Legal
Effective date: 7 June 2026·Last updated: 7 June 2026
This Privacy Policy explains how Groupys collects, uses, shares, and protects your personal data, and the rights you have over it. It is written to support compliance with the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018 where relevant, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the ePrivacy / cookie rules, and general international privacy best practice. We have tried to keep the legal language clear enough for everyday readers.
Groupys ("Groupys", "we", "us", or "our") is a community-based music platform that lets people share music taste, post and rate albums in communities, answer the Weekly Hot Take, and discover like-minded listeners through the Frequency Match feature. Groupys is currently operated as a student project developed at a European university and is not yet incorporated as a registered company. It is operated by the Groupys development team (the "Operator").
This Privacy Policy applies to the Groupys website at groupys.app, the Groupys mobile application, and all related features and services (together, the "Service"). It does not apply to third-party services we link to or integrate with, which have their own privacy practices (see Section 20).
If you do not agree with this Policy, please do not use the Service. For questions or to exercise your rights, contact us at [email protected].
The following terms are used throughout this Policy:
| Term | Meaning |
|---|---|
| Personal data / Personal information | Any information relating to an identified or identifiable natural person (e.g. name, email, online identifier). Used here interchangeably across GDPR (“personal data”) and CCPA/CPRA (“personal information”). |
| Processing | Any operation performed on personal data — collection, storage, use, disclosure, deletion, etc. |
| Controller | The party that determines the purposes and means of processing personal data. |
| Processor / Service Provider | A party that processes personal data on behalf of, and under the instructions of, the Controller / Business. |
| Third Party | A party other than the data subject, controller, or processor who may receive or process data for its own purposes. |
| Data Subject | The living individual to whom personal data relates (GDPR). |
| Consumer | A California resident whose personal information is processed (CCPA/CPRA). |
| Business / Contractor | CCPA/CPRA roles: the entity determining purposes/means (Business); a party receiving PI for a business purpose under contract (Service Provider/Contractor). |
| Sensitive data / Sensitive personal information | Special-category data under GDPR (e.g. health, race, religion, biometrics) and “sensitive personal information” under CPRA (e.g. precise geolocation, account login credentials, contents of private messages). |
| Sub-processor | A processor engaged by our processor to help deliver the service. |
| Cookies / tracking technologies | Small files or identifiers (cookies, pixels, SDKs, local storage) used to store or read information on your device. |
| Automated decision-making / Profiling | Decisions made by automated means, and the automated evaluation of personal aspects (e.g. preferences, interests) to analyse or predict. |
| Authorized Agent | A person or entity a consumer authorises to submit privacy requests on their behalf. |
| Supervisory Authority | An independent public authority that monitors GDPR application (e.g. a national Data Protection Authority). |
For most processing described in this Policy, Groupys acts as the Data Controller under the GDPR and as a Business under CCPA/CPRA, because we decide what data is collected and why.
We engage third-party vendors that act as our Processors / Service Providers (e.g. our authentication provider and email provider) — they process data only on our documented instructions. The independent music providers we query (e.g. Last.fm, Deezer, Spotify, Apple Music) generally act as independent third parties / separate controllers for the data they receive under their own terms.
Where you connect a third-party music account (for example, Apple Music) to power a feature, Groupys and that provider may each act as independent controllers for their respective processing. We do not currently consider ourselves a Joint Controller with any vendor; if that changes, we will update this Policy and put a joint-controller arrangement in place.
