Privacy Policy
Last updated: 18 September 2026
This policy explains what personal data Bower collects, why, and what you can do about it. It applies to the Bower website at bower.tv and any Bower mobile apps.
The short version
- We collect the minimum needed to run a release tracker: an email address, what you track, and where you are (country-level) so we can show you the right release dates and streaming availability.
- We do not sell your data or license it on to third parties. Bower carries no advertising today. If we ever introduce it, we will update this policy first, and any advertising cookies will stay off until you consent to them.
- Watch history is opt-in. Bower records what you have watched only when you mark it yourself, or when you choose to connect your own Plex or Jellyfin server. Your profile page is private unless you switch it on.
- We use PostHog to understand how Bower is used. A minimal, anonymous layer of this runs automatically and can't be traced back to your device; a fuller, cookie-based layer only runs if you choose "Accept all" in our cookie banner, and you can change your mind at any time.
- Bower Plus is sold by Paddle, who handle the card and the invoice; we never see your card number. Section 5 says what we receive.
- Marketing emails from us are opt-in, every one has an unsubscribe link, and we count opens and clicks so we know whether they're worth sending.
- You can download everything we hold about you, or delete your account outright, from your Settings page, with no need to ask us.
The rest of this policy is the detail behind those points.
1. Who we are
Bower is operated by Ben Hindmarch, a sole trader established in Ireland, trading as Bower.
- Contact for privacy matters: privacy@bower.tv, or our contact form
- Postal address: available on request via either of the above
We are the data controller for the personal data described in this policy. We have not appointed a Data Protection Officer, as we are not required to.
2. The short version
See the summary at the top of this page — the rest of this policy is the detail behind it.
3. What we collect
3.1 Data you give us
| Data | When |
|---|---|
| Email address | Account creation. Used to sign you in, to send you service messages about your account, and for the newsletter if you opt in. |
| Password | Never sent to or stored by Bower directly — Amazon Cognito, our identity provider, manages this entirely on our behalf. |
| Username | Chosen during sign-up. It is the address of your profile page (bower.tv/u/your-username), which stays private unless you switch it on — see 3.6. |
| Country/region, language and time zone | At sign-up or in Settings. They determine which release dates, streaming providers and interface language we show you, and which calendar day a release falls on for you. |
| Theme (light/dark) | Whenever you set it in Settings. |
| Genre preferences | If you set them during sign-up or in Settings, to shape what we recommend to you. |
| Your tracked titles, favourites, hidden titles, and the teams, players and competitions you follow | As you use the service. This is the core of what Bower does. |
| What you mark as watched, and whether you liked it | If you use the "Mark as watched" control on a title, or the "Liked it" / "Not for me" thumbs that follow it. Marking is optional and title by title; see 3.5 for watch history that comes from your own media server instead. |
| Streaming services you subscribe to | Optional, if you tell us in Settings, so we can filter availability to services you actually have. |
| Bower Plus membership | If you subscribe: the customer and subscription references Paddle assigns, the subscription's status and plan, and the date your access runs to. Never your card number; see section 5. |
| Profile visibility choices | Two separate switches in Settings: whether your profile page is public, and whether it also shows what you have watched recently. Both are off until you turn them on. |
| Marketing email preference | Whenever you set it. |
| Anything you send us in a support or feedback message | When you send it: the topic and message, your email address, an optional screenshot, and, if you tick the box, some details about your device (browser, operating system, screen size). The same applies to any email you send to one of our addresses, including any attachments. |
3.2 Data we generate about you
Personalisation. Your tracked titles and country are used to build your "today" view and calendar. Each night we also compute a list of recommendations from the titles you track and have liked, and store it with the reasons for each pick so the page can tell you why. This is ordinary personalisation, not automated decision-making with legal effects.
Sign-in date. We record the date and time of your most recent sign-in (one value, overwritten each time, not a history) so we can count active accounts and apply the inactive-account rule in section 7.
Consent records. When you accept these terms at sign-up, or change your marketing-email preference, we record the date and time. We don't currently log the IP address associated with that action.
Feedback triage. Each feedback message you send is run through an automated classifier (Amazon Bedrock, on our own AWS account) that flags urgent reports, such as a security problem, so we see them sooner. It decides how quickly we read your message, and nothing else.
