arrow_backBack to Groupys

Legal

Privacy Policy

Effective date: 7 June 2026·Last updated: 7 June 2026

This Privacy Policy explains how Groupys collects, uses, shares, and protects your personal data, and the rights you have over it. It is written to support compliance with the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018 where relevant, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the ePrivacy / cookie rules, and general international privacy best practice. We have tried to keep the legal language clear enough for everyday readers.

1. Introduction

Groupys ("Groupys", "we", "us", or "our") is a community-based music platform that lets people share music taste, post and rate albums in communities, answer the Weekly Hot Take, and discover like-minded listeners through the Frequency Match feature. Groupys is currently operated as a student project developed at a European university and is not yet incorporated as a registered company. It is operated by the Groupys development team (the "Operator").

This Privacy Policy applies to the Groupys website at groupys.app, the Groupys mobile application, and all related features and services (together, the "Service"). It does not apply to third-party services we link to or integrate with, which have their own privacy practices (see Section 20).

If you do not agree with this Policy, please do not use the Service. For questions or to exercise your rights, contact us at [email protected].

2. Definitions

The following terms are used throughout this Policy:

TermMeaning
Personal data / Personal informationAny information relating to an identified or identifiable natural person (e.g. name, email, online identifier). Used here interchangeably across GDPR (“personal data”) and CCPA/CPRA (“personal information”).
ProcessingAny operation performed on personal data — collection, storage, use, disclosure, deletion, etc.
ControllerThe party that determines the purposes and means of processing personal data.
Processor / Service ProviderA party that processes personal data on behalf of, and under the instructions of, the Controller / Business.
Third PartyA party other than the data subject, controller, or processor who may receive or process data for its own purposes.
Data SubjectThe living individual to whom personal data relates (GDPR).
ConsumerA California resident whose personal information is processed (CCPA/CPRA).
Business / ContractorCCPA/CPRA roles: the entity determining purposes/means (Business); a party receiving PI for a business purpose under contract (Service Provider/Contractor).
Sensitive data / Sensitive personal informationSpecial-category data under GDPR (e.g. health, race, religion, biometrics) and “sensitive personal information” under CPRA (e.g. precise geolocation, account login credentials, contents of private messages).
Sub-processorA processor engaged by our processor to help deliver the service.
Cookies / tracking technologiesSmall files or identifiers (cookies, pixels, SDKs, local storage) used to store or read information on your device.
Automated decision-making / ProfilingDecisions made by automated means, and the automated evaluation of personal aspects (e.g. preferences, interests) to analyse or predict.
Authorized AgentA person or entity a consumer authorises to submit privacy requests on their behalf.
Supervisory AuthorityAn independent public authority that monitors GDPR application (e.g. a national Data Protection Authority).

3. Our Role

For most processing described in this Policy, Groupys acts as the Data Controller under the GDPR and as a Business under CCPA/CPRA, because we decide what data is collected and why.

We engage third-party vendors that act as our Processors / Service Providers (e.g. our authentication provider and email provider) — they process data only on our documented instructions. The independent music providers we query (e.g. Last.fm, Deezer, Spotify, Apple Music) generally act as independent third parties / separate controllers for the data they receive under their own terms.

Where you connect a third-party music account (for example, Apple Music) to power a feature, Groupys and that provider may each act as independent controllers for their respective processing. We do not currently consider ourselves a Joint Controller with any vendor; if that changes, we will update this Policy and put a joint-controller arrangement in place.

4. Personal Information We Collect

We collect only the data we need to run the Service. The table below maps each category to its source, purpose, GDPR legal basis, CCPA/CPRA category, retention, and whether it is shared with vendors. "Active + 30 days" means data is kept while your account is active and deleted within 30 days after account deletion, unless law requires longer.

