← Back to musicpool.app
Privacy Effective 2026-06-06 v1.0

Privacy Policy

The short version: MusicPool is an anonymous-by-default music chat app. We only collect what we need to match you with someone and keep your account safe. We don't sell your data. Ever.

01Data we collect

You give us some data directly. The app generates more in the background while you use it. Here's the full list.

Account data

  • Email and password. Required to sign in. Your password is hashed; we never see the raw value.
  • Username. Chosen during onboarding.
  • Profile fields you add. Display name, avatar, music preferences, age (for safety filtering), bio. All optional except where the app says otherwise.

Activity data

  • Pools you join, matches, chat messages, music shares and likes, profile reveal requests, and reviews you submit after a chat.
  • Reports and blocks you create.
  • XP, levels, badges, streaks. Derived from your activity.

Device and technical data

  • App version, OS, device model. For crash reporting and compatibility.
  • Push token (APNs on iOS, FCM on Android). Only if you allow notifications.
  • IP address. Used for fraud prevention and rate limiting, not stored long term.

02How we use it

  • Match you with another listener in a Vibe Pool.
  • Deliver messages, song shares, and likes between you and your match.
  • Run the gamification system (XP, levels, daily tasks, badges).
  • Send transactional emails for signup confirmation, password reset, and email change.
  • Send push notifications for new matches and messages, if you've opted in.
  • Keep MusicPool safe by investigating reports, enforcing blocks, and preventing abuse and spam.
  • Improve the product using aggregated, non-identifying usage signals only.

We do not sell your data, share it with advertisers, or use it to train AI models outside the MusicPool service.

03Who we share data with

MusicPool relies on a small set of trusted vendors to run the service. We share the minimum data they need to do their job.

  • Supabase (database, authentication, realtime, storage) hosts your account and chat data.
  • Resend (email delivery) sends transactional emails from no-reply@musicpool.app.
  • Apple Push Notification service and Google Firebase Cloud Messaging deliver push notifications.
  • Apple App Store and Google Play distribute the app and handle in-app purchases (if applicable).
  • Spotify and Deezer public APIs return track metadata you choose to share in chat. We do not link your MusicPool account to your Spotify or Deezer account.

We may also disclose data when required by law (subpoena, court order, lawful government request) or to protect the rights, property, or safety of MusicPool, our users, or others.

04Anonymous chat & reveal

Every chat starts anonymous. You get a random alias per chat. Your username, real name, and profile photo are hidden from the other person.

The reveal mechanic is strictly opt-in on both sides. We don't auto-reveal anything. You can decline a reveal request at any time, and either of you can end the chat at any time.

Behind the scenes, the system knows which two accounts are matched, because that is how chat works. But the other user can't see your identity unless both of you tap to reveal.

05Music data (Spotify / Deezer)

When you share a track, we fetch its public metadata (title, artist, cover art, preview URL) from the relevant streaming service's public API. We do not require you to connect your Spotify or Deezer account. We don't see your listening history. We don't see what's in your library. We only know the songs you choose to share inside MusicPool.

06Push notifications

If you allow notifications, we send pushes for new matches, new messages, chat-ending warnings, daily-task reminders, and the occasional product announcement. You can turn them off in your device's system settings or inside the app at any time.

07Data retention

  • Active accounts. We keep your data as long as your account exists.
  • Ended chats. Messages and shared songs from chats that ended are retained for moderation and dispute resolution, then periodically purged.
  • Account deletion. When you request deletion from inside the app, the request is queued and your account plus personally identifiable data are removed within 30 days, except where we're legally required to retain something (for example, an abuse investigation or financial records).
  • Push tokens. Removed when you sign out, uninstall, or revoke notification permission.
  • Logs. Server logs are kept for up to 30 days for diagnostics, then rotated.

08Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your account and personal data.
  • Export your data in a portable format.
  • Restrict or object to certain processing.
  • Withdraw consent at any time.

You can exercise most of these from inside the app (Profile → Account), and the full walkthrough for deletion lives on our account deletion page. For anything you can't do in-app, email support@musicpool.app and we'll handle it within 30 days.

09Security

All traffic to musicpool.app and the MusicPool API is encrypted in transit (TLS). Passwords are hashed with bcrypt. Database access is restricted to the application server, with row-level security policies that prevent users from reading each other's private data. We follow industry-standard practices, but no system is 100% secure. If you suspect a security issue, please email us immediately.

10Children

MusicPool is not directed at children under 13 (or under 16 in the EU and UK, where local law applies). If you become aware that a child under the applicable age has signed up, contact us and we will delete the account.

11Changes to this policy

If we make material changes, we'll notify you in-app or by email before the changes take effect. The "Effective" date at the top will always reflect the current version.

12Contact

Privacy questions, data requests, or anything else: support@musicpool.app.

Heads up: this policy is a working draft pending final review by legal counsel. The substance reflects how the product actually works, but the exact phrasing may change before it becomes the binding version. If you spot something off, tell us at support@musicpool.app.