Courtesy translation: only the French version is legally binding.
Data & privacy
Everything that is stored, and nothing else
Snapline asks for no name, no email address and no date of birth — not even to open an account, which rests on a public username and four digits you choose. It uses no advertising tracker, no audience measurement and no third-party service. This page lists every piece of data stored, why it exists and how long it lasts.
Last updated: 22 September 2026 — the site is hosted by Cloudflare.
In one sentence
Only four features send anything to a server — the community rating average, the account, an error report when you send one, and a technical report when part of the code breaks. Without an account, your ticks and ratings are stored on this device; the account carries them from one device to another and opens friends, the duo and the group. Nothing is written and nothing is sent unless you have explicitly answered “Accept all”.
The two possible answers
On your first visit, a banner offers you two choices. They are not decorative: each really changes what the code is allowed to do. “Essentials only” has been removed: without an account, nothing is stored any more, and an account needs the server — no one was in between.
| Your answer | Stored on your device | Sent to a server |
|---|---|---|
| Accept all | Progress, ratings, favourites, profile | Yes: your ratings, linked to an anonymous identifier — and, if you create one, your account |
| Refuse | Nothing: everything lives in memory and disappears when the tab is closed | Nothing. No request is made |
Until you have answered, the site behaves as if you had refused: no writing, no network request. A profile can only be created and kept with an account, that is, after answering “Accept all”.
What is stored on your device
This information is stored in your browser’s local storage. It never leaves your device, cannot be read by any third party and is linked to no identity.
| Key | Content | Why |
|---|---|---|
consent:v1 | Your answer to the banner | Not asking you the question again on every visit |
watched:v1 | Titles ticked as watched | Your progress, with or without an account |
ratings:v1 | Your ratings | To show them again, with or without an account, and compute your statistics |
favorites:v1 | Your favourites, in the chosen order | Your personal ranking |
revoir:v1 | Titles you marked “rewatch” | Your list of titles to rewatch before the release |
skip:v1 | Titles you have set aside | To remove them from your journey: they no longer count in your percentage and are no longer suggested to you |
episodes:v1 | For a series in progress: the season and the last episode watched | Picking up where you left off |
vusle:v1 | The day you ticked each title | Show “Watched on…” on the title page; it follows your progress |
profile:v1 | Display name, emblem, colour, progress bar colour on your solo route, cached public username, internal technical identifier | Your local profile |
welcome:v1 | A simple flag | Not replaying the welcome screen |
tuto:v1 | A simple flag | Not replaying the short “How it works” guide |
langue:v1 | The language you chose in the language menu | Show Snapline in this language on your next visit. An interface preference: it is kept even without consent, like the welcome screen already seen, and is never sent to the server |
trad-…:v1 | The site’s sentences already translated by your browser, in the chosen language | Not translating them again on every visit. The translation is done by your browser, on your device: no text is sent to Snapline or to a translation service. Kept only if you answered “Accept all” |
routes:v1 | Which routes are expanded | Restoring the display where you left it |
view:v1 · stats:v1 | Grid or columns, and what the counters cover | Restoring the display you chose |
route:v1 | Route shown: solo or as a pair | A device preference: it does not leave this browser |
duo:watched:v1 · duo:skip:v1 · duo:couleur:v1 · duo:notes:v1 · salle:cache:v1 | A local copy of what the server has already answered: the progress kept as a pair (ticked and set-aside titles), the colour of its bar, your partner’s ratings and those of your teammates | Show the screen without waiting for the network. These are caches: the source is the server, and they are erased like the rest |
duo:sync:v1 | A simple flag: is copying the duo’s progress into your solo progress switched on? | A device preference, on by default, which you switch off under the route’s cog |
fini:v1 | The list of routes you have finished | Not replaying the end-of-route screen. A device preference: it is never sent to the server |
reglage:*:v1 · favvue:v1 · grpvue:v1 · rythme:v1 · marathon:v1 · roadto:v1 | Your display settings: larger text, stronger contrast, animations off, spoiler-free mode, the order of favourites, the order of a group’s members, your viewing pace, the length of a marathon evening and the film of your countdown | Device preferences: they do not leave this browser and are never sent to the server |
onglet:v1 · apres:v1 | The open screen, and a passing intention | Session storage: they die with the browser tab |
The display name is free and subject to no identity check. Nothing obliges you to use your real name, and the site recommends you don’t. As a profile is only created with an account, this display name is stored on the server next to your public username — it is what is shown to people who have accepted your friend request. ⚠️ Someone who sends you a request without yet being your friend sees only your public username.
