Draft — this document has not yet been reviewed by counsel and is not in force.
Legal
Privacy Policy
Last updated 2026-09-18
What we collect, why, who sees it, how long we keep it, and how to get a copy or erase it. Written for CCPA/CPRA now and GDPR before any EU marketing.
1. What we collect
Account: email, password (hashed), date of birth (used only to determine whether you are a minor — it is never shown and only "13–17" or "adult" is kept in practice), optional phone, and two-factor secrets (encrypted at rest).
Profile: the things you choose to publish — display name, handle, pronouns, cities, disciplines, styles, bio, reel, photos and clips, credits.
Activity: posts, comments, reactions, follows, messages, RSVPs and check-ins, bookings and orders, reports you file, and notifications we send you.
Technical: IP address and user agent in server logs (kept 30 days), and the rate-limit counters that protect logins. We do not run third-party advertising trackers.
2. Why we use it
To run the platform (show your profile, deliver messages, process bookings), to keep it safe (moderation, rate limiting, fraud checks, guardian controls for minors), to send you the notifications you have chosen, and to meet legal obligations (payment records, DMCA notices).
3. Who sees it
Public profiles and confirmed credits are visible to anyone, including search engines. "Industry only" and "private" visibility limit that. Messages are visible only to their participants and, in response to a report, to moderators.
Service providers who process data for us: our hosting provider (Railway), payment processor (when enabled), email delivery, media storage/streaming, and error monitoring. Each is bound by contract to use the data only to provide the service. We do not sell personal information and have not sold it in the past 12 months.
Guardians of 13–17 year-olds can see their ward's booking requests and approve or decline them; they do not see the ward's messages.
4. How long we keep it
Account and profile data: until you delete your account. Payment records: seven years, as tax law requires, without your name once you delete. Server logs: 30 days. Moderation audit log: retained, with the target anonymised after account deletion.
5. Your rights
Access and portability: Settings → Security → "Download my data" gives you everything we hold as JSON, instantly. Correction: edit your profile and settings at any time. Erasure: Settings → Security → "Delete my account" anonymises your account immediately; confirmed credits stay on their productions as "Deleted artist" because they are also the other confirmers' record, and payment records are kept without your identity.
California residents may also exercise these rights, and the right to non-discrimination, by emailing legal@rhythmculture.app. We respond within 45 days. We do not use "dark patterns" to discourage requests.
6. Children
We do not knowingly collect data from children under 13; such accounts are deleted when found. For 13–17 year-olds we collect the minimum needed and require guardian linkage for bookings and messaging from adults. Parents can contact legal@rhythmculture.app to review or delete their child's data.
7. Security and changes
Passwords are hashed, two-factor secrets are encrypted, transport is TLS everywhere, and access to production data is limited and logged. No system is perfectly secure; if we learn of a breach affecting you we will notify you without undue delay. We will announce material changes to this policy 14 days in advance.