We collect only the data we need to run the Service. The table below maps each category to its source, purpose, GDPR legal basis, CCPA/CPRA category, retention, and whether it is shared with vendors. "Active + 30 days" means data is kept while your account is active and deleted within 30 days after account deletion, unless law requires longer.
| Category | Examples | Source | Purpose | GDPR legal basis | CCPA/CPRA category | Retention | Shared with vendors? |
|---|---|---|---|---|---|---|---|
| Account & identity data | Email, username, user ID, password credentials (managed by Clerk) | You / Clerk | Create and secure your account, authenticate logins | Contract (Art. 6(1)(b)) | Identifiers; account login info | Active + 30 days | Yes — Clerk |
| Profile content | Display name, avatar, banner, custom background, coloured username, Album of the Week | You | Display your profile to you and others | Contract; Consent for optional fields | Identifiers; customer records | Active + 30 days | Storage (MinIO) — self-hosted |
| Community activity / user-generated content | Posts, comments, ratings, album reviews | You | Operate communities; show your contributions | Contract; Legitimate interests | Internet/network activity; customer records | Active; public posts may persist anonymised (see §13) | Storage — self-hosted |
| Weekly Hot Take answers | Your answers (public or private) | You | Power the Weekly Hot Take; enrich your profile if shared | Consent (public sharing); Contract (private storage) | Internet/network activity | Active + 30 days | No |
| Match / taste preferences | Genre preferences, favourite artists, listening habits, taste vectors | You / connected music accounts | Power Frequency Match recommendations | Consent | Inferences; internet/network activity | Active + 30 days | Music APIs (for lookups) |
| Communications / support data | Emails to us, support requests, in-app messages | You | Respond to you; deliver in-app messaging | Contract; Legitimate interests | Customer records; contents of communications | Active + up to 24 months | Email provider (Resend) |
| Device & notification data | Expo push token, device type, OS, notification preferences | Your device | Deliver push notifications you opted into | Consent; Contract | Identifiers; internet/network activity | Until token unregistered / Active + 30 days | Expo, Apple (APNs) |
| Usage & log data | IP address, browser/app type, pages/screens, timestamps, error logs | Automatic | Security, debugging, performance | Legitimate interests (Art. 6(1)(f)) | Internet/network activity; identifiers | Server logs typically up to 12 months | Hosting (self-managed) |
| Analytics data | Aggregated/pseudonymous usage events (if Google Analytics is enabled) | Automatic (cookies/SDK) | Understand and improve the Service | Consent (where required) | Internet/network activity | Per GA settings — [NEEDS INPUT: confirm GA retention window] | Yes — Google |
| Cookie & tracking identifiers | Session token, consent state, analytics IDs | Automatic | Keep you logged in; remember consent; analytics | Strictly necessary (no consent); Consent (analytics) | Identifiers; internet/network activity | Session to 12 months (see §7) | See §7 / §9 |
| Music-service tokens | Apple Music user token (encrypted at rest) | You (when you connect an account) | Fetch your music data for connected features | Consent | Account login info (sensitive) | Until you disconnect / Active + 30 days | Apple Music |
| Marketing preferences | Opt-in/opt-out status for any product emails | You | Send only communications you allow | Consent; Legitimate interests (service emails) | Customer records | Active + 30 days | Email provider (Resend) |
Children's data. The Service is not directed to children under 13, and we do not knowingly collect their data (see Section 17).
Sensitive data.We do not intentionally collect GDPR special-category data. Some categories above (login credentials, message contents, music-service tokens) are "sensitive personal information" under CPRA; see Section 11. Music taste itself is not special-category data, but content you post could reveal sensitive details — please do not share more than you intend.