Account status. If we suspend an account for a breach of our Terms, we record that we did and when.
3.3 Data collected automatically
Web request logs. IP address, user agent, requested URL, response status and timing, kept for 14 days and used for security, abuse prevention and debugging. Application logs from our backend functions may carry an account identifier alongside an error message, but never what you track or watch; they are kept for up to two years. The endpoint that receives media-server events (3.5) keeps an access log with no caller address or URL in it, for 30 days.
Your country, from your connection. On your first visit our content delivery network (Amazon CloudFront) looks up the country your IP address maps to and passes us the two-letter country code, nothing else, so we can open the right region's homepage. Once you pick a region yourself, or sign in, we use that instead.
Bot protection. The feedback form uses Cloudflare Turnstile to tell people apart from bots. Turnstile sees your IP address and some technical signals about your browser; we only ever receive a pass/fail result from it, not those signals themselves.
Sign-up abuse protection. During sign-up, the check that tells you whether an email address already has an account is rate-limited per connection. We count those requests under a one-way hash of your IP address, and the counters are deleted after an hour. The address itself is never stored for this.
Cookies. Bower sets three cookies, and only once you've answered our cookie banner: one remembers your language, one remembers your country, and one records which banner option you chose. None of them are set if you decline — declining stores literally nothing on your device, not even the fact that you were asked, so you'll see the banner again on your next visit. We don't use a session cookie to keep you signed in; sign-in state is kept in your browser's local storage instead. Our Cookie Policy lists every item of browser storage by name.
Newsletter opens and clicks. If you have opted in to the newsletter, each issue carries a tiny invisible image, and its links pass through Amazon SES, our email provider, on the way to the page they point at. When the image loads or a link is clicked, SES tells us that the issue was opened, or which link was clicked, and when, and we record that against the issue. We don't receive or keep where you were or what device or mail app you used; SES sees your IP address and mail client in the process and handles them under its own terms as our processor. We use these counts to see whether the newsletter is worth sending and which parts of it people read, and they are kept as part of the log of newsletters sent to you. The unsubscribe link is never tracked. Most mail apps let you block remote images, which stops the open being recorded.
Tracking without an account. You can track titles, mark them watched and rate them without signing up. The first time you do, Bower stores a random identifier in your browser's local storage and keeps your list on our servers against it. It is created only at that moment, not when you merely visit, and it is used for nothing except finding your list again: it isn't derived from anything about you, isn't shared, and isn't used for analytics. It stays until you clear your browser data, or until you create an account, when your list is moved onto the account and the identifier is deleted from your browser. This identifier is what keeps a service you explicitly asked for working, so it doesn't need your consent under the ePrivacy rules and is unaffected by how you answer the cookie banner.
3.4 Analytics and session recording
We use PostHog to understand how Bower is used, in two tiers.
A minimal layer runs automatically, before you answer the cookie banner and even if you decline it: PostHog counts anonymous, aggregate usage — which pages are viewed, roughly how a feature gets used — under a rotating, server-generated identifier that is never stored on your device. No cookie, no local storage entry, nothing that lets us or PostHog recognise you across visits.
If you choose "Accept all" in the cookie banner, PostHog switches to its normal mode: a persistent identifier stored in your browser, so we can see the sequence of pages one person visits over time, plus session recordings — a reconstruction of your visit (the pages as they appeared, your mouse movement, scrolling and clicks) that we watch back to diagnose confusing or broken flows. PostHog masks the values you type into form fields by default. Choosing "Only necessary" or declining the banner keeps PostHog in the anonymous, cookieless mode above, permanently.
You can use all of Bower with the banner answered either way — nothing about the service changes.
3.5 Connecting your own Plex or Jellyfin server
This is optional and only available to signed-in members. If you turn it on, Bower generates a web address containing a random token, and you paste it into your Plex account settings or your Jellyfin server's webhook settings. That address is the only credential involved: we store a one-way hash of the token, never the address itself, and we never sign in to Plex or Jellyfin, never read your library, and receive nothing at all from Plex, Inc. or the Jellyfin project. Your own server sends us an event when you play something, because you told it to.
