WatchMatrix.TV

Privacy Policy

Last updated: 2026-07-27

Status. This is the current version, and it describes how WatchMatrix.TV actually works today, so you can rely on it as our statement of what we do. It is a first version that has not yet been reviewed by a lawyer. If that review changes anything, we will update this page and move the date above.

The short version

WatchMatrix.TV is free. There are no accounts and no sign-in. We do not run a database of users, and there is no user record of you anywhere on our side, because there is nowhere to put one. The only server code we run is a single search helper for the TV guide, described in section 5.

We run no analytics. No Google Analytics, no Meta pixel, no PostHog, no Mixpanel, no Sentry, no crash reporter, no advertising software, no tag manager, and no web fonts, on any surface.

We set no cookies of our own. Not one. We do not sell your personal information and we do not share it for cross-context behavioral advertising, as those terms are defined by California law. We never have.

Everything the product remembers about you is stored on your own device: your stream layout, your saved layouts, your watch list, your minutes-watched log, and a record of whether you agreed to watch-party sharing. Clearing your browser or app data erases all of it, and we keep no copy.

Three things are still true and worth saying plainly, because a policy that only lists the good parts is not an honest policy:

1. Who we are and how to contact us

WatchMatrix.TV is operated by Links.to LLC, from California, United States. WatchMatrix.TV is the name of the product. Links.to LLC is the company responsible for the personal information described in this policy.

Privacy contact: watch.matrix.tv@gmail.com. That mailbox is where anything about this policy should go.

We do not have a Data Protection Officer, and we are not required to have one. We will not name one we do not have.

2. What this policy covers

The website is served from more than one hostname, and every hostname serves the same build. That matters for one practical reason: browser storage is separate per hostname, so anything saved on one of our hostnames is not visible on another, and clearing one does not clear the others.

3. Notice at collection

This is the short, plain summary California asks for. The detail is in the sections that follow.

One exception to “it stays on your device”, said here rather than buried later. Your watch list and your minutes log stay on your device. What you are playing right now does not, if you start or join a watch party: your play or pause state, your position, and the identifier of the stream you are watching are sent to the other people in that party. That is the entire point of the feature, it happens only when you start it, and it is behind its own consent step. Sections 7.2 and 8 describe it in full.

We do not collect your name, email address, phone number, postal address, date of birth, payment details, government identifiers, precise geolocation, contacts, photos, biometric data, or any sensitive personal information. There is no form anywhere in the product that asks for any of them, no account system, and no payment code.

We do not use automated decision-making or profiling. There is no recommendation engine, no scoring and no user profile of any kind.

4. The website: what we receive and what we do not

What happens on an ordinary visit

When you open the site, the only party contacted is our hosting provider, Google Firebase Hosting, because it is the thing serving the page. No third-party script, font, pixel or frame loads on the homepage.

Google receives, as our host, what any web server receives: your IP address, your browser’s user agent, the address you requested, the referring page if your browser sends one, and the time. We do not add anything to that and we do not have a separate log of our own.

One detail worth knowing: your stream layout is encoded into the page address, so it can be shared or bookmarked. If you open a shared layout link, that first request carries the list of streams in the address, and therefore into the hosting request log. While the app is running, layout changes are written into the address bar without contacting the server. The layout is also in your browser history, like any other address.

What we do not do

Google Cast

Casting currently uses your browser’s own built-in casting support, and our page loads no Google Cast software. If we ever enable the full Google Cast software, your browser will load a script from Google and this policy will be updated at the same time.

5. The TV guide and its search box

The TV guide is currently hidden from the site’s menus, but the page and its search helper are still deployed and still work if you have a direct link or an old bookmark. So it is described here as a live feature, because for some people it is one.

Opening the guideloads catalog data from our own site, and then loads poster images directly from the content delivery network of our catalog data provider, Movie of the Night. Loading an image from someone else’s server tells that server your IP address, your user agent, and which image you asked for. That happens as soon as the guide page opens, before you click anything. We receive nothing from it.

Typing in the guide’s search box is the one place in the whole product where text you typed reaches a server we control. After you have typed at least three characters, and after a short pause, the text is sent to our own small search function. That function:

Separately, and unavoidably, the search text is part of the request address, so it also appears in standard Google Cloud request logs alongside the IP address that sent it. If you would rather no server ever saw what you searched for, do not use the guide’s search box. Browsing the guide without searching does not send your search text anywhere, though it does load posters as described above.

“Watch on” linksopen that service’s own website in a new tab. No premium service is ever embedded. Once you are on their site, their privacy policy applies.

6. Third-party video, and the line between us and them

The product’s whole job is to arrange other companies’ official video players side by side. It is worth being precise about who receives what.

What we do:we build the platform’s own official embed address and put it in a frame on the page. That is the entire mechanism.

