1. About this Policy
This Privacy Policy explains how rivalz ("we", "us", "our") collects, uses, shares, and protects your personal data when you use the rivalz mobile application (iOS and Android), our website at rivalz.app, our administration tools, and any related services (together, the "Service").
We comply with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), the Privacy and Electronic Communications Regulations 2003 (PECR), and the UK Data Protection Act 2018.
If you do not agree with this Policy, please do not use the Service.
2. Who we are (Data Controller)
rivalz
[Trading address — to be supplied]
United Kingdom
Email: privacy@rivalz.app
You have the right to complain to the UK Information Commissioner's Office (ico.org.uk) or to your local European data protection authority.
3. The Service in plain terms
rivalz is a UK-focused social music platform. Artists upload short audio or video "snippets" (4–60 seconds). Listeners vote, comment, follow, save, and share. Artists compete in ranked ladder battles with a Glicko-2 rating system that promotes or demotes them across BRONZE → SILVER → GOLD → PLATINUM → DIAMOND → ELITE tiers. The Service also includes direct messages, artist-led communities, leaderboards, badges, and an in-app purchase system for virtual gems.
4. What we collect
4.1 Account and identity
- Email address — authentication, recovery (Contract)
- Hashed password (we never see plaintext)
- Account ID (UUID)
- Google or Apple sign-in token
- Date of birth / age confirmation (13+)
- Session tokens stored on your device in iOS Keychain / Android Keystore
4.2 Profile and settings
Username, display name, artist name, profile photo, bio (max 500 chars), location (free-text city only — no GPS), music genres, external links (Spotify, Apple Music, SoundCloud, Bandcamp, YouTube, Instagram, TikTok, Twitter/X), privacy toggles, ~25 app preferences, follow graph, blocks, and discovery feedback.
4.3 Content you upload
Audio and video snippets, titles, descriptions, captions, hashtags, tags, BPM, key, waveform data, thumbnails, background styling, visibility setting, and the automated moderation outcome on your content. Audio/video qualifies as biometric data under UK GDPR Article 4(14); we process it under your explicit consent (Article 9(2)(a)) at upload.
4.4 Interactions
Votes (likes), favourites (saves), comments, comment likes, listening / viewing events (plays, watches, shares, skips, completions, not-interested, hide-creator), and per-tag affinity scores derived from these.
4.5 Battle and competition data
Battle pairings, votes cast, vote weighting signals, your Glicko-2 rating + division, voter statistics (30-day activity, diversity, account-health), monthly tier snapshots, battle chat messages and per-battle mutes, and the Early Backer snapshot — the recipient artist's follower count at the moment of your vote (see Section 13).
4.6 Messaging
DM content (text, media URLs, snippet shares, reactions) and system messages from rivalz.
4.7 Communities
Community metadata, membership tiers, and channel messages.
4.8 Safety and moderation records
Reports you file or that are filed against you, moderation actions taken (with reasons and notes), and badges awarded to you (immutable public achievements).
4.9 Device and technical data
Push notification token (Apple APNs or Google FCM, via Expo), platform / app version / session ID in analytics, IP address (transient — only a salted SHA-256 hash stored for the landing-site waitlist), user-agent (truncated for waitlist), and on-device secure storage of session tokens.
4.10 Telemetry (crash and error reporting)
We use Sentry to collect crash reports. We send only your opaque account ID — never your email, username, or DM content. Session replays mask all text, images, and vectors. You can opt out via the in-app consent banner (Settings → Privacy).
4.11 In-app purchases
Gem purchases go through Apple App Store IAP (iOS) or Google Play Billing (Android). We receive the transaction ID, original transaction ID, product ID, an opaque app-account token, the bundle ID, and the purchase timestamp. We do not receive your payment card details.
4.12 What we do NOT collect
- No cross-app tracking — iOS Privacy Manifest declares NSPrivacyTracking = false.
