Privacy policy

Last updated:

This policy explains what personal data the Heardlist app collects, why, who can see it, how long it's kept, and how you can get it deleted. It applies to the Heardlist app for iPhone and to this website.

The short version

1. Who's responsible

The controller for your personal data is Gustaf Bratt, Sweden. In this policy, “we” and “us” refer to him. You can reach us at bratt.gustaf@gmail.com.

2. What we collect

To use Heardlist, you need to sign in with Apple or Google and choose a name and a username. Without them, we can't create your account. Everything else, such as shows, notes, follows, reports, and notifications, is up to you.

When you sign in

Heardlist has no passwords. You sign in with Apple or Google, and they give us:

We also store when your account was created and when you last signed in.

With Sign in with Apple, Apple also gives us a one-time code. We exchange it for a key from Apple (a refresh token) and store that key for one reason only: so that we can revoke Heardlist's access to your Apple account when you delete your account. It's never shown in the app, and no user can read it.

What you add

What's created when you use the app

Your phone's region setting (for example, United States) is sent along with some requests, so that artist pages can show statistics for your country and link to the right Apple Music store. We don't store it.

What we don't collect

Heardlist doesn't use your location, contacts, photos, or microphone. There are no ads, no analytics, and no tracking in the app, and it doesn't use your device's advertising identifier. We don't sell your data or share it for advertising.

3. Why we use it, and our legal basis

We only use your data to run Heardlist. Under the EU General Data Protection Regulation (GDPR), each use needs a legal basis:

PurposeDataLegal basis
Creating your account and signing you in Sign-in details, sign-in sessions Contract: needed to provide Heardlist under the Terms of Use (Article 6(1)(b))
Your collection: shows, songs, rarity, statistics, badges, and notes Shows, songs, notes Contract
Social features: your visible profile, Find people, following, Feed, leaderboards, and comparing collections Name, username, shows, songs, follows Contract. You decide whether your profile is visible.
Notifications when someone you follow logs a show Push token, the name of the person who logged the show, follows Contract. You choose whether to allow notifications.
Keeping Heardlist safe: the name filter, reports, blocking, and acting on abuse Names, usernames, reports, blocks Legitimate interest in keeping Heardlist safe for everyone (Article 6(1)(f))
Security and fixing problems Sign-in sessions, technical logs Legitimate interest in protecting accounts and keeping the service running
Revoking Sign in with Apple when you delete your account The key from Apple Contract: part of carrying out the deletion you asked for
Meeting legal requirements, for example a request from the police, and reporting serious cases, such as threats, to the police What the request or the case covers Legal obligation (Article 6(1)(c)) when the law requires it. Legitimate interest in protecting our users (Article 6(1)(f)) when we report a serious case ourselves

Heardlist doesn't make decisions about you based only on automated processing that have legal or similarly significant effects. The name filter automatically stops names that contain certain offensive words, and you can then choose another one.

4. Who can see what

Other users, if your profile is visible

Visible to others is on by default. You can turn it off when you create your profile, or later under Profile. While it's on, other signed-in Heardlist users can:

If you turn Visible to others off

Other users can't see your profile or your collection, and they can't find you. You no longer appear on leaderboards, in Feed, or under Others who were there, and the people who follow you stop getting notifications about you. Anyone who already followed you keeps the follow, but only sees “Private account,” without your name.

Always private

Blocking

If you block someone, or someone blocks you, neither of you can see the other's profile or collection, and any follows between you are removed.

Us

We can access the database to run Heardlist, review reports, and answer your requests, and we only look at personal data when that's needed. Your notes are hidden from other users, but they aren't end-to-end encrypted.

5. Who we share it with

We only share your data with the services that make Heardlist work:

Everyone listed here must protect your data at least as well as this policy describes. Supabase and Expo may only use it to provide their services to us, under their agreements with us. Apple, Google, and Cloudflare also handle it under their own privacy policies.

