Privacy Policy
Last updated 8 October 2026
This page covers the FlickCue web app at flickcue.in and the FlickCue browser extension for Chrome, Edge and Firefox, which has its own part below. The three FlickCue apps (web, extension and Android) share one list, kept in your own Google Drive.
- There are no FlickCue accounts and no FlickCue database. Your list and settings live in your browser and, once you sign in, in your own Google Drive.
- No analytics, no advertising, no tracking cookies. Your data isn't sold or shared.
- Film and show lookups go through FlickCue's title service. They can name titles from your list, but never who you are.
- A cinema ticket you add is read on your own device. It is never sent to FlickCue or to any other service; if you keep it, it goes in your own Google Drive.
- If you choose to, your reminders can also go on a calendar FlickCue makes in your own Google Calendar. FlickCue can't see any of your other calendars or events.
What is stored in your browser
The web app keeps a local copy of your list, your settings and a few things about this device in your browser's local storage. Your list can keep working offline after you sign in. When signed out, the site shows its homepage; Queue, Discover, Watched and Settings require Google sign-in. Local storage also includes your streaming region, city, Letterboxd username, theme and sort; whether alerts are on; whether your reminders go to Google Calendar, and which events FlickCue has put there; which notifications you've seen or dismissed; which of your watched films you've already put in a file for Letterboxd; streaming services' IDs for titles you've opened, so their buttons open the title (see Film and show information below); and sync status. Once you sign in, a short-lived Google access token (about an hour) is kept there too, and so is a Google refresh token, which lets the site get a new access token without asking you to sign in again each hour (see Staying signed in). Copies of cinema tickets you keep are stored in this browser too (in its IndexedDB storage), so they open offline; signing out removes them. Clearing site data for flickcue.in removes all of it.
Google sign-in and Google Drive
Google sign-in is required to use the web app's list and features. It keeps your list and settings in step between your devices and FlickCue's other apps. FlickCue asks for one permission, drive.appdata, which gives it a private app folder in your Drive that only FlickCue can open. (A second permission is asked for only if you turn on Google Calendar reminders; see Google Calendar below.) It keeps two files there:
flickcue-watchlist.json: your list, shared with the extension and the Android app.flickcue-settings.json: the web app's settings (streaming region, city, Letterboxd username, theme and Queue sort), so they follow you between browsers.- Cinema tickets you choose to keep (
flickcue-ticket-…), so you can show them at the cinema from any of your devices.
Drive keeps earlier versions of these files for about 30 days. Settings can bring back an earlier version of your list from them; that happens between your browser and Google too.
FlickCue can't see anything else in your Drive. It also reads your Google account's name, email address and photo to show which account is syncing. Your list, settings and account details travel only between your browser and Google; none of it goes to a FlickCue server. Signing in is the one step that does pass through FlickCue's proxy; see Staying signed in.
In Chrome or Edge with the FlickCue extension installed, the web app can use the extension's Google sign-in rather than asking you to sign in again. It's the same account and the same permission. Along with it, the extension passes the Letterboxd username you marked as yours in it, if any, so the web app links the same profile; profiles you follow stay in the extension. This is handed over inside your browser, not through any FlickCue server. That sign-in covers only your list, so turning on Google Calendar reminders always asks you separately.
Staying signed in
Google's access tokens last about an hour. So that you aren't asked to sign in again every hour, the web app keeps a Google refresh token in your browser's local storage on this device. It is a long-lived key to that private app folder and, if you turn on Google Calendar reminders, to the FlickCue calendar, and to nothing else. Anyone with access to your browser's storage could use it, so sign out on shared computers.
Completing sign-in, and getting a new access token from the refresh token, needs a step Google calls a client secret. FlickCue's proxy holds that secret and performs the step for the web app: the proxy sees the one-time authorization code (or the refresh token), forwards it to Google, and returns the result. It does not log or keep any of it.
The refresh token is removed from your browser, and FlickCue tells Google to revoke it, when you sign out. It also stops working if you remove FlickCue in your Google Account permissions, and clearing site data for flickcue.in removes it from this browser.
FlickCue's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can remove FlickCue's access at any time in your Google Account permissions.