- No IDFA.
- No third-party analytics SDKs (no Google Analytics, Mixpanel, Amplitude, Segment, PostHog, Meta Pixel, TikTok Pixel).
- No facial recognition or voice-print matching on your content.
- No precise GPS location — the OS permission is requested for a future feature; nothing is stored today.
5. Special-category data (Article 9)
Audio and video can contain your voice and your face. Under UK GDPR Article 4(14), biometric data is a special category even where we do not use it for identification.
We process this under Article 9(2)(a) — explicit consent, given at upload. By tapping "Upload" you confirm the recording is yours (or you have permission to share it) and consent to rivalz processing it for the purposes in this Policy.
We do not currently perform biometric identification or profiling. If we ever change this, we will ask for fresh consent first.
6. How we share your data (Sub-processors)
We use the following providers under Data Processing Agreements. Where data leaves the UK/EEA, we rely on the UK IDTA and/or EU SCCs.
- Supabase Inc. — Database, auth, storage, edge functions, realtime. EU-West-2 (London). No additional transfer mechanism needed.
- Sentry — Crash and error reporting (masked session replay). [Currently US; planned migration to EU region.] UK IDTA / SCCs.
- OpenAI L.L.C. — Automated text moderation of snippet titles, descriptions, and tags. US. UK IDTA / SCCs.
- Cloudflare Stream — Direct video upload and transcoding. Global edge. UK IDTA / SCCs.
- Vercel Inc. — Hosts landing site and admin dashboard; runs scheduled jobs. UK IDTA / SCCs if outside UK/EEA.
- Expo Inc. — Push relay (to APNs/FCM), OTA updates, build. US. UK IDTA / SCCs.
- Apple Inc. — Sign in with Apple, IAP, APNs. US. Apple Developer Program Agreement.
- Google LLC — Google Sign-In, Google Play billing, FCM. US. Google DPA.
- LiveKit Cloud — Live audio/video rooms (feature dormant for v1.0). UK IDTA / SCCs if outside UK/EEA.
We do not sell your personal data. We do not share it with advertisers. We may disclose data in response to a legally binding request from an authority, a valid court order, or to protect safety.
7. How long we keep your data
- Active account, snippets, interactions, social graph: until you delete your account
- Analytics events used for ranking: 13 months rolling
- Sentry events: 90 days
- Moderation records: 6 years from creation
- Closed reports: 2 years from closure
- Push tokens: revoked on sign-out; cleared after 90 days inactivity
- Waitlist signups: deleted at launch + 6 months
- Server access logs: 30 days
- Uploaded media: until snippet or account deletion
- Soft-deleted snippets: purged 30 days after soft-delete
- Monthly leaderboard snapshots: permanent, anonymised on account deletion
- Early Backer snapshots: permanent, anonymised on account deletion (Section 13.2)
- Badges awarded: permanent unless you request removal
8. Your rights
Under UK GDPR you have these rights. Most are exercisable in-app; the rest by emailing privacy@rivalz.app (we respond within one calendar month).
- Access — get a copy of your data
- Rectification — correct inaccurate data
- Erasure — delete your account (Settings → Account → Delete Account; subject to Section 13)
- Portability — get your data in a structured format
- Object — opt out of personalised ranking
- Restriction — limit how we use your data; blocking is a built-in restriction
- Withdraw consent — push: OS settings or sign out; crash reporting: in-app banner; personalisation: in-app toggle
- Complain to the ICO (ico.org.uk) or your local EU data protection authority
9. Children
rivalz is for users aged 13 and over. We ask your age at signup and do not knowingly collect personal data from anyone under 13. If you believe a user is under 13, report the account in-app (Report → Suspected under-13) or email safety@rivalz.app.
The App Store rating is 17+ (Apple) / Mature (Google) because the music routinely contains explicit lyrics. Parents and guardians of users aged 13–17 should review this policy with them.