We may also share data with the police or other authorities when the law requires it, or in serious cases such as threats, as described in the Terms of Use.

6. Services your phone connects to

Some things in the app load straight from other services. Your phone then connects to them directly, so they receive your IP address, and their own privacy policies apply:

7. What our server loads without your data

Our server loads shows and setlists from setlist.fm, artist facts and search results from MusicBrainz, artist descriptions from Wikipedia and Wikidata, and upcoming shows from Ticketmaster. These requests don't include anything about you. When you search for an artist, our server passes the search text on to MusicBrainz, without your IP address or anything else that identifies you.

8. Where your data is stored

Our database is hosted by Supabase in the EU, in Stockholm, Sweden. Some server functions can run on Supabase servers closer to you, which may be outside the EU.

Supabase, Expo, Apple, Google, and Cloudflare are based in the United States or can process data there. When personal data is transferred outside the EU and EEA, it's protected as follows:

To get a copy of these safeguards, email bratt.gustaf@gmail.com.

9. How long we keep it

DataHow long
Your account, profile, shows, songs, notes, follows, and blocks Until you remove them or delete your account. We don't delete inactive accounts automatically.
Push token Until you sign out, until a notification can't be delivered because Heardlist is no longer on the device, until someone else signs in to Heardlist on the same device, or until you delete your account.
The entry created when you log a show or send a report Deleted 7 days after its notification has been sent or given up on, or right away if the show or report it belongs to is deleted.
The key from Apple As long as your account exists. It's used to revoke Heardlist's access and deleted when you delete your account.
Reports you send As long as the reported account exists. If you delete your account, your reports are kept but no longer linked to you, so that nobody can erase a report about someone else by leaving.
Reports about you Deleted when your account is deleted.
Sign-in sessions Until you sign out on that device or delete your account. If you remove the app without signing out, the session is kept until you delete your account.
Technical logs A short time, currently no more than 7 days.

When you delete your account, everything that belongs to it is deleted right away: your profile, shows, songs, notes, follows, blocks, reports about you, your push token, your sign-in sessions, and the key from Apple. The only exception is reports you've sent, which are kept without being linked to you, as described above. Supabase may keep backups of the database for a limited time, and deleted data disappears from them when they expire.

10. Your rights, and how to use them

Under the GDPR, you have the right to:

Your right to object

You can object at any time to processing that's based on our legitimate interests. That covers keeping Heardlist safe (the name filter, reports, blocking, and acting on abuse), security and fixing problems, and reporting serious cases (see Why we use it). We'll then stop, unless we have compelling reasons that outweigh your interests, rights, and freedoms, or we need the data to establish, exercise, or defend a legal claim. Email bratt.gustaf@gmail.com to object.

In the app

By email

To get a copy of your data, to correct something (your name and username can't be changed in the app yet), or to use any of your other rights, email bratt.gustaf@gmail.com and include your username. We may ask you to confirm that the account is yours. We'll reply within one month.

Complaints

If you think we handle your data wrongly, you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or to the data protection authority where you live. We'd appreciate the chance to fix it first, so feel free to contact us.

11. Children

You must be at least 13 years old to use Heardlist, as stated in the Terms of Use. If you believe a child under 13 has an account, email bratt.gustaf@gmail.com and we'll delete it.

12. Security

Everything sent between the app and our servers is encrypted. Rules in the database decide what each user can read, so other users only get what's described under Who can see what. Your push token and the key from Apple can't be read through the app at all. No system is completely secure, but we work to keep your data protected.

13. This website

This website has no cookies, no analytics, and no scripts, and it doesn't load anything from other websites. It's hosted by Cloudflare, which processes your IP address to deliver the pages and protect the site from attacks.

14. Changes to this policy

If we change this policy in a way that matters, we'll let you know before the change takes effect, in the app or in some other way, for example on this page. The date at the top tells you when it was last updated.

15. Contact

Controller: Gustaf Bratt, Sweden.
Email: bratt.gustaf@gmail.com