CategoryExamplesSourcePurposeGDPR legal basisCCPA/CPRA categoryRetentionShared with vendors?
Account & identity dataEmail, username, user ID, password credentials (managed by Clerk)You / ClerkCreate and secure your account, authenticate loginsContract (Art. 6(1)(b))Identifiers; account login infoActive + 30 daysYes — Clerk
Profile contentDisplay name, avatar, banner, custom background, coloured username, Album of the WeekYouDisplay your profile to you and othersContract; Consent for optional fieldsIdentifiers; customer recordsActive + 30 daysStorage (MinIO) — self-hosted
Community activity / user-generated contentPosts, comments, ratings, album reviewsYouOperate communities; show your contributionsContract; Legitimate interestsInternet/network activity; customer recordsActive; public posts may persist anonymised (see §13)Storage — self-hosted
Weekly Hot Take answersYour answers (public or private)YouPower the Weekly Hot Take; enrich your profile if sharedConsent (public sharing); Contract (private storage)Internet/network activityActive + 30 daysNo
Match / taste preferencesGenre preferences, favourite artists, listening habits, taste vectorsYou / connected music accountsPower Frequency Match recommendationsConsentInferences; internet/network activityActive + 30 daysMusic APIs (for lookups)
Communications / support dataEmails to us, support requests, in-app messagesYouRespond to you; deliver in-app messagingContract; Legitimate interestsCustomer records; contents of communicationsActive + up to 24 months Email provider (Resend)
Device & notification dataExpo push token, device type, OS, notification preferencesYour deviceDeliver push notifications you opted intoConsent; ContractIdentifiers; internet/network activityUntil token unregistered / Active + 30 daysExpo, Apple (APNs)
Usage & log dataIP address, browser/app type, pages/screens, timestamps, error logsAutomaticSecurity, debugging, performanceLegitimate interests (Art. 6(1)(f))Internet/network activity; identifiersServer logs typically up to 12 monthsHosting (self-managed)
Analytics dataAggregated/pseudonymous usage events (if Google Analytics is enabled)Automatic (cookies/SDK)Understand and improve the ServiceConsent (where required)Internet/network activityPer GA settings — [NEEDS INPUT: confirm GA retention window]Yes — Google
Cookie & tracking identifiersSession token, consent state, analytics IDsAutomaticKeep you logged in; remember consent; analyticsStrictly necessary (no consent); Consent (analytics)Identifiers; internet/network activitySession to 12 months (see §7)See §7 / §9
Music-service tokensApple Music user token (encrypted at rest)You (when you connect an account)Fetch your music data for connected featuresConsentAccount login info (sensitive)Until you disconnect / Active + 30 daysApple Music
Marketing preferencesOpt-in/opt-out status for any product emailsYouSend only communications you allowConsent; Legitimate interests (service emails)Customer recordsActive + 30 daysEmail provider (Resend)

Children's data. The Service is not directed to children under 13, and we do not knowingly collect their data (see Section 17).

Sensitive data.We do not intentionally collect GDPR special-category data. Some categories above (login credentials, message contents, music-service tokens) are "sensitive personal information" under CPRA; see Section 11. Music taste itself is not special-category data, but content you post could reveal sensitive details — please do not share more than you intend.

5. How We Collect Information

  • Directly from you — when you register, build a profile, post content, answer the Weekly Hot Take, set match preferences, or contact support.
  • Automatically — through server logs, cookies, local storage, and mobile SDKs when you use the Service (device data, usage data, analytics where enabled).
  • From our authentication provider (Clerk) — account and credential data is handled through Clerk during sign-up and login.
  • From connected accounts — if you connect a music account (e.g. Apple Music), we receive the data needed to power that feature.
  • From third-party APIs — we query music providers (Last.fm, Deezer, Spotify, Apple Music) to display artist/album data; these calls are generally not tied to your identity beyond what a feature requires.

6. Why We Use Personal Information

PurposeGDPR legal basis
Provide and operate the ServiceContract (Art. 6(1)(b))
Create and manage your accountContract
Power Frequency Match and recommendationsConsent
Display your public profile, posts, ratings, shared Hot TakesContract; Consent (for content you choose to make public)
Deliver push notifications (e.g. the Weekly Hot Take)Consent; Contract
Customer support and communicationsContract; Legitimate interests
Security, abuse prevention, and fraud detectionLegitimate interests; Legal obligation
Analytics and Service improvementConsent (analytics cookies); Legitimate interests (aggregate insights)
Product/marketing emails (if any)Consent
Comply with legal obligations and respond to authoritiesLegal obligation (Art. 6(1)(c))
Establish, exercise, or defend legal claims; enforce our TermsLegitimate interests
Protect the vital interests of a person in an emergencyVital interests (Art. 6(1)(d)) — only if truly applicable

Legitimate-interest balancing. Where we rely on legitimate interests, we have considered whether our interest (e.g. keeping the Service secure, improving it, defending claims) is overridden by your rights and freedoms, and we limit processing to what is necessary and proportionate. You can object at any time (see Section 15), and we will stop unless we have compelling legitimate grounds or need the data for legal claims. You can request a summary of a relevant balancing assessment by emailing [email protected].

7. Cookies & Tracking Technologies

We use cookies, local storage, and mobile SDKs to keep you logged in, remember your consent choices, and — where you allow it — measure usage. Strictly necessary cookies do not require consent; analytics and any non-essential cookies are set only with your consent where the law requires it. You can change your choices at any time via your browser/device settings and, where offered, our in-product cookie controls.

