Consu

Consu Privacy Policy

Last updated: 20 August 2026

This Privacy Policy explains how Consu (“the app”, “we”, “our”) collects, uses, and protects personal data when you use the Consu mobile application.

1. Who we are (data controller)

Consu is developed and operated by:

Karl Holmes, sole developer (personal capacity). Based in Ireland. Contact: privacy@getconsu.com

For the purposes of the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018, Karl Holmes is the data controller for the personal data processed through Consu.

2. What we collect

Consu is designed to minimise data collection. The following is the full list of information we or our sub-processors handle:

2.1 Information you provide directly

2.2 Information created automatically

2.3 Information we do NOT collect

Purpose Legal basis (GDPR Article 6)
Provide the core app functionality (library, stats, social) Contract (6(1)(b))
Cloud backup and cross-device sync via Firebase Contract (6(1)(b))
Connect you with friends you choose to add Contract (6(1)(b))
Process one-time Pro upgrade payments Contract (6(1)(b))
Diagnose crashes and improve app stability Legitimate interest (6(1)(f))
Measure aggregate product usage to prioritise improvements Legitimate interest (6(1)(f))
Verify app integrity and prevent abuse and fraud Legitimate interest (6(1)(f))
Comply with legal obligations (e.g. tax records for sales) Legal obligation (6(1)(c))

We do not rely on consent as the primary legal basis for the processing above, because the processing is necessary to provide the service you requested or is based on our legitimate interests where the data is minimised and the impact on you is low. You can stop all processing at any time by deleting your account (see section 8). You can opt out of crash diagnostics and analytics under Settings → Diagnostics.

4. Third-party services and data transfers

Consu uses the following sub-processors. Each has their own privacy policy governing how they handle data.

4.1 Firebase (Google Ireland Limited / Google LLC)

Used for:

Data is processed in Google’s data centres. Consu’s Firestore instance is hosted in the europe-west2 (London, United Kingdom) region. Some core Firebase Authentication services are operated from Google’s global infrastructure, including servers in the United States; transfers outside the European Economic Area (EEA) are covered by the EU Standard Contractual Clauses in Google’s Data Processing Addendum.

Policy: https://firebase.google.com/support/privacy

4.1a Firebase Crashlytics (Google Ireland Limited / Google LLC)

Used to capture crash reports. Crashlytics receives:

Crashlytics does not receive your name, email, library contents, or friend codes. Crash data is retained by Google for up to 90 days and then deleted.

You can opt out of crash reporting under Settings → Diagnostics. When disabled, no further crash reports are sent.

Policy: https://firebase.google.com/support/privacy

4.1b Firebase Analytics (Google Ireland Limited / Google LLC)

Used to measure a minimal funnel of usage signals. Analytics receives:

Analytics does not receive your library contents, friend codes, display name, email, or any in-app messages. Analytics data is retained by Google for up to 14 months (Firebase’s default retention) and then deleted. You can opt out under Settings → Diagnostics.

Policy: https://firebase.google.com/support/privacy

4.2 Cloudflare Worker (Cloudflare, Inc.) — metadata proxy

Consu fetches most media metadata (descriptions, ratings, release dates) through a Cloudflare Worker that proxies requests to the third-party APIs listed in 4.3 below. The Worker:

Cloudflare, acting as an independent processor, may log request metadata in accordance with its own privacy policy.

Policy: https://www.cloudflare.com/privacypolicy/

4.3 Third-party metadata providers

Consu displays metadata sourced from the following services. Each receives only the query (e.g. a film title or ISBN) necessary to return a result. None of them receive your Firebase UID, email, or library contents. Section 4.3a explains which of them see your IP address and which do not.

Service Purpose Privacy policy
TMDB (The Movie Database) Film and TV metadata, posters https://www.themoviedb.org/privacy-policy
OMDB Supplementary film metadata (IMDb ratings, runtimes) https://www.omdbapi.com/
IGDB (Twitch / Amazon) Video-game metadata, cover art, screenshots, release dates and ratings — Consu’s primary games source https://www.twitch.tv/p/legal/privacy-notice/
RAWG Supplementary video-game metadata and screenshots https://rawg.io/privacy_policy
Steam (Valve) Video-game store data, and — only if you connect a Steam profile — that profile’s public game library, wishlist, playtimes and achievement counts https://store.steampowered.com/privacy_agreement/
Nintendo (Nintendo of Europe) Nintendo Switch game listings and pack art https://www.nintendo.co.uk/Privacy-policy/Privacy-policy-637785.html
Xbox (Microsoft) Xbox and Microsoft Store game listings and box art https://privacy.microsoft.com/privacystatement
PlayStation (Sony Interactive Entertainment) PlayStation Store game listings and cover art https://www.playstation.com/legal/privacy-policy/
Wikidata (Wikimedia Foundation) Awards, release dates, series order, and links between related works https://foundation.wikimedia.org/wiki/Policy:Privacy_policy
Wikipedia (Wikimedia Foundation) Author and artist biographies, critical reception https://foundation.wikimedia.org/wiki/Policy:Privacy_policy
Google Books Book metadata, covers https://policies.google.com/privacy
Open Library (Internet Archive) Supplementary book metadata, including whether a book can be borrowed free https://archive.org/about/terms
New York Times Books API Bestseller lists https://www.nytimes.com/privacy/privacy-policy
Deezer Music track and album metadata https://www.deezer.com/legal/personal-datas
MusicBrainz Open-source music database https://metabrainz.org/privacy
ListenBrainz Listening history, only if you connect a username https://metabrainz.org/privacy
Cover Art Archive Album artwork https://metabrainz.org/privacy
Apple iTunes Search API Music and album metadata, chart listings https://www.apple.com/legal/privacy/

4.3a How these requests reach the provider

There are two paths, and the difference matters for your IP address. Where a request is made directly by the app, that provider receives your device’s IP address and standard HTTP request metadata, in the same way as if you had opened a page in a browser.

