What Lodge
knows about you.
Every field named on this page is a column that exists in the database. Where it says Lodge does not collect something, there is nowhere to put it.
This page describes the software accurately, but it has not been reviewed by a lawyer and is not yet a binding policy. Passages marked Pending legal review are decisions for a lawyer, and are left open rather than guessed. If you need a reviewed policy before you can proceed, write to contact@anantex.com and say so.
Two kinds of people
A host is a customer. They hold an account, upload material and decide who sees it.
A guest never signs up. They exist in Lodge because a host entered their name and email in order to invite them. Almost everything below is about guests, because that is the part people are right to ask about.
What a host gives us about a guest
- —Display name, email address, and optionally a company or production.
- —Nothing else. There is no enrichment step, no lookup against a data provider, and no field for anything further.
The host is the source of that information and the reason it is held. If you were invited to a screening and want to know why Lodge has your address, the answer is the person who invited you.
What Lodge records while you watch
- —A per-session watermark identifier, shown to you on your own screen, which ties one copy of the picture to one seat.
- —When you joined, when you left, and how many minutes you watched.
- —Playback telemetry every two seconds: position, drift from the room clock, observed bitrate, whether you are buffering, and your browser’s user-agent string.
- —Door key attempts, so a seat that is being guessed at can be cut off.
- —Whether each email Lodge sent you was accepted by the mail provider.
The telemetry exists so a host can see that the room is holding together — a guest stuck buffering is the failure the whole product is trying to avoid. It is not behavioural profiling and it is not retained as a profile: it belongs to a session, and it dies with it.
The device id is not a fingerprint
So that a browser you have already used does not have to ask for a key every time, Lodge stores a random identifier in that browser and compares a peppered hash of it on your next visit.
There is deliberately no canvas hashing, no font enumeration and no audio-context probing. Those techniques exist to recognise a person across sites they never agreed to be tracked on. Lodge has no use for them: it already knows who you are, because a host invited you by name.
The honest consequence is that clearing your site data costs you one extra six-digit key. That is the right trade.
Who can see it
- —The host who invited you sees your attendance, your watermark and your playback telemetry. That is the product.
- —Other guests see none of it, including whether you exist. That is enforced by row-level security in the database, not by hiding a panel in the interface — the credential your browser holds cannot ask the question.
- —Lodge staff can reach the database in order to operate the service. There is no access for any other purpose.
Processors we use
- —Vercel — hosting and content delivery. Serves the pages and records ordinary request logs.
- —Supabase — the Postgres database holding everything described above.
- —Resend — outbound email: invitations, door keys, reminders and closing notices.
- —Mux — video hosting and delivery, once configured. Until then no real film passes through Lodge at all.
Pending legal review · Each of these is a sub-processor and a customer contract will normally require them to be listed, with locations and a data processing agreement in place. This list is factually complete as of the date below; the contractual wrapper around it is not written.
The form on this site
The access-request form sends what you type to one mailbox. There is no list, no sequence, no analytics on it and no third party in the path. Your address is used to reply to you.
To blunt automated abuse the endpoint keeps a count of recent submissions per network address in memory for ten minutes. It is never written to disk and never associated with anything you typed.
Cookies and storage
- —One cookie that keeps you admitted to a screening after you present a key. It expires with the session.
- —One value in your browser’s local storage: the random device identifier described above.
- —No advertising cookies, no third-party analytics, no cross-site tracking of any kind.
How long it is kept
A session and its record persist so that a host can answer “who saw this?” later — which is frequently the reason they are using Lodge at all. Deleting a guest, a session or an organisation removes the dependent rows by design; the deletion paths are explicit in the schema rather than left to chance.
Pending legal review · A defined retention period, and whether the audit trail should survive a guest deletion request, are legal calls rather than engineering ones. The mechanism supports either answer.
The Balcony browser extension
What it reads. On netflix.com only: the title you’re watching (from the page address) and the video’s position and play/pause state. It reads nothing on any other site.
What it sends. That playback state is sent through Lodge’s room service to the other people in your watch room, so their players can follow. Title lookups go through Lodge’s server to TMDB to check availability in each person’s country. Your Netflix login, viewing history and payment details are never read or sent.
What it keeps. In your browser: your room code, display name, region and a short-lived settings cache. On our side, room messages exist only while the room is open. We keep no viewing history.
Sharing. We don’t sell this data or use it for advertising. Title availability comes from JustWatch via TMDB.
Removing it. Uninstalling the extension deletes everything it stored in your browser. Contact: contact@anantex.com.
Asking us about your data
Write to contact@anantex.com. If you are a guest, tell us which screening — Lodge will normally need to involve the host who invited you, since the record belongs to their account.
Pending legal review · Statutory access, correction, erasure and portability rights, the lawful basis for processing, international transfer terms, and the controller/processor split between Lodge and its host customers all need drafting.