Cookie / toolProviderPurposeTypeDurationLegal basisOpt-out
Session / auth tokenClerk / GroupysKeep you signed inStrictly necessarySessionStrictly necessary (no consent)Cannot be disabled without breaking login
Consent stateGroupysRemember your cookie/consent choicesStrictly necessaryUp to 12 monthsStrictly necessaryClearing site data resets it
Google Analytics (_ga, _gid, etc.)GoogleAggregate usage analytics (only if GA is enabled)AnalyticsUp to 24 monthsConsentDecline analytics in the consent banner; browser controls; Google opt-out add-on
Other cookies/SDKs[NEEDS INPUT: provider][NEEDS INPUT: purpose][NEEDS INPUT: type][NEEDS INPUT: duration][NEEDS INPUT: legal basis][NEEDS INPUT: opt-out]

[NEEDS INPUT: Confirm the exact cookie/SDK names actually set in production and whether a consent management banner is deployed. Analytics must not load before consent in the EU/UK.]

9. How We Share Personal Information

We do not sell your personal data. We share it only as described below. Processors / Service Providers act on our instructions; independent third parties act under their own terms.

RecipientRoleWhat is sharedWhy
ClerkProcessor / Service ProviderAccount & credential dataAuthentication and account security
ResendProcessor / Service ProviderEmail address, message contentTransactional and (opt-in) product emails
Google (Analytics)Processor / potentially Third PartyPseudonymous usage events, identifiersAnalytics (only if enabled and consented)
Expo + Apple (APNs)Processors / independent operatorsPush token, notification payloadDeliver push notifications
Apple Music / Last.fm / Deezer / SpotifyIndependent third parties / controllersFeature-specific requests; connected-account dataDisplay music data; power connected features
Hosting & storage (self-managed servers, Postgres, MinIO)Processor / infrastructureAll stored data, at restRun the Service
Professional advisorsRecipientsAs neededLegal, accounting, or compliance advice
Authorities / law enforcementThird partiesAs legally requiredComply with valid legal process
Acquirer / successorThird partyRelevant dataBusiness transfers (see §21)

We do not currently use advertising partners or share data for cross-context behavioural advertising. If analytics tools are configured in a way that transmits identifiers to a third party for that party's own purposes, that activity is addressed in Section 10.

10. Sale or Sharing of Personal Information (CCPA/CPRA)

We do notsell your personal information for money. We also do not knowingly "share" it for cross-context behavioural advertising in the way CCPA/CPRA defines those terms.

Analytics caveat.Under CPRA, using certain third-party analytics or pixels can be treated as a "sale" or "sharing" even without payment, because identifiers may be made available to the provider. If Google Analytics (or a similar tool) is enabled, we treat this conservatively and offer an opt-out. [NEEDS INPUT: Confirm whether GA is live in production and whether its configuration constitutes a "sale/share"; if so, honour opt-out signals before loading it.]

If you are a California consumer, you have the right to:

  • Opt out of sale/sharing — email [email protected]with "Do Not Sell or Share My Personal Information", or decline analytics in our consent banner.
  • Global Privacy Control (GPC) — where applicable, we aim to treat a recognised GPC browser signal as a valid opt-out request. [NEEDS INPUT: confirm GPC detection is implemented]
  • Authorized agent — you may use an authorised agent (see Section 16).
  • Non-discrimination — we will not discriminate against you for exercising your rights.

11. Sensitive Personal Information

We do not seek out GDPR special-category data. Under CPRA, the following may qualify as "sensitive personal information":

  • Account login credentials (handled via Clerk).
  • The contents of private messages or private Hot Take answers.
  • Music-service access tokens (stored encrypted at rest).

We use this information only to provide the features you requested, secure your account, and comply with law — notto infer characteristics about you and not for purposes beyond those permitted under CPRA § 7027. Because our use is limited to these permitted purposes, the CPRA "right to limit" generally does not change our processing; even so, you may contact [email protected] to ask us to limit any sensitive-data use. We protect this data with encryption and access controls (see Section 14).

12. International Data Transfers

Groupys is operated from Europe, and our primary database and object storage are self-managed [NEEDS INPUT: confirm server location/region and hosting provider]. Some vendors are based outside the EU/EEA/UK (notably in the United States), so your data may be transferred and processed there.