What they do:everything inside that frame is the platform’s own code running on the platform’s own site. When it loads, they receive your IP address and user agent, they know which video you opened, and they can set their own cookies and use their own storage under their own domain. If you are signed in to them, they can connect the view to your account. That is their processing under their privacy policy, not ours, and none of it comes back to us.

The platforms whose players the website can load:

Two honest notes:

One technical note for completeness. Our embed page, which is the wrapper each tile loads, posts the current playback position and paused state to whatever page is framing it, without restricting the destination. It is designed to be framed by our own app and our own mobile app. The practical consequence is that if some other website chose to frame our embed address, that website would receive the playback position of the video it had itself chosen to load. No title, no identifier and nothing about you is included.

7. Watch parties, the phone remote, and Matrix View

These three features connect two or more devices directly to each other. They are the only features that send your playback state off your device, and they only run when you start them. They are not the only place anything about your viewing goes off your device: opening the TV guide loads poster images from our catalog provider, and its search box sends the text you type. Section 5 covers those.

7.1 The connection service is not ours

To connect two devices directly, something has to introduce them first. The product uses PeerJS, and it uses PeerJS’s free public service, because we have not set up our own. Concretely:

Two consequences you should know about:

We have no contract with the PeerJS project, no agreement about what they log, and no ability to tell you how long they keep anything. It is a free public service.

7.2 What a watch party sends

To the other people in your party, and to nobody else:

No video is sent in a watch party.Everyone plays their own copy from the platform’s own player. This is structural rather than a promise: nothing in the party channel carries video, a guest never broadcasts to the room at all because it holds one connection and that connection goes to the host, and the host only ever sends the message types listed above.

Shared control: another person in the party can pause or move what you are watching.A party runs in one of two modes and the host chooses which. In “Host controls”, which is the default, only the host drives playback. In “Everyone controls”, a guest who pauses, resumes or scrubs their own player sends that as a request to the host, the host applies it to their own player, and the host’s new position is then broadcast to everyone. The practical effect is that in that mode anyone in the party, including a stranger you gave the link to, can pause or move the position of what is playing on your screen. The mode itself is sent to everyone in the party and shown in the party bar, so you can always see which one you are in, and leaving the party ends it immediately. Nothing else can be reached this way: the party channel carries only the message types listed above, and there is no message that adds, removes or opens a stream.

Nothing from a party is saved. Chat, names, reactions and poll results exist only in memory and are gone when you leave or close the tab. The one thing written to your device is your consent record, described in section 8.

7.3 The phone remote

Pairing your phone as a remote connects your two devices over the same public introduction service. Over that connection travel commands (play, pause, mute, volume, add or remove a stream, shuffle, fullscreen) and a snapshot of your current grid, including each tile’s label and platform. Both devices are yours. The pairing secret is carried in the part of the link after the #, which browsers do not send to any server.

7.4 Matrix View does send video

“Matrix View” streams a picture of your own WatchMatrix.TV tab to a second screen you have paired.

So: watch parties never send video, and Matrix View does. If you have read the older version of our privacy page that said “no video is ever transmitted,” that sentence was about watch parties and did not account for this feature. This version corrects it.

8. The watch list, your viewing history, and the federal video privacy law

United States federal law, the Video Privacy Protection Act, treats records of what a person watched as especially sensitive. We take that seriously in the design, not just in the wording.

What is recorded, and where it lives

The watch list holds the titles you mark, the service, whether it is a film or a series, season and episode, how far into it you got, whether you are watching or finished, and when you last updated it.

The stats log is coarser: for each day, which platform and how many minutes. It records the platform, not the title.

Both live on your own device and nowhere else: in browser storage on the website (and the desktop and TV surfaces that reuse the same build), in app storage in the mobile app, and in extension storage in the Matrix TV extension. The exact keys are listed in section 13 and in our Cookies and storage policy.

None of it is sent anywhere

This is not a promise about our intentions, it is a property of the code. The module that manages watch records performs no network operations at all. Each surface’s storage layer writes to local storage and nothing else. There is no sync service, no cloud backup, and no account to sync to. Moving your list to another device means exporting a file and importing it yourself.

On the website and the mobile app, nothing is added to your watch list automatically. Entries are created only when you mark something.

The one place viewing information does leave your device

A watch party tells the other people in the party what you are watching right now, because that is the entire point of a watch party. This is a disclosure of viewing information, and it is why the feature is behind its own consent step rather than buried in the terms of use.

How consent is given

The first time you host or join a party, a standalone dialog appears and asks whether you want to share your playback state and the current title with the people in that party. It is its own dialog, deliberately not a checkbox inside the terms. Nothing connects until you agree. Your answer is stored on your device. After two years it is treated as stale and you are asked again.

