Privacy Policy
The short version
- We do not sell your personal information. Ever.
- We do not share your data with advertisers, and we show no ads.
- Retaz is a 16-and-over product.
- Retaz hosts no music. Playlists are lists of track references, and playback happens in your own streaming service.
- Direct messages are stored on our servers and can be read by our safety team. They are not end-to-end encrypted.
- You can export your data and delete your account at any time, from inside the app or by email.
This policy explains what Retaz LLC ("Retaz", "we", "us") collects, why, and what your rights are. It covers the Retaz mobile app (pre-launch, entering Early Access) and the retaz.fm website, including the early-access waitlist. Retaz is pre-launch: this policy describes what the product does today, not what it might do later. If we add features that change what we collect, we will update this policy first.
1. Who we are
Retaz LLC is a West Virginia limited liability company headquartered in Lewisburg, Greenbrier County, West Virginia, USA. For anything in this policy, contact info@retaz.fm.
2. What we collect in the app
You sign in to Retaz with your Apple or Google account. There is no email-and-password sign-up. When you use the app, we collect:
- Email address. Provided by Apple or Google when you sign in. If you use Apple's private relay, we receive the relay address, which is fine with us.
- Display name. The name you choose. It is visible to other people in the app. It does not have to be unique.
- Unique handle. The @handle other people see. You pick it at sign-up, it is unique to you, and you choose whether your handle or your display name is shown by default.
- Account identifier. A random ID that ties your data to your account.
- Country, and optionally a state or province and a city. Profile fields you pick, not location readings. We do not collect device location.
- Social-platform handles. Any usernames you choose to add to your profile for other platforms. These are optional.
- Profile avatar. Avatars are built-in artwork. We store the short key of the preset you pick, not an uploaded photo.
- Language preferences and locale. So Retaz can speak your language.
- Birth year and a minor flag. We ask only your birth year (never your full date of birth) to apply our 16-and-over rule and extra protections for members aged 16 to 17. This is self-declared.
- Content you create. Playlists (titles, descriptions, the "why" text, hashtags, track lists, and the visibility setting you choose), comments, your curator bio, feedback you submit, and translation suggestions you offer.
- Publish attestation. When you publish a playlist you affirm that you made it yourself. We record the time of that affirmation and the terms version you accepted.
- How you interact. Votes (hearts), saved and bookmarked playlists, songs you mark as "not for me", curators you follow, people you block, reports you file, comments you post, and direct messages you send.
- Report submissions. If you report content, we store which item you reported and the category you chose from a fixed list of 12. Reports cover playlists, profiles, comments, and direct messages. The report form has no free-text field.
Direct messages
Retaz includes one-to-one direct messages. You can message another member only when the two of you follow each other and neither has blocked the other. A message can be between 1 and 4,000 characters.
Please read this part carefully. Your direct messages are stored on our servers in readable form. They are not end-to-end encrypted. Our safety team can read message content when reviewing a report or acting to keep the community safe, and we may translate messages into the recipient's language in the future. Before you start your first conversation, the app shows you a notice that explains this and asks you to agree. You can report a direct message the same way you report anything else (Section 8). If you delete your account, your messages are deleted with it, except for specific material we are legally required to preserve (Section 7 and Section 8).
Your listening activity (Last Spin and Tuned In)
When you open a playlist to play it, we record that you opened it (we call this a spin). Your own spin history is private to you. We use it to show you Last Spin (your recent listening) and to power Tuned In, which surfaces playlists that other people have put together. This is our own product data. We do not send it to any outside analytics or advertising service, and it is never used to target ads.
3. What we do not collect
- Location. No device location, ever. Your profile country, and any state, province, or city, are fields you pick yourself.
- Contacts, photos, or audio. The app does not read your contacts, upload photos, or record audio.
- Music files. Retaz hosts no audio. Full tracks play only through your own Apple Music subscription, and short previews are provided by Apple. Playback happens through links into your own streaming service.
- Payment information. There are no purchases during Early Access.
- Advertising or tracking identifiers, third-party analytics, or advertising profiles. The app sends none of these, and we use no advertising identifier. (We do keep a private record of the playlists you open, described in Section 2. It stays on our own systems and is never used for advertising.) We include a crash-reporting library, but it is switched off and sends nothing. If we ever turn it on, we will name the provider here first.
4. The retaz.fm website and waitlist
If you join the waitlist on retaz.fm, we collect your email address and, if you use the extended signup form, the country, primary music platform, and "how did you hear about us" answer you choose. We use this only to contact you about early access, launch, and Founders benefits. No spam, and we never sell or share the list. To be removed, email info@retaz.fm and we will delete your entry.
Like any website, retaz.fm is served through hosting infrastructure (Cloudflare) that processes visitor IP addresses to deliver pages and protect against abuse. The site also loads fonts and emoji images from content delivery networks (Google Fonts, jsDelivr), which receive standard web requests from your browser. To show pricing for your region, the site also asks a geolocation service (ipapi.co) to estimate your country from your network address; the estimate is used only to pick which prices to display, and you can change the region manually on the page. We do not run advertising or cross-site tracking on retaz.fm.