VendorLikely locationTransfer safeguard
ClerkUnited StatesStandard Contractual Clauses / EU-US Data Privacy Framework
ResendUnited StatesStandard Contractual Clauses
Google (Analytics)United StatesSCCs / EU-US DPF
ExpoUnited StatesSCCs
Apple (APNs / Apple Music)United StatesSCCs / DPF
Last.fm / Deezer / Spotify[NEEDS INPUT: confirm][NEEDS INPUT: confirm safeguard]

Where we transfer personal data outside the EU/EEA or UK, we rely on appropriate safeguards — Standard Contractual Clauses (with the UK International Data Transfer Addendum for UK data), adequacy decisions where they exist, and vendor due diligence. We carry out a Transfer Impact Assessment where required. [NEEDS INPUT: verify each vendor's current transfer mechanism and complete TIAs as needed]

13. Data Retention

We keep personal data only as long as necessary for the purposes set out in this Policy, then delete or anonymise it.

Data categoryRetentionReasonDeletion / anonymisation
Account, profile, preferencesWhile active + 30 days after deletionOperate the accountHard-deleted from database and storage
Public posts, ratings, reviewsMay persist in anonymised form after deletionPreserve community historyDe-linked from your identity unless you request full removal
Private Hot Take answersActive + 30 daysFeature deliveryHard-deleted
Support / communicationsUp to 24 months [NEEDS INPUT: confirm]Handle and audit supportDeleted on schedule
Push tokensUntil unregistered / + 30 daysDeliver notificationsPruned automatically when invalid
Server / security logsUp to 12 months [NEEDS INPUT: confirm]Security & debuggingRotated and deleted
Analytics data[NEEDS INPUT: confirm GA window]Service improvementExpires per GA settings
Music-service tokensUntil disconnect / + 30 daysPower connected featuresDeleted (and held encrypted while stored)

We may retain limited data longer where required to comply with law or to establish, exercise, or defend legal claims.

14. Data Security

We use technical and organisational measures appropriate to the risk, including:

  • Encryption in transit (HTTPS/TLS) and encryption of sensitive tokens at rest.
  • Authentication and credential management handled by a specialist provider (Clerk).
  • Access controls and least-privilege access to production systems.
  • Network isolation — application services bound behind a reverse proxy.
  • Logging and monitoring for errors and suspicious activity.
  • Backups and a documented restore process.
  • Dependency and vulnerability management.
  • Confidentiality expectations for everyone with data access.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal-data breach affects you, we will notify you and the relevant Supervisory Authority where required by law.

15. Your GDPR Rights

If you are in the EU/EEA or UK, you have the right to:

  • Access — get a copy of your personal data.
  • Rectification — correct inaccurate data.
  • Erasure — delete your data ("right to be forgotten").
  • Restriction — limit how we process your data.
  • Portability — receive your data in a structured, machine-readable format.
  • Object — object to processing based on legitimate interests or to direct marketing.
  • Withdraw consent — at any time, without affecting prior processing.
  • Automated decisions — rights relating to automated decision-making and profiling (see Section 18).
  • Lodge a complaint— with your local Supervisory Authority. We'd appreciate the chance to resolve concerns first.

To exercise any right, email [email protected]. We may need to verify your identity (typically by confirming control of your account email) before acting, to protect your data. We aim to respond within one month, extendable by two further months for complex requests, as the GDPR allows.

16. Your California Privacy Rights

If you are a California resident, you have the right to:

  • Know / access the categories and specific pieces of PI we collect, use, and disclose.
  • Delete PI we hold about you, subject to legal exceptions.
  • Correct inaccurate PI.
  • Opt out of any sale or sharing of PI (see Section 10).
  • Limit the use of sensitive PI to permitted purposes (see Section 11).
  • Data portability — receive PI in a portable format where applicable.
  • Non-discrimination for exercising your rights.

How to submit. Email [email protected]. Authorized agents may submit requests with proof of authorisation; we may still ask you to verify your identity directly. We verify requests by confirming control of your account email and, for sensitive requests, additional account details. We respond to verifiable requests within 45 days, extendable by another 45 days with notice. If we decline a request, you may ask us to reconsider by replying to our response.

17. Children's Privacy

The Service is intended for users aged 13 and over and is not directed to children under 13. We do not knowingly collect personal data from children under 13.

In parts of the EU/EEA, the minimum age to consent to information-society services without parental authorisation is 16 (or a lower age, down to 13, set by national law). Where that applies and you are below the local digital-consent age, you should use the Service only with verifiable parental/guardian consent.

If you believe a child has provided us personal data without appropriate consent, contact [email protected] and we will delete it promptly. [NEEDS INPUT: confirm the App Store age rating and whether any users are under 16/18 in practice]

18. Automated Decision-Making, AI & Profiling

Frequency Matchuses your music-taste data — genres, favourite artists, listening habits — to build a taste profile (a numeric "vector") and compare it with other users to suggest people you might connect with. This is a form of profiling.

