RETAZ

Privacy Policy

Effective August 8, 2026 · Retaz LLC · Lewisburg, Greenbrier County, West Virginia, USA
Supersedes the version effective August 5, 2026. The minimum age to use Retaz is now 18. It was 16 in earlier versions. Nobody under 18 can hold a Retaz account, so the sections below that described extra protections for 16 and 17 year olds no longer describe anyone, and say so.
The August 5 note follows, unchanged. That version superseded the one effective July 29, 2026. This update is written ahead of two changes that begin on October 3, 2026, so that you read about them before they happen rather than afterwards. First, on the free tier Retaz will start showing you short messages about Retaz itself after your first playlist creation, import and export; the previous version said flatly that we show no ads, which will stop being true even though these are our own messages and involve no advertiser. Section 2 and Section 3 now describe them, and the counters that make the free allowance work. Second, memberships open, so Section 2 now describes what a membership record contains and Section 3 states plainly that your card details never reach us. The July 29 update corrected what we say about crash reporting, and that correction stands unchanged.

The short version

This policy explains what Retaz LLC ("Retaz", "we", "us") collects, why, and what your rights are. It covers the Retaz mobile app (pre-launch, entering Early Access) and the retaz.fm website, including the early-access waitlist. Retaz is pre-launch: this policy describes what the product does today, not what it might do later. If we add features that change what we collect, we will update this policy first.

1. Who we are

Retaz LLC is a West Virginia limited liability company headquartered in Lewisburg, Greenbrier County, West Virginia, USA. For anything in this policy, contact info@retaz.fm.

2. What we collect in the app

You sign in to Retaz with your Apple or Google account. There is no email-and-password sign-up. When you use the app, we collect:

Direct messages

Retaz includes one-to-one direct messages. You can message another member only when the two of you follow each other and neither has blocked the other. A message can be between 1 and 4,000 characters.

Please read this part carefully. Your direct messages are stored on our servers in readable form. They are not end-to-end encrypted. Our safety team can read message content when reviewing a report or acting to keep the community safe, and we may translate messages into the recipient's language in the future. Before you start your first conversation, the app shows you a notice that explains this and asks you to agree. You can report a direct message the same way you report anything else (Section 8). If you delete your account, your messages are deleted with it, except for specific material we are legally required to preserve (Section 7 and Section 8).

Notifications

Retaz can send you a notification when you earn your Curator badge. Notifications are off unless you turn them on: you have to tap "Notify me when I earn it" in the app and then allow notifications when your phone asks. Nothing is sent, and no notification address is stored, until you do both.

When you turn them on, we store a push token for your device. A push token is an address your phone's notification service gives us so a message can reach that device. It is not a name, an email, or a location, and it cannot be used to read anything on your phone. We store one per account, we use it only to send you notifications about your own account, and we never use it for advertising. If you turn notifications off in your phone's settings, the address stops working and we delete it the next time we try to use it. It is deleted with the rest of your data if you delete your account.

Crash and performance reports

When the app crashes or hits an error, we receive a technical report so we can fix it. A report contains the error itself, where in the app it happened, and basic device information such as the model and operating system version. We also sample a small share of sessions (about one in ten) for performance timings, so we can find what is slow.

These reports are configured NOT to include personal identifiers: no IP address, no account identifier, and no request headers or cookies, so a sign-in token can never travel with one. They are technical diagnostics about the software, not a record of what you listened to or who you talked to.

Your listening activity (Last Spin and Tuned In)

When you open a playlist to play it, we record that you opened it (we call this a spin). Your own spin history is private to you. We use it to show you Last Spin (your recent listening) and to power Tuned In, which surfaces playlists that other people have put together. This is our own product data. We do not send it to any outside analytics or advertising service, and it is never used to target ads.

Messages from Retaz about Retaz

This describes something that begins on October 3, 2026. We are telling you before it starts, not after.

Retaz has a free tier and a paid membership. From October 3, on the free tier, your first playlist creation, your first import and your first export are unmetered for as long as you have the account. After that, each time you create, import or export, we show you a short message about Retaz once the action has finished. The action always completes first: the message never blocks it, and you can dismiss it after three seconds.

This is Retaz talking to you about Retaz. There is no advertiser, no ad network and no advertising software involved, nothing about you is sent anywhere, and no advertising identifier exists in the app. Which message you see depends only on which of the three things you just did.

To make the free allowance work, we keep a small count on our own servers of how many times you have created, imported or exported. It is a set of counters attached to your account, nothing more, and we keep it on our servers rather than on your phone so that reinstalling the app does not quietly reset it. Paid members are not counted at all. These counters are deleted with your account.

Your membership

This also begins on October 3, 2026, when memberships open. There are no purchases before then.

We never see your card. Payment is handled entirely by Apple, Google or Stripe, depending on where you subscribe. Your card number does not reach Retaz and we could not store it if we wanted to.

What we do keep is a record of the membership itself: that you have one, when it starts and ends, how it was acquired (a purchase, a Founders place, a referral, or a benefit you earned), the price tier and the amount charged in the currency you were charged in, and the transaction identifier the store gives us. We use it to know whether your membership is active, to recognise a renewal or a refund, and to reconcile our own figures against what the stores report. It is deleted with your account, except where tax and accounting law requires us to keep a record of a transaction.

