Scapetone Privacy Policy
Effective date: September 12, 2026
Last updated: September 14, 2026
Scapetone LLC (“Scapetone,” “we,” “us,” or “our”) provides the Scapetone mobile application, website, and related services (together, the “Services”). This Privacy Policy explains what information we collect, why we use it, when it may be disclosed, how long we keep it, and the choices available to you.
By using the Services, you acknowledge the practices described in this Privacy Policy. If you do not agree, please do not use the Services.
Information We Collect
Information you provide
Account information: Email address, username, password credentials handled by Firebase Authentication, account creation information, and, if you choose to verify it, your phone number.
Profile information: Display name, profile photo, biography, favorite genres, and account visibility or comment preferences.
Music and social content: Albums or projects you mark as heard; imported library or collection information; ratings, reviews, rankings, recommendations, Record of the Week selections, inquiries, comments, likes, mentions, follows, follow requests, and other content or interactions you create.
Safety and moderation information: If you report a profile, post, comment, inquiry response, or recommendation conversation, we collect the report category, any optional details you provide, the reported content’s location, a limited snapshot of the reported material, your Scapetone account identifiers, timestamps, and the report’s review status. If you block an account, we maintain the limited relationship records needed to apply the block to both accounts, prevent or hide interactions between the accounts, and remove related follows, pending follow requests, and applicable notifications.
Support and communications: The content of messages you send to support and information needed to respond. If you ask us to assist with a Spotify library import, the request may include your Spotify email address and Scapetone username.
Please do not include sensitive personal information in public posts, reviews, comments, reports, or other user-generated content.
Contacts, if you grant permission
Scapetone can help you find people you may know and invite contacts. If you grant Contacts permission, the app reads contact names, email addresses, and phone numbers on your device to support those features. To match existing Scapetone users, normalized email addresses and phone numbers are converted on your device into one-way SHA-256 hashes before being sent to our servers. Scapetone does not upload your contacts’ address-book names or raw contact email addresses and phone numbers for matching.
If you choose to send an invitation, Apple’s messaging interface is used, and the recipient information and message are handled by Apple and your carrier or messaging provider. Scapetone may retain a one-way hash of the invited phone number and a timestamp to prevent duplicate achievement credit and abuse.
Contacts access is optional. You can deny or revoke it in iOS Settings, although contact discovery and invitations will then be unavailable.
Connected music services
If you choose to connect a service, Scapetone receives and processes the information needed to provide that integration:
Spotify: Authorization tokens are stored in the device Keychain. Scapetone may access your saved albums and the Spotify account email needed for a user-requested import-support workflow.
Apple Music: With your permission, MusicKit provides access to saved-album metadata. The app stores a local indicator that Apple Music is linked.
SoundCloud, TIDAL, and Discogs: Scapetone may store authorization tokens or connection records on our servers and access account identifiers, usernames, saved music, favorites, or collection metadata needed for the feature you request.
Connecting a music service is optional. You can disconnect it from Scapetone Settings or revoke access through the provider. Disconnecting stops future access, but music you previously imported into your Scapetone heard history remains until you remove it or delete your Scapetone account.
Information collected automatically
When you use the Services, Scapetone and its service providers may automatically process:
Scapetone and Firebase user identifiers;
push-notification tokens and installation identifiers;
device and app information, such as device model, operating-system and app versions, language, and time zone;
network and request information, such as IP address, the Firebase function called, timestamps, and security or error information;
product interactions needed to operate features, such as activity, notification state, privacy settings, imports, and feature preferences; and
app and device-integrity information used by Firebase App Check, which may include App Check tokens and attestation material generated through Apple App Attest or DeviceCheck. This information is used to help verify that protected requests come from an authentic copy of Scapetone on an eligible device. Attestation material may be sent to Apple for validation according to the configured attestation service.
Our website host may also process ordinary web-request information and cookies required to deliver, secure, and operate the site. Scapetone does not use this information for third-party advertising or cross-app tracking.
Information from music catalog services
Scapetone sends music searches and album or artist identifiers to catalog and artwork services such as MusicBrainz and the Cover Art Archive to return search results, metadata, and cover images. Those providers receive the network information normally associated with a request.
How We Use Information
We use information to:
create, authenticate, protect, and administer accounts;
provide profiles, social feeds, music discovery, reviews, ratings, rankings, recommendations, comments, notifications, achievements, and connected-service imports;
apply account visibility, comment, and notification choices;
match contacts when you request contact discovery and prevent duplicate or abusive invitation credit;
send transactional push notifications and respond to support requests;
apply automated screening to user-generated text submitted through supported app posting flows;
receive, investigate, document, and respond to reports of harmful, abusive, illegal, or privacy-invasive content;
apply user blocks, prevent blocked accounts from interacting, remove related social connections where applicable, enforce report-rate limits, and maintain safety and moderation records;
maintain, troubleshoot, secure, and improve the Services;
prevent fraud, abuse, and violations of our terms; and
comply with law and protect the rights, safety, and integrity of Scapetone, our users, and others.
Scapetone does not sell personal information. Scapetone does not use personal information for third-party targeted advertising and does not track you across apps or websites owned by other companies for advertising purposes.
When Information Is Shared
We may disclose information in the following circumstances:
Other Scapetone users. Your username, profile image, display name, and basic profile details may be visible to other Scapetone users so they can find and interact with your account. When your account is public, your posts, reviews, rankings, comments, likes, and follow relationships may be shown to other users through applicable features. When your account is private, account content is made available only to you and users authorized by the applicable follower or friendship settings. Ratings are shown only to friends. Direct recommendation conversations are available only to their sender and recipient.
