Privacy Policy

This policy explains what information we collect, why we collect it, and the choices artists have while using Rhune.

Last updated: 11 December 2025

Who we are

Rhune (“Rhune”, “we”, “us”) is the controller responsible for the invite-only artist platform at rhune.co (the “Service”). We are based in the United Kingdom. If you have privacy questions or requests, email hello@rhune.co.

Data we collect

We collect the information needed to set up invites, keep accounts secure, and run the catalogue:

  • Invite and account details: the artist name and Spotify link we use to create your profile, the one-time invite token, the email address you choose, and the basic login logs that show when a magic link was used.
  • Artist Content: any notes, edits, or other materials you add. If we later support media uploads (photos, audio, etc.) they will fall under this policy too.
  • Spotify Metadata: the public catalogue data (artwork, titles, release years, track lists) we import from Spotify to display your work.
  • Listener Note data: fan aliases (if provided), note text, moderation metadata such as hashed IP addresses, browser signatures, and timestamps, plus any actions you take (e.g., highlighting or featuring a note). This allows us to run listener sessions and enforce per-IP limits.
  • Technical logs: IP address, browser, device type, timestamps, error reports—so we can keep things stable and secure.
  • Billing and subscription data: the plan you select, payment tokens or identifiers from our processor, invoices, receipts, and tax information needed to deliver Rhune Premium.
  • Support messages: emails or other contact you send us.

We do not currently run third-party behavioural analytics or ad trackers. If that changes, we will update this policy and ask for consent where required.

How we use personal data

We use personal data to:

  • Authenticate invited artists and keep accounts secure.
  • Refresh catalogue pages with Spotify Metadata and power reading room views.
  • Store and publish Artist Content, including across future fan or community features.
  • Invite fans, run listener note sessions, moderate submissions, and surface curated fan notes in reading rooms.
  • Send operational emails such as login links, feature updates, or policy notices.
  • Monitor security, prevent abuse, and fix technical issues.
  • Process payments, issue invoices, apply taxes, and provide subscription management for Rhune Premium.
  • Comply with legal obligations and enforce our Terms.
  • Plan future features, including possible advertising or subscription options.

Legal bases (UK & EU)

Where UK or EU law applies, we rely on:

  • Contract – to deliver the Service you signed up for.
  • Legitimate interests – to secure the Service, prevent misuse (including listener note abuse), improve features, and send essential communications.
  • Consent – for optional marketing or non-essential cookies/analytics, if we introduce them.
  • Legal obligation – when we have to comply with law or lawful requests (such as tax rules covering payments).

How we share data

We share personal data with a short list of providers who help us run Rhune:

  • Render (United States) for hosting and infrastructure.
  • Zoho Mail for sending transactional emails.
  • Stripe (or other payment processors we tell you about) for billing Rhune Premium and securely storing payment methods.
  • Anti-abuse or content-delivery vendors that help us enforce listener note limits and deliver images/audio quickly.
  • Other vendors we may add later, for example analytics or advertising partners. We will update this policy if the list changes materially.

Each processor is bound by a written agreement requiring them to protect personal data and only act on our instructions.

We may also disclose data if required by law, to protect people’s safety, or to defend our legal rights. We do not sell personal data.

International transfers

Because we use providers outside the UK and EU, personal data may be transferred internationally (for example to the United States). We rely on recognised safeguards such as the UK International Data Transfer Addendum and EU Standard Contractual Clauses, together with the processor agreements noted above, to protect those transfers.

Retention

Account data and Artist Content stay in our systems while your account is active. If you delete your account we remove live content and anonymise or delete associated personal data within 90 days, except where we need to keep it longer for legal, security, or backup reasons (routine backups usually cycle within 180 days). Listener Notes and related moderation data may be retained for as long as the hosting artist keeps the session active plus any legal hold period needed to investigate abuse. Payment and invoice records are retained for the statutory period required by tax law (typically 6 years in the UK). Log data is generally retained for up to 12 months.

Security

We use reasonable safeguards such as TLS encryption in transit, access controls, and least-privilege practices for staff. No system is perfect, so we encourage you to protect your own devices and email accounts too.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or restrict the use of your personal data, to object to certain processing, and to request a portable copy. You can withdraw consent for optional processing at any time. To exercise these rights, email hello@rhune.co. You also have the right to complain to the UK Information Commissioner’s Office or your local regulator.

Cookies and similar tech

Right now we only use essential cookies that keep you signed in. They are required for the Service to function. If we ever add optional cookies (analytics, ads, etc.) we will give you clear notice and obtain consent where needed.

Eligibility

Rhune is for invited artists aged 18 or older. We do not knowingly collect personal data from anyone younger. If you believe someone under 18 has provided personal data, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy when the Service evolves or the law changes. We will notify you of important updates by email, artist study notice, or another appropriate method. We will date each version so you can see when it last changed. If you continue using the Service after an update takes effect, that means you accept the revised policy.

Contact

Privacy questions or requests? Email hello@rhune.co.

© 2025 Rhune · About · Privacy · Terms · Instagram

Metadata sourced from Spotify