Get app
Log in Enquire Search About Learn more

Privacy Policy

This policy explains what information we collect, why we collect it, and the choices artists and curators have while using Rhune.

Last updated: 19 September 2026

Current status: Rhune Premium has not launched, so Rhune does not currently collect or process billing or subscription data. The conditional references below explain how that data would be handled if a paid service is introduced later.

On this page+
Who we are Data we collect How we use personal data Legal bases (UK & EU) How we share data International transfers Retention Security Your rights Cookies and similar tech Eligibility Changes to this policy Contact

Who we are

Rhune (“Rhune”, “we”, “us”) is the controller responsible for the invite-only artist platform and curator experience at rhune.co (the “Service”). We are based in the United Kingdom. If you have privacy questions or requests, email hello@rhune.co.

Data we collect

We collect the information needed to set up invites, keep accounts secure, and run the catalogue:

  • Invite and account details: the artist name and Spotify link we use to create your profile, the one-time invite token, the email address you choose, and the basic login logs that show when a magic link was used.
  • Authentication data: email login codes, verification timestamps, and session records needed to keep accounts signed in securely.
  • Artist Content: any notes, edits, profile images, or other materials you add. Uploaded images fall under this policy too.
  • Spotify Metadata: the public catalogue data (artwork, titles, release years, track lists) we import from Spotify to display your work.
  • Apple Music preview data: Apple Music preview URLs attached to tracks and the related network requests your browser makes to Apple Music delivery endpoints when preview audio is played.
  • Curator account data: curator profile information (display name, slug, avatar, uploaded profile images), selected public Spotify content identifiers, playlist titles, playlist images, track metadata, and curator notes or reviews tied to those tracks.
  • Curator review data: ratings, review text, release-group selections, publishing state, public URLs, and timestamps associated with curator reviews.
  • Notification data: an app-specific Apple push token and notification delivery status, linked to your curator account so we can send follow and save alerts to your iPhone. Rhune does not use this token for advertising or tracking.
  • Safety and moderation data: reports, report reasons, optional supporting notes, account blocks, the content or account reported, review status, and relevant timestamps. Reports are private and used only to investigate abuse, enforce our rules, and protect users.
  • Listener Note data: fan aliases (if provided), note text, moderation metadata such as hashed IP addresses, browser signatures, and timestamps, plus any actions you take (e.g., highlighting or featuring a note). This allows us to run listener sessions and enforce per-IP limits.
  • Partner distribution data: records of which approved partner integrations receive Rhune content, endpoint and access logs, and delivery metadata needed for security, audits, and contractual compliance.
  • Technical logs: IP address, browser, device type, timestamps, error reports—so we can keep things stable and secure.
  • Billing and subscription data, if a paid service is introduced: the plan you select, payment tokens or identifiers from our processor, invoices, receipts, and tax information needed to deliver that service.
  • Support messages: emails or other contact you send us.

We do not currently run third-party behavioural analytics or ad trackers. If that changes, we will update this policy and ask for consent where required.

How we use personal data

We use personal data to:

  • Authenticate invited artists and keep accounts secure.
  • Authenticate curator accounts via email code login.
  • Refresh catalogue pages with Spotify Metadata and power reading room views.
  • Stream short preview clips for tracks where preview audio is available, including previews delivered from Apple Music endpoints.
  • Import selected public playlist and catalogue data and keep curator reading rooms up to date.
  • Store and publish Artist Content, including across future fan or community features.
  • Store and publish Curator Notes, reviews, ratings, and curator profile content (including uploaded images) across curator reading rooms.
  • Use curator profile images and related profile content to promote Rhune (for example on discovery pages or product updates).
  • Fetch and display Spotify release metadata and artwork for artist and curator pages.
  • Invite fans, run listener note sessions, moderate submissions, and surface curated fan notes in reading rooms.
  • Investigate reports, prevent blocked accounts from interacting, and enforce our safety and content rules.
  • License and deliver Artist Content (including notes and forewords) to approved third-party partners via authenticated APIs or feeds, under contractual controls.
  • Send operational emails such as login links, feature updates, or policy notices.
  • Send optional iPhone notifications about new follows and saves when you enable notifications.
  • Monitor security, prevent abuse, and fix technical issues.
  • If a paid service is introduced, process payments, issue invoices, apply taxes, and provide subscription management.
  • Comply with legal obligations and enforce our Terms.
  • Plan future features, including possible advertising or subscription options.

