Entertainment & Streaming
Everything you play is logged and turned into a guess at your tastes, and that profile is traded both ways: your interests go out to advertisers, demographic data is bought back in. Almost no policy says how long it is kept.
The read at a glance
They hold a taste profile built from everything you have watched.
A leak exposes what you watch and listen to, which implies a great deal about you.
Viewing and subscription history is kept for years; profiles linger until you object.
A sign-up needs payment; ID is rare outside age checks.
Industry profile reviewed 23 August 2026. Also machine-readable via the free API.
If it leaks
What you watch is treated as sensitive enough that US law puts a price on disclosing it. A leak turns a viewing history into something a stranger can read back to you.
What repeats in the policies
Behaviour becomes a profile
Every show you open, song you play or event you attend is logged. From that history, policies build what they call inferences: your age, your interests, and preferences you never entered. Nobody asked you for any of it.
The profile is traded both ways
Your interests and identifiers go out to advertising partners, and demographic data is bought back in to sharpen who the service thinks you are. Ad-supported plans say so outright. Where the service belongs to a larger group, the profile also travels to the other companies in it, sometimes for their own purposes.
Kept for as long as they judge useful
Most policies give no figure for how long your profile lives. They keep it as long as they judge a purpose needs it, and hold it longer wherever a law merely permits it, not only where one requires it. Where a number does appear it runs long: ticketing accounts can keep your purchase and attendance history for seven years after your last use.
What a company here typically holds
Worked out from the industry, not from any one company. What you actually handed over is yours to record.
What this can reveal about you
Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.
Political views Possible
Viewing choices can imply leanings.
Sexual orientation Possible
What you watch can reveal orientation.
What lawfully stays after you leave
Two kinds of hold. Law sets it: a statute makes them keep it. They set it: a ground the company grants itself.
Tax and accounting records Law sets it about 6 years
Tax and company law makes them keep billing and payment records.
Online-safety and child-protection reports Law sets it 1 year for content, 5 for the report reference
A legal duty to preserve child-safety reports, which overrides an erasure request for that data.
Records tied to a live or potential dispute They set it the limitation period of the claim
They can keep records to defend a live or possible legal claim.
Who wants this data
In the US, the law covering video records prices one wrongly disclosed viewing record at 2,500 dollars. Streaming and ticketing services also buy demographic and interest data from ad partners to sharpen the profiles they hold. One ticketing platform was fined by a regulator after a security failure exposed payment data for millions.
Sold or shared Likely
Viewing habits are strong targeting and recommendation data.
AI training Moderate
What you watch trains recommendation models.
Even anonymised, this can still be you
In 2008 researchers re-identified people in a streaming service's released "anonymous" ratings dataset by matching viewing patterns to public reviews (Narayanan and Shmatikov, 2008).
Name, date of birth, postcode Typical
Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).
Payment patterns Typical
Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).
Browsing fingerprint Typical
Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).
The studies Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)
The wording that does the work
Clauses that recur across this industry, and what each one actually permits.
“to provide and improve our services”
The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.
The move An objection tells them to use your data to run the service and nothing more.
“we do not sell your personal information”
Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.
The move Use the do-not-sell switch where there is one, and put an objection in writing as well.
“service providers, partners, and affiliates”
This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.
The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.
“aggregated or de-identified information”
Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.
The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.
“retained as long as necessary, or as required by law”
They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.
The move Which reasons apply to you, and how long each runs, is a request of its own.
“you grant us a licence to use your content”
This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.
The move Their terms say whether the licence ends when the account does. Close the account and log the date here.
“inferences of your age, interests and preferences based on your usage”
Working out your age, your interests and your preferences from what you watch and play, then using that profile to target advertising. It is data about you that did not exist until they built it.
The move A See request reaches the profile they built, not only the data you handed in.
“we share your information with Event Partners so they can run the event, for reasons described in their privacy policies”
Buying one ticket hands your details to everyone behind the event: the promoter, the venue, the artist and label, the organiser. Each holds them under its own policy, and the platform usually says what happens next is not its responsibility.
The move A See request asks who your ticket was handed to, and their reply should name them.
Their own policy is the one that binds them. Pin it down with a request, and keep the reply.