slipcue

privacy

last updated — 29 July 2026

slipcue is a small app for sending songs to people you actually know. this is the plain-language version of what we hold, why, and how to get it back or get rid of it.

01 — who we are

who we are

slipcue ("we", "us") is the controller of your personal data under UK GDPR. you can reach us any time at [email protected].

02 — what we collect

what we collect

  • sign-in. apple or google only. from your provider we get a subject id and your email address — that's how we know it's you. we never see or hold a password.
  • your profile. your @handle, a display name, an optional avatar (stored in our database and served publicly, for example on the links you share), and your device locale (a BCP-47 language tag, so anything we send speaks your language).
  • what you share. the songs you send (track details and streaming links), the notes and replies you write, and receipts — whether a song was opened, and whether it was listened to.
  • push tokens. one per signed-in device (via Expo), so we can notify you when a real person does something — a reply, a receipt, an invite. never "we miss you".

03 — apple music (optional)

apple music, only if you connect it

if you connect apple music, we store a music token — encrypted at rest with AES-256-GCM, never in plain text. we use it in one way: to check your recently-played on apple's servers so we can mark listened receipts on the songs friends sent you. we don't keep a history of what you listen to beyond those receipt facts, and you can disconnect apple music at any time.

04 — contacts

your contacts stay on your phone

if you let slipcue see your contacts, we use them only on your device to help you pick who to invite. your address book is never uploaded — this is enforced, not just promised. on Android the build doesn't even hold the contacts-write permission, and nothing in the app transmits your contacts to us or anyone else.

05 — receipts

receipts, and your control over them

receipts are honest by design: a green "listened" only ever means a real listen. and they're yours to switch off — when read-receipts are off, your opens and listens are never reported to anyone, on any song.

06 — analytics

analytics and crash reports

we use PostHog (on an EU-hosted project) for product analytics — which features get used, so we can make the app better. our public smart-link pages also log basic view and tap events. if the app crashes, a crash report goes to Sentry (also EU-hosted) — a stack trace and the device model, with no account identity attached — so we can fix what broke. we don't run ads, and we don't build advertising profiles.

07 — where your data lives

where your data lives

your data is stored on DigitalOcean (London) and served through Cloudflare. we don't sell your data, and we never will.

08 — your rights

export, deletion, and your rights

both of these live in the app, under your account:

  • export my data. gives you a JSON file with your profile (handle, display name, email, primary service, whether receipts are on, and when you joined), how many friends and threads you have, every song you've sent (the track, your note, and when), and every reply you've written (the text and when).
  • delete my account. we tombstone your identity: your apple and google sign-in ids, your email, your avatar, your push tokens, and any connected-service tokens are wiped; your display name becomes "deleted" and your @handle is replaced with a random one, so you're no longer identifiable or searchable. your friendships and any invites you sent that hadn't been redeemed are deleted outright.

one honest caveat: songs and replies you already sent stay in your friends' threads — the same way an email or a text you sent still sits in someone else's inbox after you delete your own account. we keep those so your friends' conversations don't fall apart, but they're no longer tied to an identifiable you.

no longer have the app installed? email [email protected] from the address on your account and we'll run the same deletion for you — no reinstall needed.

under UK GDPR you also have the right to access, correct, or object to how we use your data, and to complain to the ICO (ico.org.uk) if you think we've got it wrong — though we'd rather you told us first.

09 — changes

changes to this policy

if we change something that matters, we'll flag it in the app rather than quietly editing this page. the date at the top always tells you the current version.

questions about any of this? email [email protected].