And the translation offered by your browser? If you use its “Translate” menu (Chrome, Edge, Safari, Firefox), your browser handles it, under its own rules: Snapline does not trigger it and receives nothing from it.
Why your refusal, and the welcome screen already seen, are stored. If the site kept no trace of your “Refuse” answer, the banner would reappear on every page — precisely the pestering that refusing is meant to stop. Likewise, the chosen language and two flags record that the welcome screen and the short “How it works” guide have already been seen, so they are not shown again on every visit if you browse without an account. These four pieces of information — two keywords and two booleans, no personal data — are kept as strictly necessary storage, which requires no consent. Choosing “Refuse”, signing out or deleting your account immediately erases all the other keys.
What is sent to a server
Only if you answered “Accept all”: for the community rating average, and — if and only if you create an account — for that account.
The voting cookie
| Name | mcu_voter |
|---|---|
| Content | A random identifier, generated by the server. It is derived from no information about you |
| Purpose | To ensure “one person, one vote” and let you change your rating while you are not signed in: once signed in, your ratings are attached to your account and the cookie is no longer read |
| Running time | 1 year |
| Protection | HttpOnly, Secure, SameSite=Lax — inaccessible to JavaScript, not sent to third-party sites |
This cookie is neither an advertising tracker nor an audience measurement tool. It follows no browsing, keeps no history and is shared with no one.
Your ratings
When you rate a title, the pair title identifier / rating is linked to a voting identity: the cookie’s anonymous identifier if you are not signed in, an internal identifier of your account if you are — which gives you the same ratings on all your devices. The averages shown are computed from these votes. No rating is ever attached to an identifiable person.
Your IP address
The server uses your IP address to limit the number of writes per minute and stop a bot from skewing the averages. It is used as a mere counter, kept for 60 seconds, then deleted automatically. It is linked neither to your ratings, nor your cookie, nor any profile.
Legal basis: legitimate interest in protecting the integrity of the service (Article 6(1)(f) GDPR).
Importing a list from another site
The Progress menu lets you drop in a file exported from another service (Letterboxd, for example) to tick in one go the titles you have already watched. This file does not leave your device: it is read by your browser, and no request is sent — neither to this site nor to the original service. The site connects to no third-party account and asks for no password.
Only two things are kept from it, and they go into the progress data described above: the recognised titles and, if there is one, the viewing date. Everything else in the file — ratings, comments, links, titles outside the catalogue — is ignored and never kept. An import adds titles; it never removes any.
Report an error
Each title page has a Report an error section. If you send a report, the server stores four things only: the title concerned, the chosen category, the optional text you wrote (300 characters at most) and the date. Not your account, not your IP address, no cookie: the report is anonymous. It is read only by the site’s publisher, to correct the catalogue, and is shown nowhere. Only the last 500 reports are kept; older ones are erased automatically. Do not write personal information in it.
Sending is only possible after “Accept all”. Legal basis: legitimate interest in keeping an accurate catalogue (Article 6(1)(f) GDPR).
Site errors
When part of the site’s code breaks in your browser, the page sends a technical report so the publisher can fix it. This report does not say who you are, and it is deliberately sparse: the error message, the file name and line number where it broke, your browser family (Chrome, Firefox, Safari, Edge, Opera or “other”), and the page path — picked from the list of the site’s pages, never copied from your address bar.