5. Why we use your data (purposes and legal bases)
| Purpose | Data involved | GDPR legal basis |
|---|---|---|
| Provide your account and the core service (playlists, votes, saves, translation) | Account data, content, interactions | Performance of a contract (Art. 6(1)(b)) |
| Apply the 16-and-over rule and protections for members aged 16-17 | Birth year, minor flag | Legal obligation and legitimate interests (Art. 6(1)(c), (f)) |
| Safety, moderation, and community integrity (reviewing reports, enforcing guidelines, keeping voting honest) | Content, reports, blocks, account data | Legitimate interests (Art. 6(1)(f)); legal obligation where reporting is required by law |
| Waitlist and early-access communication | Waitlist email and signup answers | Consent (Art. 6(1)(a)); withdraw any time |
| Delivering direct messages between two members who follow each other | Message content, sender and recipient | Performance of a contract (Art. 6(1)(b)) |
| Showing you Last Spin and Tuned In from your own listening activity | Playlist-open (spin) records | Legitimate interests (Art. 6(1)(f)) |
| Responding to your requests and legal compliance | Whatever the request involves | Legal obligation and legitimate interests |
6. Who processes data for us
We use a small number of service providers, and only to run Retaz. Where a provider processes personal information on our behalf, it does so under a data processing agreement:
- Supabase: our backend infrastructure and database, hosted in the European Union (eu-west-1). Supabase is a service provider under a data processing agreement; it does not use your data for its own purposes.
- Apple and Google: sign-in and app distribution. Their own privacy policies govern what they collect on their side of sign-in.
- Songlink/Odesli: resolves track links across streaming services. It receives track URLs, not your personal information.
- Cloudflare: hosts the retaz.fm website.
Direct messages are stored on the same Supabase infrastructure as the rest of your account data; no separate third-party messaging provider is involved.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We disclose data only to these providers, when the law compels us, or to protect people from serious harm (see Section 8).
7. How long we keep data
- Account data and content: kept while your account is active.
- When you delete your account: deleting in the app removes your account and its data immediately and permanently. If you request deletion by email instead, we complete it within 30 days. See our account deletion page for the exact steps.
- What we may retain after deletion: records we are legally required to keep (for example tax, accounting, or legal-process records), records needed to resolve an active dispute or enforce our terms, and safety-related material we are required by law to preserve, kept only as long as the law requires.
- Direct messages: kept while both accounts remain active and until either party deletes their account, except for messages preserved for an active safety report or a legal preservation duty.
- Spin history (Last Spin, Tuned In): kept while your account is active, and deleted with the rest of your account data.
- Waitlist emails: kept until launch communication ends or you ask to be removed, whichever comes first.
8. Moderation and safety reports
When you report content, the report goes into a restricted queue that only authorized staff can read, and a human reviews it. Reports are stored with the category you chose (one of 12: covering playlists, profiles, comments, and direct messages) and the content you flagged. We aim to review reports involving an immediate safety risk within 24 hours, other reports within 72 hours, and to resolve the remainder within 7 days. To reach our safety team directly, email safety@retaz.fm. If we find material depicting child sexual abuse, we preserve and report it to the authorities as United States law requires; that material is not deleted on account deletion while a legal preservation duty applies.
9. Your rights
Exercising a right never costs you anything and never results in worse service.
- Export your data any time from inside the app (Settings > Account).
- Delete your account any time from inside the app, or by email. Details: retaz.fm/delete-account.
- If you are in the EU/EEA or UK (GDPR): you can access, correct, delete, and receive a portable copy of your data; restrict or object to processing; withdraw consent at any time; and complain to your supervisory authority.
- If you are in California or another US state with a privacy law: you can know what we collect, delete it, and correct it. We do not sell or share personal information as those laws define it, and we will never discriminate against you for exercising a right.
To exercise any right, email info@retaz.fm from the address associated with your account. We respond within 30 days.
10. Age policy: 16 and over
You must be at least 16 years old to create an account or use Retaz, everywhere we operate. We ask for your birth year at sign-up; this is self-declared. Members aged 16-17 are treated as minors and receive additional design protections. If we learn that an account belongs to someone under 16, we close the account and delete its data.
11. International transfers
Retaz is a United States company. App data is stored with Supabase in the European Union, and we access it from the United States to operate the service. Where data crosses borders, we rely on our providers' data processing agreements and the safeguards they incorporate, such as standard contractual clauses where applicable.
12. Security
Data moves between the app and our backend over encrypted connections (HTTPS/TLS), and access to production data is restricted. Direct messages are encrypted in transit and at rest on our servers, but they are not end-to-end encrypted: our safety team can access message content as described in Section 2. No online service can promise perfect security, and we will not pretend otherwise; if a breach ever affects your data, we will notify you as the law requires.
13. Changes to this policy
When we change this policy, we will post the new version here with a new effective date. For material changes we will give you notice in the app or by email before the change takes effect. This policy has not yet been reviewed by outside counsel; it describes our actual practices honestly and will be refined as Retaz grows.
14. Contact
Retaz LLC, Lewisburg, Greenbrier County, West Virginia, USA.
Privacy questions, requests, and complaints: info@retaz.fm
Safety reports: safety@retaz.fm
EU representative (GDPR Art. 27): [TBD (counsel, pre-Oct-3 EU availability)]
EU Digital Services Act contact point (Art. 11): [TBD (counsel, pre-Oct-3 EU availability)]