Privacy Policy

Last updated 10 August 2026.

Listening Buddy is run by one person, and this policy is written to be read rather than skimmed past. The short version: we collect the music you choose to put on your profile and the messages you choose to send, we don't track you, we don't run ads, and we don't sell anything about you to anyone.

The person responsible for your data (the "data controller") is Ian Swain, Virginia, United States. You can reach me at hello@listeningbuddy.fm.

What we collect

Things you give us

  • Your email address. Required — it's how you log in, since we use emailed sign-in links rather than passwords.
  • Your username. Public. Other people in the pool see it.
  • Your profile. The albums and artists you pick, your bio, your answers to the listening questions, and the shows and purchases you list. All of it is chosen by you — we never connect to a streaming service or scrape your play history.
  • What you send other people. Messages, album cards, notes attached to a request, and your picks and replies in an exchange.
  • Your settings. Whether you're in the pool, how many matches you want, what kind, and whether you want notification emails.
  • A record that you confirmed you're 18 or over — the date you ticked the box, and nothing else. We don't ask for or store your date of birth.
  • Feedback you send us. If you use the feedback box, we keep what you wrote, along with the page you were on and your browser window size — the two things that make a layout bug reproducible. Nothing else about your browser or device.
  • A password, only if you set one. It's optional and stored hashed.

Things that happen automatically

  • One cookie. A session cookie that keeps you logged in. It is strictly necessary — the site cannot work without it — which is why there's no cookie banner here. We set no analytics or advertising cookies at all.
  • Your IP address, briefly. Held in memory to rate-limit sign-in emails so nobody can use the login form to spam someone's inbox. It is never written to our database.
  • Crash reports. When something breaks, a report goes to our error-monitoring provider. It can include your IP address, the page you were on and your account ID. Sign-in tokens are stripped out before the report is sent.
  • A record of the steps you take through the app. Things like signed up, joined the pool, viewed matches, said interested, passed, sent a message. We record that the step happened, when, and — for a match — how highly our algorithm had ranked the person you were looking at. That last part is the whole reason this exists: it's how we find out whether our matching is any good, which is the question this app is trying to answer. We never record what you actually wrote — no message text, no notes, no bios, no report reasons.
  • Ordinary server logs, kept short-term by our host.

All of this is measured by us, on our own servers. There's no third-party analytics service involved, which is also why there's nothing here to consent to.

What we don't do

No advertising. No third-party analytics or tracking pixels. No selling, renting or sharing your personal data with data brokers, advertisers or anyone else for their own purposes — not now, and it isn't a thing we're keeping open for later. No training of AI models on your messages.

Who else touches your data

Running the site means using a few service providers. They process data on our instructions, under contract, and nothing more:

  • Render — hosting and the database (servers in Oregon, USA).
  • Cloudflare — DNS, encrypted database backups, forwarding mail sent to our address, and serving album artwork.
  • Resend — sending the emails we send you.
  • Sentry — crash reports.
  • MusicBrainz — the open music database our catalogue comes from. When you search for an album, the text you typed is sent to them. Nothing identifying you goes with it.
  • The Cover Art Archive — where album artwork comes from, run by the Internet Archive. The artwork reaches you through our own server rather than straight from them, so what they see is our request and not yours. Your address never goes to them.

The other people who see your data are other users: your username and profile are visible to people in the pool, and anything you write to a buddy is visible to that buddy.

You can also make your profile public, which makes it readable by anyone who has the link — including people with no account here. That is off unless you turn it on, it is separate from being in the pool, and you can make it private again at any time. We ask search engines not to index public profiles, though we can't force them to obey.

We'd also disclose data if the law genuinely required it — a valid legal order — or to deal with a serious safety issue.

How long we keep it

Your data stays while your account does. When you delete your account, it is deleted immediately and permanently from the live database — profile, messages, exchanges, connections, the lot. Conversations you were part of disappear for the other person too. There is no hidden copy and no "deactivated" limbo.

One exception is backups, which exist so the site can be recovered if something goes badly wrong. Deleted data can persist in them for up to 30 days, after which it ages out permanently. Our error and email providers keep their own short-term logs under their own policies.

The other is the step-by-step record described above, and we want to be straight about it rather than bury it. Those rows are not deleted — but at the moment you delete your account we cut them loose from you: your account ID is removed, and the precise times are blurred to the day, so what's left can't be traced back to you or reassembled into your particular path through the app. What survives is arithmetic — this many people joined the pool, this many found a buddy — and your leaving still counts in it. We keep it because a product that forgets everyone who left only ever gets to look at the people who stayed.

Being honest about the limit of that: while the number of people here is small, a determined person with enough outside information could still make good guesses from coarse data. It gets stronger as more people join, which is the nature of the thing rather than an excuse for it.

Your rights

Two of these you can do yourself, right now, without asking:

  • Get a copy of everything — the download button in Settings gives you a JSON file with your account, profile, connections, conversations and exchanges in it.
  • Delete your account — also in Settings, and immediate.
  • Correct anything — edit your profile and settings whenever you like.

Depending on where you live — the UK, EU, California and several other US states — you may also have the right to object to or restrict certain processing, and to complain to your data protection authority. Email hello@listeningbuddy.fm and I'll deal with it. There is no charge and I won't treat you differently for asking.

Why we're allowed to process it

For readers under UK/EU data protection law: we process your profile, messages and settings to perform our contract with you — that is, to actually provide the thing you signed up for. We process IP addresses and crash reports under legitimate interests, specifically keeping the service secure, available and free of abuse. Where consent is required, we ask for it and you can withdraw it.

Where your data lives

Listening Buddy is hosted in the United States, so if you're outside it, your data is transferred there. Our providers cover those transfers with the standard legal mechanisms — the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

Age

Listening Buddy is for adults — you must be 18 or over to have an account. See the Terms of Use for why. If you believe someone under 18 has an account, email me and I'll remove it.

Changes

If this policy changes in a way that actually matters, the date at the top changes and you'll be told by email before it takes effect. Small clarifications will just appear.