What arrives with each event: the kind of event (play, pause, resume, stop, or passing the 90% mark), the catalogue identifiers of the film or episode (TMDB, IMDb or TVDB ids, season and episode number), how far into it you are, and the account name and server name that sent it. What we keep: which films and episodes you have watched, as a state (with a play count and the last time), how far you are through anything unfinished, and, on the connection itself, the account name and server name, a one-line summary of the last event and counts of events handled, so the Settings page can show you the connection is alive. What we discard on arrival: the artwork and thumbnail attached to the event, your avatar, the IP address of the device you played on, and any event about someone else using your server: a Plex event is only accepted when your server says it is for the account that set up the address, and a Jellyfin address is bound to one user on that server. Events for a title we don't yet have in our catalogue are queued as identifiers only, and removed with the connection.
Removing the connection in Settings revokes the address immediately and stops all collection. It does not delete the watch history already recorded, since that is a record of your own plays that you sent us directly: you can remove it title by title with the Watched control, or all at once by deleting your account. Nothing from a media server is ever shown to anyone else unless you turn on the second profile switch in 3.6.
3.6 Your profile page
Every account has a profile page at bower.tv/u/your-username, and it is private by default: a visitor sees only that the profile is private. If you switch it on, it shows your username and the shows, films, teams and competitions you track, and to a signed-in visitor it also shows how much your tracked lists overlap with theirs. A separate switch adds what you have watched recently, limited to finished episodes and films, by episode number, with no times or partial progress. Your email address is never shown, and we never request a profile picture from Gravatar for a page someone else is looking at. We don't record who views a profile.
3.7 RSS feeds of what you track
Optional, and part of Bower Plus. From Settings you can generate up to two RSS feeds, one of the TV shows you track and one of the movies, in the same format as a Plex watchlist, and give their addresses to other apps or a feed reader. Each address contains a random token and is the only credential involved: anyone who has the address can read that list (each title's name, its IMDb or TMDB identifier, its poster and the date you tracked it) and nothing else about you. Unlike a media-server address, the feed address is stored as it is, so Settings can show it to you again; you can generate a new one at any time, which stops the old one working immediately, or remove the feed altogether. On each feed we keep only when it was last read and how many times, so you can see it is working. We do not record who or what read it.
4. Why we use it, and our legal basis
Under the GDPR we need a lawful basis for each use. Ours are:
| Purpose | Legal basis |
|---|---|
| Creating and running your account; showing you your tracked titles, calendar, release dates and recommendations | Performance of a contract with you (Art. 6(1)(b)) |
| Keeping a tracked list for you before you have an account | Performance of a service you asked for (Art. 6(1)(b)), and our legitimate interest in letting people try Bower without signing up (Art. 6(1)(f)) |
| Recording what you watch, when you mark it yourself or connect your own media server | Performance of a service you asked for (Art. 6(1)(b)); you can stop it at any time |
| Publishing your profile page, and what you watched, to other people | Your choice, made in Settings and reversible at any time (Art. 6(1)(a)) |
| Service emails: password resets, changes to these terms, notices about your membership | Performance of a contract (Art. 6(1)(b)) |
| Marketing/newsletter email, if you opt in | Your consent (Art. 6(1)(a)), withdrawable at any time |
| Baseline anonymous, cookieless product analytics (see 3.4) | Our legitimate interests in understanding overall usage without identifying you (Art. 6(1)(f)) |
| Full identified analytics and session recording, once you accept | Your consent (Art. 6(1)(a)), withdrawable at any time |
| Answering your feedback and support messages, including sorting them by urgency | Our legitimate interests in running a responsive service (Art. 6(1)(f)) |
| Keeping the service secure, preventing abuse (including bot protection and sign-up rate limiting), fixing bugs | Our legitimate interests in running a functioning and secure service (Art. 6(1)(f)) |
We do not process special category data, and we ask you not to send us any. What you watch can say something about you, which is why watch history is collected only at your instruction and shared only at your instruction.
