1. Who is responsible
The responsible party has not been configured, so this policy does not identify a data controller — which is a requirement, not a formality. Set NUXT_PUBLIC_LEGAL_NAME, NUXT_PUBLIC_LEGAL_ADDRESS, NUXT_PUBLIC_LEGAL_EMAIL in the deployment environment.
No Data Protection Officer has been appointed; the scale and nature of the processing described here does not require one. You reach a person directly at the address above.
2. The short version
- The app is local. Your music files, playlists, library and settings stay on your computer. We never receive them.
- Usage sharing is off by default. Nothing is sent unless you turn it on.
- An account is optional. The app works fully without one.
- We sell nothing and share with no advertisers. There are no third-party trackers, ad pixels or analytics services on this site.
- You can delete everything from Account → Delete my data, and from Settings → Privacy in the app.
3. What we collect, and why
3.1 If you create an account
| Data | Why | Lawful basis |
|---|---|---|
| Email address, password | To create and secure your account | Performance of a contract |
| Display name (optional) | To address you in the interface | Contract |
| Country, time zone, language | Derived from your browser's time zone — never from your IP address — so we can understand which markets use Colada | Legitimate interest |
| Consent records | To prove what you agreed to and when | Legal obligation |
3.2 The optional survey
On your account page you can volunteer an age band, gender, how you found Colada, when you listen, your DJ experience and a rough library size. Every question is skippable, the whole thing is optional, and you can edit or delete the answers at any time. Lawful basis: your consent. We report these only in aggregate, and suppress any group smaller than five people so nobody is identifiable.
3.3 Usage data — only if you switch it on
Off by default, in both the app and this website. When enabled, we record events against a random identifier created on your device — not your account, not your name, not your IP address. We hold no way to connect that identifier to you.
- Which parts of the app you use, and for how long — split into active time and idle time, so a window left open isn't counted as use
- Features used, buttons pressed, setup steps completed and how long they took
- Errors, and searches that returned nothing (including what you searched for, so we can tell what people expect to find)
- Tracks played: title, artist, genre, mood, how much of it you listened to, whether you skipped. This is what makes "most played today" possible
- App version, operating system, language, country, device type
- On this website: pages visited, referring site, campaign tags in the link you followed, how far you scrolled, time on page
Lawful basis: your consent. You can withdraw it at any time, and nothing further is sent.
3.4 What we never collect
- Your music files, or any part of them
- Your library listing, folder names, file paths or playlists
- API keys or credentials you enter in the app — those stay in a file on your computer
- Your IP address stored alongside usage events
- Anything at all, if you have not switched usage sharing on
4. The shared track catalogue
With usage sharing on, the app also contributes information about recordings — title, artist, album, genre, mood analysis, lyrics and cover art embedded in your files — to a shared catalogue, so nobody has to re-derive work another user has already done.
That catalogue records a source, never a person. It holds no user identifiers of any kind, which is also why erasing your data leaves it untouched: it is information about music, not about you. Cover art has its embedded metadata (which can include camera details and location) stripped before storage.
5. How long we keep it
| Data | Retention |
|---|---|
| Account details and survey answers | Until you delete your account |
| Individual usage events | 180 days, then deleted automatically |
| Anonymous aggregate statistics | Indefinitely — these are counts and totals that reference no individual and cannot be traced back to one |
| Server logs | Short-lived operational logs; not used to build profiles |
6. Who else sees it
We do not sell your data, and we do not share it for advertising. We use these processors:
| Processor | Purpose | Where |
|---|---|---|
| DigitalOcean | Hosting and backups | European Union (Frankfurt) |
| Let's Encrypt | Website security certificates | Not given personal data |
Your data is stored in the EU. Separately, the app itself can connect to services you choose and configure yourself — Spotify, YouTube, LRCLIB, Last.fm, Deezer, or an AI provider. Those connections are made from your computer using your credentials, and are governed by those services' own policies. We are not a party to them.
7. Your rights
Under the GDPR you can:
- See what we hold — Account → Export my data
- Correct it — edit your profile and survey answers directly
- Delete it — Account → Delete my data closes the account and erases your survey answers and this browser's usage data. The app keeps its own separate record: delete that from Settings → Privacy in the app. Nothing links the two, which is precisely why each must be asked for separately
- Withdraw consent — switch usage sharing off; nothing further is collected
- Object, restrict, or take your data elsewhere — contact us
- Complain to your national data protection authority
We respond within one month, free of charge.
8. Cookies
We use no advertising or tracking cookies, and no third-party cookies at all. A single cookie holds your sign-in session; it exists only when you are signed in. Your consent choice and the random usage identifier are kept in your browser's local storage, not in cookies, and never leave your device except as described above.
9. Age
Colada accounts are for people aged 16 or over. We do not knowingly collect data from anyone younger. If you believe a child has created an account, contact us and we will delete it.
10. Security
Traffic is encrypted in transit. Passwords are hashed by our identity provider and never stored by us in readable form. Sign-in attempts are rate-limited. Usage data is pseudonymous by design, so even a full compromise of the analytics store would not reveal who did what.
No system is perfectly secure. If we discover a breach affecting your rights we will notify the relevant authority within 72 hours, and you directly where the risk to you is high.
11. Changes
We will post any change here and update the version and date at the top. If a change materially affects how we use your data we will ask for your consent again rather than assume it.
