Legal

Privacy

What SpoilerGate stores, why, and who can reach it.

Last updated: September 2026

SpoilerGate lets friends watch the same YouTube video on their own schedule while keeping takes spoiler-safe. This page describes the personal data we process to run watch rooms. We do not sell personal data or run advertising profiles on your activity.

Account

Google sign-in and guest sessions.

You can sign in with Google OAuth via Auth.js. We store the account identifiers Auth.js needs (such as your Google email, name, and profile image URL) so a session can resolve to your viewer profile. Alternatively, you may join a room as a guest by providing a display name; guest sessions are stored so your takes and progress can be attributed within that room.

Rooms & takes

Watch progress and pinned reactions.

When you create or join a watch room, we store the room metadata (YouTube video id, title, invite code), your playback progress, finish state, and the takes, replies, and reactions you post. Takes ahead of your progress are shown in blurred form until you reach that timestamp. Room data is visible to participants who have the invite link — it is not listed publicly or indexed in search.

YouTube

Embedded playback and metadata.

Videos play through YouTube's embedded player. We may fetch public video metadata (title, duration, chapters) via the YouTube Data API or oEmbed to set up the room. When you watch in the browser, YouTube may set its own cookies and collect usage data under Google's policies. SpoilerGate does not download or re-host YouTube video content.

Processors

Where the work runs.

The app runs on Vercel (Node.js serverless) with Neon Postgres for persistent data. Google is a subprocessor for OAuth sign-in; YouTube / Google is a subprocessor for embedded playback and optional metadata lookups. We do not use your watch activity to train third-party models.

Contact

Questions about this policy.

Reach the operator via the Impressum page for contact details.