Not your account, not your IP address, no cookie, not the full address you were viewing: the report is anonymous. The full address is deliberately left out, because it could contain the public username of a shared profile; your browser details are too, because they could single you out. Nothing you have written or ticked is included.
Your browser sends at most three reports per open page, and never the same one twice; only the last 300 are kept on the server, older ones being erased automatically. These reports are read only by the site’s publisher, to fix things, and are shown nowhere.
Sending is only possible after “Accept all”: if you refuse, no report is sent. Legal basis: legitimate interest in keeping the site working (Article 6(1)(f) GDPR).
The account, and its access code
No account is needed to browse the site, open a title page, search, tick a title or rate it. Without an account, your ticks and ratings are stored on this device and for it alone: they go nowhere, and another device will never see them.
The account becomes necessary for everything else: favourites, “Rewatch”, series tracking, importing a list, the display name, the emblem, statistics, friends, the duo and the group. It also lets you find your progress on another device, and be found by a friend. The site offers it when you make one of these moves, never on arrival.
What happens when you create an account. If this device already holds ticks or ratings, the site asks you what to do with them: carry them into the new account, or start from zero. The choice is yours, and it is never made for you.
What happens when you sign in. The site takes back everything that belongs to that account — progress, titles set aside, ratings, favourites, rewatches, series in progress, profile, duo, group, friends — and replaces what this device held without an account. The two never mix: at any given moment, it is the device or the account, not both. The ratings you gave without an account still count in the site’s averages: they were real ratings.
What happens when you sign out or delete your account. This device starts again from zero, progress and ratings included, and receives a new anonymous voting identifier. Here too, ratings already given stay in the averages.
Your access code is never stored as is. The server keeps only an irreversible fingerprint of it (PBKDF2-SHA256, 210,000 iterations, with a salt drawn at random for your account): it can check a code, never recover it. Five failed attempts lock the account for a quarter of an hour.
A nine-character recovery code is given to you when the account is created. It opens the account on its own, and lets you choose a new access code if you forget yours. It is stored exactly like the access code: an irreversible fingerprint, with its own salt. ⚠️ The site therefore cannot show it to you again: write it down when it is given to you. You can get a new one at any time from your account — the previous one then stops working.
| Data | Content | Why |
|---|---|---|
| Public username | The @username you choose | To be found by a friend, without giving anything else |
| Display name | The one from your profile | Shown instead of the username |
| Access code fingerprint | The irreversible result of a computation on your four digits, and the salt that goes with it | To check that it really is you signing in, without ever storing the code |
| Recovery code fingerprint | The irreversible result of a computation on the recovery code’s nine characters, and the salt that goes with it | To let you reopen your account if you forget your access code, without ever storing that code |
| Progress | Ticked titles and the day they were ticked, titles set aside, ratings, favourites, titles to rewatch, current episode of series, display name, emblem, colour | Finding it on another device. It is sent to your account as you click |
| Technical identifier | A random string, generated by the server | To link the above together. It is derived from no information about you |
No email address, no phone number, no real name: the site asks for none and stores none. A session cookie (mcu_acc, HttpOnly, Secure, SameSite=Lax, 1 year) keeps you signed in on this device. It is the only one the account sets.
Legal basis: your consent (Article 6(1)(a) GDPR), given twice — through the banner, then by creating the account itself.
You can delete your account at any time, from the Account tab, with one button: the account, its two codes, its saved progress and its public username are then erased from the server, permanently. What is on your device remains.
Suspension. If the Publisher suspends an account (see the Terms), two pieces of information are added to that account on the server: the fact that it is suspended and the date of the suspension. They are removed when the suspension is lifted, and erased with the account.
Friends, the duo and groups
These three features exist only with an account, and they are switched on only if you decide so: no one adds you without your consent, and nothing is published until you have accepted.
The public card. As soon as two people are friends, each sees of the other: their public username, display name, emblem, colour, progress percentage and top three favourites. Nothing else comes down — not your ratings, not the full list of what you have watched, not your codes. Someone who sends you a request without yet being your friend sees only your public username.
