Privacy Policy
Last updated: September 21, 2026
Songkrate ("we", "us", "our") is a music player for families: a parent or guardian curates a music library, and children play from it. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
Who holds the account
Songkrate accounts belong to parents and guardians. A grown-up signs up, curates the music, and creates one or more child profiles with a name and an emoji. Children use those profiles without creating their own Songkrate accounts or providing contact details. Profile information and activity within the player are collected as described below.
Information we collect
Account information. When you create an account, we collect your email address and a securely hashed password. A display name is optional. We never store your password in plain text.
Profile data. You create child profiles within your account (a name and an avatar emoji you choose). These are stored to provide the service.
Music preferences and activity. We store your curation choices (the albums, artists, tracks, and playlists added to each profile) and the playback history within each profile, so parents can see what their kids have been listening to. This is core functionality.
Apple Music connection. Songkrate plays music through your existing Apple Music subscription using Apple's MusicKit. Authorization is handled by Apple on your device; we do not receive or store your Apple ID password.
Subscription information. Songkrate subscriptions are billed by Apple through the App Store. We receive transaction identifiers, subscription status, purchase dates, and available price and currency information from Apple to manage your entitlement and measure subscription conversion. We never see or store your payment card details.
Referrals. If you share your referral link and someone subscribes, we record that connection so we can credit the reward. This is tied to your account and the referred account only.
Usage and diagnostics. We collect basic server logs (IP address, request timestamps), product-analytics events (such as signing in, entering a child profile, or starting playback), and crash/error reports to keep the app reliable.
Apple Ads attribution. When attribution is enabled in a supported version of the app, we use Apple's AdServices framework to obtain a temporary token and send it through our server to Apple's attribution service. Apple may return information about an Apple Ads campaign credited with the download, including campaign, ad group, keyword and ad identifiers, placement, campaign country or region, whether an ad was tapped or viewed, and whether the download was new or a redownload. Some fields may be unavailable.
We also store a randomly generated installation identifier, app version and build, lookup status, and timestamps for our processing. We use a separate secret to associate the installation's attribution with your parent account when you sign up or sign in. Once associated, this data is linked to your account, not anonymous. We use it alongside account, household activity, and subscription information to understand which campaigns lead to signup, music selection, return use, and payment.
This integration does not use the device's advertising identifier (IDFA) or track your activity across other companies' apps and websites. We do not send parent email addresses, child profiles, or listening histories to Apple for attribution. Campaign attribution records are stored on our servers and are not sent to PostHog. If an attribution response cannot be validated, response data and error details may be sent to Sentry for troubleshooting. Attribution tokens and account-association secrets are excluded from these reports.
How we use your information
- To provide and operate the Songkrate service
- To authenticate your account and protect your data
- To manage your subscription and any referral rewards
- To send transactional emails (verification, password resets, invites)
- To understand how the app is used in aggregate and improve it
- To measure the effectiveness of our Apple Ads campaigns using account-linked attribution, activity, and subscription information
- To diagnose crashes and fix bugs
Data storage & security
Your data is stored on secure servers. Passwords and parent PINs are hashed using bcrypt. API tokens are cryptographically signed. All connections use HTTPS encryption.
Third-party services
- Apple Inc. provides playback and catalog browsing via MusicKit, subscription billing through the App Store, and Apple Ads attribution through AdServices when enabled.
- PostHog provides product analytics to help us understand usage and improve the app. Analytics can include your parent account identifier, email address and display name, profile identifiers and names, and music-related activity such as searches, selections, and playback events.
- Sentry provides crash and error reporting to improve reliability. Reports about failed attribution validation can include Apple's response data, the failed validation check, and an attribution-record reference. Attribution tokens and account-association secrets are excluded.
- Resend — sending transactional email (verification, password resets, invites). Your email address is shared only for delivery.
We do not sell your personal information, and we do not use your data for third-party advertising.
Data retention
We retain your data as long as your account is active. You can permanently delete your account and all associated data — including every child profile and its history — at any time from within the app: open Settings → Delete Account and confirm with your password. You can also request deletion by emailing us at hello@songkrate.app.
Attribution retention. Raw attribution tokens are held temporarily for delivery and lookup retries. The app stores pending token information in the device's Keychain, clears the token after successful delivery, and discards a token older than 24 hours before retrying delivery. Our server encrypts retained raw tokens and removes them when the lookup finishes or scheduled cleanup processes their expiry. The server stores the account-association secret as a hash rather than in plain text.
Attribution records that have not been linked to an account are deleted by scheduled cleanup after 30 days. Account-linked attribution is retained with the account and deleted when the account is deleted. Deleting your account in the app also stops its local attribution outbox and clears its stored token and association proof. Retention cleanup continues even when new attribution collection is disabled.
Attribution-validation error reports sent to Sentry follow the retention settings of our Sentry service, separately from the attribution-record cleanup described above.
Your rights
You have the right to access, correct, or delete your personal data. As the account holder, you can manage or delete child profiles at any time in the app. Contact us at hello@songkrate.app for any privacy-related request.
Children's privacy
Parents manage accounts and music collections; children listen through parent-curated profiles. We store the profile information supplied by the parent and the activity generated while a profile is used, including music selections and playback history. We do not require children to provide an email address or create a Songkrate account. Parents can manage or delete profiles and can request help with their family's data at hello@songkrate.app.
Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a notice in the app.
Contact us
If you have questions about this Privacy Policy, contact us at hello@songkrate.app.