10. Automated decision-making (Article 22)
Several parts of the Service make automated decisions about you that have a meaningful effect:
- Ladder matchmaking (Glicko-2) — who you battle, how your rating changes
- Artist tier rollover — monthly promotion / demotion, public division on your profile
- Tastemaker score — public reputation as a voter (correct predictions, streak, percentile)
- Automated content moderation — snippet text sent to OpenAI; "rejected" blocks publication
- Feed ranking — what appears at the top of your feed
- Vote weighting — how much your vote counts (activity, diversity, account-health)
You have the right to: request human review (email support@rivalz.app — response within 14 days), express your point of view, and contest the decision.
11. Direct Messages
DMs are stored on our servers in plaintext (not end-to-end encrypted). They are protected by row-level security so only sender and recipient can read them.
rivalz staff may access DM content only when strictly necessary for safety, abuse prevention, or to respond to a valid legal request. Routine staff browsing of DMs is forbidden by internal policy.
12. Storage and security
Audio/video files are in private storage buckets gated by row-level security; reads require a short-lived signed URL. Authentication tokens on your device are in iOS Keychain or Android Keystore. All data in transit is encrypted with TLS. Sentry session replays mask all text, images, and vectors. Production secrets and service-role keys are never in the mobile app. Your IP is hashed before storage in the landing-site waitlist.
No service can guarantee absolute security. If a personal-data breach affects you, we will notify the ICO within 72 hours where required and notify you without undue delay where the breach is high-risk to your rights.
13. Special retention notices
13.1 Monthly leaderboard snapshots
At month-end your final rank, points, division, and active-pool size are written into a permanent table. This is public and forms historical leaderboards. On account deletion your row is anonymised but persists.
13.2 Early Backer
You become an Early Backer of an artist if you vote for them while their follower count is below 1,000. A snapshot of their follower count at the moment of your vote is recorded permanently. The relationship is bilateral and private (only you and the artist see the badge).
On account deletion, your identifier is removed but the snapshot persists. By voting you accept this permanent record. If you do not want one, do not vote for artists below the 1,000 threshold.
13.3 Moderation records
Warnings, suspensions, and bans are kept for 6 years for legal-claim defence and the repeat-violator policy, even after account deletion.
13.4 Content shared into a DM
If you share a snippet into a DM and delete the snippet, the message still exists on the recipient's side (with the snippet reference set to null). We cannot reach into a recipient's account to delete a message you sent them.
14. International data transfers
Most user data sits in Supabase EU-West-2 (London) and never leaves the UK/EEA. The exceptions are in Section 6; for each, we rely on the UK IDTA and/or EU SCCs and a Transfer Risk Assessment.
15. Cookies and similar technologies
The landing site uses only strictly-necessary Vercel routing cookies (exempt under PECR §6(4)(b)). The mobile app does not use browser cookies and loads no third-party scripts.
16. Marketing communications
We do not currently send marketing emails. If we ever start, only after a clear opt-in, and every message will have an unsubscribe link. Service emails (verification, password reset, security) are not marketing.
System messages inside the app (announcements, moderation notices, change-of-terms) are operational; you cannot opt out without losing access. We never use system messages for marketing.
17. Third-party services and links
The Service contains links to third-party services. When you click through, you leave rivalz and the destination's privacy policy applies. QR codes encode only your public profile URL. Sharing via Snapchat, WhatsApp, or the system share sheet is governed by the destination once you tap Send.
18. Changes to this Policy
We may update this Policy. When we make material changes we will notify you via a system message in the App and update the "Last Updated" date at the top. Continued use after the update means you have read and accepted the change.
19. Contact us
- Privacy questions / data subject requests: privacy@rivalz.app
- Safety, suspected under-13 accounts: safety@rivalz.app
- Copyright (DMCA): copyright@rivalz.app
- General support, appeals: support@rivalz.app
Postal address: [Trading address — to be supplied]