Privacy Policy
Zyrk for iPhone. Last updated 18 September 2026.
- No accounts, no ads, no selling of data. The app is free.
- Your suggestion history, ratings and seen marks stay on your device.
- Anonymous usage statistics and crash reports go to Firebase (Google) — only if you agreed to it. You can turn it off at any time: History → ⋯ → Share Usage Data.
- To show titles, overviews and where to watch a film, the app talks to TMDB.
Who is responsible
Zyrk is an independent app made by Oleksii Huralnyk (Ukraine). In GDPR terms I am the data controller for what is described below.
Privacy questions: hello@zyrk.dev.
What stays on your device only
Everything that makes the app useful is stored locally and never sent anywhere:
- the films the ball has already shown, and when;
- your Good / Nope ratings and seen marks;
- the country you picked for streaming availability;
- your choice about usage statistics;
- a cache of titles, overviews and production countries fetched from TMDB.
This lives in the app's own storage on your iPhone. It disappears when you delete the app, and the “Start Over” button erases the history, ratings and marks. If you back up your device, it may end up in that backup — that is Apple's backup, and I have no access to it.
Usage statistics
The app uses Google Analytics for Firebase to understand whether the core idea works: how often the ball hands out a film, how many of those get marked as good, whether people find where to watch them. Collection only starts after you agree to it on first launch.
These events are sent: a film was shown, the list ran out, a film was rated, a film was marked seen, the details screen was opened, the history was filtered, the history was reset, streaming options finished loading, a provider was tapped, a JustWatch search was opened, IMDb was opened, the country was changed, and a screen was viewed.
Each event carries: the film's rank in the list and its TMDB id, its title, year, genre and TMDB rating, how the draw started (shake or tap), how long the shake lasted, how many films have been shown so far, the selected country, the streaming service name and offer type, and the screen name. Two user properties are stored as well: a rough bucket for how many films you have been shown (for example “6-20”) and your selected country.
Firebase adds technical details to every event: a random app-installation identifier, device model, iOS and app version, language, an approximate region derived from the IP address, and the time of the event.
What is not there: your name, email, precise location, contacts, or advertising identifier (IDFA). The app shows no ads, does not track you across other apps or websites, never asks for tracking permission, and has ad personalisation switched off in its configuration. The installation identifier is reset when you delete the app.
Crash reports
If the app crashes, Firebase Crashlytics sends a report: where in the code it happened, the device model, iOS and app version, memory state and the time. It exists so the bug can be fixed. It contains none of your viewing history. The same “Share Usage Data” switch turns these reports on and off.
Requests to TMDB
All film data comes from TMDB: the catalogue built into the app is compiled from TMDB and refreshed with every new version, and the app asks separately for localised titles and overviews, production countries, and the services carrying a film. When you open a film, the app asks TMDB about that film, passing the language and the selected country. TMDB, like any website, sees the IP address of the request. The app sends no identifiers of yours, and TMDB has no way of knowing whose screen the film is on. Responses are cached on the device for no longer than six months, as TMDB's terms require. TMDB's own privacy policy applies to them.
This product uses the TMDB API but is not endorsed or certified by TMDB.
Links out
Streaming provider buttons, the JustWatch search and IMDb links open in your browser. From there, those sites' privacy policies apply — I have no control over them.
Legal basis, retention and transfers
The legal basis for statistics and crash reports is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with the “Share Usage Data” switch; sending stops immediately.
Events are kept in Google Analytics according to the project's retention setting — by default two months for event-level data, while aggregated reports live longer. Crashlytics keeps crash reports for up to 90 days.
Google processes this data on its servers, including in the United States, under the European Commission's standard contractual clauses. See Firebase's privacy documentation for details.
Your rights
You have the right to access your data, correct or delete it, restrict or object to its processing, and to data portability, as well as the right to lodge a complaint with a data protection authority.
Note that the statistics are anonymous and tied only to a random installation identifier, so I cannot pick you out of them. The fastest way to stop and remove everything is to turn the switch off and delete the app. If you need more than that, write to hello@zyrk.dev and I will do whatever is technically possible.
Children
The app is not directed at children under 13 and does not knowingly collect their data.
Changes
If this policy changes, the updated version appears on this page with a new date. Anything substantial will also be explained in the app's release notes.