3. What we do not collect

4. The retaz.fm website and waitlist

If you join the waitlist on retaz.fm, we collect your email address and, if you use the extended signup form, the country, primary music platform, and "how did you hear about us" answer you choose. We use this only to contact you about early access, launch, and Founders benefits. No spam, and we never sell or share the list. To be removed, email info@retaz.fm and we will delete your entry.

Like any website, retaz.fm is served through hosting infrastructure (Cloudflare) that processes visitor IP addresses to deliver pages and protect against abuse. The site also loads fonts and emoji images from content delivery networks (Google Fonts, jsDelivr), which receive standard web requests from your browser. To show pricing for your region, the site also asks a geolocation service (ipapi.co) to estimate your country from your network address; the estimate is used only to pick which prices to display, and you can change the region manually on the page. We do not run advertising or cross-site tracking on retaz.fm.

5. Why we use your data (purposes and legal bases)

PurposeData involvedGDPR legal basis
Provide your account and the core service (playlists, votes, saves, translation)Account data, content, interactionsPerformance of a contract (Art. 6(1)(b))
Apply the 18-and-over rule, and catch a wrongly-entered birth yearBirth year, minor flagLegal obligation and legitimate interests (Art. 6(1)(c), (f))
Safety, moderation, and community integrity (reviewing reports, enforcing guidelines, keeping voting honest)Content, reports, blocks, account dataLegitimate interests (Art. 6(1)(f)); legal obligation where reporting is required by law
Waitlist and early-access communicationWaitlist email and signup answersConsent (Art. 6(1)(a)); withdraw any time
Delivering direct messages between two members who follow each otherMessage content, sender and recipientPerformance of a contract (Art. 6(1)(b))
Showing you Last Spin and Tuned In from your own listening activityPlaylist-open (spin) recordsLegitimate interests (Art. 6(1)(f))
Sending you a notification when you earn your Curator badgePush tokenConsent (Art. 6(1)(a)); withdraw any time in your phone's settings
Diagnosing crashes and performance problemsError reports and device type; no personal identifiersLegitimate interests (Art. 6(1)(f)) in a working, secure app
Responding to your requests and legal complianceWhatever the request involvesLegal obligation and legitimate interests

6. Who processes data for us

We use a small number of service providers, and only to run Retaz. Where a provider processes personal information on our behalf, it does so under a data processing agreement:

Direct messages are stored on the same Supabase infrastructure as the rest of your account data; no separate third-party messaging provider is involved.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We disclose data only to these providers, when the law compels us, or to protect people from serious harm (see Section 8).

7. How long we keep data

8. Moderation and safety reports

When you report content, the report goes into a restricted queue that only authorized staff can read, and a human reviews it. Reports are stored with the category you chose (one of 12: covering playlists, profiles, comments, and direct messages) and the content you flagged. We aim to review reports involving an immediate safety risk within 24 hours, other reports within 72 hours, and to resolve the remainder within 7 days. To reach our safety team directly, email safety@retaz.fm. If we find material depicting child sexual abuse, we preserve and report it to the authorities as United States law requires; that material is not deleted on account deletion while a legal preservation duty applies.

9. Your rights

Exercising a right never costs you anything and never results in worse service.

To exercise any right, email info@retaz.fm from the address associated with your account. We respond within 30 days.

10. Age policy: 18 and over

You must be at least 18 years old to create an account or use Retaz, everywhere we operate, or older where your country sets a higher age of majority. We ask for your birth year at sign-up; this is self-declared, which means we rely on you telling us the truth rather than verifying it. If we learn that an account belongs to someone under 18, we close the account and delete its data. Earlier versions of this policy set the minimum at 16 and described extra protections for members aged 16 and 17; with the minimum at 18 there are no such members.

11. International transfers

Retaz is a United States company. App data is stored with Supabase in the European Union, and we access it from the United States to operate the service. Where data crosses borders, we rely on our providers' data processing agreements and the safeguards they incorporate, such as standard contractual clauses where applicable.

12. Security

Data moves between the app and our backend over encrypted connections (HTTPS/TLS), and access to production data is restricted. Direct messages are encrypted in transit and at rest on our servers, but they are not end-to-end encrypted: our safety team can access message content as described in Section 2. No online service can promise perfect security, and we will not pretend otherwise; if a breach ever affects your data, we will notify you as the law requires.

13. Changes to this policy

When we change this policy, we will post the new version here with a new effective date. For material changes we will give you notice in the app or by email before the change takes effect. This policy has not yet been reviewed by outside counsel; it describes our actual practices honestly and will be refined as Retaz grows.

14. Contact

Retaz LLC, Lewisburg, Greenbrier County, West Virginia, USA.
Privacy questions, requests, and complaints: info@retaz.fm
Safety reports: safety@retaz.fm
EU representative (GDPR Art. 27): [TBD (counsel, pre-Oct-3 EU availability)]
EU Digital Services Act contact point (Art. 11): [TBD (counsel, pre-Oct-3 EU availability)]