Legal

Privacy Policy

This Privacy Policy explains what information Sceenz collects, how we use it, who we share it with, and the choices you have. We try to collect the minimum data needed to run the Service well.

Last updated: May 27, 2026

§ Overview

Sceenz is operated from the United States. By using the Service, you understand that your information is processed in the US and by the third-party processors listed below.

We don’t sell your personal information. We don’t run third-party advertising trackers. The data we collect exists so the Service works — accounts, content delivery, payment processing, abuse prevention.

§ Information We Collect

Information you provide:

  • Account info — email address and password at signup. Passwords are hashed by Supabase Auth before storage; we never see them in plain text.
  • Profile info — username, display name, bio, location (city/state, optional), avatar and banner images, top 4, custom CSS, interests, mood, online-status preference.
  • Featured track — a YouTube video ID and optional artist/title you choose to feature on your profile.
  • Content you post — bulletinz, blogz, photos, forumz posts, messagez sent to other users.
  • Band/artist fields (if you have an artist account) — Spotify, SoundCloud, Apple Music, and merch links; member names, instruments, hometown, genre, influences, established year; tour dates; merch table entries with external store links.
  • Social graph — friend connections, top 4 choices.
  • Premium-theme purchase records— which themes you bought and when (we don’t store your payment card; Stripe does).

Information collected automatically:

  • Session cookies for authentication, so you stay signed in. Strictly necessary; no advertising cookies.
  • Last-seen timestamp — so other users can see when you were last active. You can hide this in settings.
  • Traffic and device data via Vercel — IP address, browser type, OS, referrer, and pages visited. Used for service operation, abuse prevention, and aggregate analytics. Not used to build advertising profiles.

§ How We Use Information

  • To run the Service — show your profile, deliver messagez, render the feed.
  • To authenticate you and keep your account secure.
  • To process premium-theme purchases (via Stripe).
  • To detect and prevent spam, fraud, and abuse.
  • To respond to support and legal requests.
  • To improve Sceenz (aggregate, non-identifying analytics).
  • To send service-critical email (password resets, security alerts, billing notices). We will not add you to a marketing list without your opt-in.

§ Who We Share Information With

We share information with the following categories of recipients — and only as needed:

Service providers (data processors):

  • Supabase — database hosting and authentication. Stores profile data, content, friend graph, session tokens.
  • Stripe — payment processing for premium themes. Receives the data needed to charge your card (card details flow directly from your browser to Stripe; we receive a transaction reference, not your card number).
  • Vercel — web hosting and traffic analytics. Receives request metadata to serve the Service and aggregate usage stats.

We sign data-processing agreements (DPAs) with each provider and use them only for the purposes described above.

Other Sceenz users:

Your public profile information is visible to other users and to anyone with the URL — that’s the point of a social profile. This includes your username, display name, bio, avatar, banner, top 4, friends list (unless you make it private), public bulletinz, public blogz, mood, online status (unless you hide it in settings), tour dates, merch links, and anything else you choose to post publicly. Search engines may also index your public profile.

Legal and safety:

We may disclose information to comply with applicable law, court orders, or other legal process; to enforce these Terms and our policies; or to protect the safety, rights, or property of Sceenz, our users, or the public.

Business changes:

If Sceenz is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We’ll notify you in advance and give you a chance to delete your account first.

§ Third-Party Embeds and Links

Sceenz embeds YouTube videos for featured tracks. When a YouTube embed loads on a profile page, YouTube may set cookies and collect data per Google’s privacy policy. The same applies to any external link you click from Sceenz (Spotify, SoundCloud, Apple Music, Bandcamp, ticket retailers, merch stores). We don’t control those third parties’ practices.

§ Data Retention

  • Active accounts: we retain your data while your account is active.
  • After account deletion: profile data and posts are deleted promptly. Backups containing your data may persist for up to 90 days before being overwritten.
  • Payment / transaction records: kept as required by tax and financial law (typically around 7 years), in an isolated form not tied to an active profile.
  • Abuse and security logs: retained as long as reasonably needed to investigate or prevent incidents.

§ Your Rights

You can:

  • Access your data — most of it is visible in your profile and account settings.
  • Correct it — edit any field via your profile settings.
  • Delete your account — via account settings; this cascades to your profile content.
  • Export your data — email legal@sceenz.net and we’ll send what we have on you in a portable format within a reasonable time.
  • Opt out of optional processing or hide your online status — most controls live in settings; for anything not exposed in the UI, email us.

§ California Residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (as amended by the CPRA):

  • The right to know what personal information we have collected, sold, or shared about you.
  • The right to delete personal information.
  • The right to correct inaccurate personal information.
  • The right to limit use of sensitive personal information.
  • The right to opt out of “sale” or “sharing” of personal information for cross-context behavioral advertising. Sceenz does not sell or share personal information for advertising purposes.
  • The right to non-discrimination for exercising these rights.

To exercise any of these rights, email legal@sceenz.net. We will verify your identity (typically by emailing you from the address on your account) before acting on a request.

§ EU / UK Residents (GDPR)

If you’re in the EU, EEA, or UK, we process your personal data on one of these lawful bases:

  • Contract — to provide the Service you signed up for.
  • Legitimate interest — for fraud prevention, service security, and product improvement.
  • Consent — for optional features you opt into.
  • Legal obligation — to comply with law (tax, court orders, etc.).

You have the rights to access, rectify, erase, restrict processing of, and port your data; to object to processing based on legitimate interest; to withdraw consent at any time for processing based on consent; and to lodge a complaint with your local supervisory authority. Contact legal@sceenz.net to exercise any of these rights.

Sceenz does not currently have an EU representative. Our processing is limited in scope: no large-scale behavioral profiling, no special-category data, no data about children under 16.

International transfers: our processors are based in the United States. Transfers from the EU/EEA/UK rely on Standard Contractual Clauses with each processor.

§ Children’s Privacy

Sceenz is not directed to children under 13 (or under 16 in the EU/EEA/UK). We don’t knowingly collect personal information from anyone under those ages. If we learn we have, we delete it. If you believe a child has signed up, email legal@sceenz.net and we’ll act promptly.

§ Data Security

We use industry-standard security practices: encrypted connections (HTTPS), hashed passwords, server-side row-level security, isolated database access via service-role credentials, and regular dependency updates. No internet service is perfectly secure — if a breach materially affects you, we’ll notify you as required by law.

§ Changes to This Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent change. For material changes, we’ll provide reasonable notice on Sceenz before they take effect.

§ Contact

Privacy questions or requests? Email legal@sceenz.net.