Privacy Policy
OUTERLIGHT is a generative music streaming platform for original music created or shaped with generative technology. This policy explains what the mobile app, Creator Studio and support service collect, why the data is needed, and the choices available to you.
Effective 13 August 20261. Who is responsible
For the current free beta, Jan Jacobs operates OUTERLIGHT as an individual in the Netherlands and is the controller of the personal data described in this policy. Privacy questions and requests can be sent through OUTERLIGHT Support or to outerlight.help@outlook.com.
OUTERLIGHT is not currently registered as a business and therefore does not yet have a KVK or VAT number. Registration and business contact details will be added before commercial operation begins where they are legally required.
2. Information we process
| Category | Examples | Why it is used |
|---|---|---|
| Account information | Email address, account identifier, sign-in provider, session information and whether the account has a Listener profile, Creator profile or both. | Create and secure your account, keep you signed in, provide account recovery and help authorised administrators handle account support and deletion requests. |
| Creator and catalogue information | Artist names, release titles, genres, lyrics, creation tool/version, rights confirmations and review status. | Review, organise and publish eligible releases. |
| Uploaded media | Audio, cover artwork and optional private review evidence. | Review, store, process and stream approved music. |
| Listening, library and app-use activity | Likes, follows, playlists, play progress, skips, playback history, verified-listener eligibility, signed-in foreground session timing, last activity and daily usage totals. | Operate playback, libraries, charts and recommendations, understand whether the beta works reliably and protect the service from abuse. Authorised MFA-protected administrators can view per-account and aggregated usage totals for support and service decisions. Private-session activity is not added to listening history, sent for verified-listener counting or included in foreground app-use totals. |
| Limited app diagnostics | Installed app version and short technical category/code for playback, login, download, connection, update or general app failures. | Tell users when an update is available or required and identify technical problems affecting the beta. OUTERLIGHT does not collect exception messages, passwords, audio recordings, raw internet addresses or detailed listening history as app diagnostics. |
| Reports and support | Song reports, support email, category, subject, message and moderation decisions. | Respond to requests and keep the catalogue safe. |
| Security signals | One-way installation and network codes, account age, completion percentage, timing and sequence signals, device or network cluster totals and suspected automated-playback patterns. | Verify listener statistics and detect bots, coordinated accounts, stream manipulation, spam and repeat serious abuse. Raw internet addresses are not stored in the playback-fraud database. |
| First-party website and download analytics | Total page visits and APK downloads, an OUTERLIGHT first-party random browser code, and daily aggregate totals. The stored server identifier is a salted one-way code; the administrator does not receive a readable internet address. | Measure beta interest, estimate unique browsers, count repeat APK downloads and understand conversion. Administrator pages and known bots are excluded. OUTERLIGHT does not use advertising cookies or third-party marketing analytics. |
| Device data stored locally | App preferences, a random OUTERLIGHT installation code, cached catalogue information and music saved for offline listening. | Make the app work, count one first successful app open per installation and support offline playback. The installation code is not an Android hardware or advertising identifier. Offline audio remains on your device until you remove it or delete the app. |
3. Legal reasons for using data
- Providing the service: account access, playback, libraries, uploads and creator review.
- Legitimate interests: platform security, fraud prevention, catalogue moderation, service improvement and protecting users and rights holders.
- Legal obligations: responding to valid legal requests and handling copyright, safety or data-protection matters.
- Consent: where a specific optional feature requires it. Consent can be withdrawn without affecting earlier lawful processing.
4. Service providers and transfers
OUTERLIGHT uses carefully selected providers to operate the service:
- Supabase provides authentication, session and database services.
- Cloudflare provides private media storage, delivery, network protection, Worker services and Turnstile anti-bot checks. Cloudflare may receive network and browser security information, including an internet address, while delivering and protecting the service. OUTERLIGHT stores only a one-way network code in its playback-fraud database, not the raw internet address.
- Google processes information only when you choose Google sign-in.
