Privacy Policy
**Effective date:** 11 June 2026
**Version:** 1.3
This Privacy Policy describes how The Rock God ("Rock God", "we", "us", or "our") collects, uses, and shares information about you when you use our music discovery service via the web app, progressive web app (PWA), or any related interfaces (collectively, the "Service").
By using the Service, you agree to the practices described in this policy. If you do not agree, please do not use the Service.
1. Information we collect
We collect only the information needed to operate the Service. Specifically:
- **Account information** — your email address, an encrypted password hash (if you register with email/password), and the language you've chosen.
- **Recommendation sessions** — the inputs you provided (artists or songs), the recommendations we generated for you, and any title you gave the session. These let you revisit and share past discoveries.
- **Usage data via Heap.io** — Heap.io collects anonymized interaction events (clicks, page views, errors) so we can improve the Service. This analytics runs by default; you can opt out by blocking cookies and local storage for this site in your browser settings.
- **Audit logs** — security-relevant events (admin actions and account deletions) are written to an internal audit log accessible only to authorized administrators.
We do **not** collect: phone numbers, real names, postal addresses, dates of birth, precise location, advertising identifiers, biometric data, financial account numbers, or any data about users under 13.
2. Why we collect it — lawful bases under GDPR
Under the EU and UK General Data Protection Regulation (GDPR), every collection of personal data needs a lawful basis. Ours are:
- **Performance of contract** (Article 6(1)(b)) — account information and recommendation sessions. Without these, we cannot deliver the Service you signed up for.
- **Legitimate interest** (Article 6(1)(f)) — security audit logs, basic operational error logs, transient IP-based rate limiting to deter abuse, and anonymized product analytics (Heap.io) used to understand how the Service is used and improve it. We've weighed these against your rights and concluded that the processing is narrowly scoped and necessary to keep the Service trustworthy. You can object to analytics processing at any time (see Section 5) by blocking cookies and local storage for this site.
3. How long we keep it
- **Active account data** is retained for as long as your account exists.
- **Soft-deleted account data** is retained for **90 days** after you delete your account, then purged permanently. This window exists in case you change your mind or we need to investigate fraud.
- **Audit logs** are retained for **2 years** to support security investigations and regulatory inquiries.
- **Last.fm cache data** is stored briefly (up to 30 days) to reduce duplicate API calls; it is keyed by a hash of the query, not by user.
When a retention period ends, the data is deleted in full from active systems and from backups during the next backup-rotation cycle (no later than 35 days).
4. Who we share it with
We share information only with third parties who help us operate the Service, and only the minimum data each one needs:
- **Resend (Resend, Inc.)** — transactional email (account verification and security notices). Receives your email address and the message body. Resend's privacy policy.
- **Heap, Inc. (Heap.io)** — product analytics. Receives anonymized event data. Heap's privacy policy.
- **Amazon Web Services (AWS)** — hosting and storage. Receives all data described above, encrypted at rest and in transit. AWS's privacy notice.
- **Last.fm (Audioscrobbler Ltd.)** — music similarity data. Receives the artist or track name you searched for; receives no information about you personally. Last.fm's privacy policy.
We do **not** sell or rent personal information to anyone, ever. We do **not** share data with advertising networks.
We may disclose information if compelled by valid legal process (subpoena, court order) — in which case we will notify you unless prohibited by law.
5. Your choices
- **Analytics** — Heap.io analytics loads by default. To turn it off, block cookies and local storage for this site in your browser; this disables it without affecting any feature.
- **What you store** — recommendation sessions contain only the artists, songs, and titles you choose to enter. Don't enter anything you'd rather we not keep.
- **EU / EEA / UK** — the Service is **not offered** in those regions; visitors there are blocked (see the Terms). Because we do not knowingly serve data subjects there, the GDPR / UK GDPR data-subject-request process does not apply.
This is a small personal hobby project with **no support inbox**, so we cannot action individual data requests by email.
6. California users (CCPA / CPRA)
We do **not** sell or share your personal information for cross-context behavioral advertising, we do **not** collect "sensitive personal information" as the CPRA defines it, and we will not discriminate against you for exercising any privacy right. As a small non-commercial project we fall well below the CCPA's business thresholds; the limited data we hold is listed in Section 1, and you can disable analytics from your browser (Section 5).
7. Cookies
We use the following cookies and similar storage:
- **Session cookies (essential)** — set by our authentication system to keep you signed in. These cannot be disabled because the Service does not work without them.
- **Refresh-token cookies (essential)** — `HttpOnly`, `Secure`, and `SameSite=Lax` so we can quietly refresh your access token without forcing you to sign in again.
- **Analytics cookies and local storage** — set by Heap.io to measure product usage. They contain a randomly-generated identifier; no personal data is encoded in them. These load by default. You can block or delete them in your browser settings without losing access to any feature.
Most browsers let you block or delete cookies in their settings. Blocking essential cookies may sign you out and require re-authentication; blocking analytics storage only opts you out of Heap.io.
8. Requests
This is a hobby project run by one person, with no support inbox. The controls in Section 5 (disabling analytics, choosing what you enter) are the practical way to manage your data. Self-service account deletion is planned but not yet available.
9. Where your data lives
The Service is hosted in AWS's **us-east-1** region in the United States; all data is stored and processed there. The Service is not offered in the EU, EEA, or the UK, so EU/UK cross-border-transfer mechanisms (such as Standard Contractual Clauses) do not apply.
10. Children's privacy
The Service is **not directed at children under 13**, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it.
11. Security
We protect data with:
- **TLS 1.2+** for all data in transit.
- **AES-256 encryption at rest** for the production database and object storage.
- **Strict IAM least-privilege roles** for production AWS resources.
- **Encrypted application secrets** in AWS Secrets Manager with role-based access.
- **Audit logs** for security-relevant administrative actions.
- **Regular dependency and image scans** in our CI/CD pipeline.
No system is perfectly secure, but we take reasonable steps and notify affected users without undue delay if a personal-data breach occurs.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes (new categories of data, new sharing relationships, expanded retention) will be communicated:
- via **email** to your account address, **and**
- via an updated effective date and version number at the top of this policy.
We will not retroactively apply a material change to data already collected unless we get fresh consent.
13. Contact
This is a personal hobby project and does not operate a contact inbox. Updates to this policy are posted on this page with a new effective date and version number (Section 12).