Legal bases (UK & EU)

Where UK or EU law applies, we rely on:

  • Contract – to deliver the Service you signed up for.
  • Legitimate interests – to secure the Service, prevent misuse (including listener note abuse), improve features, and send essential communications.
  • Consent – for optional marketing or non-essential cookies/analytics, if we introduce them.
  • Legal obligation – when we have to comply with law or lawful requests (such as tax rules covering payments).

How we share data

We share personal data with a short list of providers who help us run Rhune:

  • Render (United States) for hosting and infrastructure.
  • Amazon Simple Email Service (SES) for sending transactional emails.
  • Stripe (or another payment processor we tell you about), if a paid service is introduced, for billing and securely storing payment methods.
  • Spotify for catalogue and review metadata, artwork, and destination links.
  • Apple Music for preview-audio delivery and release-link destinations where we surface Apple Music listening options.
  • Apple Push Notification service to deliver optional iPhone notifications.
  • Cloud storage and content delivery (such as Amazon S3 or similar providers) to store and serve uploaded images.
  • Anti-abuse or content-delivery vendors that help us enforce listener note limits and deliver images/audio quickly.
  • Approved distribution partners who integrate licensed Rhune content through API or feed access, under contracts that limit use, sharing, retention, and onward disclosure.
  • Other vendors we may add later, for example analytics or advertising partners. We will update this policy if the list changes materially.

Each processor or approved partner is bound by a written agreement requiring appropriate data protection and limiting how information can be used.

We may also disclose data if required by law, to protect people’s safety, or to defend our legal rights. We do not sell personal data to data brokers.

International transfers

Because we use providers outside the UK and EU, personal data may be transferred internationally (for example to the United States). We rely on recognised safeguards such as the UK International Data Transfer Addendum and EU Standard Contractual Clauses, together with the processor agreements noted above, to protect those transfers.

Retention

Account data, Artist Content, Curator Notes, Curator Reviews, and uploaded profile images stay in our systems while your account is active. App push tokens are removed when you sign out or delete your account, and invalid tokens are disabled when Apple rejects them. If you delete your account we remove live content and anonymise or delete associated personal data within 90 days, except where we need to keep it longer for legal, security, or backup reasons (routine backups usually cycle within 180 days). Listener Notes and related moderation data may be retained for as long as the hosting artist keeps the session active plus any legal hold period needed to investigate abuse. Payment and invoice records are retained for the statutory period required by tax law (typically 6 years in the UK). Log data is generally retained for up to 12 months.

Security

We use reasonable safeguards such as TLS encryption in transit, access controls, and least-privilege practices for staff. No system is perfect, so we encourage you to protect your own devices and email accounts too.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or restrict the use of your personal data, to object to certain processing, and to request a portable copy. You can withdraw consent for optional processing at any time. To exercise these rights, email hello@rhune.co. You also have the right to complain to the UK Information Commissioner’s Office or your local regulator.

Cookies and similar tech

Right now we only use essential cookies that keep you signed in. They are required for the Service to function. If we ever add optional cookies (analytics, ads, etc.) we will give you clear notice and obtain consent where needed.

Eligibility

Rhune is for invited artists and curators aged 18 or older. We do not knowingly collect personal data from anyone younger. If you believe someone under 18 has provided personal data, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy when the Service evolves or the law changes. We will notify you of important updates by email, artist workspace notice, or another appropriate method. We will date each version so you can see when it last changed. If you continue using the Service after an update takes effect, that means you accept the revised policy.

Contact

Privacy questions or requests? Email hello@rhune.co.

Rhune
About Enquire Search
Privacy Account Terms Site Terms
© 2026 Rhune

Metadata sourced from Spotify. Preview audio sourced from Apple Music.