The duo invitation link. From the Propose a duo screen, the site gives you a link like …/?duo=your-username to send. It carries only your public username, nothing else; it is not secret, and anyone who receives it can pass it on. Opening it shows no data about you: only your username and a proposal. Answering it requires an account, and goes through the usual steps — a friend request if you are not friends yet, then the duo invitation. Nothing is formed unless both people want it.
The public profile, and its link. A setting in the Account section, on when the account is created (you can turn it off at any time), makes your profile viewable through a link like …/?p=your-username. While it is off, the site answers that link exactly as if the account did not exist. Once on, anyone who has the link — no account, no friendship needed — sees your public username, display name, emblem, colour, progress percentage and top three favourites. Nothing else: not your watched titles, ratings, dates, friends or group name. Switching the setting off closes access immediately. The link is not secret: it carries your public username, so anyone who receives it can pass it on.
The duo. Two friends can form a duo. This opens: a shared route, which holds only the ticked titles, the set-aside titles and the colour of its bar — both write it, and it disappears with the duo; a nickname each gives themselves in the duo, visible on both sides and subject to the same filter as the display name; and a ratings channel, readable by your partner alone, which shows them the rating you gave each title. Ending the duo erases all of this, on both sides.
The duo proposal, and how long it lasts. A proposal made to a friend is kept for seven days, then disappears on its own: after that it can no longer be accepted, and it leaves both screens. Forming a duo also makes every other proposal received lapse, on both sides — they could not succeed anyway. A lapsed proposal is reported to no one; it can be renewed.
What the duo copies into your solo progress. By default, a title ticked on the route kept as a pair also enters your personal progress, and it is an addition: nothing is ever removed from it. If you had set it aside on your side, it stops being set aside. Conversely, a title set aside as a pair never touches your personal progress. Unticking a title as a pair removes nothing on your side, and switching the copy off — under the route’s cog — does not undo what has already been added. This setting lives on this device and is not sent to the server. What has been copied belongs to you: it survives the end of the duo.
Groups. A group has a name, an emblem and a colour, seen by all its members — the name goes through the same filter as the display name. You can belong to only one group; accepting an invitation makes you leave the previous one, and its members are told. Each member sees the others’ public card. A room channel, readable by your teammates only, shows them the titles you have ticked and the ratings you gave them; it is erased as soon as you leave your last group, and it goes with your account.
⚠️ Sharing ticked titles is a setting, and you can switch it off. It is on when you join a group: that is what lets a group show who has watched what. Switching it off immediately erases the list your teammates saw — it is not kept in the meantime. Your ratings follow the same channel and the same setting.
Invitations. You join a group only on invitation from its leader. A received invitation carries the group’s name and the public username of the person inviting, and nothing else: until you have accepted, you see none of its members, and the group does not see you. The site keeps, on your side, the invitations you received, and on the other the list of usernames already invited, so as not to ask you twice. Accepting or refusing erases both; a refusal is notified to no one.
Notifications. What happened while you weren’t looking — a friend request, a friendship made, a duo or group invitation, someone joining or leaving — is stored in a queue of fifty lines at most, the fifty-first pushing out the oldest. A line carries a public username, a group name and a date. Never a technical identifier, never a code. Opening the bell erases nothing: it only marks what you have seen. The Clear button, at the top of the menu, erases the whole queue immediately — it undoes no friendship, no duo and no group: a notification tells of an event that has already happened.
