Naar inhoud

Privacy Policy

Last updated: August 2026

At KinoLoom, privacy is not a promise but an architecture. A VPN says “we don't log” — KinoLoom cannot log, because nothing reaches us in the first place. This is verifiable: open your browser's network tab and you'll see that no personal data is sent to our servers.

What we do NOT collect

No account, no email address, no password. No tracking cookies. No third-party analytics, advertising, or fingerprinting scripts. No server-side profile of your viewing behavior.

What stays on your own device

Your preferences, likes, watch history, saved videos, and searches are stored exclusively and locally in your browser (IndexedDB/localStorage). This data never leaves your device and is not visible or retrievable by us. Personalization is computed entirely within your own browser.

What does briefly pass through our server

To fetch search results we send your search term to our serverless function (in the request body, not in the URL). We do not link it to any identity and we do not retain it. For playback, your browser loads video segments and thumbnails directly from the sources (CDNs) — using your own IP address, not ours; we are not in between and therefore cannot see what you watch. For abuse prevention we use a temporary, non-traceable hash (which rotates daily) purely for rate limiting; no IP address is stored.

Reporting content

A report contains only the reported item and the reason — no personal data about the reporter.

Erasing your data

Because no server-side copy exists, a single tap on “Erase all my data” (in Settings) is a complete deletion. That is your right to erasure under the GDPR, exercised instantly — there is nothing left on our end.

Encrypted backup

Because your profile lives only on this device, it disappears if the browser clears its storage or you switch phones. Settings offers an encrypted backup: a file you download and keep yourself. It is encrypted with AES-GCM-256 under a key derived from a generated six-word phrase (PBKDF2-HMAC-SHA-256, 600,000 iterations). We never see the file, the phrase, or the key — there is no upload and no account.

Two things we would rather say plainly than bury. First: losing the phrase means losing the backup, permanently and by design — we cannot reset it, because we do not have it. Your current on-device profile is untouched either way. Second: the encryption protects the file if someone else gets hold of it. It cannot protect you against a weak phrase you chose yourself (which is why we generate one) or against a compromised copy of this website, since we are the ones serving the JavaScript that holds the key. That is the honest limit of browser-side encryption.

Age

The service is intended exclusively for adults (18+) and is not intended for minors.

Contact and exercising your rights

The “Erase all my data” button in Settings is the fastest and most complete route — there is no server-side copy for us to delete. For anything the button cannot do (a question about the rate-limiting hash, an objection, or any other GDPR request), write to info@kinoloom.com. Operator and place-of-business details are published on our contact page.