This Privacy Policy describes how Shortmox Agency (“we”, “us”) processes personal data in connection with Shortmox, a curated short-film discovery product built around embedded third-party video (primarily YouTube). It is meant to be plain-language and product-accurate. Where specialist rules apply (for example GDPR or KVKK), this policy works alongside them and does not replace them.
Who operates the service
Controller: Shortmox Agency. Address: [Postal Address], Istanbul, Turkey. For privacy-related requests: info@shortmox.com.
What we collect and store
We only describe categories that the product actually uses today or may reasonably use to run the service. We do not rely on this list to introduce new processing beyond what the product supports.
- Account data: information you provide to register and sign in (such as email address and password credentials stored in hashed form), and account identifiers such as a username where the product collects one.
- Email verification and security: data needed to verify your email address, reset your password, detect abuse, and protect accounts (including tokens, timestamps, and related technical metadata tied to those flows).
- Session and authentication data: cookies or similar technologies used to keep you signed in and to secure requests to the service.
- Preferences and settings: choices you save in product settings—such as interface or subtitle preferences, mature-content visibility preferences, newsletter or email-marketing consent flags, and similar preference fields exposed in the app.
- Activity on the service: when you are signed in, the product may store interactions such as titles you save, continue-watching or library state, likes, ratings, and comments you submit. Related metadata (for example timestamps and which title the interaction refers to) may be stored as needed to display the feature.
- Comment reports: when a signed-in member reports another member’s comment, we store the selected reason, any optional note you add, your account as the reporter, timestamps, and the association to the reported comment so operators can review the matter. Reports are used for moderation and safety, not for public display.
- Communications: messages you send through contact or support flows, including the content of your message and your contact details.
- Technical and operational data: standard web server and security information such as IP address, user agent, and request metadata; limited product analytics or diagnostics where used to keep the service reliable and to understand aggregate usage.
How we use personal data
- To create and maintain accounts, authenticate users, manage sessions, verify email addresses, and handle password resets.
- To provide features you ask for (watchlists, ratings, comments, recommendations informed by preferences or history where the product implements them).
- To respect your preferences, including mature-content settings and newsletter consent.
- To operate moderation and safety: reviewing, hiding, flagging, or removing comments or other interactions; investigating abuse; and restricting or ending access for accounts that violate rules or threaten the service.
- To respond to you, handle rights or legal requests, and meet legal obligations.
- To secure the platform, prevent fraud, debug issues, and improve stability.
Moderation and enforcement
Community features such as comments and ratings are subject to rules and technical limits. Operators may moderate content, remove or hide posts, and suspend, disable, or ban accounts when reasonably necessary for safety, legal compliance, or enforcement of our Terms. Processing for these purposes may include reviewing account and activity data.
Catalog signals, maturity, and related notices
Shortmox may display title-level information such as maturity labels, content notices, language or subtitle hints, and similar catalog metadata drawn from publishers, ingestion pipelines, or editorial work. Your own mature-content preference in Settings helps filter what we show you in the product. **None of this is a substitute for full age verification**, parental controls, or platform rules: when you play embedded YouTube videos or follow links to creator or channel pages, YouTube and the publisher apply their own restrictions and data practices.
Legal bases (where EU-style rules apply)
Depending on context, processing may rely on performance of a contract with you, legitimate interests (for example securing the service and understanding aggregate usage), consent where we ask for it (such as certain marketing or optional cookies), or legal obligation. This summary is not a jurisdiction-specific legal analysis.
Cookies, sessions, and similar technologies
We use cookies or similar technologies that are needed for authentication and session continuity, and may use additional technologies described in our Cookie Policy where applicable. You can control some non-essential cookies through browser settings or any in-product controls we provide. Where Settings offers it, you can also end other active sessions (for example “log out of all devices”), which clears server-side session validity for your account except as needed for security logging.
Newsletters and account-related email
If you opt in to a newsletter or similar promotional email, we process your address and consent records to send those messages and to show your choice in Settings. You can withdraw marketing consent through the controls we provide there. **Transactional email** (such as address verification, password reset, and important security or service notices) may still be sent when reasonably necessary to operate or protect your account, even if marketing opt-in is off.
Service providers and sharing
We may use infrastructure and communications providers (for example hosting, email delivery, logging, and error monitoring) to run Shortmox. Those providers process data on our instructions and for our purposes, not for their own independent marketing. We do not sell your personal data as a product line.
Third-party video, embeds, and outbound links
Playback relies on embedded players from third-party platforms (primarily YouTube). Those platforms may collect their own data when you load or interact with a player or leave our site for a channel or watch page. Their processing is governed by their own terms and privacy policies. Shortmox does not claim ownership of publisher video files and is not responsible for how third parties process data on their services.
International transfers
Where personal data is processed in countries other than your own, we take into account applicable safeguards where required (for example adequacy decisions or standard contractual clauses under EU law).
Retention
We keep personal data only as long as needed for the purposes above, including providing the service, meeting legal requirements, resolving disputes, and maintaining security backups in line with good practice.
Security
We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, or misuse. No online service can guarantee perfect security.
Your choices, access, and deletion
Depending on applicable law, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. Where the product offers in-app controls—such as deleting your account, adjusting preferences, or revoking other sessions—you can use them directly in Settings where available. You may also contact us at info@shortmox.com for privacy requests. We may need to verify your identity before acting on sensitive requests.
Children
Shortmox is not directed at children under 13, and we do not knowingly collect personal data from children under 13 as part of a child-directed service. Parents or guardians who believe a minor has provided data should contact us.
Updates to this policy
We may update this Privacy Policy as the product changes. When we do, we will adjust the “Last updated” date at the top of this page. Material changes may also be highlighted in-product where practical.
Contact
Privacy questions or requests: info@shortmox.com. You can also reach us through the Contact page linked in the site footer.