import type { Metadata } from "next";

import { LegalPage, LegalSection } from "@/components/legal/legal-page";
import { siteConfig } from "@/config/site";

export const metadata: Metadata = {
  title: "Privacy Policy",
  description: `What ${siteConfig.name} stores, why, and for how long.`,
  alternates: { canonical: "/privacy" },
};

export default function PrivacyPage() {
  return (
    <LegalPage
      eyebrow="Legal"
      title="Privacy Policy"
      updated="1 September 2026"
      intro={`This policy explains what ${siteConfig.name} stores, why it stores it, and how long it keeps it. It is deliberately short because the service keeps very little.`}
    >
      <LegalSection n={1} title="The short version">
        <p>
          Your account, your watchlist, your watch history and your preferences live in this
          server&rsquo;s own data file. There is no advertising, no third-party analytics, and no
          data broker. Nothing is written to <code>localStorage</code> or{" "}
          <code>IndexedDB</code> in your browser.
        </p>
      </LegalSection>

      <LegalSection n={2} title="What is stored">
        <ul className="list-disc space-y-1.5 pl-5 marker:text-ink-faint">
          <li>
            <strong className="text-ink">Account</strong> — username, email address, display name
            and a scrypt hash of your password. The password itself is never stored.
          </li>
          <li>
            <strong className="text-ink">Session</strong> — a random token, its expiry, and the
            IP address and user agent seen at sign-in, so you can recognise unfamiliar sessions.
          </li>
          <li>
            <strong className="text-ink">Library</strong> — titles you add to your watchlist or
            mark as favourites.
          </li>
          <li>
            <strong className="text-ink">What you have watched</strong> — which titles and
            episodes you opened and when, plus their running time, used to show
            &ldquo;continue watching&rdquo; and your history. We do not record how far into
            something you got: video plays inside a third-party player we cannot
            read, so FlixTV has no way to know, and we would rather store nothing
            than store a guess.
          </li>
          <li>
            <strong className="text-ink">Preferences</strong> — theme, autoplay, reduced motion
            and your preferred streaming and download providers.
          </li>
        </ul>
      </LegalSection>

      <LegalSection n={3} title="Cookies">
        <p>
          Two cookies are set, both strictly necessary and both first-party: a session cookie that
          identifies you, and a CSRF token that proves a form submission came from this site
          rather than another. Both are scoped to this domain and are not shared with anyone.
        </p>
        <p>
          Clearing your cookies signs you out. There is no advertising, attribution or tracking
          cookie to consent to.
        </p>
      </LegalSection>

      <LegalSection n={4} title="Third parties">
        <p>
          Catalogue data and artwork are fetched server-side from the TMDB API. The request
          carries no information about you &mdash; the API token stays on the server, and your IP
          is seen by TMDB&rsquo;s infrastructure rather than by this service&rsquo;s application
          code.
        </p>
        <p>
          If you configure a streaming or download provider, your browser will contact that
          provider directly, and that provider&rsquo;s own privacy policy then applies to you.
        </p>
      </LegalSection>

      <LegalSection n={5} title="Server logs">
        <p>
          The web server keeps request logs — path, status, timestamp and IP address — for a short
          rolling window for security and debugging. These are not used to build a profile of you
          and are not joined to your account.
        </p>
      </LegalSection>

      <LegalSection n={6} title="How long it is kept">
        <p>
          Account data is kept for as long as your account exists. Watch history is kept until you
          clear it from the History page. Expired sessions are removed by a periodic maintenance
          job. There is no in-app account deletion; to remove an account and everything attached
          to it, the operator of the server must delete the database.
        </p>
      </LegalSection>

      <LegalSection n={7} title="Your choices">
        <p>
          You can change your display name and password at any time from Settings, clear your watch
          history from the History page, remove individual titles from your list, and sign out of
          every device at once. Because this deployment is self-hosted, the operator of the server
          is the only party able to export or delete the database itself.
        </p>
      </LegalSection>

      <LegalSection n={8} title="Security">
        <p>
          Passwords are hashed with scrypt. Cookies are marked <code>HttpOnly</code> and{" "}
          <code>SameSite=Lax</code>, and <code>Secure</code> once this site is served over HTTPS
          (set <code>COOKIE_SECURE=true</code>). State-changing requests are rejected unless they
          carry a same-origin check and a valid CSRF token.
        </p>
      </LegalSection>

      <LegalSection n={9} title="Contact">
        <p>
          Because {siteConfig.name} is self-hosted, privacy requests go to whoever operates the
          server you are connected to.
        </p>
      </LegalSection>
    </LegalPage>
  );
}
