Privacy
Last updated: 31 July 2026
Showkeep is built around a simple idea: your film collection belongs on your device, not in an advertising profile.
Contact
For privacy questions or requests, email hey@showkeep.app.
Your library stays on your device
Showkeep stores your library using Apple’s SwiftData framework on your device. This can include film records, physical editions, wishlist items, ratings, tags, watch history, prices, purchase details, retailer links, notes, preferences and custom poster images.
Showkeep does not operate an account system or a cloud database for your library. It does not receive your collection, sell it or use it for advertising.
Film searches and metadata
When you search for or add a film, the app sends the search words or selected catalogue identifier to the Showkeep gateway. The gateway retrieves film metadata from TMDB and returns only the information the app needs. Showkeep does not send your library, notes, ratings, edition details or other collection data to the gateway.
The gateway processes:
- Search terms and TMDB catalogue identifiers.
- IP addresses and security signals needed to deliver and protect the service.
- A random installation identifier generated by the app and stored in Keychain for fair-use controls. It is not authentication and is not based on an account, Apple identifier or hardware identifier.
- Rate-limit counters used to apply fair-use controls.
This processing is necessary to provide the film lookup you request and reflects Showkeep’s legitimate interest in protecting the online service from misuse. The gateway is hosted by an infrastructure provider within the European Union.
Gateway storage and retention
Showkeep does not create an identifiable history of your searches. The application’s completion logs exclude request bodies, search terms, installation identifiers and client IP addresses. Infrastructure providers still process routine network information to deliver and protect requests.
Redis is used to reduce repeated requests to TMDB. Normalised search terms are hashed before being used as cache keys, so raw search words are not stored in those keys. Successful searches are fresh for seven days and retained for up to 30 days. Empty searches are retained for one hour. Film details are fresh for 30 days and retained for up to 180 days. Poster references are fresh for seven days and retained for up to 30 days. Missing film identifiers are retained for one hour. These caches are shared across installations and are not linked to a person or account.
Redis also holds rate counters and short-lived concurrency leases. The installation identifier and IP address are transformed with a secret keyed hash before they are used in those Redis keys. Minute counters, daily counters and abandoned leases expire automatically. The gateway does not keep an account or a permanent installation record.
Artwork
Posters and backdrops download directly from TMDB’s image CDN rather than passing through the Showkeep gateway. TMDB therefore receives routine network information such as your IP address when the app requests an image.
Downloaded artwork is cached on your device for performance. The cache is limited to approximately 250 MB and files older than 30 days are removed as the cache is maintained. TMDB handles its own request data under its privacy policy.
Backups, exports and Photos
You can choose a photo as custom artwork and export your library as a backup or CSV file. The system photo picker only gives Showkeep the image you select. Exported files are written to the location you choose and are not uploaded to Showkeep.
You control those exported copies. Deleting an item or uninstalling the app does not remove backup files that you saved elsewhere.
No tracking
The app contains no advertising SDKs, client analytics SDKs or third-party crash-reporting SDKs. Showkeep does not access the advertising identifier, track you across apps or websites or use gateway activity to build an identifiable search history.
The website
The Showkeep website sets no cookies. The site does not use third-party advertising or analytics scripts. Its fonts and promotional artwork are hosted with the site rather than requested from an advertising or analytics provider.
The site is hosted by Cloudflare. Cloudflare may process routine request information such as IP addresses, browser details and security signals to deliver and protect the site. Cloudflare may also apply security or protection features at the network edge. That processing is described in Cloudflare’s privacy policy.
Launch-list emails
If you join the launch list, Showkeep uses your email address to send occasional product and launch updates. You can unsubscribe at any time using the link included in each email.
Launch-list signups are processed by Buttondown. When you submit the form, Buttondown receives your email address and routine request information and processes it under its privacy policy.
Buttondown handles subscription confirmation, duplicate prevention and unsubscribe links. Showkeep uses the address only for occasional launch and product updates.
Support, privacy and legal emails
If you email Showkeep, the message includes your email address and the information you choose to provide. Showkeep uses iCloud Mail, provided by Apple, to receive and reply to support, privacy and legal messages. Apple describes its processing in its privacy policy.
Messages are kept while they are needed to answer your request and for necessary record-keeping. This processing is based on your request and Showkeep’s legitimate interest in providing support and keeping essential correspondence. You can ask for a message to be deleted where applicable.
Your choices and rights
You can edit or delete records in the app, export your library and remove all local app data by uninstalling Showkeep. Because Showkeep does not receive your library, it cannot inspect or recover that local data for you. The random installation identifier may remain in Keychain after uninstalling according to iOS behaviour, while short-lived Redis counters expire automatically.
For information held by Showkeep, you may ask for access, correction, deletion, restriction or a portable copy where applicable. You may also object to processing. Temporary gateway counters may not be reasonably linkable to you without additional information from your installation. Email hey@showkeep.app to make a request.
If you are in the European Union, you may complain to your local supervisory authority. In Ireland, that is the Data Protection Commission.
Changes
This page will be updated before Showkeep introduces a material change such as accounts, cloud storage, analytics or advertising.