Privacy Policy
Effective date: June 12, 2026
Digger Music ("Digger", "we", "us", "the app") is a music-discovery iOS app that surfaces new album and EP releases worldwide. This Privacy Policy explains what data we collect when you create an account and use the app, how we use it, who we share it with, and what rights you have over your data.
1. Account creation and sign-in
Using Digger Music requires creating an account. We do not offer an anonymous browsing mode — sign-in is mandatory after the on-boarding flow so your follows, saved releases, and preferences stay synced across every device you sign in with.
You sign in through one of three OAuth identity providers:
- Sign in with Apple — we receive your Apple-issued user identifier and (optionally, if you don't opt for Apple's Hide My Email relay) your email and full name.
- Sign in with Google — we receive your Google-issued user identifier, your email, and your name as set on your Google account.
- Sign in with Spotify — we receive your Spotify-issued user identifier, your email, and your display name as set on Spotify.
We do NOT receive your password from any provider. Authentication is delegated entirely to Apple, Google, or Spotify; the app only gets a short-lived token that proves the provider verified your identity.
2. What we collect
2.1 Account profile
- User identifier — a UUID generated by our authentication service when you first sign in.
- Email address — the one your chosen provider shares with us. With Apple Sign In, this may be a private-relay address (
@privaterelay.appleid.com) you can revoke at any time. - Display name — first and last name (or display name) as your provider shares it. Used only to greet you on the Profile screen.
- Primary provider — which of Apple / Google / Spotify you signed in with. Used to surface the right "Continue with…" button on re-authentication.
- Last-seen timestamp — updated on each cold launch of the app. Used to compute aggregate daily/weekly/monthly active-user counts.
2.2 App content tied to your account
- Followed artists — the list of artists you follow. Each row stores the artist's slug, display name, and genre.
- Saved releases and Listen-later queue — the release identifiers you've hearted or queued.
- Preferences — your selected music genres, your "show reissues & compilations" toggle, your preferred streaming service (Apple Music, Spotify, Deezer), and your notification settings.
2.3 Device-level data
- Apple Push Notifications (APNs) device token. When you grant notification permission, iOS issues an opaque per-device token. We send this token to our server along with your followed-artist list so we can push a notification when a followed artist releases a new album. The token cannot identify you personally and cannot deliver pushes to any other device.
- Apple Music authorization status (if you grant it). Used solely to enable in-app preview playback and to fetch additional catalog data; your Apple Music listening history is never sent to our server.
3. What we do NOT collect
- No password — authentication is delegated to your chosen provider.
- No phone number, postal address, or government ID.
- No advertising identifiers (IDFA).
- No location data — neither precise nor coarse.
- No contact list, no calendar, no photo library, no microphone access.
- No third-party advertising or marketing SDKs are integrated.
- No crash-report SDKs that transmit personal data. Apple's standard TestFlight / App Store crash logs may be collected by Apple under their own policy.
4. Anonymous product analytics
We use PostHog to understand how the app is used in aggregate — which onboarding step is the most frequent drop-off, how often the search feature yields results, how many users grant notification permission. This lets us improve the app without bothering you with surveys.
The analytics integration is configured for maximum privacy and is NOT linked to your account:
- No personal profile is ever created in PostHog. The "person profile" feature is explicitly disabled; PostHog only sees a random per-install UUID that cannot be linked to your account UUID, your email, your phone number, or your Apple ID.
- No IP address is captured. PostHog drops the IP before it reaches their geo-resolution layer, so we cannot tell which city or country you opened the app from.
- No user-typed text is captured. When you search the catalog, we only log how long your query was and how many results it returned — never the words you typed.
- No screen recording, no session replay. Both features are disabled at the SDK level.
Events captured include: app open, onboarding step viewed/completed/skipped, artist followed/unfollowed, notification permission granted/denied, search performed (length + result count, never the query text), release opened, release shared, tab navigation. The full list is documented in the app source code under Analytics.Event.
5. How we use your data
- To authenticate you and persist your session across launches and devices.
- To sync your followed artists, saved releases, and preferences across every device you sign in with.
