Privacy
How Hive, Marquee and this site handle your data
TweakApps is run by one independent developer based in the United Arab Emirates. I am the "controller" of the data described here. I do not sell data, run advertising, or use analytics or tracking scripts on any of these sites. This page explains, in plain terms, what is collected when you use each tool, why, how long it is kept, and how to have it removed.
AioFin is not covered by this policy. AioFin is software you download and run on your own server. I never see any data from your installation. Whoever runs an AioFin server is responsible for the data it processes.
1. The website (tweakapps.uk)
The homepage and these legal pages are static. They set no cookies and load nothing from third parties: fonts are served from this domain. The web server keeps standard access logs (your IP address, browser identifier, the page requested and the time) for security and troubleshooting. Logs are deleted within 30 days. The site is fronted by a content delivery network for DNS and DDoS protection, which may see the same connection details; see the Cookies page for the one security cookie it can set.
2. Hive (hive.tweakapps.uk)
What Hive receives
- Your settings, inside your Hive link. The setup page builds a link that encodes the sources you enabled and any API key you typed in. Nothing is saved when you build the link; it lives in your AIOStreams configuration. Each time AIOStreams asks Hive for results, that link, the title or episode being requested, and the requesting IP address (usually your AIOStreams server, not your device) reach Hive.
- API keys you enter are used only to query the source they belong to, and only while answering a request. They are not stored in a database. Result caches are keyed by a short hash of your settings, not by the key itself.
- Result caches. Results for a title are cached for a limited time and can be reused for anyone with the same source settings. Caches contain release metadata, not personal data.
- Server logs as described above, deleted within 30 days.
Why
To answer the request you made (performance of the service you asked for). Logs are kept on the basis of legitimate interest in keeping the service secure and working.
3. Marquee (marquee.tweakapps.uk)
Marquee only works if you connect a watch-history service. When you do, Marquee stores:
- Access tokens for Trakt, Simkl or PublicMetaDB, encrypted at rest. Authorisation happens on the provider's own site; Marquee never sees your password.
- Your watch history and ratings as returned by that service: titles, dates, episode progress, ratings. This is the raw material for your lanes.
- Your feedback and settings: items you marked "Seen it" or "Not interested", lane preferences, the rating gate, and the profile id that forms your addon link.
Who else sees what
- TMDB receives the titles Marquee looks up to build recommendations (for example "films similar to X"). It does not receive your name, account or tokens. Marquee uses the TMDB API but is not endorsed or certified by TMDB.
- Trakt, Simkl, PublicMetaDB receive the API calls needed to read your history, under their own privacy policies and the permissions you granted.
- Nobody else. Tokens and history are not shared with any other party.
Why and on what basis
Connecting a service is your explicit consent to fetch and process that history to generate your lanes. Storing your feedback and settings is necessary to provide the service you set up. You can withdraw consent at any time by disconnecting the service or deleting your profile from the dashboard; this deletes the tokens and history held for that profile.
How long
Until you delete the profile or disconnect. Profiles that have not been refreshed for 12 months may be deleted. Backups are kept for up to 30 days after deletion.
The dashboard also keeps a sign-in token in your browser's local storage so you stay signed in on that device. It is not a tracking cookie and is not shared; see Cookies.
4. Where data is stored and international transfers
Hive and Marquee run on servers in the European Union (Germany). If you use them from the United Kingdom, the European Economic Area, the United Arab Emirates or anywhere else, your data is processed there. Because I am based in the UAE, some administration happens from the UAE. By connecting a service or generating a Hive link you agree to this. Standard protections apply: encrypted connections (TLS) for every request, encrypted tokens at rest, and access limited to me.
5. Your rights
Wherever you live, you can ask me to tell you what I hold about you, correct it, delete it, or stop processing it, and you can take your data with you. Most of this you can do yourself from the Marquee dashboard (disconnect, delete profile) or by simply not using a Hive link any more. For anything else, contact me and I will respond within 30 days.
If you are in the UK or the EEA, these rights come from the UK GDPR and the EU GDPR and you can complain to your supervisory authority (in the UK, the Information Commissioner's Office). If you are in the UAE, the same rights are provided under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, and processing of your data is based on your consent, which you can withdraw as described above.
6. Children
These tools are not directed at anyone under 16, and I do not knowingly hold data about children. If you believe a child has connected an account, contact me and it will be removed.
7. Security
All traffic uses TLS. Tokens are encrypted at rest with a key that is not stored alongside the data. There are no third-party scripts on the pages. No system is perfectly secure; if I become aware of a breach affecting your data I will tell you and, where required, the relevant authority.
8. Changes
If this policy changes in a way that matters, the "last updated" date above changes and the Marquee dashboard shows a notice on your next visit.
9. Contact
For privacy requests, removal requests or questions: open an issue or a discussion at github.com/tweakapps, or use the contact details on that profile. Requests are answered by the developer personally.