Chrome Web Store Limited Use

WatchCat limits extension data to the user-facing purposes described in the extension, its store listing, and this policy. The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. We do not transfer extension browsing activity for personalized advertising, sale by data brokers, lending, or unrelated purposes.

19. Changes to this policy

We update this policy when WatchCat changes its data categories, purposes, sync scope, providers, retention, user controls, or applicable obligations. Editorial corrections may not trigger a notice. For material changes, we will change the version and effective date and provide an in-product notice; where a new use requires consent, we will request it before that use begins. Earlier versions may be requested by email.

20. Contact

Email hello@getwatchcat.com with the subject “Privacy request.” Include enough information to identify the relevant account, waitlist entry, or support reference, but do not send passwords, session tokens, or PINs. The same address takes commercial, billing, refund, and legal questions; the Terms of Service and the Refund and Cancellation Policy set out that relationship. Ordinary product questions and feedback belong on the support page, which gives you a reference number.

← Back to WatchCat