NIGHTS
# Privacy Policy
**Updated September 8, 2026**
Nights is a private movie-ticket collection for iPhone developed by Jake Standley. It turns supported AMC confirmation emails into ticket records stored on your device. Nights does not operate a developer-controlled server that receives your Gmail messages or ticket collection.
## Gmail access
When you choose to connect Gmail, Google grants Nights read-only access to your mailbox through the `gmail.readonly` permission. This technical permission can read mailbox content. Nights limits its own searches to supported AMC confirmation-email senders and retrieves matching messages so it can identify and parse your tickets.
Nights cannot send, edit, or delete your email. Connecting Gmail is optional, but automatic ticket import does not work without it.
## Information processed and retained
For supported confirmations, Nights may process and retain:
- Movie title, showtime, theatre, auditorium, presentation format, and seats
- Confirmation or order identifiers
- Gmail message identifiers and synchronization checkpoints
- Import and repair metadata for confirmations that need attention
- AMC entry-code image URLs or tokens and a cached entry-code image for offline access
- Limited ticket metadata such as A-List or Entourage indicators when present in the confirmation
Matching message content is processed by the app on your iPhone. Nights retains the parsed information above rather than a browsable copy of your mailbox.
## Where information goes
Nights communicates with:
- **Google Sign-In and the Gmail API**, to authenticate you and retrieve supported confirmation emails
- **AMC-hosted image services**, to download the entry-code image referenced by a confirmation for offline use
- **Apple services required by iOS and TestFlight**, when you install or test the app
- **Google Analytics for Firebase and Firebase Crashlytics**, in releases configured for usage analytics and diagnostics as described below
Gmail-derived messages, parsed tickets, and cached entry codes are not uploaded to a server controlled by the Nights developer. Nights does not sell personal information, display advertising, track you across other companies’ apps or websites, or use Gmail data for generalized artificial-intelligence model training.
## Usage analytics and diagnostics
Releases configured for telemetry send limited usage events to Google Analytics for Firebase and diagnostic reports to Firebase Crashlytics. Builds without telemetry configuration do not configure Firebase. Development builds and automated tests do not enable this telemetry.
Our explicit usage events describe app activity, sign-in and reconnect outcomes, import completion, ticket-detail views, entry-code display, opening the ticket-sharing sheet, and the success, failure, and duration of app operations. Displaying an entry code does not tell us whether a venue accepted it. Analytics also collects basic lifecycle and engagement events. Crashlytics helps identify crashes and handled failures, using technical stack traces, device/app information, and recent diagnostic breadcrumbs.
An app-generated random installation identifier connects our usage events and diagnostics. Firebase also creates its own app-instance and installation identifiers. We do not attach your name, email address, Google account identifier, or advertising identifier. Identifiers can persist with app preferences and device backups; counts of installations are not exact counts of people.
Our explicit events and handled-error reports exclude mailbox contents, movie titles, showtimes, seats, order identifiers, entry codes, access tokens, raw request URLs and original error descriptions. We disable automatic screen reporting, advertising consent and vendor-identifier collection, and use the Analytics library without advertising identity support. We do not enable session recordings, screenshots, network tracing or Firebase Performance Monitoring. Crashlytics creates native crash reports independently of our handled-error filter; the exact release's diagnostic payloads are reviewed before enabling collection. Like other network services, Google receives the connection's IP address and processes SDK metadata; our custom events do not include an IP-address property.
Before enabling a release, Nights configures Analytics event/user retention to two months with reset-on-new-activity disabled. Crashlytics retains crash data for 90 days before beginning deletion from its systems; aggregate Analytics reports may remain longer. See [Firebase's data handling documentation](https://firebase.google.com/support/privacy) and [Analytics retention documentation](https://support.google.com/analytics/answer/7667196). Deleting Nights Data erases the local ticket collection and sync state, but does not automatically delete telemetry already sent. Contact support for questions about telemetry or deletion of previously sent reports.
## Storage and retention
Imported ticket information and cached entry-code images remain on your iPhone until you delete Nights data or remove the app, subject to the backup and device-management behavior you have configured with Apple. Disconnecting Gmail stops future access but intentionally preserves your existing collection.
## Disconnecting and deleting
Use **Settings → Disconnect Gmail** to ask Google to revoke Nights’ authorization while retaining imported tickets.
Use **Settings → Delete Nights Data** to erase tickets, cached entry-code images, repair items, Gmail message identifiers, and synchronization state stored by Nights. Local deletion works without a network connection. If Google cannot be reached, Nights signs out locally and tells you how to revoke the remaining authorization from your [Google Account connections](https://myaccount.google.com/connections).
These actions do not delete your Google Account, Gmail messages, AMC Account, or AMC purchase history.
## Google API Limited Use
The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
## Children
Nights is not directed to children under 13, and the developer does not knowingly collect children’s personal information through a developer-controlled service.
## Changes to this policy
Material changes will be published on this page with a new effective date. The policy applicable to an installed build will remain publicly available.
## Contact
Questions or privacy requests can be sent to [support@getnights.app](mailto:support@getnights.app).