The short version. We collect what we need to run a social music app: your account, what you log and post, and who you follow. We don't sell your data and we don't show ads. Analytics and crash reports carry only a random user id, never your email. You can download or delete everything from Settings.

1. Who is responsible

The controller of your personal data is [Company legal name], CNPJ[CNPJ], [Registered address], Brazil ("faxa", "we"). Our data protection officer (Encarregado, under the LGPD) is [DPO name], reachable atprivacy@faxa.app.

This policy covers the faxa app and faxa.app. It is written for users in Brazil (Lei Geral de Proteção de Dados, Lei 13.709/2018), the European Economic Area and the UK (GDPR / UK GDPR) and everywhere else we're available.

2. What we collect

You give us

Collected when you use faxa

From services you connect

3. Why we use it and on what legal basis

PurposeDataLegal basis (LGPD art. 7 / GDPR art. 6)
Create and run your account, show your diary, posts and profile, deliver previews, RSVPs and pollsAccount, activity, content, artist materialPerformance of a contract (our Terms)
Check the minimum ageYear of birthLegal obligation and contract
Send notifications you turned onPush tokens, settingsContract; you can turn them off
Show artists who listened to their previewsPreview listens, usernameContract (core feature of previews)
Spotify stats and importsSpotify tokens and dataConsent, which you can withdraw by disconnecting
Understand usage and fix bugsAnalytics and crash reports (user id only)Legitimate interest in a working, improving product
Safety, moderation, rate limits, copyright noticesReports, IP, content, noticesLegitimate interest, legal obligation, and the exercise of rights in legal proceedings
Answer youMessages and contact detailsLegitimate interest or contract
Keep records the law requiresAccess logs and recordsLegal obligation (for example, Marco Civil da Internet, Lei 12.965/2014)

We don't sell personal data, don't use it for third-party advertising and don't make automated decisions that have legal or similarly significant effects on you.

4. Who can see what

5. International transfers

Some providers store or process data outside Brazil and outside your country (for example, in the United States or the European Union). When that happens we rely on the safeguards the LGPD (art. 33) and GDPR (chapter V) allow, such as standard contractual clauses or adequacy decisions. Our database is hosted in[region].

6. How long we keep it

7. Your rights

Under the LGPD (art. 18) and the GDPR (arts. 15–22) you can:

For anything you can't do in the app, write to privacy@faxa.app. We may ask you to confirm you own the account, and we'll answer within 15 days (LGPD) or one month (GDPR).

8. Children

faxa is not for children under 13. We ask for your year of birth at sign-up and don't let people under 13 create an account. If we learn that a child under 13 has an account, we delete it. If you think that happened, write toprivacy@faxa.app. Users between 13 and 18 are treated with extra care, in line with the LGPD (art. 14) and the ECA (Lei 8.069/1990).

9. Security

Data is encrypted in transit, access to the database is controlled row by row, third-party keys and Spotify tokens live only on our servers, and audio previews are served through short-lived signed links. No system is perfect; if a breach puts you at risk, we'll tell you and the authorities as the law requires.

10. Changes

If we change this policy in a way that matters, we'll tell you in the app or by email before it takes effect. The date at the top shows the current version.

11. Contact

privacy@faxa.app · [Company legal name],[Registered address]. EU representative (GDPR art. 27), if required:[EU representative name and address].