Scope
This page is about personal data on amo.watch, area.amo.watch, and app.amo.watch. It is not the Termini and it is not the Cookie list, but those pages complete it.
Amo accounts live on Area, in the same MariaDB as this WordPress site. WordPress users are bridged by email. The public catalog never puts your account into cacheable HTML.
Who holds the data
Amo is the controller for account, billing state, and app data described here. Privacy and deletion requests: [email protected] from the same address as the account. Ordinary support: [email protected].
What we collect
Only what we need to run Amo:
- Account: email, bcrypt password hash (cost 12), display name, role, email verification, trial and subscription dates, plan code. Google-linked accounts store a Google subject id and Google email. Facebook-linked accounts store a Facebook user id, email when granted, name, and avatar (see Terms → Facebook Login permissions). Telegram-linked accounts store a Telegram id, name, username, and photo. Social-only accounts may have no password until you create one.
- Session: an opaque session id in an HttpOnly cookie, CSRF token, IP, user agent, expiry. Production cookie domain is .amo.watch so the app sees the same login. Sessions last up to one year and slide forward while you keep using Area or the app. Sign-out revokes the row.
- Devices: paired TVs and pairing codes. The TV never receives your password. Scan is not authorize.
- Billing: WooCommerce orders (email, amounts, SKU, paid date) and Area order/payment rows. We do not store raw card numbers. Card data, if you pay by card, stays with the payment processor.
- App data bound to the account: profiles, avatars (JPEG/PNG/WebP ≤ 256 KB, magic-byte sniffed), bookmarks, timeline / watch progress, IPTV playlists you add, playback and notification prefs, reviews, reactions, notices.
- Optional CUB import: CUB email and a stored token so you can resync. The token is never returned to the browser. Unlink drops the token; Amo data stays.
- Security: login attempts, captcha challenges, security_events without raw secrets. Brute-force windows can lock an address.
- Support mail you send to support@ or security@.
- Catalog: TMDB metadata and artwork requested server-side. No TMDB secret in browser JavaScript.
- Public WordPress usage: Yandex Metrika (counter 112317402) records pages, clicks, and checkout goals after the page is idle. Session replay (Webvisor) is on marketing pages, not cart or checkout. Area and the app do not load Metrika.
What we do not do
- We do not sell your email or watch history.
- We do not publish watch history on amo.watch.
- We do not run advertising cookies, Google Analytics, Meta Pixel, or Hotjar. WordPress public pages load Yandex Metrika after the page is idle. Area and app.amo.watch do not.
- We do not put a TMDB API key in the browser.
- We do not use cub.best, tmdb.cub.best, or public CUB mirrors for identity.
Why we hold it
- To create the account, verify email, run the 21-day trial, and decide entitlement on the server, never in Lampa JavaScript.
- To take payment, issue receipts, stack paid time, and handle refunds.
- To pair TVs, keep profiles, resume playback, and sync bookmarks across official apps and compatible Lampa clients.
- To stop abuse: captcha, brute-force limits, review suspension, chargeback closure.
- To run the referral program: count clicks, unique visitors, and credit 35% + $1 on referred payments. The referrer sees the email of people who registered with their link.
- To answer you when you write to support or security.
- To see which public WordPress pages and checkout steps work (Yandex Metrika on amo.watch only).
Legal bases we rely on: performing the contract (account, playback, billing), legitimate interests (security, fraud, keeping the service up, understanding public WordPress usage), and consent where you choose Google, Facebook, or Telegram sign-in or a CUB import. You can unlink those providers or CUB on Area.
How long we keep it
The account stays while you use Amo and for a reasonable period after it expires, so you can sign in and renew. Sessions die when they expire or you sign out. Password-reset tokens last hours, not days. Captcha challenges last minutes. Orders and invoices stay as long as tax and chargeback rules require. Watch progress and bookmarks stay until you clear them or we delete the account after a deletion request.
You can edit name, email, password, profiles, IPTV, and Google / Facebook / Telegram links on Area account. A new email is used only after that inbox confirms it. Deletion of the whole account: write to security@ from that email.
Your rights
Where data-protection law applies (including GDPR-style rights), you can ask to access, correct, export, or delete your account data, or to object to some processing. Write to [email protected] from the account email. We may need to verify it is you. We reply within 30 days, sooner when we can.
You can also close Google, Facebook, or Telegram access, change the password, sign out everywhere by changing the password, and unlink CUB. Refunds of money are a separate track. See Refunds.
Children
Amo is not aimed at children under 16 as account holders. A Kids profile is a pin inside an adult account. Do not create an Area login for a child. 18+ stays behind a PIN and off Kids profiles.
How we protect it
Passwords are bcrypt 12. Session cookies are HttpOnly, Secure, SameSite=Lax. Mutating API calls need a CSRF token. Captcha and brute-force limits sit on public auth. Avatars are sniffed and size-capped; SVG and PHP uploads are rejected. App, Lampac, Area, and the database are not exposed on the public internet except through nginx. We still cannot promise a system is never attacked. Write to security@ if you find a hole.
Where the data sits
Production is a single VPS (mail.amo.watch). Cloudflare and Google, if you use them, process data in their regions. Yandex Metrika processes analytics in Yandex regions (including Russia). If you are in the EEA or UK, that is an international transfer. We keep it to what the product needs.
Changes
The date at the top is the current version. If we add a new processor that changes this page in a material way, we will update it here.
Contact
[email protected] for privacy, deletion, and a suspected breach. [email protected] for the product. Cookies: Cookie. Denaro: Rimborsi.