want your data gone? delete your account from the web, or in the app under you › settings.
privacy policy
DRAFT for attorney review — not legal advice. Written to be GDPR, UK GDPR and CCPA/CPRA ready. Items marked [PLACEHOLDER] need the founder or attorney. Retention periods marked (proposed) are suggestions for the attorney to confirm and for the build to implement.
MELAÜDIC Privacy Policy
Effective date: [PLACEHOLDER — effective date] Last updated: [PLACEHOLDER — date]
This policy explains what we collect when you use MELAÜDIC (the app listed as "MELAUDIC" and the website itsmelaudic.com), why, who we share it with, how long we keep it, and how you can control it. Short version:
- No ads. We don't sell your data. We don't share it for cross-context behavioural advertising. No tracking across other apps or sites.
- We collect what we need to run a music app: your account, what you listen to, what you like, and what you post or send.
- You can download your data and delete your account right in the app.
1. Who's responsible
Lau Holdings [PLACEHOLDER — full legal entity name], [PLACEHOLDER — legal address], company number [PLACEHOLDER], is the controller of your personal data.
- Privacy contact: privacy@itsmelaudic.com [PLACEHOLDER — confirm inbox]
- Data Protection Officer (if appointed): [PLACEHOLDER — DPO name/contact, or "not required" per attorney]
- EU representative (GDPR Art. 27): [PLACEHOLDER — if Lau Holdings is not established in the EU]
- UK representative (UK GDPR Art. 27): [PLACEHOLDER — if Lau Holdings is not established in the UK]
2. What we collect
Things you give us
| Data | Examples | Required? |
|---|---|---|
| Age data | Birth month and birth year (not the day) | Yes, to check you're 13+ and set the right content rules |
| Account details | Email address, password (stored only as a secure hash), or your Apple / Google sign-in ID and the email they share (which may be a private relay address) | Only for a full account (guests don't need this) |
| Profile | Display name, handle, profile photo, bio, pronouns, favourite houses, public/private setting | Optional (a handle is needed for some features) |
| Choices | Houses and artists you pick at onboarding, settings (notifications, playback, privacy, explicit on/off, language) | Yes, to run the app |
| Parental PIN | A 4-digit PIN (stored only as a secure hash) | Optional |
| Activity you create | Likes, follows, playlists, request-wall ideas and votes, ballot votes, "pulses" on posts | When you use those features |
| Chat messages | What you send to AI artists and their replies | Only if you use chat (and agree to AI processing) |
| Support messages | What you send to our help assistant or by email | When you contact us |
| Reports, blocks and appeals | What you report, who you block, appeal text | When you use them |
Things we collect automatically
| Data | Examples |
|---|---|
| Listening history | Track played, seconds listened, your local hour (for things like the "Night owl" badge), live listening heartbeats while a track plays |
| Device and session | A random install ID for guest mode, session tokens, app version, OS, device model, language, time zone |
| Push token | The token Apple / Google / Expo give us so we can send you notifications (only if you allow notifications) |
| Technical logs | IP address, request times, errors. Our servers and CDN process IP addresses to deliver the service and block abuse |
| Crash reports | App crash details and diagnostics (via Sentry) |
| Analytics events | In-app events like "opened a playlist" or "finished onboarding", linked to your account ID, to understand what works. You can turn this off in Settings → Privacy |
| Age signals | If your phone's app store offers it (Apple Declared Age Range, Google Play Age Signals), the age range it reports, never your exact birthday |
| Consent records | When you agreed to the terms, this policy and AI chat, and which version |
| Safety signals | Moderation results on content you post, and a log if our systems detect a possible crisis signal so we can show you help resources |
We don't collect: precise location, contacts, photos library (we only ask for permission to save a share card to Photos), microphone, health data, or payment card details. When purchases arrive later, they're handled by Apple or Google and we only get a receipt status, not your card.
3. Why we use it, and our legal bases
For people in the UK, EU and EEA, we must tell you the legal basis for each use.
| Purpose | Data used | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Create and run your account, sign you in, keep you signed in | Account, device/session, profile | Contract (Art. 6(1)(b)) |
| Check you're 13+ and apply teen protections (clean versions, stricter chat) | Age data, age signals | Legal obligation (Art. 6(1)(c)) where required (e.g. UK Online Safety Act), otherwise legitimate interests in protecting young people (Art. 6(1)(f)) |
| Stream music, build your library, playlists, home feed, mood picks, stats and badges | Listening history, likes, follows, playlists, choices | Contract |
| Personalise recommendations ("For you") | Listening history, likes, follows, houses | Contract for basic personalisation; for teens, kept to what's needed for the feature [ATTORNEY: confirm vs UK Children's Code "profiling off by default"] |
| Request wall, ballots, public profile | Profile, ideas, votes | Contract |
| AI artist chat | Chat messages, age band, artist public profile | Consent (Art. 6(1)(a)) for sending your messages to our AI provider; contract to provide the feature once you've agreed |
| Safety and moderation (filters, AI safety review, reports, appeals, crisis resources) | Content you post, reports, chat flags, safety signals | Legitimate interests (keeping the community safe) and legal obligation where required |
| Support | Support messages, account info | Contract and legitimate interests |
| Notifications | Push token, notification settings | Consent (your OS permission) |
| Marketing notifications or emails | Email, push token | Consent (off by default) |
| Analytics to improve the app | Analytics events | Legitimate interests (you can opt out at any time); consent where required by local law (e.g. ePrivacy rules for non-essential device access) [ATTORNEY: confirm] |
| Crash reports and security | Logs, crash reports, IP address | Legitimate interests (keeping the app working and secure) |
| Legal compliance, fraud prevention, enforcing our terms | Any relevant data | Legal obligation, legitimate interests |
Special category data. We don't ask for it. Pronouns are optional and free text. If you mention health, beliefs or other sensitive things in chat or support, we only process them to provide that conversation and keep you safe. Crisis-signal logs are processed to protect vital interests (Art. 6(1)(d)) and, where needed, Art. 9(2)(c). [ATTORNEY: confirm Art. 9 analysis for self-harm signals.]