4.3b Artwork and cover images

Posters, box art, album covers, cast photographs and service logos are loaded directly by your device from each provider’s image servers while you browse — they are not proxied. The image address itself is the only thing sent, but the provider’s image server does receive your device’s IP address and standard HTTP request metadata, exactly as any website’s images would.

The image servers involved belong to the same companies listed in 4.3 — principally TMDB, IGDB, RAWG, Steam, Nintendo, PlayStation, Xbox, Deezer, Apple, Google Books, Open Library and the Wikimedia Foundation (author and artist photographs come from Wikimedia Commons). Their privacy policies are the ones already linked in the table above.

The single exception is described in 4.2: when you generate a shareable image, that artwork is fetched through the Cloudflare Worker instead.

Some screens offer links to services we do not fetch data from — an Internet Archive page where a book can be borrowed free, a store page for a game, a YouTube trailer, or a music link-out page. Consu sends nothing to these services unless you tap the link, and nothing from them is embedded in the app. Once you tap, you are on that service’s own site and its privacy policy applies.

This product uses the TMDB API but is not endorsed or certified by TMDB. Similarly, Consu is not affiliated with or endorsed by any of the other metadata providers listed.

4.4 App-store billing (Apple / Google)

If you purchase Consu Pro, the payment is processed by the app store you bought it through — the Apple App Store (Apple Distribution International Ltd.) on iOS, or Google Play Billing (Google Ireland Limited) on Android. Consu never sees your card details.

Policies: https://www.apple.com/legal/privacy/ · https://policies.google.com/privacy

4.5 RevenueCat (RevenueCat, Inc.)

If you purchase Consu Pro, RevenueCat acts as the purchase-validation layer between the app store (Apple App Store or Google Play) and Consu. RevenueCat receives your anonymous Firebase UID (to associate the purchase with your account) and the standard purchase receipt from Apple or Google. RevenueCat does not receive your name, email, or library contents.

Policy: https://www.revenuecat.com/privacy

4.6 Google Fonts (Google Ireland Limited / Google LLC)

Consu’s typefaces are loaded from Google Fonts when the app opens, and again whenever you open the font picker or choose a different font under Settings → Appearance (opening the picker loads a sample of each font it offers). The stylesheet comes from fonts.googleapis.com and the font files themselves from fonts.gstatic.com. Google therefore receives your device’s IP address and standard HTTP request metadata, along with the name of the typeface being requested. It receives nothing else — no Firebase UID, no email, no library contents — and these requests set no cookie and load no Google script.

Policy: https://policies.google.com/privacy

5. Where your data is stored

6. How long we keep your data

7. Your rights under GDPR

If you are in the EEA, UK or Switzerland you have the right to:

To exercise any of these rights, email privacy@getconsu.com. We will respond within one month.

8. How to delete your data

In the app: scroll to the bottom of Settings, tap Delete My Account & All Data, type DELETE, confirm. This removes your profile, library, ratings, cloud backup and its restore points, friend connections, follow graph, feed activity, notifications, reactions, public profile, custom avatar and Firebase Auth account. For users who signed in with Apple, we also revoke the Apple sign-in token as part of deletion.

What may survive in someone else’s account, and how to have it removed. Some things you create are, by design, copies held by other people:

If anything of yours is still visible after deletion, or the in-app flow fails for any reason, email privacy@getconsu.com from the address linked to your account — or with your display name and friend code — and we will delete it manually.

9. Children

Consu is intended for users aged 13 and over and is not directed at children under 13. The age ratings shown on the Apple App Store and Google Play describe content suitability and are set through each store’s own questionnaire; the minimum age for using Consu is the one stated in our Terms of Service.

In countries where the digital age of consent under GDPR is higher than 13 (Ireland: 16; Germany: 16; Netherlands: 16; Italy: 14; France: 15; etc.), users under that age must have the consent of a parent or legal guardian to use Consu. If we become aware that we have collected personal data from a child below the applicable age without parental consent, we will delete it.

Parents: to request deletion of a child’s data, email privacy@getconsu.com.

10. Profile visibility — who else can see your data

Firebase Storage and Firestore enforce per-user security rules. What other people can see depends on the visibility setting you choose for your profile:

Where your profile is visible, it can include your display name and avatar, a snapshot of your library and ratings, your taste statistics, what you are currently reading, watching or playing, your follower and following counts, your estimated tracked time, the milestones you have earned and your current day-streak, and an approximate last-active time.

You can change this setting at any time in the app, and you can choose which sections are included. Seven parts of your profile have their own switch: top-rated items, what you are currently consuming, your backlog, your taste statistics and genres, your completed count, hours tracked, and achievements and streak.

Two levels of control, and the difference matters:

Either way the effect is real rather than cosmetic: hidden content is stripped before your profile is written out, so it never leaves your device.

Two things this setting does not cover. Setting your profile to Private does not retract them, so they are worth knowing about:

Separately, you can block another user at any time from their profile, and review or undo that under Settings → Blocked Users.

11. Security

No system is perfectly secure. If you believe your account has been compromised, contact privacy@getconsu.com and change your linked Google or Apple account password immediately.

12. Changes to this policy

We may update this Privacy Policy to reflect changes to the app, legal requirements, or sub-processors. The “Last updated” date at the top of this document indicates when the most recent change was made. Material changes will be announced in the app before they take effect.

13. Contact

For any privacy-related question, request or complaint:

Karl Holmes — privacy@getconsu.com