- To send push notifications when a followed artist releases a new album or EP (only if you grant notification permission).
- To send the optional weekly digest email of coverage gaps, if you've opted in.
- To improve the app via anonymous, aggregate behavioural analytics (see section 4).
We do not sell your data, do not share it with advertisers or data brokers, and do not use it for targeted advertising in any context — neither inside Digger nor anywhere else.
6. Third-party services
- Apple, Google, Spotify (sign-in). Each handles your authentication and shares with us only the identifiers listed in section 2.1. Their own privacy policies govern what happens before the sign-in callback returns to Digger.
- Apple Music / MusicKit. When you tap a release, the app opens it in Apple Music. Apple's privacy policy applies for any interaction inside Apple Music.
- Apple Push Notification Service. Used to deliver new-release notifications. Your APNs token is the only identifier shared with this service.
- Supabase (database + authentication). Hosts your account profile, follows, saved releases, and preferences. Data is stored in the European Union (Frankfurt region) and protected by row-level security so your data is only accessible with a valid session token issued by your sign-in provider.
- Vercel (hosting). Serves our backend API. Standard server access logs (IP, timestamp, request path) are processed by Vercel under their own policy; we do not retain or analyze these logs.
- Spotify Web API. Used to ingest public release data for the shared catalog. No data about you is sent to Spotify outside the OAuth sign-in flow (if you chose Spotify as your provider).
- Resend (transactional email). Used to send the optional weekly digest. The only data shared is the destination email address and the message body.
- PostHog (analytics). See section 4 for the privacy posture. PostHog stores the anonymous event stream and is the only third-party service that sees behavioural data about the app; they do not see your account identity, your IP, or anything you typed.
7. Data retention
We keep your account data and all linked rows (follows, saved releases, preferences, APNs subscriptions) for as long as your account is active. If you delete your account, all of this data is wiped from our database within 30 days. PostHog's anonymous event stream is retained for 12 months for aggregate analysis, then deleted.
If you uninstall the app without deleting your account, your data is preserved so it can be restored when you sign in again on a new install. Push notifications stop reaching the uninstalled device automatically once Apple Push Notification Service reports the token as unregistered (typically within a few weeks).
8. Your rights
You have the following rights over your personal data, regardless of where you live:
- Access. Email us and we will provide a copy of every data point we hold about your account, in a machine-readable format, within 30 days.
- Correction. Update your display name and email at any time by re-authenticating with your provider (the latest values from Apple / Google / Spotify will be synced to our database).
- Deletion. Email us asking to delete your account, or use the in-app account-deletion option once we ship it. We will wipe all your account data from our database within 30 days. The anonymous PostHog stream cannot be retroactively linked to you, so it is unaffected.
- Portability. The same data-export response described under "Access" is provided in a portable JSON format.
- Object. Stop the weekly digest by replying to any digest email with "STOP". Stop push notifications by toggling them off in iOS Settings → Notifications → Digger Music.
For users in the European Union, the UK, California, Brazil, or other jurisdictions with applicable data-protection laws (GDPR, UK GDPR, CCPA, LGPD, etc.), you have the same rights under those laws and may exercise them by contacting us at the address below. If you believe we have not handled your request properly, you may also lodge a complaint with your local supervisory authority.
9. Children
Digger Music is not directed at children under the age of 13. We do not knowingly collect data from children under 13. If you believe we may have collected data about a child under 13, please contact us and we will delete it.
10. Security
Account authentication is delegated to Apple, Google, and Spotify, who each use industry-standard OAuth 2.0 with cryptographic verification. Data in transit between the app and our backend is encrypted end-to-end via HTTPS (TLS 1.3). Data at rest in Supabase is encrypted with AES-256. Row-level security policies prevent any signed-in user from reading another user's data — the database itself enforces the isolation.
11. Changes to this policy
We will update the "Effective date" above whenever the policy changes. Material changes will be announced through an in-app notification on the next cold launch after the update ships.
Contact
Questions about this policy, data-access requests, or data-deletion requests:
Email: romaric.gattin@whiz.pro
Data controller: Romaric Gattin / Whiz
© 2026 Digger Music. All rights reserved.