REVEL
TermsPrivacySupport
Your data

Privacy notice.

Last updated 27 September 2026

REVEL at watchrevel.com is operated under the trading name Caswell Labs in England, United Kingdom. We use your data to run your account and make film and TV recommendations. For privacy requests, contact [email protected]. This notice describes the service as currently built.

Operator and contact details

REVEL is operated in England, United Kingdom, under the trading name Caswell Labs. The individual operating as Caswell Labs is the controller of personal data processed by REVEL.

Legal name of sole trader: Bray Caswell.

Business/contact address:
Caswell Labs
30 Spencer Street
Northwich
CW8 1BP
United Kingdom

Email: [email protected].

What REVEL holds

We store your username, email address, a password hash, email verification state, and account and session records. Signup codes and password reset links are stored as hashes with expiry and use status. We store your optional display name and bio; title and actor ratings; optional review notes; watchlist; streaming service, language, subtitle, length, franchise and genre preferences; content exclusions; recommendation history, reasons and feedback; and a generated taste profile. Friend requests, friendships, Watch Together membership, invites and group picks are stored when you use those features.

For Premium, we store the entitlement and Stripe Checkout, customer and payment identifiers, payment status, amount and currency. REVEL does not store your full card number. Our media catalogue and cached search or availability responses are held in PostgreSQL; search terms may appear in the provider cache. For abuse prevention, we store a hash derived from the request address with a short rate limit window. The VPS, Cloudflare and providers may also process technical request and delivery logs.

Why we use it

Account, session and verification data lets us provide the service and secure sign in. Ratings, preferences, exclusions, history and feedback shape picks and prevent repeats. Friend and group data lets members coordinate Watch Together. Purchase records let us confirm and preserve Premium access, prevent duplicate purchases and handle payment support. Security logs and rate limits help prevent abuse. We rely on providing the service you request and legitimate security interests, and on legal obligations where we must retain payment records. Please contact us if you want more detail about the lawful basis for a particular use.

What other services receive

Streaming Availability API / Movie of the Night receives media search, title detail and region requests for search fallback or availability enrichment. Wikidata receives scheduled catalogue import queries, without your account details. TVmaze receives catalogue, cast and TV search queries. Open Cinema receives coordinates and screening filters only when cinema listings are requested. These requests use REVEL’s provider credentials; we do not send it your account password or email. Groq is an optional AI-assisted selector for recommendations. When available, REVEL sends Groq up to 30 already-filtered candidate titles, each with a REVEL media ID, film or TV type, title, a shortened synopsis, catalogue rating, genre names, runtime and franchise name. It also sends the requested pick count and limited taste signals: genre-affinity scores derived from ratings and feedback, preferred film or TV type, Safe or Wildcard setting, preferred franchises, and up to 12 liked titles with their title, type, rating and genres. REVEL asks Groq to select IDs from that shortlist, rejects unknown or duplicate IDs, and applies its exclusions before saving a pick. Groq cannot access the full catalogue database or add a title to it. We do not send Groq your username, email, payment details, password, session token or full recommendation history. If Groq is unavailable, REVEL uses deterministic catalogue ranking instead.

Resend receives your email address and the verification code or account link needed to send transactional messages. Stripe receives the email and account reference used for Checkout and handles payment details under its own terms. Cloudflare routes public traffic to the private REVEL origin. PostgreSQL on the VPS stores the account and product records. These providers may process data outside the UK; their own privacy terms and transfer arrangements also apply.

Friends and group visibility

Other users can find your username and optional display name or avatar through username search. Friends see your username, optional profile details and whether Premium is active when planning a group. Watch Together participants can see session names, member names, invitations and group recommendations. The group picker processes each active member’s ratings and preferences to make a shared pick; it does not display each person’s private ratings or password to the group.

Fonts and images

Your browser loads Google Fonts and poster, backdrop or service images from their external hosts. Those hosts receive your IP address and technical request information when the assets load. REVEL stores image URLs rather than copies of the image files.

Cookies and security

REVEL uses a secure, HttpOnly, SameSite session cookie to keep you signed in. The cookie contains a random session value; REVEL stores only its hash in PostgreSQL. It is needed for account features. We do not currently use advertising or analytics cookies, and the app does not store auth secrets in browser local storage. Browser, hosting and provider logs can contain technical data such as request time and IP address.

Retention and deletion

We keep account and preference data while the account is active, unless you ask for deletion or law requires a longer period. Session cookies and session records have an expiry; verification codes last 10 minutes and account links last one hour, though expired token records can remain until maintenance removes them. Rate limit entries are periodically trimmed. Provider cache entries are kept until refreshed or removed so REVEL can conserve its API quota. Payment records and records held by Stripe may need to be kept for accounting, disputes and legal obligations.

To request access, correction or account deletion, email [email protected] from your account email. We will verify the request, explain any records we must keep and arrange deletion of eligible account data. REVEL does not currently offer a self service deletion button. Deleting an account removes its linked ratings, preferences, watchlist, friend and session records from the live PostgreSQL account tables; provider and payment records may require separate handling.

Your rights

Depending on the circumstances, UK data protection law gives you rights to access, correct, erase, restrict or object to processing, and receive portable data. You can change some account and taste details in Settings. Contact us for other requests. You can complain to the UK Information Commissioner’s Office if you are unhappy with our response. See Support for contact help and Terms for purchase and service rules.

REVEL · watchrevel.com
HomeTermsPrivacySupport
[email protected]