| Purpose | GDPR legal basis |
|---|---|
| Provide and operate the Service | Contract (Art. 6(1)(b)) |
| Create and manage your account | Contract |
| Power Frequency Match and recommendations | Consent |
| Display your public profile, posts, ratings, shared Hot Takes | Contract; Consent (for content you choose to make public) |
| Deliver push notifications (e.g. the Weekly Hot Take) | Consent; Contract |
| Customer support and communications | Contract; Legitimate interests |
| Security, abuse prevention, and fraud detection | Legitimate interests; Legal obligation |
| Analytics and Service improvement | Consent (analytics cookies); Legitimate interests (aggregate insights) |
| Product/marketing emails (if any) | Consent |
| Comply with legal obligations and respond to authorities | Legal obligation (Art. 6(1)(c)) |
| Establish, exercise, or defend legal claims; enforce our Terms | Legitimate interests |
| Protect the vital interests of a person in an emergency | Vital interests (Art. 6(1)(d)) — only if truly applicable |
Legitimate-interest balancing. Where we rely on legitimate interests, we have considered whether our interest (e.g. keeping the Service secure, improving it, defending claims) is overridden by your rights and freedoms, and we limit processing to what is necessary and proportionate. You can object at any time (see Section 15), and we will stop unless we have compelling legitimate grounds or need the data for legal claims. You can request a summary of a relevant balancing assessment by emailing [email protected].
We rely on the following legal bases, matched to specific processing:
Withdrawing consent. Disable the relevant feature in settings (e.g. notifications, match preferences), decline analytics in the consent banner, or email [email protected].
We do notsell your personal information for money. We also do not knowingly "share" it for cross-context behavioural advertising in the way CCPA/CPRA defines those terms.
Analytics caveat.Under CPRA, using certain third-party analytics or pixels can be treated as a "sale" or "sharing" even without payment, because identifiers may be made available to the provider. If Google Analytics (or a similar tool) is enabled, we treat this conservatively and offer an opt-out. [NEEDS INPUT: Confirm whether GA is live in production and whether its configuration constitutes a "sale/share"; if so, honour opt-out signals before loading it.]
If you are a California consumer, you have the right to:
We do not seek out GDPR special-category data. Under CPRA, the following may qualify as "sensitive personal information":
We use this information only to provide the features you requested, secure your account, and comply with law — notto infer characteristics about you and not for purposes beyond those permitted under CPRA § 7027. Because our use is limited to these permitted purposes, the CPRA "right to limit" generally does not change our processing; even so, you may contact [email protected] to ask us to limit any sensitive-data use. We protect this data with encryption and access controls (see Section 14).
Groupys is operated from Europe, and our primary database and object storage are self-managed [NEEDS INPUT: confirm server location/region and hosting provider]. Some vendors are based outside the EU/EEA/UK (notably in the United States), so your data may be transferred and processed there.
| Vendor | Likely location | Transfer safeguard |
|---|---|---|
| Clerk | United States | Standard Contractual Clauses / EU-US Data Privacy Framework |
| Resend | United States | Standard Contractual Clauses |
| Google (Analytics) | United States | SCCs / EU-US DPF |
| Expo | United States | SCCs |
| Apple (APNs / Apple Music) | United States | SCCs / DPF |
| Last.fm / Deezer / Spotify | [NEEDS INPUT: confirm] | [NEEDS INPUT: confirm safeguard] |
Where we transfer personal data outside the EU/EEA or UK, we rely on appropriate safeguards — Standard Contractual Clauses (with the UK International Data Transfer Addendum for UK data), adequacy decisions where they exist, and vendor due diligence. We carry out a Transfer Impact Assessment where required. [NEEDS INPUT: verify each vendor's current transfer mechanism and complete TIAs as needed]
We keep personal data only as long as necessary for the purposes set out in this Policy, then delete or anonymise it.
| Data category | Retention | Reason | Deletion / anonymisation |
|---|---|---|---|
| Account, profile, preferences | While active + 30 days after deletion | Operate the account | Hard-deleted from database and storage |
| Public posts, ratings, reviews | May persist in anonymised form after deletion | Preserve community history | De-linked from your identity unless you request full removal |
| Private Hot Take answers | Active + 30 days | Feature delivery | Hard-deleted |
| Support / communications | Up to 24 months [NEEDS INPUT: confirm] | Handle and audit support | Deleted on schedule |
| Push tokens | Until unregistered / + 30 days | Deliver notifications | Pruned automatically when invalid |
| Server / security logs | Up to 12 months [NEEDS INPUT: confirm] | Security & debugging | Rotated and deleted |
| Analytics data | [NEEDS INPUT: confirm GA window] | Service improvement | Expires per GA settings |
| Music-service tokens | Until disconnect / + 30 days | Power connected features | Deleted (and held encrypted while stored) |
We may retain limited data longer where required to comply with law or to establish, exercise, or defend legal claims.
