Skip to content
LEGAL · PRIVACY

Privacy Policy

EFFECTIVE
[To be set]
UPDATED
[To be set]

1. About this Policy

This Privacy Policy explains how rivalz ("we", "us", "our") collects, uses, shares, and protects your personal data when you use the rivalz mobile application (iOS and Android), our website at rivalz.app, our administration tools, and any related services (together, the "Service").

We comply with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), the Privacy and Electronic Communications Regulations 2003 (PECR), and the UK Data Protection Act 2018.

If you do not agree with this Policy, please do not use the Service.

2. Who we are (Data Controller)

rivalz
[Trading address — to be supplied]
United Kingdom
Email: privacy@rivalz.app

You have the right to complain to the UK Information Commissioner's Office (ico.org.uk) or to your local European data protection authority.

3. The Service in plain terms

rivalz is a UK-focused social music platform. Artists upload short audio or video "snippets" (4–60 seconds). Listeners vote, comment, follow, save, and share. Artists compete in ranked ladder battles with a Glicko-2 rating system that promotes or demotes them across BRONZE → SILVER → GOLD → PLATINUM → DIAMOND → ELITE tiers. The Service also includes direct messages, artist-led communities, leaderboards, badges, and an in-app purchase system for virtual gems.

4. What we collect

4.1 Account and identity

4.2 Profile and settings

Username, display name, artist name, profile photo, bio (max 500 chars), location (free-text city only — no GPS), music genres, external links (Spotify, Apple Music, SoundCloud, Bandcamp, YouTube, Instagram, TikTok, Twitter/X), privacy toggles, ~25 app preferences, follow graph, blocks, and discovery feedback.

4.3 Content you upload

Audio and video snippets, titles, descriptions, captions, hashtags, tags, BPM, key, waveform data, thumbnails, background styling, visibility setting, and the automated moderation outcome on your content. Audio/video qualifies as biometric data under UK GDPR Article 4(14); we process it under your explicit consent (Article 9(2)(a)) at upload.

4.4 Interactions

Votes (likes), favourites (saves), comments, comment likes, listening / viewing events (plays, watches, shares, skips, completions, not-interested, hide-creator), and per-tag affinity scores derived from these.

4.5 Battle and competition data

Battle pairings, votes cast, vote weighting signals, your Glicko-2 rating + division, voter statistics (30-day activity, diversity, account-health), monthly tier snapshots, battle chat messages and per-battle mutes, and the Early Backer snapshot — the recipient artist's follower count at the moment of your vote (see Section 13).

4.6 Messaging

DM content (text, media URLs, snippet shares, reactions) and system messages from rivalz.

4.7 Communities

Community metadata, membership tiers, and channel messages.

4.8 Safety and moderation records

Reports you file or that are filed against you, moderation actions taken (with reasons and notes), and badges awarded to you (immutable public achievements).

4.9 Device and technical data

Push notification token (Apple APNs or Google FCM, via Expo), platform / app version / session ID in analytics, IP address (transient — only a salted SHA-256 hash stored for the landing-site waitlist), user-agent (truncated for waitlist), and on-device secure storage of session tokens.

4.10 Telemetry (crash and error reporting)

We use Sentry to collect crash reports. We send only your opaque account ID — never your email, username, or DM content. Session replays mask all text, images, and vectors. You can opt out via the in-app consent banner (Settings → Privacy).

4.11 In-app purchases

Gem purchases go through Apple App Store IAP (iOS) or Google Play Billing (Android). We receive the transaction ID, original transaction ID, product ID, an opaque app-account token, the bundle ID, and the purchase timestamp. We do not receive your payment card details.

4.12 What we do NOT collect

5. Special-category data (Article 9)

Audio and video can contain your voice and your face. Under UK GDPR Article 4(14), biometric data is a special category even where we do not use it for identification.

We process this under Article 9(2)(a) — explicit consent, given at upload. By tapping "Upload" you confirm the recording is yours (or you have permission to share it) and consent to rivalz processing it for the purposes in this Policy.

We do not currently perform biometric identification or profiling. If we ever change this, we will ask for fresh consent first.