Cinema tickets (optional)
On a film's page you can add a ticket you've booked, from a screenshot, photo or PDF, or by typing it in. The file is read in your browser: a PDF's text is read directly, and an image goes through text recognition that runs on your device, using files served from flickcue.in. The ticket is not sent to FlickCue, to the title service or to any AI service.
You check what was read before saving. What you save (the showtime, cinema, screen, seats and booking ID) becomes part of that title in your list, in your own Google Drive. If you choose to keep the ticket itself, a copy goes in FlickCue's private folder in your Drive and another stays in this browser, so it opens at the cinema without a signal. Removing the ticket deletes both; signing out removes the copy in this browser.
Google Calendar (optional)
If you turn on Add reminders to Google Calendar in Settings, FlickCue asks Google for a second permission, calendar.app.created. It lets FlickCue create one calendar of its own, named FlickCue, and add, change and delete events on that calendar only. It gives FlickCue no access to your other calendars or their events, and FlickCue can't read them.
For each reminder still to come, FlickCue adds an event to the FlickCue calendar with the title's name, the reminder time, a link back to it on flickcue.in, and a pop-up alert at the reminder time. It removes the event when the reminder is cleared or changed, or the title is watched or removed. This happens between your browser and Google; nothing goes to a FlickCue server. Whether it is on, and the id of the FlickCue calendar, are kept with your other settings in flickcue-settings.json, so your devices share one calendar.
Reminders you change in the extension or the Android app reach the calendar the next time you open FlickCue on the web. Turning the setting off deletes the FlickCue calendar and everything on it, including anything you added to it yourself.
Film and show information
Titles, posters, cast and where-to-watch information come from TMDB, through FlickCue's title service: a Cloudflare Worker that adds FlickCue's TMDB key. Requests to it contain:
- what you search for, and the lists you browse in Discover;
- the titles you open, with your streaming region; and, for the Tomatometer, audience and IMDb scores shown on a title's page, its TMDB number, which the title service passes to MDBList; and, so a streaming service's button can open the title itself rather than a search, its TMDB number and your region, which the title service passes to Watchmode;
- titles from your list, by their TMDB number: your recent saves for "For you" suggestions, and shows you're watching, to keep their episode schedules current.
They never include your Google account, your name or your list as a whole. Like any website, the title service sees your IP address; it uses it only to limit how many requests one connection can make, and doesn't store or log it.
So that a streaming service's button opens the title's own page there rather than a search, the website asks Wikidata (Wikimedia's open database, under its privacy policy) for the services' IDs of a title you open, by its TMDB number, directly from your browser. The answer is kept in your browser for 30 days. Wikidata sees that number and your IP address, never your account or your list.
Posters and photos load from TMDB's image servers. Trailers play from YouTube's privacy-enhanced player (youtube-nocookie.com), which loads only when you press play. Links to streaming services, IMDb and Letterboxd open those sites; nothing is sent to them before you do.
Cinema showtimes
For a film in cinemas, FlickCue links to its showtimes on Google, BookMyShow and District. Your city goes into those links, and so reaches the site you open, and only then.
Where FlickCue lists showtimes itself, it sends the film, the date and your city's centre point (not your own location) to its title service, which asks MovieGlu, a cinema listings provider, for the nearest shows. Booking a time opens the cinema's own website.
The contact form
If you write to us from the contact page, your name, email address, subject and message are sent from your browser to FlickCue's title service, which emails them to FlickCue's support address through Zoho Mail, the email service that hosts that address. They are used only to read and answer your message. The title service doesn't store them, and, like the rest of the site, doesn't keep your IP address, using it only to limit how many messages one connection can send. Your reply lives in the support inbox, where it can be deleted on request: write to support@flickcue.in. To tell people from automated spam, the contact page also runs Cloudflare Turnstile, a check that is usually invisible; while you are on that page, Cloudflare receives your IP address and some browser signals to decide, and sends the title service a one-time pass. Nothing else on FlickCue uses it.
Notifications
The Notifications page (reminders due, releases, new episodes and seasons of shows you watch) is worked out in your browser from your list. If you turn on alerts, your browser shows them while FlickCue is open, created on your device. No push service is involved and nothing is sent anywhere. (Google Calendar reminders, if you turn them on, work differently: see Google Calendar.)
Deleting your data
- Google Calendar: turn off Add reminders to Google Calendar in Settings, which deletes the FlickCue calendar. Or delete that calendar yourself in Google Calendar's settings. Removing FlickCue from your Google Account permissions also ends its access to the calendar, but doesn't delete it.