How consent is withdrawn

An honest limitation.Today the withdrawal button lives on the party screen. If you agreed once, left, and now want to withdraw without going back to a party, your options are to open the party screen and use the button there, or to clear the site’s stored data. There is no general settings page with a consent switch on any surface.

What we cannot do

Because your consent record is stored only on your device and never sent to us, we have no record that you consented and no record that you withdrew. That is the honest consequence of a design with no server. We cannot look up, confirm, or produce your consent history, because we do not have it.

9. The Matrix Browser desktop app

This app is not currently available for download and no installer is served. It is described here so the description is ready, and because some people installed an earlier build before the download was paused.

If you run it:

10. The mobile app

Not currently in any app store.

Everything it saves stays on the device, in the app’s own storage: your current layout, saved layouts, your watch list, your stats log, website tiles you pinned, saved link lists, the ambient display toggle, your party consent record, and a marker recording that the app asked you once to rate it. Website addresses you pin as tiles are deliberately excluded from share links, saved layouts and cast payloads.

Other things worth knowing:

11. The browser extensions

Neither extension is published to any store.

“Matrix” (window tiler) asks for one permission, the ability to arrange windows, and no permission to read any website. It stores nothing.

“Matrix TV” works on Netflix and Disney+ only, and on nothing else. Those two are its entire permitted list.

12. The TV app

Not published.The webOS TV app is a redirect: it sends the TV’s browser to a page on our website. Everything in section 4 then applies to the TV.

13. What is stored on your device, and how to clear it

None of the stored items below is ever transmitted to us. One of them deserves a footnote rather than a blanket claim: your layout also lives in the page address, and a page address does reach our host’s request log, as section 4 explains. The stored copy is not what travels; the address is.

Website

There is no session storage and no browser database anywhere in the product.

Clearing it:

Mobile app

Ten storage keys; the full list is in our Cookies and storage policy. The Settings screen offers export and import of your watch list, and the stats screen offers a clear control. There is no single “erase everything” button inside the app today. Deleting the app removes all of it, and on Android you can also clear app data from the system settings.

Extensions

Removing the extension removes its storage. Switching a site off stops it reading anything.

Desktop app

Deleting the app’s data folder removes the three files listed in section 9 along with the browser sessions for the sites you signed in to.

14. Cookies and similar technologies

We set no cookies. What we use instead is your browser’s own local storage, listed in section 13. Nothing in it is an identifier, we send none of it anywhere, and we give no third party access to it. We will not go further than that, because there is one thing we cannot promise: when you add a controllable Twitch stream, Twitch’s player-control script is loaded into our own page rather than into a frame, and code running in our page can technically read our page’s storage. It is the only third-party code that ever runs in our page, we have no reason to think it reads anything, and we are not in a position to tell you it could not. The items themselves are either your own settings or content you created.

Third-party players set their own cookies and use their own storageon their own domains, and we cannot prevent that without breaking the players. If you want to limit it, your browser’s third-party cookie controls, or not adding streams from a given platform, are the effective options.

There is no cookie consent banner on the site, which is consistent with there being no cookies of ours to consent to. Whether the European rules on storing information on a user’s device require a consent step for the third-party players is a question for counsel. Our Cookies and storage policy covers all of this in detail.

15. How long anything is kept

On your device: until you delete it. Two items have an age rule inside the app rather than an expiry date: the resume layout is ignored after 7 days, and the party consent record is treated as stale after 2 years, which asks you again. In both cases the stored value itself stays until you clear it.

Our search helper:the per-address rate-limit counters exist only in the server’s memory and are lost when the instance is recycled. Search results are cached for one hour with no user identifier attached.

Server logs:our hosting provider and our cloud platform keep standard request logs, which include IP addresses and, for guide searches, the search text in the request address. These are the platform’s logs, kept for the platform’s retention period.

We do not have a retention schedule of our own, because we do not hold any records of our own.

16. Security

We would rather describe this accurately than impressively.

We do not run a formal vulnerability-disclosure programme. If you find a security problem, the contact address in section 1 reaches us and we would rather hear about it.

Because we hold no contact details for anyone, we could not notify you directly about a security incident even if one occurred. We would post a notice on the website.

17. Children

WatchMatrix.TV is a general-audience tool and is not directed to children. It has no child-oriented content, characters, activities or advertising. Because it can display unfiltered live content from other platforms, it is intended for people aged 17 and older.

We do not knowingly collect personal information from children under 13. There is no account system, no form and no analytics through which a child could give us any. If you believe a child has provided personal information through this service, contact us at watch.matrix.tv@gmail.comand we will investigate and delete anything we find, though in almost every case the honest answer will be that there is nothing on our side to delete, and that the information is on the child’s own device where it can be cleared as described in section 13.