4. Who we share it with
We never sell your data and never share it for advertising. We share it only with service providers (processors / sub-processors) who help us run MELAÜDIC, under contracts that limit what they can do with it.
| Provider | What they do | Data involved | Location |
|---|---|---|---|
| Hostinger (VPS) | Hosts our own servers, database (Postgres) and cache (Redis) | All app data | [PLACEHOLDER — data centre region, e.g. EU/UK/US] |
| Cloudflare | CDN, firewall (WAF), DNS, bot protection | IP address, request data, cached public content | Global edge network |
| Backblaze B2 | Stores media, profile photos and encrypted backups | Profile photos, database backups | [PLACEHOLDER — B2 region, e.g. US-West / EU-Central] |
| Anthropic | AI replies in artist chat; AI moderation and support assistants | Chat messages, support messages, content being moderated, age band (teen/adult). No email, no real name sent on purpose | US |
| Postmark (ActiveCampaign) | Sends account emails (verification codes, security notices) | Email address, email content | US |
| Sentry | Crash and error reports | Device info, app version, error details, account ID | US [PLACEHOLDER — or EU region if chosen] |
| Expo push service, Apple Push Notification service, Google Firebase Cloud Messaging | Deliver push notifications | Push token, notification content | US / global |
| Apple, Google | Sign in with Apple / Google; app store age signals; (later) in-app purchases | Sign-in identifiers, age range, purchase status | US / global |
| Modal | AI generation of our artists' media | No fan data | US |
We may also share data:
- if the law requires it (for example a valid court order), or to report illegal content, including child sexual abuse material, to the authorities (e.g. NCMEC in the US, the NCA in the UK);
- to protect someone's safety, or our rights;
- with a buyer if MELAÜDIC is sold or merged (we'd tell you first).
What other fans see. If your profile is public, other fans can see your display name, handle, photo, bio, pronouns, favourite houses, stamps and badges, and your top artists only if you turn on "Show what I'm listening to". Your handle may show next to request-wall ideas and in song credits ("Idea by @you"). Private profiles show only your handle and photo.
5. International transfers
We're based in [PLACEHOLDER — country]. Some providers above are in the US or operate globally. When your data leaves the UK, EU or EEA, we use approved safeguards: an adequacy decision (for example the EU–US Data Privacy Framework and the UK Extension, where the provider is certified), or Standard Contractual Clauses / the UK International Data Transfer Addendum, plus extra measures like encryption in transit and at rest. You can ask us for a copy of the relevant safeguards.
6. How long we keep it
| Data | How long |
|---|---|
| Account, profile, settings, choices | While your account is open. Deleted when you delete your account |
| Guest data | While the guest session is active. Guests inactive for 12 months are deleted (proposed) |
| Listening history (individual plays) | 13 months on the server (proposed), then kept only as anonymous totals. Deleted with your account; anonymous play counts stay |
| Likes, follows, playlists | While your account is open |
| Request-wall ideas and votes | While on the wall or your account is open. Ideas picked for a song are kept as a credit record (handle and idea text) for as long as the song is available (proposed). Vote totals stay as anonymous numbers |
| Chat messages | 12 months, rolling (proposed). The app shows your last 100 messages per artist. Deleted with your account |
| Chat sent to Anthropic | Anthropic keeps API inputs and outputs for a limited period (currently up to 30 days by default under its commercial terms, longer only if flagged for policy violations) and does not use them to train its models. [ATTORNEY: confirm current Anthropic commercial terms and any zero-data-retention arrangement] |
| Support messages | 24 months after the conversation ends (proposed) |
| Reports, moderation records, appeals | 24 months (proposed), or longer if needed for a legal claim or a ban |
| Evidence of illegal content (e.g. CSAM) | Kept in a restricted vault only as long as the law requires for reporting [ATTORNEY: e.g. US 18 U.S.C. §2258A preservation period] |
| Crisis-signal log | 90 days (proposed) |
| Ban records | For as long as the ban lasts, using the minimum data needed to stop the person rejoining (proposed) |
| Age data and age signals | While your account is open. If you're under 13, we close the account and delete its data straight away, keeping only a minimal record that the device was blocked (proposed: 30 days) |
| Consent records | While your account is open plus 6 years (proposed), to prove consent |
| Push tokens | Until you turn off notifications, sign out, or the token stops working |
| Analytics events | 13 months (proposed), then aggregated |
| Crash reports (Sentry) | 90 days (proposed; set in Sentry) |
| Server and CDN logs | 30 days (proposed) |
| Backups | Rolling [PLACEHOLDER — e.g. 35] days (deleted data disappears from backups when they roll over) |
| Email delivery logs (Postmark) | 45 days (proposed; Postmark default) |
7. Children and teens
- MELAÜDIC is not for children under 13. We ask for birth month and year with a neutral age screen (it doesn't hint at the "right" answer). If you're under 13, we close the account and delete its data, and you won't be able to sign up again on that device for a while. We don't knowingly collect data from children under 13. If you're a parent and think your under-13 child is using MELAÜDIC, email privacy@itsmelaudic.com [PLACEHOLDER] and we'll delete the account.