- On one device: clear site data for flickcue.in in your browser settings. Signing out removes FlickCue's access on that device but leaves your list and settings in your Drive.
- Everywhere: in Google Drive, go to Settings, then Manage apps, find FlickCue and choose "Delete hidden app data". That removes all of FlickCue's files there, tickets included. Then remove FlickCue from your Google Account permissions.
The browser extension
FlickCue saves films and shows you want to watch and reminds you about them. This part describes exactly what the extension does with data, written against what the code actually does rather than in general terms.
There is no analytics, no telemetry, no advertising, and no account with the developer. Everything below is either kept on your own device, sent directly from your browser to a service you can identify by name, or relayed to one through FlickCue's small proxy server, which keeps no log of what passes through it (see "Routed via FlickCue's proxy" below).
What is stored on your device
Held in the browser's extension storage, readable only by FlickCue:
- The titles you save, with the media type, year, rating and poster image URL that a film database returned for them.
- Your reminder times, and whether you have marked something watched.
- The page a title was saved from, a saved note, viewing status, and episode checkmarks - plus anything the FlickCue Android app keeps on the same title (such as Interested, your rating, like and review), which the extension stores and syncs unchanged.
- Your excluded scanning sites and whether on-page cards are quiet.
- A record of titles you deleted, kept for 90 days so a deletion is not undone the next time your devices sync.
- Your settings, including your selected streaming region. The streaming region is a country code used only to show availability for the region you choose; FlickCue does not determine your physical or precise location.
- If you connect Google sync, the connection state needed to keep the feature working. This may include OAuth access and refresh tokens, the identifier of FlickCue's private Drive file, and the email address of the connected Google account.
Removing the extension deletes all of this.
What leaves your device
Page scanning
The extension reads the page you are on to work out whether it is about a film or a show. It looks at the page title, headings, image labels, structured metadata, and the address. This reading happens entirely on your device. The full page contents and address are not sent to film databases. A discovery address is stored when you save a title; it follows that title into your own Drive account if sync is enabled, or into a backup you explicitly export. If online matching is enabled, only a candidate title or identifier derived from the page may be sent to the services listed below.
Film database lookups
When online matching is on, a short candidate title — for example The Odyssey (2026) — is sent so the extension can confirm the title is real and fetch its poster, synopsis, rating and streaming availability. Where that request goes:
| Service | What is sent | Routed via |
|---|---|---|
| TMDB | Candidate title, or an IMDb/TMDB id read from the page | FlickCue's proxy |
| AniList | Candidate title | Directly from your browser |
| TVmaze | Candidate title | Directly from your browser |
| Wikidata | Candidate title | Directly from your browser |
| MDBList | Confirmed TMDB id | FlickCue's proxy |
| Watchmode | Confirmed TMDB id and streaming region | FlickCue's proxy |
| Cloudflare Turnstile | Your IP address and browser signals, on the contact page only | Directly from your browser |
| OMDb | The confirmed IMDb id when known, otherwise the confirmed title and year | FlickCue's proxy |
| Fanart.tv | Confirmed TMDB/TheTVDB id | Always via FlickCue's proxy |
Only the candidate title or an identifier is sent to any of these. The page's address and your private notes are not.
Directly from your browser means exactly that: no FlickCue server sits in the middle, and each request carries your IP address to that service under its own privacy policy, linked above.
Routed via FlickCue's proxy applies to services that need a shared API key: rather than bundling that key inside the extension (readable by anyone who inspects it), FlickCue operates a small proxy server that holds those keys and forwards your request to the real service, unmodified. That proxy does not log or store request contents — it relays the request and forwards the response, nothing more. To prevent abuse of the shared keys it applies a per-minute rate limit keyed by your IP address, using Cloudflare's built-in rate limiting, which holds only a short-lived request count and is never linked to your saved titles or account. If you'd rather nothing pass through any FlickCue-operated server, turn online matching off.
MDBList ratings come through the proxy. FlickCue reads the tomatoes critic score and the popcorn audience score from the response. It does not scrape or connect directly to Rotten Tomatoes.
OMDb ratings work out of the box via the shared proxy key (1,000 requests/day across all FlickCue users, not per person). FlickCue reads the imdbRating, imdbVotes and imdbID fields from the response to show an IMDb score. It does not scrape or connect directly to IMDb.