There is currently no age check anywhere in the product. The statement above is our intention, not an enforced control. Our Children’s Privacy statement covers this in more detail.

18. California privacy notices

The operator is in California. The following notices are provided because they are useful and honest, regardless of whether the thresholds that make them mandatory are met. We do not claim to be a “business” as California’s consumer privacy law defines that term, and we do not claim compliance with it.

Notice at collection

See section 3. It lists every category we handle, why, and how long it is kept.

Sale and sharing

We do not sell your personal information. We do not share it for cross-context behavioral advertising. We have not done either in the preceding twelve months, and we have never done either. There is no advertising or analytics code in any part of the product, no advertising network is contacted, no identifier is created for you, and nothing is transferred to anyone for money or for anything else of value.

Because there is nothing to opt out of, we do not publish a “Do Not Sell or Share My Personal Information” link. Publishing one would imply we sell or share, and would advertise a request process we have no need to operate. If that ever changes, the link will appear and this policy will say so.

Your rights, and what they mean when we hold nothing

California residents have the right to know what personal information is collected and how it is used, to delete it, to correct it, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be treated differently for exercising any of these.

Here is the plain truth about what those rights come to here:

How to contact us about any of this: email watch.matrix.tv@gmail.com. We are being deliberately plain here: we do not operate a rights-request portal, an identity-verification process, or an authorized-agent workflow, because a service with no accounts and no user records has nothing to verify you against. We will answer questions honestly at that address. We will not pretend to run a process we do not run.

Do Not Track and Global Privacy Control

California law requires us to tell you how we respond to these signals.

We do not currently detect or respond to Do Not Track or Global Privacy Control signals. There is no code anywhere in the product that reads either one. The reason is that they exist to stop tracking across websites over time, and we do not do that at all: we run no analytics, set no cookies, create no identifier, and sell or share nothing. There is nothing for such a signal to switch off.

We also have to tell you this: third parties can observe you when their player loads. When you add a YouTube, Twitch, Kick, Rumble or X stream, that platform’s player runs in your browser and may collect information about your activity, on their sites and potentially over time, under their own policies. We do not control that and we do not receive it. How each of them treats a Do Not Track or Global Privacy Control signal is up to them.

Shine the Light (California Civil Code section 1798.83)

We do not disclose personal information to third parties for their own direct marketing purposes, so there is nothing to request under this law. If you would like that confirmed in writing, email us.

Complaint contact (California Civil Code section 1789.3)

Users of this service are entitled to the following notice. To file a complaint about this service, or to receive further information, contact us at watch.matrix.tv@gmail.com. You may also contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs, in writing or by telephone, at the address and telephone number published by the Department of Consumer Affairs. The service is free of charge, so the price disclosure that section 1789.3 also requires does not apply.

19. Other US states

Several other states now have consumer privacy laws with rights similar to California’s. Whether any of them applies to us depends on thresholds we almost certainly do not meet and, in the two states that have no threshold, on small-business exemptions we appear to qualify for.

Rather than argue about that, here is the substance: we do not sell personal data, do not process it for targeted advertising, and do not profile anyone. Those are the three things those laws are mainly concerned with. As with California, requests to know, delete or correct come down to the same answer: there is no record of you on our side, and section 13 tells you how to erase what is on your device. Write to us with any question.

Some states also require us to describe an appeal process if we refuse a request. We do not have a formal appeals process, because we do not have a request process to refuse anything through. If you are not satisfied with an answer from us, you can contact your state’s Attorney General.

20. People outside the United States

The service is available worldwide, but it is offered from the United States and is not aimed at any particular country outside it. The site is in English only, takes no payment in any currency, and runs no advertising anywhere.

If you use the service from outside the United States, the ordinary web requests described in this policy reach servers in the United States and elsewhere, as chosen by our hosting provider.

If European or UK data protection law does apply to us, then, for the small amount of server-side processing that exists (IP addresses in hosting logs and in our search helper’s rate limiter), our basis would be our legitimate interest in serving the site securely and preventing abuse. You would have the rights to access, correct, erase, restrict, port and object, and the right to complain to your national data protection authority. In practice, for the reasons in section 18, most of those rights resolve to “we hold nothing keyed to you, and here is how to clear what is on your device.”

We have not appointed a representative in the EU or the UK, and we have not appointed a Data Protection Officer.

21. Changes to this policy

If this policy changes, we will change the date at the top of it and publish the new version on the website.

Because we do not hold contact details for anyone, we cannot notify you directly. There is no mailing list and no account to email. If a change is significant, we will say so on the site itself for a period after it takes effect.

22. Contact

Privacy questions, and anything else about this policy: watch.matrix.tv@gmail.com.

← Back to WatchMatrix.TV