6. International transfers
Our infrastructure, including hosting and our database, is currently provided by Amazon Web Services in the United States. Our analytics provider, PostHog, processes data in the EU (Frankfurt). Where personal data is transferred outside the EEA, that transfer is covered by the European Commission's Standard Contractual Clauses incorporated into our agreement with the relevant provider, or, for a provider in the United Kingdom, by the Commission's adequacy decision for the UK. You can ask us for details of the safeguards in place.
7. How long we keep it
| Data | Retention |
|---|---|
| Account and tracking data, including watch history and votes | For as long as your account exists |
| Account and tracking data, after you delete your account in Settings | Removed from our database and from our identity provider immediately. Copies in our database backups age out within 7 days. |
| Tracked list kept without an account | Until you remove the items, or until it is moved onto an account you create. A list whose identifier your browser has forgotten can no longer be reached by anyone; we don't currently delete such lists on a schedule. |
| Media-server connection | Until you remove it in Settings or delete your account. Events still waiting to be matched to our catalogue are removed with it. |
| Bower Plus membership record | For as long as your account exists; it is deleted with the account. Paddle keeps its own record of your purchase and invoices under its own policy, for as long as tax law requires it to. |
| Web request logs | 14 days |
| Application logs (see 3.3) | Up to 2 years |
| Sign-up rate-limit counters (a hash of your IP address) | 1 hour |
| Session recordings (only if you've accepted full analytics) | 90 days |
| Analytics events | 12 months |
| Feedback reports | Kept as a record of the report and our response. If you delete your account, the report stays but your email address and the link to your account are removed from it. Screenshots are deleted after 12 months. |
| Email you send to one of our addresses | Kept as a record of the correspondence. The original message file is deleted after 12 months; a message our filters set aside as spam is deleted after 30 days. |
| Consent records (privacy policy acceptance, marketing opt-in) and the log of newsletters and notices sent to you, including whether an issue was opened or a link in it clicked | For as long as your account exists, as part of your account |
| Inactive free accounts | We may delete accounts with no sign-in for 24 months, after warning you by email first |
8. Your rights
If you are in the EEA or the UK, you have the right to:
- Access the personal data we hold about you
- Correct anything inaccurate
- Delete your data ("right to be forgotten")
- Export your data in a portable, machine-readable format
- Restrict or object to processing based on legitimate interests
- Withdraw consent at any time, without affecting processing that already happened
Access, export and deletion are self-service. At the foot of your Settings page, "Export your data" gives you a file containing everything we hold about your account (your profile, lists, votes, watch history, connections, the feedback you have sent us and a log of the newsletters and notices we have sent you, plus the account record held by our identity provider), and "Delete my account" removes all of it at once, after you confirm by typing your email address. Deletion is immediate and cannot be undone, so download first if you want a copy. Your country, language, time zone and every preference can be changed in Settings too.
If you track titles without an account, your list lives against an identifier in your own browser: untrack the items, or clear the site's data in your browser, and nobody can reach it again. For anything else (a request about an account you have already deleted, an objection, or a correction we don't offer as a control), email privacy@bower.tv or use our contact form and we will respond within one month.
If you are unhappy with how we have handled your data, you can complain to the Irish Data Protection Commission at dataprotection.ie, or to your own national supervisory authority. In the UK, that is the Information Commissioner's Office at ico.org.uk.
9. Security
Data is encrypted in transit (TLS) and at rest. Passwords are managed by Amazon Cognito and are never visible to us in plain text; signing out cancels your sign-in token on our side, so a copy of it cannot be reused. The address that links your media server to Bower is stored only as a one-way hash. Access to production systems is restricted and protected by multi-factor authentication. If a breach occurs that puts your rights at risk, we will notify the Data Protection Commission within 72 hours and tell you directly where required.
Bower is run by a very small team. We take security seriously, but no system is perfect — please report anything you find via our contact form or to privacy@bower.tv.
10. Children
Bower is not intended for children. You must be at least 16 to create an account — Ireland's digital age of consent. If we learn we hold data from a child below that age, we will delete it.
11. Changes to this policy
We will post any changes here and update the date at the top. If a change materially affects how we use your data, we will email you before it takes effect.
12. Contact
Email privacy@bower.tv, use our contact form, or write to us — a postal address is available on request from either.
Ben Hindmarch, trading as Bower, Ireland.
