← Back to Tonic.fm
Privacy Policy
Last updated: August 18, 2026 · Governing law: State of Texas, USA
1. Introduction
Tonic.fm ("we", "our", "the app") is a personal music catalogue and journal. This Privacy Policy explains what data we collect, how we use it, and your rights. This policy applies to all users, including residents of Texas, California, and other U.S. states.
2. Data We Collect
- Account information: Email address and password (stored via Supabase Auth).
- Catalogue data: Songs, ratings, tags, albums, artists, playlists, notes, and people you add — stored in Supabase and cached in your browser's localStorage.
- Usage analytics: Anonymous event logs (page views, feature usage) stored locally in your browser. These are not sent to any third-party analytics service. You may opt out at any time.
- Profile data: Display name and optional avatar, stored in Supabase.
3. How We Use Your Data
- To provide and sync your music catalogue across devices.
- To display your data on the site (e.g. tier boards, stats, friend comparisons).
- To improve the app through anonymous, local-only usage analytics (opt-in only).
We do not sell your personal data. We do not use your data for targeted advertising.
4. Data Sharing
We do not sell, trade, or share your personal data with third parties for marketing purposes. The only external services we use are:
- Supabase — for authentication and data storage (hosted on AWS).
- iTunes Search API — to look up album art (no personal data is sent).
- Tidal API — for playlist imports (no personal data is sent beyond the playlist URL).
5. Data Storage & Security
Your data is stored in Supabase (hosted on AWS). We implement the following security measures:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security).
- Encryption at rest: Stored data is encrypted at rest using AES-256 (provided by AWS/Supabase infrastructure).
- Row-Level Security (RLS): Supabase RLS policies ensure each user can only access their own data.
- Authentication: Passwords are hashed and salted using bcrypt (via Supabase Auth). We never store or have access to your plain-text password.
- Access controls: Administrative access to databases is restricted and logged.
While we take reasonable precautions, no method of transmission or storage is 100% secure. We encourage you to use a strong, unique password.
6. Your Rights
You have the following rights regarding your personal data:
- Access: You can view all your data at any time within the app.
- Export: You can download a complete copy of your data in JSON format from Account Settings (GDPR Art. 20, CCPA §1798.100).
- Deletion: You can permanently delete your account and all associated data from Account Settings. This removes all data from our servers within 30 days.
- Correction: You can edit your profile, catalogue, and all personal data at any time within the app.
- Opt-out of analytics: You can disable all analytics tracking at any time via the consent banner or Account Settings.
7. Texas Privacy Protection Act (TPPA)
As a Texas-based service, we comply with the Texas Privacy Protection Act and the Texas Business and Commerce Code. This means:
- We provide clear notice of what data we collect and how it is used (this policy).
- We do not sell your personal information.
- We do not engage in targeted advertising based on your personal data.
- You may request access to, correction of, or deletion of your personal data at any time.
- We will not discriminate against you for exercising your privacy rights.
8. California Consumer Privacy Act (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to delete: You may request deletion of your personal information.
- Right to opt out: You may opt out of the sale of your personal information. We do not sell personal information, so this right is inherently satisfied.
- Non-discrimination: We will not discriminate against you for exercising any CCPA rights.
To exercise any of these rights, use the Export or Delete buttons in Account Settings, or contact the developer directly.
9. Children's Privacy (COPPA)
Tonic.fm is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you are under 13, you may not create an account. If we become aware that a user is under 13, we will promptly delete their account and all associated data. If you believe a child has provided us with personal information, please contact us immediately.
10. Cookies & Tracking
We do not use third-party cookies, tracking pixels, or advertising networks. The only cookies/session data are from Supabase Auth for authentication purposes. Local analytics data is stored in your browser's localStorage and is not transmitted to any server. You may clear this data at any time by opting out of analytics or clearing your browser storage.
11. Data Retention
We retain your data for as long as your account is active. When you delete your account, all data is permanently removed from our servers within 30 days. Local browser data (localStorage) is cleared immediately upon account deletion. Analytics logs older than 90 days are automatically pruned.
12. Data Breach Notification
In the event of a data breach that affects your personal information, we will notify you promptly via email and provide information about the nature of the breach and steps you can take. We will also comply with all applicable Texas and federal breach notification laws, including the Texas Identity Theft Enforcement and Protection Act (Tex. Bus. & Com. Code §521.053), which requires notification to affected Texas residents within 60 days of discovering a breach.
13. Changes to This Policy
We may update this policy. Material changes will require re-consent via the app. The version number is tracked in the app's code. We will notify users of material changes via the app and, where required, by email.
14. Contact
If you have questions about this policy or your data, please email us at samannleblanc@gmail.com or open an issue at our GitHub repository. For DMCA requests, see our Terms of Service.
Tonic.fm · Built with care for music lovers. Based in Texas, USA.