| Data | Who sees it | Running time |
|---|---|---|
| Your friends, your requests received and sent | You alone | Until removed, or the account is deleted |
| Your public card | Your friends, your duo partner, your teammates | As long as the link exists |
| Your public profile (on when the account is created) | Anyone who has the link, without an account | As long as the setting is on |
| The duo: partner, nicknames, shared route, ratings channel | Your partner | Erased when it ends, on both sides |
| Groups: membership, name, room channel (your ticked titles and your ratings) | The group’s members | Until you leave, the group is dissolved, or as soon as you switch sharing off |
| Group invitations received and sent | You, and the person inviting | Until accepted, refused, or the group is dissolved |
| Duo proposals received and sent | You, and the person proposing | 7 days, or until answered — and a duo formed makes the others lapse |
| Notifications | You alone | 50 lines at most, the oldest pushed out; or immediately, with Clear |
All of this goes with the account. Delete my account erases your friendships, your duo and its shared route, your group memberships, your channels, your invitations and your notifications — including the traces that live on other people’s side and which, left behind, would show them a relationship that no longer exists. A group you led is dissolved: no one else could close it.
Legal basis: your consent (Article 6(1)(a) GDPR), given through the banner, by creating the account, then by each action that connects you with someone.
Processors
| Provider | Role | Data concerned |
|---|---|---|
| Cloudflare, Inc. | Site hosting, rating feature | Technical logs, IP address |
| Cloudflare D1 (Western Europe) | Ratings and accounts database | Anonymous voting identifier, ratings, temporary per-IP counter; and, if you create an account: public username, display name, access code fingerprint, recovery code fingerprint, progress; and, if you send any: your error reports, anonymous; and, if the code breaks: an anonymous technical report |
The host is an American company and may route requests through servers located outside the European Union; the database itself is located in Western Europe. Any transfers take place on the basis of the European Commission’s standard contractual clauses. As no identifying data is collected, the data that may be transferred is limited to a random identifier and technical data.
The site uses no other third-party service: no Google Analytics, no external delivery network, no remote font, no social sharing button. Fonts, images and code are served from this domain alone.
Retention periods
- Local data — until you erase it, answer “Refuse”, or clear your browser’s data.
- Voting cookie — 1 year, renewed on each active visit.
- Ratings on the server — kept as long as the average exists. You can remove a rating at any time: it is then deleted from the database.
- Account — as long as you keep it. Deleting it erases everything, immediately.
- Friends, duo, groups and their channels — as long as the link exists. Undoing it erases them, on both sides.
- Group invitations — until accepted, refused, or the group disappears. An invitation to a dissolved group is swept away on first reading.
- Duo proposals — 7 days, or until answered. After that the proposal can no longer be accepted and disappears from both screens; forming a duo makes the others lapse.
- Notifications — 50 lines at most per account; beyond that, the oldest are pushed out. The Clear button erases them all, immediately.
- Released public username — reserved for 30 days after a change, so that no one can impersonate you to your friends.
- Error reports — the last 500, all accounts combined; beyond that, the oldest are erased.
- IP counter — 60 seconds.
Your rights
You have the rights of access, rectification, erasure, objection, restriction and portability provided by the GDPR. Given how the site is designed, most are exercised directly, without going through anyone:
- Access and portability — your local data can be read in your browser’s storage; your profile shows everything that is stored.
- Rectification — edit your profile, ratings and favourites at any time.
- Erasure — choosing “Refuse” immediately purges all of the site’s data on your device. Removing a rating deletes it from the server. Clear, at the top of the bell menu, erases all your notifications. Delete my account, in the Account tab, erases the account, its codes, its saved progress, its public username, its friendships, its duo, its groups, its invitations and its notifications — permanently, and without having to write to anyone.
- Withdrawing consent — as easy as giving it, with the button below.
For any request about your data, write to the address given in the legal notice. You also have the right to lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL), the French data protection authority.
Minors
The site is aimed at a general audience and deliberately collects no data from minors. As no identifying data is requested from anyone, no special processing is needed.
Security
Exchanges with the server are encrypted (HTTPS). The voting cookie is inaccessible to JavaScript. No sensitive data within the meaning of Article 9 GDPR is collected. With no identifying data at all, a breach of the ratings database would identify no one.
Changes to this page
This policy may change with the site. In the event of a substantial change — in particular if new data were to be shared with other users — you would be informed on the site, and your consent asked again before any new collection.