Privacy policy
Aldebaran Privacy Policy
Last updated: September 2, 2026
Aldebaran is an app for iPhone and iPad running iOS or iPadOS 26 or later. This document describes what data the app handles, where it is stored, and which external services are involved.
1. Scope and accounts
Aldebaran lets you discover movies and TV shows, keep a personal library, track progress by season and episode, receive release alerts, and optionally sync with iCloud and with a Trakt account. Aldebaran does not create a first-party account or maintain a user profile on its own server. The app is free, has no purchases or advertising, and has no social features.
Neither iCloud nor Trakt is required to use local features. Any external service you choose to use applies its own privacy policy.
2. Data stored on the device
Your library, progress, lists, personal notes, settings, and the cache needed to operate Aldebaran are stored locally with SwiftData. The app can be browsed offline with information already downloaded.
If you connect Trakt, the access and refresh tokens, along with the basic Trakt profile information used by the app, are stored in the device Keychain. The operating system protects access to that storage.
3. Optional iCloud sync
When enabled in Settings → Sync, your library, progress, and lists are synchronized across your devices through CloudKit, in the private database of your iCloud account. That data is accessible only to you and to Apple under the Apple Privacy Policy; the Aldebaran developer cannot read it and operates no servers holding user data.
To keep devices up to date, the app uses CloudKit silent notifications that show nothing to the user. Sync can be turned off at any time; data already uploaded is managed from the device's iCloud settings.
4. TMDB catalogue and streaming availability
Aldebaran uses TMDB to retrieve its movie and TV catalogue, metadata, and current availability, and Trakt public calendars to locate candidate titles for platform updates in your country. This product uses the TMDB API but is not endorsed or certified by TMDB. The app keeps a local cache of responses to display content and reduce repeated requests.
These requests first pass through the Aldebaran Cloudflare Worker, which adds the technical credentials of each service and forwards only the required route, search text, language, configured country, selected platforms, and title identifiers. The app also sends the Worker a random installation identifier for rate limiting; this UUID is not forwarded to the providers. None of these messages includes your library, progress, notes, or Trakt account.
The Worker may temporarily cache catalogue responses on Cloudflare and store the first and last detection for each title, country, and platform in D1. Those observations contain no user data. Handling of associated technical data is governed by the privacy policies of TMDB, Trakt, and Cloudflare.
5. Optional Trakt connection
When you connect a Trakt account, Aldebaran can retrieve and sync the profile, history, progress, and personal lists needed for the features you enable in Settings → Sync. Synced actions change the data held in that Trakt account.
Content stored by Trakt, its retention, and the controls available in the account are governed by the Trakt Privacy Policy. You can continue using Aldebaran locally without connecting Trakt.
6. Cloudflare Worker
Authorization starts on the Trakt website. After approval, Aldebaran receives a code through the app callback and uses a Cloudflare Worker to exchange it for Trakt credentials. Aldebaran never asks for your Trakt password inside the app.
The Worker acts as an intermediary for the catalogue, streaming availability, and Trakt token exchange, refresh, and revocation. Its code does not store or log OAuth request bodies, codes, tokens, searches, or the installation identifier. That random UUID is generated and stored by the app on the device; it is not an account and does not identify a person by itself.
The Worker has Cloudflare observability (Workers Logs) enabled. Cloudflare collects invocation logs and operational metadata about requests and responses—such as the route, query parameters, status code, timestamp, and network data—according to the account's configuration and retention period. These logs are used solely to diagnose errors and prevent abuse, are not combined with any other data, and are not shared with third parties. Cloudflare describes its handling of this information in the Cloudflare Privacy Policy.
7. Notifications
Aldebaran can alert you to new episodes of the shows you follow and to releases you are waiting for. These are local notifications scheduled by the app on the device itself from catalogue dates; your library is not sent to any server to generate them. Permission is requested only when you enable the corresponding setting and can be withdrawn at any time in the system Settings.
8. On-device translation
Catalogue overviews, titles, and genres are translated into your language with Apple's Translation framework, which runs on the device itself. Aldebaran does not send text to any first- or third-party translation service. The system may ask to download a language the first time; Apple describes that technology's data handling on its Translation privacy page.
9. Sharing and the "Open in Aldebaran" extension
When you share a title, the app generates a card on the device with the title's information and any personal note you choose to include, and hands it to the system share sheet. Aldebaran never posts anything on its own and requires no social account.
The share extension receives the URL of a web page (for example, from TMDB) to add the title to your library. Only that URL is processed; the rest of the page content and your browsing history are not accessed.
10. Analytics, advertising, and tracking
Aldebaran embeds no third-party SDKs, whether for advertising or behavioural analytics, and does not track you across apps or websites. TMDB, Trakt, Apple, and Cloudflare may handle technical data under their own policies when the app uses their services.
11. Choices and data deletion
- You can use the local library without signing in to Trakt or enabling iCloud.
- iCloud sync and Trakt sync are enabled and disabled independently in Settings → Sync.
- When you disconnect Trakt, Aldebaran revokes the authorization if a network connection is available; if Trakt or the network rejects the revocation, it retains the local session so it can retry.
- Data held in the Trakt account is managed through Trakt and remains subject to its controls and policy.
- Deleting the app removes local data and the associated Keychain items; iCloud data can be deleted from Settings → iCloud → Manage Storage on the device.
12. Children
Aldebaran is not directed at children under 13 and does not knowingly collect personal data from them. The catalogue excludes content flagged as adult by the providers.
13. Third-party services
The official policies for the services used are:
- TMDB, for catalogue, metadata, and availability by platform.
- Trakt, for calendars, optional account connection, and sync.
- Cloudflare, for the catalogue and OAuth Worker and its infrastructure logs.
- Apple, for iCloud/CloudKit, notifications, and Translation.
14. Controller, changes, and contact
The data controller is the independent developer of Aldebaran. Privacy enquiries and data-rights requests can be sent to jcpdev2030@gmail.com. Technical issues can be reported by the same email or in the public Aldebaran issue tracker; do not post personal data, OAuth codes, tokens, or screenshots that expose them.
The policy will be reviewed when the app's data flows, providers, or features change. The date of the last update appears at the top of this document.