ACCOUNT AND COMMUNITY

Privacy and security.

Runscars is designed to save your Oscar ballot without turning your personal data into part of the show.

ACCOUNTS

A familiar sign-in

Accounts are managed with Supabase Auth. You can confirm your email address or sign in with Google. New passwords must contain at least 12 characters and are never visible to Runscars.

Your email address is used to authenticate you. It is not published on your profile or included in shared cards.

CONTROL

You decide what is public

Profiles and rankings are private by default. Only a ballot published from a public profile can appear in Community and share its watch states.

Only the states of films included in that ranking are shown: watched, not watched or unmarked. Watch states outside public rankings are never exposed.

PROTECTION

Several safeguards

Secure cookies preserve your session and the server checks every action again. PostgreSQL Row Level Security prevents accounts from reading or changing another person's private profile, rankings or watch states. Email confirmation and rate limits also protect access.

YOUR DATA

Your account remains yours

You can export your data or delete your account and its content from your account page. We do not sell personal data or use APIs to post automatically on social media: sharing a ballot always begins with an explicit action from you.

COOKIES

Only what the service needs

Runscars uses essential cookies for authentication, security and your language choice. Vercel Web Analytics and Speed Insights measure aggregate usage and performance without adding advertising trackers.

PROCESSORS

Services we rely on

Supabase processes account and database data, Vercel hosts the application and Google processes data only when you choose Google sign-in. Their own privacy terms also apply to those services.

CONTACT

Questions and rights

For privacy questions or requests that cannot be completed from your account, email ortizserratosa@gmail.com.

Read the terms of use →