Privacy Policy
Last updated: 22 July 2026
The short version
- RateTheThings works with no account at all. Used that way, your ratings never leave your browser and we hold nothing about you.
- An account is optional and only exists to enable cloud backup, friends, and shareable lists. Nothing else in the app requires one.
- We run no analytics, no ad networks, and no third-party trackers. We do not sell or share your data with anyone for advertising.
- Your list data is private by default. It only becomes visible to someone else if you explicitly publish a list or add a friend.
- You can delete your account and everything in it at any time. See Deleting your data.
Who we are
RateTheThings is a free, independently operated web app for rating and ranking things. This policy covers the website at ratethethings.com and the app at ratethethings.com/app.
Using RateTheThings without an account
This is the default. Your lists, items, ratings, notes, and images are stored in your own browser using IndexedDB. They are not transmitted to us, and we have no way to read them. Clearing your browser data deletes them permanently, which is why the app offers a one-tap JSON export you keep yourself.
The one exception is the catalog search feature, which contacts external databases even when you are logged out. See Catalog search.
If you create an account
Accounts are created by signing in with Google. We never see or store your Google password. When you sign in, we receive and store:
| Data | Why we hold it |
|---|---|
| Name | Shown as your display name to you and to friends you connect with. |
| Email address | Identifies your account so the same login always reaches the same data. |
| Profile picture | Shown as your avatar. We store the image URL from your provider, not a copy of the image. |
| Sign-in tokens from your provider | Required to complete and maintain the sign-in. Not used for anything else. |
| Session records | A session token, its expiry, plus the IP address and browser user-agent from sign-in. Keeps you signed in and lets us identify suspicious session activity. |
We request only basic profile and email from these providers. We do not request access to your contacts, posts, friends lists, photos, or anything else in your provider account.
Cloud backup
If you turn on cloud backup, the app uploads a snapshot of your app data (lists, items, ratings, rating history, notes, and any images you attached) to our storage, where it is associated with your account. It exists so you can restore your data on a new device or after clearing your browser.
- Backups are private to your account. No other user can request them.
- We keep your latest backup plus the five most recent previous versions, so a bad snapshot does not destroy a good one. Older versions are deleted automatically.
- We do not read, mine, or analyse the contents of your backups.
- You can turn on end-to-end encryption with a passphrase of your choosing. Backups are then encrypted on your device before upload, and our servers only ever store ciphertext we cannot read. The passphrase never leaves your device; if you lose it, we cannot recover an encrypted backup for you.
- Without that passphrase, backups are encrypted in transit (HTTPS) and at rest by our storage provider, which means we technically could access them. We do not, but you should know the difference.
Friends and comparing taste
Adding a friend is opt-in and works through an invite link you generate and send. Invite links expire after 7 days. If someone accepts, we store the fact that the two of you are connected.
To compare taste, the app uploads a compare profile: a reduced summary of your ratings used to compute overlap. Your friends can see your display name, avatar, and the parts of that profile the compare feature shows. They cannot see your backups, your other lists, or your email. Removing a friend stops the sharing.
Published lists
You can publish a single list to a public share link (ratethethings.com/p/…). This is strictly opt-in and off unless you choose it, per list.
- A published list is readable by anyone who has the link, without an account. Treat the link as public even though it is unguessable.
- We ask search engines not to index share pages, but a link can still be indexed or reshared if you post it somewhere public.
- A published snapshot contains only item names, ratings, and totals. Notes, custom fields, images, and rating history are never included, and published lists are not covered by backup end-to-end encryption, because anyone with the link must be able to read them.
- Unpublishing removes the list from our storage and breaks the link. You can also revoke every share link you have ever created at once from your account page. Copies others have already saved are outside our control.
Catalog search
When you search for a movie, game, or board game to add, your search text is sent to the relevant third-party database (TMDB, IGDB, or BoardGameGeek) through our server so we can return matches. Those services receive the search text and our server's request, not your identity or your account. This happens whether or not you are signed in. Their handling of that request is governed by their own privacy policies.
Cookies
We use one kind of cookie: a session cookie set when you sign in, so the server knows the request is yours. It is not used for tracking, profiling, or advertising, and it is not shared with anyone. There are no advertising cookies, no analytics cookies, and no third-party cookies. Signing out invalidates the session.
The app also uses your browser's local storage for your own data and preferences. That is not a cookie and never leaves your device.
Who else touches your data
We keep this list short on purpose.
- Cloudflare hosts the site, the API, the database, and backup storage. All account data and backups live on Cloudflare infrastructure.
- Google handles sign-in if you create an account. Google necessarily learns that you signed in to RateTheThings. It does not receive your ratings or list data.
- TMDB, IGDB, and BoardGameGeek receive catalog search text as described above.
We do not sell your personal data, and we do not share it with advertisers, data brokers, or analytics companies. If we are ever legally compelled to disclose data, we will comply with valid legal process.
How long we keep things
- Account record: until you delete your account.
- Backups: latest plus five previous versions, until replaced by newer ones or until you delete your account.
- Sessions: until they expire or you sign out.
- Friend invites: 7 days, then they expire.
- Published lists: until you unpublish or delete your account.
- No account: nothing to keep. Your data is on your device and stays there.
Deleting your data
Everything here is self-serve. You do not need to ask us, and we do not gatekeep it.
- Local data: delete lists in the app, or clear the site's data in your browser settings. If you never made an account, this is all of your data.
- Published lists: unpublish from the list's share settings in the app. This removes the snapshot from our storage and breaks the share link.
- Friends: removing a friend ends the connection and stops sharing your compare profile with them.
- Your whole account: use the delete-account control in the app's account settings. It erases your account record, every backup version, your compare profile, your friend connections, and your published lists. This is immediate and permanent, so export your data first if you want to keep it.
Your data is also exportable at any time as a JSON file from the app, with or without an account. Revoking RateTheThings' access from your Google account settings stops future sign-ins, but does not by itself delete data we already hold. Use the delete-account control for that.
Your rights
Depending on where you live (for example the EEA/UK under GDPR, or California under CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. RateTheThings is built so you can exercise those rights yourself, without asking permission: the app's export gives you a copy of your data, and the delete-account control erases it. See Deleting your data. Where we need a legal basis, ours is your consent (which you give by choosing to create an account) and our legitimate interest in operating and securing the service. EEA/UK users also have the right to complain to their local data protection authority.
Security
All traffic is encrypted with HTTPS. Backups are stored under per-account keys and every request for them is checked against your session. Backups are not end-to-end encrypted, as noted above. No service can promise perfect security, but the strongest protection here is structural: if you never create an account, we hold nothing to lose.
Children
RateTheThings is not directed at children under 13, and we do not knowingly collect personal data from them. An account created by a child can be removed with the delete-account control described in Deleting your data.
Where your data lives
Our infrastructure runs on Cloudflare's global network, so data may be processed on servers outside your country, including the United States. Cloudflare provides the safeguards for those transfers as our hosting provider.
Changes to this policy
If we change how we handle your data, we will update this page and the "last updated" date above. Material changes will be announced in the app. Continuing to use RateTheThings after a change means you accept the updated policy.