Privacy Policy
Welcome to Blabify ("we," "our," or "us"). We are committed to protecting your privacy and ensuring you understand how your information is collected, used, and safeguarded when you use our mobile application and services (collectively, the "Service").
This Privacy Policy explains our practices regarding data collection and use. By using Blabify, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Information from Spotify
When you connect your Spotify account to Blabify, we receive and process the following information through Spotify's API:
- Account Information: Your Spotify display name, user ID, and profile image (if available)
- Playback Information: Current track, playback position, play/pause state, and device information
- Access Tokens: OAuth tokens to authenticate requests to Spotify on your behalf
We do not receive or store your Spotify password, payment information, or listening history beyond the current session.
1.2 Room and Session Data
When you create or join a listening room, we collect:
- Room Information: Room codes, names, and settings you configure
- Participant Data: Which users are in a room and their role (host/participant)
- Queue Data: Songs added to the room queue and who added them
- Playback Sync Data: Timing information to keep everyone's music synchronized
1.3 Voice Data
Blabify allows voice messaging ("Voice Drops"). Important information about voice data:
- Store & Forward: Voice messages are recorded locally on your device, sent to our server, and broadcast to room participants
- Temporary Storage: Voice messages are briefly queued on our server during playback, then immediately deleted after delivery
- Not Archived: We do not permanently store, archive, or retain voice recordings beyond the immediate playback session
- Encrypted: All voice data is encrypted in transit using TLS/SSL
- Metadata: We log metadata (who spoke, duration, timestamp) for quality and debugging purposes
1.4 Device and Technical Information
We automatically collect certain technical information:
- Device type and operating system version
- App version
- IP address (for connection purposes)
- Crash reports and error logs
- General usage statistics (rooms created, sessions joined)
1.5 Information We Do NOT Collect
- Your contacts or address book
- Your location data
- Your photos or camera roll
- Your Spotify listening history
- Any payment or financial information
2. How We Use Your Information
We use the collected information for the following purposes:
2.1 To Provide the Service
- Authenticate you with Spotify
- Create and manage listening rooms
- Synchronize music playback across participants
- Enable real-time voice communication
- Manage the song queue
2.2 To Improve the Service
- Analyze usage patterns to improve features
- Debug issues and fix bugs
- Monitor system performance
2.3 To Communicate with You
- Respond to support requests
- Send important service updates (rare, and you can opt out)
3. How We Share Your Information
3.1 With Other Users
When you join a room, other participants can see:
- Your Spotify display name
- Your profile picture (if you have one on Spotify)
- Songs you add to the queue
- When you're speaking (voice indicator)
3.2 With Third Parties
We share information with:
- Spotify: We send playback commands to Spotify's API on your behalf
- Infrastructure Providers: We use cloud services (servers, databases) that may process data on our behalf, all under strict confidentiality agreements
3.3 We Do NOT
- Sell your personal information
- Share your data with advertisers
- Use your data for targeted advertising
- Share your information with data brokers
4. Data Retention
4.1 Active Data
- Session Data: Room and playback data is kept only while a room is active. When a room ends, associated data is deleted within 24 hours
- Account Data: Your Spotify connection info is retained while you use the app
4.2 Deletion
- Automatic: Room data is automatically deleted when rooms are closed
- On Request: You can request deletion of all your data by contacting us at support@blabify.app
- Token Revocation: You can revoke Blabify's access to your Spotify account at any time through Spotify's account settings
5. Data Security
We implement appropriate security measures:
- Encryption in Transit: All data transmitted between your device and our servers uses TLS/SSL encryption
- Secure Storage: Sensitive data is encrypted at rest
- Access Controls: Only authorized personnel have access to systems containing user data
- Token Security: Spotify access tokens are stored securely and refreshed automatically
6. Your Rights and Choices
6.1 Access and Portability
You have the right to request a copy of your personal data. Contact us at support@blabify.app.
6.2 Deletion
You can request deletion of your data at any time. Note that this will also end your ability to use the service until you reconnect.
6.3 Spotify Access
You can revoke Blabify's access to your Spotify account:
- Go to your Spotify account page at spotify.com/account
- Click "Apps" in the sidebar
- Find "Blabify" and click "Remove Access"
6.4 Microphone Access
You can control microphone access through your device settings at any time. Denying microphone access will disable voice drops but all other features will continue to work.
7. Children's Privacy
Blabify is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.
8. International Data Transfers
Our servers are located in the United States. If you are accessing the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last updated" date
- Sending an in-app notification for material changes
10. Third-Party Services
10.1 Spotify
Blabify integrates with Spotify. Your use of Spotify is governed by Spotify's Privacy Policy.
10.2 Apple App Store
If you download Blabify from the Apple App Store, Apple's privacy practices apply to information collected by Apple. See Apple's Privacy Policy.
11. California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to know whether your personal information is sold or disclosed
- Right to say no to the sale of personal information (we do not sell your data)
- Right to access your personal information
- Right to equal service and price
12. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
Our legal basis for processing your data is your consent (by using the app) and legitimate interests (providing and improving the service).
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
- Email: support@blabify.app
- Support: blabify.app/support
By using Blabify, you acknowledge that you have read and understood this Privacy Policy.