  • Data used: your stated preferences and taste signals you provide or connect.
  • Purpose: recommend potential connections and relevant content.
  • Impact: it affects suggestions only — it does not produce legal or similarly significant effects, set prices, or restrict access.
  • Control: Frequency Match runs on consent. You can decline it, edit or remove your preferences, or stop using the feature at any time.
  • Human review / objection: contact [email protected] to object to profiling or request human review.

We do not use automated decision-making that produces legal or similarly significant effects within the meaning of GDPR Article 22.

19. User Content & Public Areas

Content you choose to make public — profile details, posts, ratings, reviews, and shared Hot Take answers — is visible to other users and, potentially, to the wider internet. Once public, it may be copied, cached, or archived by others and by search engines, and we cannot guarantee complete removal from such third-party systems. Please think before you post, and avoid sharing sensitive information you do not want public.

21. Business Transfers

If Groupys is incorporated, restructured, merged, acquired, or its assets are sold (or in the event of insolvency), personal data may be transferred to a successor or acquirer as part of that transaction. We will require the recipient to honour this Policy or give you notice and choices as required by law.

22. Changes to This Privacy Policy

We may update this Policy as the Service evolves. The "Last updated" date at the top reflects the latest version. For material changes, we will provide reasonable advance notice — typically by email or an in-app notice at least 14 days before the change takes effect — and, where required, seek your consent.

23. Contact Information

  • Operator: Groupys (student project; not yet an incorporated company)
  • Privacy / data requests: [email protected]
  • General contact: [email protected]
  • Mailing address: [NEEDS INPUT: add a postal address before publishing if required by your stores/jurisdiction]
  • Data Protection Officer: not appointed — [NEEDS INPUT: confirm a DPO is not legally required for your processing]
  • EU/UK Representative: not appointed — [NEEDS INPUT: confirm whether an Art. 27 representative is required]

24. Region-Specific Notices

EU/EEA & UK users

Groupys acts as Controller. The legal bases, rights, transfer safeguards, and complaint rights described in Sections 6, 8, 12, and 15 apply to you. You may complain to your local Supervisory Authority.

California users

Sections 10, 11, and 16 set out your CCPA/CPRA rights, our position on sale/sharing, our treatment of sensitive PI, and how to submit requests (including via an authorised agent).

Other US state privacy laws

Residents of states with comprehensive privacy laws (e.g. Virginia, Colorado, Connecticut, Utah, and others) may have similar rights to access, correct, delete, and opt out of targeted advertising or profiling. Contact [email protected] to exercise them. [NEEDS INPUT: confirm which state laws apply based on your user base]

Other jurisdictions

If you are elsewhere, your local law may grant additional rights; we will honour valid requests to the extent the law requires.

25. Compliance Gap Checklist

Confirm the following before publishing or relying on this Policy:

  • Exact data categories actually collected match Section 4.
  • Final vendor / sub-processor list (Clerk, Resend, Google, Expo, Apple, music APIs, hosting).
  • Real cookie/SDK list and a deployed consent banner (analytics gated until consent in EU/UK).
  • Confirmed retention periods (support, logs, analytics).
  • International-transfer countries and per-vendor safeguards (SCCs/DPF/UK IDTA) + TIAs.
  • Whether analytics/pixels count as "sale/share" under CPRA; GPC handling.
  • Whether any sensitive data is processed beyond permitted purposes.
  • Actual minimum-age handling and App Store age rating; under-16 consent flow.
  • AI/profiling scope (Frequency Match) and opt-out mechanics.
  • Whether a DPO and/or EU/UK Art. 27 Representative is legally required.
  • Working consumer/data-subject request workflow and identity verification.
  • Security measures as actually implemented.
  • Signed Data Processing Agreements with each processor; documented sub-processor list.
  • Records of Processing Activities (Art. 30) maintained.
  • DPIA completed where processing is high-risk.
  • Legitimate Interest Assessments documented for each LI basis.
  • A postal contact address and (if incorporated) legal entity details.

26. Legal Review Notes

This document is a strong, structured draft — not legal advice. Please note:

  • A qualified privacy lawyer or DPO should review it before you rely on it.
  • The Policy must match your actual practices; inaccurate statements create legal and regulatory risk.
  • Technical implementation must match the words here — especially cookie consent, opt-outs, GPC, deletion requests, and vendor data flows.
  • We make no absolute guarantee of compliance or security; obligations differ by jurisdiction and processing.
  • Resolve every [NEEDS INPUT: ] marker above before publishing.
  • If Groupys incorporates, update the controller identity, address, and any representative/DPO details.

© 2026 Groupys. All rights reserved. Return to homepage