- Teens (13–17) get extra protection by default:
- clean versions only, explicit songs can't be played;
- stricter AI chat rules (no mature topics, extra care around feelings, no contact-sharing);
- their profile is private by default [confirm in build], "Show what I'm listening to" is off by default, and marketing notifications are off;
- stricter content filters on what they post (for example contact details are hidden);
- no ads, no sale of data, no targeted advertising.
- Parental controls. A parent or guardian can set a 4-digit PIN that locks the explicit setting. They can also use Apple Screen Time / Family Sharing or Google Family Link.
- If you're 13–15 in California, we don't sell or share your data, so there's nothing to opt in to.
8. Your rights, and how to use them
Depending on where you live, you have rights over your data. Many are built right into the app:
| Right | How |
|---|---|
| Access / get a copy (portability) | Settings → Account → Download my data. You get a file (JSON) with everything tied to your account |
| Correct | Edit your profile and settings in the app. For anything else (for example a birth date you entered wrongly), email us |
| Delete | Settings → Account → Delete account. This deletes your account, personal data and every session. Anonymous totals stay. You can also ask by email or at itsmelaudic.com/delete-account [PLACEHOLDER — confirm web route] |
| Withdraw consent | Turn off AI chat consent, notifications, marketing or analytics in Settings at any time. It doesn't affect what we did before |
| Object / opt out of analytics | Settings → Privacy → Analytics off |
| Restrict | Email us and we'll pause processing while we look into it |
| Not be subject to solely automated decisions | See section 9; you can always ask a human to review |
| California (CCPA/CPRA) | Right to know, delete, correct, and to opt out of sale/sharing (we don't sell or share) and to limit use of sensitive personal information (we only use it for permitted purposes). We won't treat you differently for using your rights. You can use an authorised agent |
| Complain | To us first, please. You can also complain to your data protection authority, for example the ICO in the UK (ico.org.uk) or your local EU authority |
We reply within one month (GDPR/UK GDPR) or 45 days (CCPA), and may need to check it's you. Email privacy@itsmelaudic.com [PLACEHOLDER].
Global Privacy Control. We honour GPC signals on our website as an opt-out of sale/sharing (which we don't do anyway).
9. Automated decisions
MELAÜDIC is run by the founder with the help of AI agents, so some decisions are automated. We want you to know where:
| What | Automated? | Human involved? |
|---|---|---|
| Age band (teen/adult) from birth month/year and store age signals; under-13 block | Yes, fully automated | You can ask us to review if you think it's wrong (we may ask for proof of age) |
| Content filters on posts, bios, handles, chat (block, hide or queue) | Yes | Hidden or queued items are reviewed by our AI safety agent and, where needed, the founder. You can appeal |
| AI safety review of flagged or reported content | Yes (AI agent) | The founder reviews serious cases and every appeal |
| Bans and suspensions | No | Always approved by the founder |
| Chat replies | Yes (AI) | No human writes them |
| Support answers | Our AI help assistant (Concierge) answers first | Hand-off to the founder for anything it can't solve, refunds, account security or complaints |
| Recommendations | Yes | They don't have legal or similarly significant effects |
To ask for a human review of any automated decision, use Appeal on the notice in the app or email appeals@itsmelaudic.com [PLACEHOLDER].
10. Security
We protect your data with: encryption in transit (HTTPS/TLS everywhere), passwords and PINs stored only as strong hashes, databases that aren't reachable from the internet, a web application firewall and rate limits, scoped access keys for each service, encrypted off-site backups with object lock, founder-only admin access with strong login (passkey or password + 2FA) and a full audit log, and secrets kept out of our code. No system is perfectly secure. If a breach affects you, we'll tell you and the authorities as the law requires.
11. Changes to this policy
If we change this policy in a way that matters, we'll tell you in the app or by email before it applies, and ask for your consent again where needed.
12. Contact
privacy@itsmelaudic.com [PLACEHOLDER] · Lau Holdings, [PLACEHOLDER — legal address] · DPO: [PLACEHOLDER — DPO contact]