Privacy Policy
OUTERLIGHT is an AI music streaming platform for original AI-created and AI-assisted music. This policy explains what the mobile app, Creator Studio and support service collect, why the data is needed, and the choices available to you.
Effective 9 August 20261. Who is responsible
For the current free beta, Jan Jacobs operates OUTERLIGHT as an individual in the Netherlands and is the controller of the personal data described in this policy. Privacy questions and requests can be sent through OUTERLIGHT Support or to [email protected].
OUTERLIGHT is not currently registered as a business and therefore does not yet have a KVK or VAT number. Registration and business contact details will be added before commercial operation begins where they are legally required.
2. Information we process
| Category | Examples | Why it is used |
|---|---|---|
| Account information | Email address, account identifier, sign-in provider and session information. | Create and secure your account, keep you signed in and provide account recovery. |
| Creator and catalogue information | Artist names, release titles, genres, lyrics, AI tool/version, rights confirmations and review status. | Review, organise and publish eligible releases. |
| Uploaded media | Audio, cover artwork and optional private review evidence. | Review, store, process and stream approved music. |
| Listening and library activity | Likes, follows, playlists, play progress, skips and playback history. | Operate playback, libraries, charts, recommendations and abuse protection. Private-session activity is not added to listening history. |
| Reports and support | Song reports, support email, category, subject, message and moderation decisions. | Respond to requests and keep the catalogue safe. |
| Security signals | One-way installation and network codes, timing signals and suspected automated-playback patterns. | Detect bots, stream manipulation, spam and repeat serious abuse. Raw internet addresses are not stored in the playback-fraud database. |
| Device data stored locally | App preferences, cached catalogue information and music saved for offline listening. | Make the app work and support offline playback. Offline audio remains on your device until you remove it or delete the app. |
3. Legal reasons for using data
- Providing the service: account access, playback, libraries, uploads and creator review.
- Legitimate interests: platform security, fraud prevention, catalogue moderation, service improvement and protecting users and rights holders.
- Legal obligations: responding to valid legal requests and handling copyright, safety or data-protection matters.
- Consent: where a specific optional feature requires it. Consent can be withdrawn without affecting earlier lawful processing.
4. Service providers and transfers
OUTERLIGHT uses carefully selected providers to operate the service:
- Supabase provides authentication and database services.
- Cloudflare provides private media storage, delivery, network protection and Worker services.
- Google processes information when you choose Google sign-in or install OUTERLIGHT through Google Play.
These providers process data under their own security and privacy commitments. Data may be processed outside the European Economic Area where the provider uses an appropriate legal transfer mechanism. OUTERLIGHT does not sell personal data and does not share it for third-party advertising.
5. Retention and deletion
- Account, creator, library and upload information is normally kept while your account is active.
- Deleting your account removes the login, associated creator data and uploaded media from the active service. Deleted releases do not remain publicly available. The process is described on the Account Deletion page.
- Limited information may temporarily remain where necessary for security, fraud or abuse prevention, moderation disputes, legal obligations or backups.
- A moderation report may remain as a de-identified safety record when it is necessary to protect the catalogue or resolve a rights dispute.
- Support messages are kept only while reasonably needed to answer the request, maintain service security or meet a legal obligation. You can request their deletion.
- After manually confirmed serious playback abuse, unreadable security codes may be retained for up to 90 days. They do not contain a readable email, profile, song, message or raw internet address.
6. Automated checks and human review
Automated rules and technical checks may flag suspicious playback, repeated reports, unsafe upload patterns or other suspected policy violations. A flag or user report does not automatically prove wrongdoing. It may temporarily hold activity or hide a release for review, but final moderation and serious-abuse decisions are made by an authorised administrator.
Where reasonably practicable and legally permitted, an affected creator will receive the main reason for a restriction or account action and information about any available way to contest it through OUTERLIGHT Support.
7. Your choices and rights
Depending on applicable law, including the GDPR, you may request access, correction, deletion, restriction, portability or object to certain processing. You may also complain to the Dutch Data Protection Authority or your local supervisory authority.
Use the private support form to make a request. OUTERLIGHT may ask you to verify account ownership before acting. Requests are answered without undue delay and ordinarily within one month.
8. Children
OUTERLIGHT is not directed to children under 16. Do not create an account if you are under 16 or are unable to agree to these terms under the law where you live.
9. Security and changes
OUTERLIGHT uses encryption in transit, access controls, private media storage, row-level database permissions, rate limits and administrator MFA. No online service can promise absolute security. Material policy changes will be dated here and, when appropriate, shown in the app or Creator Studio.