Overview
Dead Media Labs ("we", "us", "our") operates the Dead Media mobile application and the website at deadmedialabs.com (collectively, "the Service"). This policy describes how we collect, use, store, and protect your information when you use our Service.
By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.
Information We Collect
Information you provide directly:
- Account information — email address and username when you create an account.
- Phone number — provided during marketplace identity verification. Required to buy or sell on the marketplace.
- Collection data — discs, reviews, ratings, and wishlist items you add to your profile.
- Marketplace data — listings you create, messages with other users, and transaction details.
- Photos — spine images, listing photos, and profile photos you upload.
Information collected automatically:
- Device information — device type, operating system version, and app version.
- Push notification tokens — a device identifier used to deliver push notifications if you enable them.
- Usage data — app interactions and feature usage, collected via privacy-friendly analytics. No IP addresses are stored by our analytics provider.
How We Use Your Data
- To provide, maintain, and improve the Dead Media app and your account.
- To display your collection, reviews, and listings to other users.
- To facilitate marketplace transactions and messaging between buyers and sellers.
- To verify your identity via phone number for marketplace access.
- To send account-related emails, including confirmation, password reset, and transaction updates.
- To deliver push notifications about messages, listing updates, and other activity you have opted into.
- To send SMS updates if you opt in during phone verification (see SMS Communications below).
- To detect and prevent fraud, abuse, and security threats.
- To analyze usage patterns and improve features.
Legal Basis for Processing
If you are located in the EU/EEA or a jurisdiction that requires a legal basis for processing personal data, we rely on the following:
- Contract performance — processing your account data, collection data, marketplace data, and messages is necessary to provide the Service you signed up for.
- Legitimate interest — analyzing usage data to improve the app, detecting fraud, and maintaining security. You may object to processing based on legitimate interest by contacting us.
- Consent — SMS marketing messages, push notifications, and analytics tracking. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal obligation — retaining certain data as required by applicable laws, including tax and financial regulations.
SMS Communications
During phone verification, you may opt in to receive SMS messages from Dead Media. By opting in, you consent to receive up to 4 messages per month, which may include product updates, feature announcements, and marketplace notifications.
- Message and data rates may apply depending on your mobile carrier and plan.
- SMS consent is not a condition of purchasing any goods or services.
- You can opt out at any time by replying STOP to any message, or by changing your preference in the app under Settings.
- Reply HELP for support, or contact support@deadmedialabs.com.
- Supported carriers include but are not limited to AT&T, T-Mobile, Verizon, and Sprint. Carrier participation may vary.
Your phone number is used solely for identity verification and, if opted in, SMS communications. We do not sell, rent, or share your phone number with third parties for their marketing purposes.
Push Notifications
With your permission, we send push notifications about new messages, marketplace activity, and other relevant updates. You can disable push notifications at any time through your device's system settings. Disabling notifications does not affect the functionality of the app.
Third-Party Services
We integrate with the following services to operate the app. Each processes data in accordance with their own privacy policies:
- Supabase — authentication, database, and file storage (US-based).
- TMDB — movie and TV show metadata, posters, and cast info. Dead Media is not endorsed or certified by TMDB.
- Brevo — transactional and notification email delivery.
- Twilio — phone number verification via SMS and optional SMS communications.
- Expo — push notification delivery.
- PostHog — privacy-friendly product analytics. PostHog is configured to not collect IP addresses. You can opt out of analytics tracking in Settings > Privacy.
We do not share your personal information with these providers beyond what is necessary for them to perform their services.
Data Sharing
We do not sell, rent, or trade your personal information to third parties. We do not share your data for third-party advertising purposes.
We may share your information only in the following circumstances:
- With service providers — as described in Third-Party Services above, solely to operate the Service.
- With other users — your profile, collection, reviews, and marketplace listings are visible to other Dead Media users as part of the app's core functionality.
- For legal compliance — if required by law, court order, subpoena, or government request.
- To protect rights and safety — if we believe disclosure is necessary to prevent fraud, enforce our Terms of Service, or protect the safety of our users.
- In a business transfer — if Dead Media Labs is acquired, merged, or sells substantially all of its assets, your data may be transferred as part of that transaction. We will notify you of any such change.
Data Security
We implement reasonable technical and organizational measures to protect your personal information, including:
- Encrypted data transmission (TLS/HTTPS) for all communications between the app and our servers.
- Secure credential storage using device-level secure storage (Keychain on iOS, Keystore on Android).
- Row-level security policies on our database to ensure users can only access their own data.
- Authentication tokens with automatic expiration and refresh.
No method of electronic storage or transmission is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials.
Data Retention
- Account data — retained for as long as your account is active.
- Phone number — retained for as long as your account is active to maintain your marketplace verification status.
- Messages — retained for as long as both parties' accounts are active, or until deleted by the user.
- Analytics data — anonymized and aggregated analytics data may be retained indefinitely as it cannot be linked back to you.
When you delete your account through the app, all associated data is permanently removed from our systems within 30 days, including your collection, reviews, listings, messages, uploaded images, phone number, and profile information.
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users via email within 72 hours of becoming aware of the breach. Where required by law, we will also notify the relevant supervisory authority. Notification will include the nature of the breach, the data affected, and the steps we are taking in response.
International Data Transfers
Dead Media is operated from the United States. Our service providers (Supabase, PostHog, Twilio, Brevo, Expo) process and store data on servers located in the United States and other countries.
If you access the Service from outside the US, your data will be transferred to and processed in the US. For users in the EU/EEA, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission, or equivalent safeguards provided by our service providers, to ensure adequate protection for international data transfers.
Your Rights
All users:
- Access, update, or delete your account information at any time through the app.
- Request a full export of your data by contacting support@deadmedialabs.com.
- Opt out of analytics tracking in Settings > Privacy.
- Opt out of push notifications through your device settings.
- Opt out of SMS updates by replying STOP or changing your preference in Settings.
California residents (CCPA/CPRA): You have the right to:
- Know what personal information we collect and how it is used.
- Request deletion of your personal information.
- Opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising.
- Not be discriminated against for exercising your privacy rights.
- Designate an authorized agent to make requests on your behalf.
To exercise your CCPA rights, contact support@deadmedialabs.com or delete your account directly through the app. We will respond to verifiable requests within 45 days.
EU/EEA residents (GDPR): You have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate personal data.
- Erasure — request deletion of your personal data ("right to be forgotten").
- Restrict processing — request that we limit how we use your data.
- Data portability — receive your data in a structured, machine-readable format.
- Object — object to processing based on legitimate interest.
- Withdraw consent — withdraw consent for SMS, push notifications, or analytics at any time.
To exercise your GDPR rights, contact support@deadmedialabs.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
Children's Privacy
Dead Media is not directed at children under 13 (or under 16 in the EU/EEA). We do not knowingly collect personal information from children under these ages. If we learn that we have collected data from a child under the applicable age, we will promptly delete that information and terminate the associated account.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at support@deadmedialabs.com.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the effective date at the top of this page and, where appropriate, providing notice through the app or via email. Your continued use of the Service after any changes constitutes acceptance of the updated policy.
We encourage you to review this policy periodically.
Attribution
This product uses the TMDB API but is not endorsed or certified by TMDB. All movie and TV show metadata, posters, and cast information are provided by TMDB.
Contact
If you have questions about this Privacy Policy or wish to exercise any of your data rights, contact us at:
Dead Media Labs
Email: support@deadmedialabs.com