We use technical and organisational measures appropriate to the risk, including:
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal-data breach affects you, we will notify you and the relevant Supervisory Authority where required by law.
If you are in the EU/EEA or UK, you have the right to:
To exercise any right, email [email protected]. We may need to verify your identity (typically by confirming control of your account email) before acting, to protect your data. We aim to respond within one month, extendable by two further months for complex requests, as the GDPR allows.
If you are a California resident, you have the right to:
How to submit. Email [email protected]. Authorized agents may submit requests with proof of authorisation; we may still ask you to verify your identity directly. We verify requests by confirming control of your account email and, for sensitive requests, additional account details. We respond to verifiable requests within 45 days, extendable by another 45 days with notice. If we decline a request, you may ask us to reconsider by replying to our response.
The Service is intended for users aged 13 and over and is not directed to children under 13. We do not knowingly collect personal data from children under 13.
In parts of the EU/EEA, the minimum age to consent to information-society services without parental authorisation is 16 (or a lower age, down to 13, set by national law). Where that applies and you are below the local digital-consent age, you should use the Service only with verifiable parental/guardian consent.
If you believe a child has provided us personal data without appropriate consent, contact [email protected] and we will delete it promptly. [NEEDS INPUT: confirm the App Store age rating and whether any users are under 16/18 in practice]
Frequency Matchuses your music-taste data — genres, favourite artists, listening habits — to build a taste profile (a numeric "vector") and compare it with other users to suggest people you might connect with. This is a form of profiling.
We do not use automated decision-making that produces legal or similarly significant effects within the meaning of GDPR Article 22.
Content you choose to make public — profile details, posts, ratings, reviews, and shared Hot Take answers — is visible to other users and, potentially, to the wider internet. Once public, it may be copied, cached, or archived by others and by search engines, and we cannot guarantee complete removal from such third-party systems. Please think before you post, and avoid sharing sensitive information you do not want public.
The Service links to and integrates with third-party services (e.g. Clerk, Last.fm, Deezer, Spotify, Apple Music). Their privacy practices are governed by their own policies, not this one. We encourage you to review them — for example, Clerk's Privacy Policy. We are not responsible for third-party content or data practices.
If Groupys is incorporated, restructured, merged, acquired, or its assets are sold (or in the event of insolvency), personal data may be transferred to a successor or acquirer as part of that transaction. We will require the recipient to honour this Policy or give you notice and choices as required by law.
We may update this Policy as the Service evolves. The "Last updated" date at the top reflects the latest version. For material changes, we will provide reasonable advance notice — typically by email or an in-app notice at least 14 days before the change takes effect — and, where required, seek your consent.
Groupys acts as Controller. The legal bases, rights, transfer safeguards, and complaint rights described in Sections 6, 8, 12, and 15 apply to you. You may complain to your local Supervisory Authority.
Sections 10, 11, and 16 set out your CCPA/CPRA rights, our position on sale/sharing, our treatment of sensitive PI, and how to submit requests (including via an authorised agent).
Residents of states with comprehensive privacy laws (e.g. Virginia, Colorado, Connecticut, Utah, and others) may have similar rights to access, correct, delete, and opt out of targeted advertising or profiling. Contact [email protected] to exercise them. [NEEDS INPUT: confirm which state laws apply based on your user base]
If you are elsewhere, your local law may grant additional rights; we will honour valid requests to the extent the law requires.
Confirm the following before publishing or relying on this Policy:
This document is a strong, structured draft — not legal advice. Please note:
© 2026 Groupys. All rights reserved. Return to homepage