Privacy Policy

Last updated: September 1, 2026

Who operates Critics Room

Critics Room is owned and operated by Critics Room, the verified business publisher of the Critics Room plugin. This policy applies to criticsroom.com, the Critics Room MCP server, and the Critics Room experiences in ChatGPT, Codex, Claude, and other compatible clients.

The short version

We store the account information needed to sign you in and the reviews, drafts, and review-writing messages you choose to save. We use that data to provide the service, secure it, and respond to support requests. We do not sell personal data, serve ads, or use your reviews or messages to train AI models. Reviews are public by default only after the posting flow discloses that visibility; you can choose private instead.

Personal data we collect

  • Account and profile data. Depending on how you sign in, this can include your email address, display name, profile photo URL, authentication-provider user ID, and a Critics Room user ID. Google and X provide this information when you choose their sign-in buttons. Firebase Authentication processes email/password sign-in; Critics Room does not store your plaintext password.
  • Review content. Movie or show title, rating, headline, summary, review text, tags, visibility, and related movie metadata. Public reviews, your display name, and your profile photo can appear on public review, profile, movie, feed, sitemap, and social-preview pages. Private reviews are available only to your account and an AI client you authorize to act for that account.
  • Review-writing data. If you use a conversational review workflow, we receive the task-specific messages that the connected client sends to our save-message tool, along with a conversation ID. We do not receive unrelated chats from that client.
  • Connection and security data. We process OAuth client metadata, authorization codes, access tokens, refresh-token hashes, revocation records, request time, route, response status, latency, client surface, and an opaque internal user ID. We do not write raw prompts, review text, passwords, access tokens, or refresh tokens to operational logs.
  • Support data. If you contact us, we receive the email address and information you include in the message.

How we use personal data

  • Authenticate you and keep your connection scoped to your account.
  • Create, retrieve, sort, update, publish, make private, or delete reviews when you request it.
  • Save and resume a review-writing workflow you choose to persist.
  • Prevent abuse, investigate errors, maintain security, and keep the service reliable.
  • Answer support, privacy, access, and deletion requests.
  • Comply with legal obligations and enforce our Terms of Service.

Who receives data

We disclose data only as needed to provide the service, at your direction, or when required by law. Recipient categories are:

  • Google Firebase and Google Cloud for authentication, hosting, database storage, and 30-day operational logs.
  • OpenAI, Anthropic, or another client provider you choose when that client sends a tool request or receives the result for your authorized Critics Room account. Their handling is governed by the provider and account you use.
  • Google or X when you choose that provider to sign in.
  • TMDB for movie and TV metadata. We send search terms such as a title and year, not your account information or review text. Critics Room uses the TMDB API but is not endorsed or certified by TMDB.
  • The public for reviews and profile fields you publish with public visibility.
  • Authorities or professional advisers when reasonably necessary to comply with law or protect rights and security.

Critics Room does not run advertising trackers or third-party session-recording scripts on criticsroom.com.

Retention

  • Account, profile, review, and saved review-conversation data remain while your account is active, unless you delete the content or request account deletion.
  • Deleting a review permanently deletes its linked saved review conversation and messages. Account-deletion requests are completed within 30 days.
  • Temporary prepared-review drafts expire automatically after 24 hours.
  • OAuth authorization codes expire after 10 minutes, access tokens after 7 days, and refresh-token records after 30 days without use. A successful refresh can extend the refresh record for another 30 days. Disconnecting revokes access sooner.
  • Operational application and security logs are retained for 30 days.
  • We may retain a minimal record when required by law, to resolve a dispute, or to enforce our agreements, and will delete or de-identify it when that need ends.

Your choices and controls

  • Choose public or private visibility before posting and change it later.
  • Edit or permanently delete any review from Critics Room or an authorized client.
  • Disconnect the plugin to revoke its current OAuth grant.
  • Request a copy, correction, or deletion of your account data by emailing contact@criticsroom.com. We may need to verify that the request belongs to the account holder.

Security and international processing

We use access controls, encrypted HTTPS connections, scoped OAuth tokens, and server-side authorization checks. No system is perfectly secure. Critics Room and its service providers may process data in the United States and other countries where they operate, subject to applicable law and provider safeguards.

Children

Critics Room is not directed to children under 13, and we do not knowingly collect personal data from children under 13. Contact us if you believe a child has provided data so we can investigate and delete it.

Contact

Privacy questions and requests: contact@criticsroom.com. You can also use our support page.