6. How we share your data (Sub-processors)

We use the following providers under Data Processing Agreements. Where data leaves the UK/EEA, we rely on the UK IDTA and/or EU SCCs.

We do not sell your personal data. We do not share it with advertisers. We may disclose data in response to a legally binding request from an authority, a valid court order, or to protect safety.

7. How long we keep your data

8. Your rights

Under UK GDPR you have these rights. Most are exercisable in-app; the rest by emailing privacy@rivalz.app (we respond within one calendar month).

9. Children

rivalz is for users aged 13 and over. We ask your age at signup and do not knowingly collect personal data from anyone under 13. If you believe a user is under 13, report the account in-app (Report → Suspected under-13) or email safety@rivalz.app.

The App Store rating is 17+ (Apple) / Mature (Google) because the music routinely contains explicit lyrics. Parents and guardians of users aged 13–17 should review this policy with them.

10. Automated decision-making (Article 22)

Several parts of the Service make automated decisions about you that have a meaningful effect:

You have the right to: request human review (email support@rivalz.app — response within 14 days), express your point of view, and contest the decision.

11. Direct Messages

DMs are stored on our servers in plaintext (not end-to-end encrypted). They are protected by row-level security so only sender and recipient can read them.

rivalz staff may access DM content only when strictly necessary for safety, abuse prevention, or to respond to a valid legal request. Routine staff browsing of DMs is forbidden by internal policy.

12. Storage and security

Audio/video files are in private storage buckets gated by row-level security; reads require a short-lived signed URL. Authentication tokens on your device are in iOS Keychain or Android Keystore. All data in transit is encrypted with TLS. Sentry session replays mask all text, images, and vectors. Production secrets and service-role keys are never in the mobile app. Your IP is hashed before storage in the landing-site waitlist.

No service can guarantee absolute security. If a personal-data breach affects you, we will notify the ICO within 72 hours where required and notify you without undue delay where the breach is high-risk to your rights.

13. Special retention notices

13.1 Monthly leaderboard snapshots

At month-end your final rank, points, division, and active-pool size are written into a permanent table. This is public and forms historical leaderboards. On account deletion your row is anonymised but persists.

13.2 Early Backer

You become an Early Backer of an artist if you vote for them while their follower count is below 1,000. A snapshot of their follower count at the moment of your vote is recorded permanently. The relationship is bilateral and private (only you and the artist see the badge).

On account deletion, your identifier is removed but the snapshot persists. By voting you accept this permanent record. If you do not want one, do not vote for artists below the 1,000 threshold.

13.3 Moderation records

Warnings, suspensions, and bans are kept for 6 years for legal-claim defence and the repeat-violator policy, even after account deletion.

13.4 Content shared into a DM

If you share a snippet into a DM and delete the snippet, the message still exists on the recipient's side (with the snippet reference set to null). We cannot reach into a recipient's account to delete a message you sent them.

14. International data transfers

Most user data sits in Supabase EU-West-2 (London) and never leaves the UK/EEA. The exceptions are in Section 6; for each, we rely on the UK IDTA and/or EU SCCs and a Transfer Risk Assessment.

15. Cookies and similar technologies

The landing site uses only strictly-necessary Vercel routing cookies (exempt under PECR §6(4)(b)). The mobile app does not use browser cookies and loads no third-party scripts.

16. Marketing communications

We do not currently send marketing emails. If we ever start, only after a clear opt-in, and every message will have an unsubscribe link. Service emails (verification, password reset, security) are not marketing.

System messages inside the app (announcements, moderation notices, change-of-terms) are operational; you cannot opt out without losing access. We never use system messages for marketing.

17. Third-party services and links

The Service contains links to third-party services. When you click through, you leave rivalz and the destination's privacy policy applies. QR codes encode only your public profile URL. Sharing via Snapchat, WhatsApp, or the system share sheet is governed by the destination once you tap Send.

18. Changes to this Policy

We may update this Policy. When we make material changes we will notify you via a system message in the App and update the "Last Updated" date at the top. Continued use after the update means you have read and accepted the change.

19. Contact us

Postal address: [Trading address — to be supplied]