Privacy Policy — ReelSync

Last updated: August 27, 2026 • Official Chrome Web Store Disclosure for rs.tmott.dev

ReelSync is a browser extension that keeps video playback in sync between friends and provides a shared text chat. This policy describes what the extension collects, where it goes, and how long it stays.

1. What the Extension Stores and Shares

In your browser only (never transmitted):

  • Your chosen display name
  • A random per-install session id
  • Your Google profile (name, email, picture) when you sign in
  • Cached Google Drive file ids
  • The list of sites you have enabled sync on
  • The last position of the last 50 videos you watched in a room, so a new room can offer to resume there

Sent to the operator's Firebase Realtime Database while you are in a room:

  • Playback state: Whether the video is playing, current timestamp position, playback rate, and a media identifier (e.g. YouTube video id or Drive file checksum). This is how sync works.
  • Presence: Your display name and session id, so room members can see who is in the room, plus your current offset from the host (milliseconds) and the identifier of the video you have open, so the room can show who is in sync and who is on a different video.
  • Chat messages: The text and reactions you send within the watch-party chat, with your display name.
  • Shared media pointer: When someone picks a Drive video or shares a page URL, that file's name, size, checksum, or the URL is stored for the room.

Sent when you sign in with Google:

  • Your Google name, email address, and profile picture are stored under your account so friends can find you by email and see your name.
  • Your Google email address is indexed so that friends can send you requests by entering it.
  • Friend relationships, friend requests, watch invitations, and your block list.

2. Film Companion (Public Sources)

When you identify the movie in the Film tab, the extension sends only the title (and year) you typed to public reference services to fetch facts: Wikipedia and Wikiquote (no account or key), and TMDB if you added your own API key in Settings. Poster images are fetched only from TMDB or Wikimedia; the extension never fetches an arbitrary URL another member wrote into the room.

Nothing identifying about you is sent — only the search query. Results (credits, article sections, quotes, poster artwork) are cached on your computer for a week. Subtitles you load and text you import stay on your computer. In a room, the identified film, your notes and reactions, the quiz, and ratings are stored with the room so members see them. No AI or generative service is used.

3. Google Drive Integration & Limited Use

If you use the Drive player, the extension requests read-only access to Google Drive (drive.readonly). It uses this scope solely to:

  • List your video files so you can choose one;
  • Find your own copy of a file a friend chose, by name and checksum;
  • Stream the video you choose directly from Google Drive to your browser;
  • Look for a subtitle file with the same name.

The video itself is never uploaded, copied, or shared. Only the file's name, size, and checksum are shared with the room so that other members can locate their own copies. The extension never modifies or deletes anything in your Drive.

Google API Limited Use Disclosure: ReelSync's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. Data Retention

  • Rooms: Playback state, presence, chat, and media pointers are automatically deleted when the last member leaves. Rooms abandoned without leaving are cleaned up after 12 hours of inactivity.
  • Account Data: Account profiles, email indexes, friends, requests, invites, and block lists persist until you delete them. Signing out removes your local session.
  • OAuth Tokens: Authentication tokens are managed securely by Chrome identity and are immediately revoked and cleared when you sign out.

5. Who Can See Your Data

Anyone in the same room can see your display name, playback state, offset, video identifier, and chat messages. Anyone signed in with Google can look up whether an email address is registered (this is how friend requests work). Your profile (name, picture) and online status are visible only to you, your friends, and people with a pending friend request between you. Only you can read your friends, requests, invites, and block list; database security rules enforce this. A room's host can lock it and remove members; a removed member's account is barred from that room.

Zero Trackers: The extension has no analytics trackers, no third-party advertisements, and does not sell any user information. The only servers communicated with are Google (Firebase, Google Sign-In, Google Drive) and public reference endpoints (Wikipedia, TMDB).

6. Operator & Data Controller

The extension connects to the Firebase project configured by whoever set it up. That person is the data controller for the data listed above. For inquiries regarding ReelSync, visit rs.tmott.dev or contact tyler@tmott.dev.