Privacy Policy for Melos
Last Updated: May 25, 2025
1. Introduction
Welcome to Melos ("we," "us," or "our"). We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application, Melos (the "Application"). Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the Application.
We reserve the right to make changes to this Privacy Policy at any time and for any reason. We will alert you about any changes by updating the "Last Updated" date of this Privacy Policy. You are encouraged to periodically review this Privacy Policy to stay informed of updates.
2. Information We Collect
We may collect information about you in a variety of ways. The information we may collect via the Application depends on the content and materials you use, and includes:
2.1. Personal Data You Provide to Us
- Account Information: When you register for an account, we collect your email address. If you choose to create or update your profile, we may also collect your username and avatar URL. This information is associated with your unique user ID.
- Authentication Information (Third-Party Sign-In):
- If you choose to log in or sign up using Google, we will receive information from Google such as your name, email address, and profile picture, as permitted by Google and your Google privacy settings. This is facilitated via an ID Token.
- If you choose to log in or sign up using Apple (on iOS devices), we will receive information from Apple such as your name and email address (which may be a private relay email), as permitted by Apple and your Apple ID settings. This is facilitated via an Identity Token and a nonce for security.
- User-Generated Content: If you create playlists, we collect the playlist name and description you provide.
2.2. Usage Data and Automatically Collected Information
- Song Interaction Data: We collect information about your interactions with songs and albums, including:
- Songs you "like" (
song_likes
).
- Albums you save to your library (
user_saved_albums
).
- Your listening history, including albums played and when they were last played (
user_listening_history
).
- Learning Progress: We track your progress within the Application, including:
- Quiz scores (last score, highest score, total questions attempted) for songs (
user_song_progress
).
- Number of times a song's learning module (e.g., quiz) has been completed.
- Timestamps for when progress was last updated or a quiz was last attempted.
- Guest Onboarding Status: If you use the Application as a guest, we store a flag locally on your device (using AsyncStorage) to indicate whether you have completed the guest onboarding tutorial (
GUEST_ONBOARDING_COMPLETED_KEY
). This information is not typically transmitted to our servers unless you subsequently create an account.
- Device and Connection Information: Like most mobile applications, we may collect standard device information (such as device type, operating system version) and network information (such as IP address, network status via NetInfo) automatically through our backend provider (Supabase) and for the proper functioning of the Application.
- Error and Performance Data: We may collect anonymized or pseudonymized data related to errors, crashes, and performance of the Application to help us improve its stability and functionality.
2.3. Information from Third Parties
We use Supabase as our backend service provider, which handles authentication, database storage, and file storage. Supabase may collect information as described in their privacy policy when you use our Application.
When you use Google Sign-In or Apple Sign-In, these services provide us with the authentication tokens and profile information mentioned in section 2.1.
3. How We Use Your Information
Having accurate information about you permits us to provide you with a smooth, efficient, and customized experience. Specifically, we may use information collected about you via the Application to:
- Create and manage your account.
- Authenticate your access to the Application, including via email OTP, Google, and Apple.
- Provide and deliver the core services of the Application, such as displaying lyrics, playing music, and offering language learning features.
- Personalize your experience by, for example, showing your liked songs, saved albums, and listening history.
- Track your learning progress, display quiz scores, and manage your educational journey within the app.
- Operate and maintain the Application, including monitoring and analyzing usage and trends to improve your experience.
- Respond to your requests and provide customer support (if applicable).
- Communicate with you regarding your account or important service-related notices (e.g., OTP codes).
- Ensure the security and integrity of our Application, such as by using nonces for OAuth sign-ins.
- Comply with legal obligations.
4. How We Share Your Information
We do not sell your personal information. We may share information we have collected about you in certain situations. Your information may be disclosed as follows:
- By Law or to Protect Rights: If we believe the release of information about you is necessary to respond to legal process, to investigate or remedy potential violations of our policies, or to protect the rights, property, and safety of others, we may share your information as permitted or required by any applicable law, rule, or regulation.
- Third-Party Service Providers: We share your information with Supabase, our backend service provider, which hosts our database, handles authentication, and stores files (like avatars and audio). Supabase's use of your information is governed by their privacy policy. We may also use other third-party vendors for services such as analytics or error reporting, who will only receive the information necessary to perform their designated functions and are obligated to maintain the confidentiality and security of that information.
- Third-Party Authentication Services: If you log in using Google or Apple, your interaction with these services is governed by their respective privacy policies. We only receive the necessary tokens and profile information to authenticate you.
- With Your Consent: We may share your information with third parties when you explicitly consent to such sharing. For example, if you use a feature that involves sharing content via the device's native sharing capabilities (e.g., copying a share link to the clipboard).
- Business Transfers: We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
5. Data Storage and Security
We, through our service provider Supabase, use administrative, technical, and physical security measures to help protect your personal information. While we have taken reasonable steps to secure the personal information you provide to us, please be aware that despite our efforts, no security measures are perfect or impenetrable, and no method of data transmission can be guaranteed against any interception or other type of misuse. Any information disclosed online is vulnerable to interception and misuse by unauthorized parties. Therefore, we cannot guarantee complete security if you provide personal information.
Your information is stored on Supabase servers, which may be located in various regions globally. Supabase implements industry-standard security practices.
Locally on your device, we use AsyncStorage to store your guest onboarding completion status.
6. Data Retention
We will retain your personal information for as long as your account is active or as needed to provide you services, comply with our legal obligations, resolve disputes, and enforce our agreements. Data related to your learning progress, likes, and playlists will be retained as long as your account exists to ensure a consistent user experience. If you delete your account, we will take reasonable steps to delete your personal information, subject to any legal or operational retention needs.
Guest onboarding status stored locally will persist until the Application's data is cleared or the Application is uninstalled.
7. Your Data Rights and Choices
Depending on your location, you may have certain rights regarding your personal information. These may include the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate personal information.
- Request deletion of your personal information.
- Object to or restrict certain processing of your personal information.
To exercise these rights, please contact us at support@mymelos.com. We will respond to your request within a reasonable timeframe and in accordance with applicable laws.
You can typically manage your Google and Apple account information and privacy settings through their respective platforms.
You can manage your username and avatar (if this feature is enabled) within the Application's profile settings.
8. Children's Privacy
Melos is not intended for use by children under the age of 13 (or 16 in certain jurisdictions in the European Economic Area). We do not knowingly collect personal information from children under these ages. If we become aware that we have collected personal information from a child under the relevant age without parental consent, we will take steps to delete that information.
9. Third-Party Services and Links
The Application uses third-party services for its functionality, as detailed below:
- Supabase: For backend database, authentication, and storage. Supabase Privacy Policy
- Google Sign-In: For authentication. Google Privacy Policy
- Apple Sign-In: For authentication. Apple Privacy Policy
- Expo (React Native Services): Our application is built using Expo, which may collect certain diagnostic and usage data. Expo Privacy Policy
- React Native Community NetInfo: Used for checking network connectivity. This library itself does not collect PII but provides information about the device's network state.
- React Native Track Player: Used for local audio playback. Does not inherently transmit PII.
- React Native Clipboard: Used when you choose to copy share links. Data is copied to your device's clipboard.
We are not responsible for the privacy practices of these third-party services. We encourage you to review their privacy policies.
10. Contact Us
If you have questions or comments about this Privacy Policy, please contact us at:
support@mymelos.com