Email addresses, verified phone numbers, private account records, safety-report details, connected-service credentials, contact-discovery identifiers, and private authorization records are not included in public profile records or displayed to other users.
Service providers. We use providers that process information for us to host, authenticate, store, secure, support, and deliver the Services, including Google Firebase and Google Cloud; Apple, including MusicKit, push notifications, App Attest, and DeviceCheck; Squarespace; and communications providers. Firebase App Check may send attestation material to Apple for validation and attaches resulting App Check tokens to protected Firebase requests. We require service providers to use personal information only to perform services for us and to provide the same or equivalent protection described in this policy, subject to their applicable terms and privacy notices.
Connected services you select. When you connect or use Spotify, Apple Music, SoundCloud, TIDAL, or Discogs, information is exchanged with that provider at your direction. MusicBrainz and the Cover Art Archive receive requests needed to supply catalog data and images.
Legal and safety reasons. We may disclose information when reasonably necessary to comply with law or valid legal process; enforce our terms; investigate reports; detect or prevent fraud, security incidents, illegal activity, or abuse; or protect the rights, property, or safety of Scapetone, users, or others.
Business transfers. Information may be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to this policy and applicable law.
With your direction or consent. We may disclose information when you ask us to or otherwise consent.
Data Retention
We retain account and content information while your account is active and as needed to provide the Services. Feature preferences stored only on your device remain until you clear the app’s data, uninstall the app, or delete your account. Connected-service credentials are retained only while needed to maintain the connection and are removed when you disconnect the service or delete your account, subject to provider processing and backups.
Safety reports may retain a limited snapshot of reported content and related moderation records after the original content or an account is deleted when reasonably necessary to investigate abuse, document our response, enforce our rules, comply with law, resolve disputes, or protect users and the Services.
When a reporting user deletes their account, Scapetone removes that user’s account identifiers from active report records and may retain the report in de-identified form. Reports cannot ordinarily be withdrawn through the app.
Short-term report-rate-limit records are configured for deletion after approximately eight days, although deletion may not occur immediately. Blocking relationship records are removed when they are no longer needed to enforce a block, when a user unblocks an account and no block remains in the other direction, or when the applicable account-deletion process completes.
When in-app account deletion completes, Scapetone removes the account and associated app content from active Scapetone systems, including profile and private account records, user content, social relationships, notifications, contact-discovery entries, invitation markers, stored profile images, and server-held connected-service authorization records. Device-only Spotify and Apple Music link data are also cleared by the app.
Where reasonably necessary for safety, security, legal compliance, dispute resolution, or enforcement, limited moderation or de-identified records may be retained as described above even after account deletion.
Service providers may retain deleted information in encrypted backups, security logs, or disaster-recovery systems for a limited period. Google states that deletion from relevant Firebase live and backup systems may take up to 180 days. We may also retain limited information when required by law, necessary to resolve disputes, enforce agreements, prevent fraud or abuse, or protect safety. Aggregated or de-identified information that cannot reasonably identify you may be retained.
Support correspondence is kept only as long as reasonably needed to handle the request, maintain necessary business records, and meet legal or security obligations.
Your Choices and Controls
Profile and privacy settings: Edit profile details and choose account visibility and who may comment from within the app.
Contacts: Grant or revoke Contacts permission in iOS Settings.
Notifications: Change notification settings in iOS Settings and use available in-app controls.
Connected services: Disconnect a music service in Scapetone Settings and, if desired, revoke Scapetone access in that provider’s account settings.
Content: Edit or remove available content and interactions through the app’s controls.
Reporting and blocking: You can report supported profiles and user-generated content from their in-app menus. You can block an account to hide interactions between the accounts and remove related social connections. Accounts you blocked can be reviewed and unblocked by opening Profile → Settings → Blocked Accounts. Reports cannot ordinarily be withdrawn through the app, but you may contact support@scapetone.com regarding a report.
Account deletion: In Scapetone, open Profile → Settings → Delete Account and confirm your password. Deletion is permanent and cannot be undone.
Access, correction, or privacy request: Contact support@scapetone.com. We may need to verify your identity before acting on a request.
Depending on where you live, you may have additional rights regarding access, correction, deletion, portability, restriction, objection, or appeal. You may also have the right to complain to a local data-protection authority. We will honor applicable rights and will not discriminate against you for exercising them.
Security and International Processing
We use administrative, technical, and organizational safeguards designed to protect information, including encrypted network transport, access controls, Firebase App Check with Apple App Attest or DeviceCheck for protected requests, server-controlled reporting and blocking operations, report-rate limits, password reauthentication before account deletion, device Keychain storage for Spotify tokens, and restricted server-side account deletion. These measures reduce risk but do not eliminate it, and no system can be guaranteed completely secure.
Scapetone and our service providers may process information in the United States and other countries where privacy laws may differ from those where you live. Where required, we use appropriate protections for international transfers.
Children’s Privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us at support@scapetone.com so we can investigate and delete it. Higher minimum ages may apply where required by local law.
Third-Party Services and Links
Third-party services are governed by their own terms and privacy policies. Scapetone does not control their independent practices. Review the policies of Google Firebase and Google Cloud; Apple, including MusicKit, push notifications, App Attest, and DeviceCheck; Spotify; SoundCloud; TIDAL; Discogs; MusicBrainz; the Cover Art Archive; Squarespace; and applicable communications providers before using the relevant features.
Changes to This Policy
We may update this Privacy Policy as the Services or legal requirements change. We will post the updated policy with a new “Last updated” date and provide additional notice when required. Material changes apply prospectively unless otherwise permitted by law.
Contact Us
For privacy questions, requests, complaints, or concerns about a report, contact:
Scapetone LLC
Email: support@scapetone.com