You can switch this off. With online matching disabled, no title ever leaves your device, and the extension only suggests on pages that identify themselves as a film or show in their own metadata.
AI title guess (last resort only)
On a page the pattern-based scan above cannot make sense of, FlickCue sends the page's <title> and a short excerpt of its visible text (up to 2,000 characters) to an AI model, asking only "which single film or show, if any, is this page about" — nothing else is asked, and the reply is discarded if the page isn't about one specific title. This step only runs when every regular database lookup above has already come back empty for that page.
One of four providers handles this, tried in order and stopped at the first one that answers, so a busy or exhausted quota on one doesn't stop the feature working. All four are called through FlickCue's own proxy (see the film database lookups section above for what that means and does not mean — no logging of what's sent, only a per-minute rate limit), never directly from your browser, since this step relies on shared keys with no personal-key alternative:
| Service | What is sent |
|---|---|
| Google (Gemini) | Page title and a text excerpt |
| Mistral | Page title and a text excerpt |
| Groq | Page title and a text excerpt |
| OpenRouter | Page title and a text excerpt, and OpenRouter may itself route the request to one of several underlying model providers |
This is a wider excerpt of the page than the film-database lookups above receive (which only ever get a short candidate title), so private notes still never leave your device, but this step can send more of the page's own visible text than the rest of online matching does. It is covered by the same online matching toggle: turning that off stops this along with everything else in this section.
Google sync
Google sync is off until you turn it on and is optional.
When enabled, your saved list—including attached notes, the pages titles were saved from and episode progress—is written to your own Google Drive, in the hidden application-data folder reserved for this extension. The extension requests one scope, drive.appdata, which grants access to that folder alone. It cannot read, list or modify any other file in your Drive, and it never requests one that could.
FlickCue also reads the email address reported by Google Drive for the connected account. It uses that address only to label the active account in the popup, so you can tell which account is being synchronized. The address is stored locally in the extension, is not written into the synchronized watchlist, and is never sent to the developer.
Google supplies OAuth tokens that authorize this limited Drive access. FlickCue or the browser keeps those tokens locally as needed to maintain the connection. On Chrome, sign-in and token refresh happen entirely through the browser's own Google integration and never pass through any FlickCue server. On Edge, Firefox and Brave, completing sign-in and refreshing an expired token both require a step Google's OAuth process calls a client secret; rather than storing that secret inside the extension, FlickCue's proxy holds it and performs that one step on the extension's behalf — the proxy sees only the one-time authorization code (or refresh token) needed to complete that step, forwards it to Google, and returns the resulting access token; it does not log or retain it. Once obtained, all ongoing Drive reads and writes (the appdata folder itself) go directly from your browser to Google, on every browser, same as always.
The list is stored in your Google account, under your control, governed by Google's privacy policy. Signing out removes the stored token; the copy in your Drive stays until you delete it.
Letterboxd profiles
Nothing is read from Letterboxd until you add a profile in Settings → Letterboxd, and adding one is optional. You can add up to ten public profiles: one marked as yours, and others you follow — a friend's, say, or a critic's. For each one you choose what comes across, and you can change or remove it at any time.
FlickCue requests only the pages a profile's choices need, directly from letterboxd.com — the same pages anyone can already see by visiting that profile in a browser, signed out. It does so when you look a profile up while adding it, once an hour after that, and whenever you press "Sync" on it:
| Page | What FlickCue reads from it | Read for |
|---|---|---|
/watchlist/ | Title and year of each film on the watchlist | Any profile that brings in its watchlist |
/films/ | Title, year, star rating and whether it was liked | Your profile, if it brings in watched films; a followed profile, if it brings in the films they loved |
/reviews/ | The same, plus the text of published reviews | Your profile only, if it brings in reviews |
/films/diary/ | The date each viewing was logged | Your profile only, if it brings in diary dates |
The profile page (/<username>/) | Display name, avatar image and the number of films logged | Every profile, so Settings can show whose it is |
Looking a profile up while adding it reads its profile, watchlist and films pages whatever you go on to choose, to show whose it is and how many films it has.
No Letterboxd account, password or sign-in is involved; FlickCue never authenticates with Letterboxd, and reads nothing that is not already public on the profile.
