The short version. We collect what we need to run a social music app: your account, what you log and post, and who you follow. We don't sell your data and we don't show ads. Analytics and crash reports carry only a random user id, never your email. You can download or delete everything from Settings.
1. Who is responsible
The controller of your personal data is [Company legal name], CNPJ[CNPJ], [Registered address], Brazil ("faxa", "we"). Our data protection officer (Encarregado, under the LGPD) is [DPO name], reachable atprivacy@faxa.app.
This policy covers the faxa app and faxa.app. It is written for users in Brazil (Lei Geral de Proteção de Dados, Lei 13.709/2018), the European Economic Area and the UK (GDPR / UK GDPR) and everywhere else we're available.
2. What we collect
You give us
- Account: email address, password (stored hashed by our authentication provider), username and display name, and optionally a profile photo and bio.
- Year of birth: to confirm you're at least 13. We don't ask for your full date of birth.
- Phone number (optional): only if you add it. It is kept in a private table, never shown on your profile.
- Your activity and content: music logs (date, rating, relisten), reviews, lists, "listen later", posts, comments, likes, reposts, saves, community and event discussions, setlist poll votes, RSVPs and event roles, follows and friendships, blocks and reports you make.
- Artist material: if you run an artist page, the releases, audio previews, artwork and details you upload, team membership, and information you send to verify or claim a page.
- Messages to us: support requests, copyright notices and counter-notices, and the contact details in them.
- Settings: language, notification preferences and privacy choices.
Collected when you use faxa
- Push tokens: a device token from Apple or Google so we can send the notifications you turned on.
- Preview listens: when you play an artist's preview, the artist sees that you listened, when, and which track. That is how previews on faxa work.
- Product analytics (PostHog): which screens and features are used (for example "log created", "preview played"), tied to your random user id only. No email, username or content is sent.
- Crash and error reports (Sentry): technical details about errors (device model, OS and app version, the error itself), tied to your user id only. IP addresses and email are not sent.
- Security data: your IP address is used briefly to rate-limit forms (for example copyright notices) and protect against abuse.
- Approximate location (optional): if you allow it, to find shows near you. It's sent to the event search and not stored on your profile.
From services you connect
- Spotify (optional): if you connect Spotify, we receive access tokens and the listening data you authorise (such as top artists and recently played). The tokens are kept server-side, readable only by our backend, never by the app or other users. You can disconnect at any time.
- Catalog data: song, album, artist and event information from Spotify, Last.fm and Ticketmaster. That's public catalog data, not data about you.
3. Why we use it and on what legal basis
| Purpose | Data | Legal basis (LGPD art. 7 / GDPR art. 6) |
|---|---|---|
| Create and run your account, show your diary, posts and profile, deliver previews, RSVPs and polls | Account, activity, content, artist material | Performance of a contract (our Terms) |
| Check the minimum age | Year of birth | Legal obligation and contract |
| Send notifications you turned on | Push tokens, settings | Contract; you can turn them off |
| Show artists who listened to their previews | Preview listens, username | Contract (core feature of previews) |
| Spotify stats and imports | Spotify tokens and data | Consent, which you can withdraw by disconnecting |
| Understand usage and fix bugs | Analytics and crash reports (user id only) | Legitimate interest in a working, improving product |
| Safety, moderation, rate limits, copyright notices | Reports, IP, content, notices | Legitimate interest, legal obligation, and the exercise of rights in legal proceedings |
| Answer you | Messages and contact details | Legitimate interest or contract |
| Keep records the law requires | Access logs and records | Legal obligation (for example, Marco Civil da Internet, Lei 12.965/2014) |
We don't sell personal data, don't use it for third-party advertising and don't make automated decisions that have legal or similarly significant effects on you.
4. Who can see what
- Other users see your username, display name, photo, bio and what you choose to make public (public logs, reviews, posts, lists, follows, RSVPs). Private logs stay private.
- Artists see who listened to their previews and who votes in their setlist polls and RSVPs to their events.
- Service providers that process data for us under contract: [confirm list] Supabase (database, authentication, file storage), PostHog (product analytics), Sentry (error reports), Expo, Apple and Google (push notifications), and our hosting provider for the website.
- Connected services such as Spotify receive what's needed for the connection you asked for.
- Authorities, when the law requires it or to protect people's safety and rights.
- A buyer or successor, if faxa is ever sold or merged, under this policy.
5. International transfers
Some providers store or process data outside Brazil and outside your country (for example, in the United States or the European Union). When that happens we rely on the safeguards the LGPD (art. 33) and GDPR (chapter V) allow, such as standard contractual clauses or adequacy decisions. Our database is hosted in[region].
6. How long we keep it
- Account and content: while your account exists. When you delete your account, your profile, logs, posts, comments, lists, follows, RSVPs, push tokens, Spotify tokens and uploaded files are deleted. Backups roll off within [30] days.
- Analytics and crash reports: kept by PostHog and Sentry for up to [12] months and [90] days, then deleted.
- Access logs: 6 months, as required by the Marco Civil da Internet.
- Copyright notices, reports and enforcement records: as long as needed to handle repeat infringement and legal claims, up to [5] years.
- Anything else we must keep by law, for the period the law sets.
7. Your rights
Under the LGPD (art. 18) and the GDPR (arts. 15–22) you can:
- Access and export your data: Settings → Download my data gives you a copy in a machine-readable file.
- Correct it: edit your profile and account in Settings, or ask us.
- Delete it: Settings → Delete account deletes your account and data as described above.
- Withdraw consent at any time, for example by disconnecting Spotify or turning off notifications. That doesn't affect what was done before.
- Object to processing based on legitimate interest, or ask us to restrict it.
- Ask which providers we share data with, and get information about the consequences of not giving consent.
- Complain to a supervisory authority: the ANPD in Brazil (gov.br/anpd), or the data protection authority where you live in the EEA or the UK.
For anything you can't do in the app, write to privacy@faxa.app. We may ask you to confirm you own the account, and we'll answer within 15 days (LGPD) or one month (GDPR).
8. Children
faxa is not for children under 13. We ask for your year of birth at sign-up and don't let people under 13 create an account. If we learn that a child under 13 has an account, we delete it. If you think that happened, write toprivacy@faxa.app. Users between 13 and 18 are treated with extra care, in line with the LGPD (art. 14) and the ECA (Lei 8.069/1990).
9. Security
Data is encrypted in transit, access to the database is controlled row by row, third-party keys and Spotify tokens live only on our servers, and audio previews are served through short-lived signed links. No system is perfect; if a breach puts you at risk, we'll tell you and the authorities as the law requires.
10. Changes
If we change this policy in a way that matters, we'll tell you in the app or by email before it takes effect. The date at the top shows the current version.
11. Contact
privacy@faxa.app · [Company legal name],[Registered address]. EU representative (GDPR art. 27), if required:[EU representative name and address].