These providers process data under their own security and privacy commitments. Data may be processed outside the European Economic Area where the provider uses an appropriate legal transfer mechanism. OUTERLIGHT does not sell personal data and does not share it for third-party advertising.
5. Retention and deletion
- Your shared sign-in account is normally kept while it is active. A Listener profile, Creator profile or both may be connected to the same sign-in.
- Deleting the Creator Studio profile removes its creator information, every submitted or published release and uploaded media. It does not delete the Listener profile or shared sign-in.
- Deleting the Listener profile removes its likes, follows, listening history, linked playback sessions and other listener records. It does not delete the Creator Studio profile, releases or shared sign-in. Offline music on the device is removed by the app.
- Raw foreground app-session records are kept for no more than 90 days. Daily foreground-use totals may remain while the Listener profile is active and are removed when that Listener profile is deleted.
- The latest installed app version is kept while the Listener profile is active. Limited code-only diagnostic events are kept for no more than 90 days and are removed when that Listener profile is deleted.
- Complete deletion of the shared sign-in and all connected profiles can be requested through OUTERLIGHT Support. The separate deletion routes are described on the Account Deletion page.
- A verified-listener record is normally kept while the connected Listener profile and song remain active so that the same listener cannot increase that song's verified-listener total more than once.
- Playback verification and fraud-review records may be kept while needed to calculate verified-listener statistics, investigate manipulation and document an administrator decision. Records that remain linked to an active listener or song may remain for the lifetime of that Listener profile or song.
- Limited information may temporarily remain where necessary for security, fraud or abuse prevention, moderation disputes, legal obligations or backups.
- Anonymous website, download and first-open totals may be retained as aggregate business records. One-way browser and installation codes are not used for advertising or cross-site tracking and can no longer be linked back to a readable identifier by the administrator.
- A moderation report may remain as a de-identified safety record when it is necessary to protect the catalogue or resolve a rights dispute.
- Support messages are kept only while reasonably needed to answer the request, maintain service security or meet a legal obligation. You can request their deletion.
- After manually confirmed serious playback abuse, unreadable security codes may be retained for up to 90 days. They do not contain a readable email, profile, song, message or raw internet address.
6. Automated checks and human review
A signed-in listener can contribute once to a song's public Verified listeners total when at least 80% of the song is confirmed through server playback signals, the account is at least seven days old, the listener is not the song's creator and the activity passes fraud checks. An eligible result waits at least 48 hours before it can become public. The public sees only the aggregated total, not listener identity or security evidence.
Automated rules and technical checks may flag multiple accounts connected to one app installation, unusual one-way network clusters, coordinated song sequences or timing, sudden growth, repeated reports, unsafe upload patterns or other suspected policy violations. Network similarity alone is not proof of abuse. Flagged listener activity can be held for administrator review and excluded from the public total unless it is approved.
Where suspicious growth affects a creator, OUTERLIGHT may temporarily hold only that creator's new statistics while an authorised administrator investigates. Existing verified-listener totals remain visible and the music remains playable. Final moderation, verified-listener approval or rejection and serious-abuse decisions are made by an authorised administrator using MFA.
Where reasonably practicable and legally permitted, an affected creator will receive the main reason for a restriction or account action and information about any available way to contest it through OUTERLIGHT Support.
7. Your choices and rights
Depending on applicable law, including the GDPR, you may request access, correction, deletion, restriction, portability or object to certain processing. You may also complain to the Dutch Data Protection Authority or your local supervisory authority.
Use the private support form to make a request. OUTERLIGHT may ask you to verify account ownership before acting. Requests are answered without undue delay and ordinarily within one month.
8. Children
OUTERLIGHT is not directed to children under 16. Do not create an account if you are under 16 or are unable to agree to these terms under the law where you live.
9. Security and changes
OUTERLIGHT uses encryption in transit, access controls, private media storage, row-level database permissions, rate limits and administrator MFA. No online service can promise absolute security. Material policy changes will be dated here and, when appropriate, shown in the app or Creator Studio.