Your own profile. Titles from it are saved to your FlickCue library so you can browse them under its Letterboxd tab. Watchlist titles arrive in your queue; if you choose to bring in watched films, titles you have already logged arrive marked watched — dated by when your diary says you watched them, if you bring in diary dates — so they do not appear in your queue. Adding it can therefore add several hundred titles at once, depending on the size of your Letterboxd history; when Letterboxd shows the number, the add button says it before you confirm.
If you bring them in, your rating, like and the first 600 characters of your published review for a title are stored alongside that title on your device, so the Letterboxd tab can show them. Like the rest of your saved list, that travels to your own Google Drive if you have sync enabled, and to any backup you export yourself. Resolving a title also sends its candidate title to TMDB, under the same terms as the film database lookups above; review text is never sent to TMDB or anywhere else.
Profiles you follow. Their titles are not added to your library. They go on a separate shelf in the Letterboxd tab — the film's title, year, poster, and that person's rating and like — which stays on this device: it is not part of Drive sync or exported backups. A title reaches your library only when you add it from the shelf yourself, and then it is saved like any title you save, filed under a "From @username" collection.
The list of profiles you have added, and each profile's display name, avatar image and counts, are also kept only on this device, outside Drive sync and backups.
Removing a profile stops all requests for it and deletes its shelf and cached details. Removing your own profile asks whether to keep the titles it brought in or to delete the ones you haven't changed since (no notes, tags, collections, progress, reminders or corrections); either way, nothing you have changed is deleted.
A profile set to private shows nothing. Removing every profile stops all requests to letterboxd.com.
A file for Letterboxd (web app). Settings → Letterboxd can make a CSV file of the films you watched, with your own stars, reviews and watch dates, in the format Letterboxd's importer reads. The file is made in your browser and saved to your device. The web app sends it nowhere, to neither FlickCue nor Letterboxd: you upload it to Letterboxd yourself, if you want to. Films that came from Letterboxd are not put back in it. The web app keeps a record on this device of which films it has put in a file, so the next file holds only what is new or changed; that record is outside Drive sync and backups.
What is never collected
- Your browsing history.
- The full contents of pages you visit. Page scanning is local; online matching sends a candidate title or identifier and, only when nothing else identifies a page, its title and up to 2,000 characters of its visible text to an AI provider, as described above.
- Contacts, payment information, health information, personal communications, or precise location.
- Anything sold, shared or transferred to a third party for advertising.
Backups
Exported backups contain your private title data and no settings. Imports add missing titles without overwriting current entries. Excluded sites turn off scanning there; the extension still retains its installed host permissions, which you can manage separately in your browser settings.
Permissions and why each is needed
- Access to websites — to read the page you are on and detect a title. Used on the page only; nothing is sent to the developer.
- Access to letterboxd.com — to read the public pages of the Letterboxd profiles you add in Settings, only once you add one.
- Access to FlickCue's own proxy server — to reach the shared TMDB, MDBList, OMDb, Fanart.tv and AI-provider keys described above, and to complete Google sign-in on Edge, Firefox and Brave, without those keys or that one-time authorization step being embedded in the extension itself.
- Storage — to keep your list, settings, reminders, cached metadata and, if you enable Google sync, its connection state on your device.
- Alarms — to fire your reminders, and to run Drive sync and Letterboxd sync on their own schedule.
- Identity — to sign in to Google, only if you enable sync.
FlickCue does not request the browsing-history permission.
Data retention and removal
Local extension data remains on your device until you remove it. Deleting a title removes it immediately, leaving only a dated marker for 90 days so the deletion propagates to your other browsers.
If Google sync is enabled, a copy of the watchlist remains in your private Google Drive application-data folder. Signing out clears FlickCue's locally stored connection information, including the connected email address and OAuth tokens, but does not delete that Drive copy. Uninstalling the extension removes its local data but does not delete the Drive copy either.
To remove everything: uninstall the extension, and if you used Google sync, revoke its access at myaccount.google.com/permissions and delete the app data from your Drive.
Children
FlickCue isn't directed at children under 13 and doesn't knowingly collect their information.
Changes and contact
If this policy changes, the date at the top changes with it. For questions or requests, including deleting your data, email support@flickcue.in. You can also open an issue on GitHub; issues are public, so please don't include personal details there.