This draft explains how personal information relates to listening, creating, buying music, and managing an Undiscovered One account. It describes known services and intended safeguards; optional and future practices are identified as such. It is not an adopted policy or an effective-date announcement.
Scope and responsibility
This policy is intended to cover listeners, creators and artists, purchasers, subscribers, visitors, and people who contact Undiscovered One. It applies to the music platform, radio and streaming, discovery, creator dashboards, purchases, Music Plus, creator memberships, and related account management where this policy is linked.
Central sign-in is handled through Undiscovered One Accounts using Supabase-based authentication. Account information may be used across connected Undiscovered One services to recognize your account and manage access. Separate notices may explain service-specific processing. A third-party service you visit independently has its own privacy terms.
The formal organization responsible for personal information is [Company legal name]. Its legal identity, mailing address, and any legally required representative or privacy contact must be confirmed before public adoption. These placeholders do not identify a registered entity or a data-protection officer.
Information you provide
Account and profile information may include your email address, account identifiers, display name, authentication information, profile image, biography, and settings. The fields collected depend on the account and features you use. Authentication credentials are handled through the account and authentication systems; you should never send passwords or verification codes in a support message.
Creator and release information includes uploaded audio and artwork, artist and release names, credits, descriptions, genres, rights declarations, AI-related labels, and other release metadata you submit. Public release and profile fields are intended to be visible to listeners. Files and metadata may also contain personal information about collaborators; provide it only when you are authorized to do so.
Payment and payout setup may involve billing details, transaction references, tax information, and creator verification or onboarding information. Stripe or Stripe Connect may collect identity documents, bank details, and other information directly. Undiscovered One may receive the information or status needed to administer an account, verify payout eligibility, and meet legal obligations, rather than every item submitted to Stripe.
Support communications include what you send when asking for help, reporting infringement, requesting a privacy action, or appealing a decision. This can include contact details, order or release references, correspondence, and attachments. Avoid sending unrelated sensitive information.
Information from platform use
Depending on the feature, the platform may record listening and playback activity, including tracks played, radio sessions, playback progress, skips, and activity needed for authorized-device offline access. Purchase records, owned-music entitlements, subscription and membership state, follows, favorites, and playlists support your library and account experience.
Discovery interactions may include searches, releases viewed, recommendation impressions, selections, and feedback. These signals may support personalization and measurement. Creator analytics events may describe plays, purchases, engagement, and release performance without requiring private listener identities to be shown to creators.
Device, browser, and session information may include IP addresses, browser and operating-system details, device or session identifiers, timestamps, error information, sign-in events, and security logs. Where used, an IP address may support an approximate location, such as a country or region; this does not mean precise GPS location is collected.
The categories above describe information relevant to the platform, not a claim that every listed event, identifier, or analytics system is already implemented. Optional collection should be explained when introduced and should use consent or another permitted basis where required.
Payments and card information
Stripe processes payment card and bank information for purchases and subscriptions. Undiscovered One generally does not store full payment card numbers. It may receive payment confirmations, provider identifiers, limited payment-method details such as card brand and last digits, billing information, and transaction, refund, dispute, or subscription status.
Payment records help deliver purchased music, manage recurring billing, investigate transaction problems, prevent fraud, and meet accounting or legal requirements. Stripe may process some information for its own compliance, security, and fraud-prevention purposes under its own notices. Checkout may also use payment-provider cookies and similar technologies.
Creator onboarding and payouts
Creator payouts use Stripe Connect. Onboarding may require information about the creator or business, authorized representatives, identity, tax status, and payout account. Requirements depend on location, account type, and Stripe’s verification rules. Stripe may request additional evidence or update an onboarding status over time.
Undiscovered One may use connected-account identifiers, verification results, payout eligibility, earnings and transaction records, and necessary tax or compliance information to administer creator payments. Information should be limited to what is needed for the relevant payout and compliance purpose. A payout review may require records about disputed activity or rights to a release.
Uploads and rights-protection checks
Uploaded music is reviewed. Review may include release metadata, rights declarations, audio or artwork analysis, and third-party content-recognition, copyright-protection, fraud, or abuse-detection services. Processing may involve sending necessary files, extracts, fingerprints, or metadata to a provider to identify potential matches or risks.
A match or automated signal is not, by itself, a definitive finding of infringement or misconduct. Relevant evidence, user explanations, and review or appeal should inform important decisions where appropriate. Review records may be retained to investigate repeat disputes, protect rights, and comply with law. The intended approach to fair treatment is described in the Digital Bill of Rights; detailed enforcement policies remain drafts.
How information is used
Information is used as needed to provide the service: create and authenticate accounts, maintain profiles and libraries, host and play music, enable radio, deliver purchases and authorized offline playback, manage memberships and Music Plus, and operate creator dashboards and payouts.
Information may also support discovery and recommendations, measure release or service performance, troubleshoot errors, improve features, provide support, communicate account or transaction updates, and investigate fraud, security threats, prohibited conduct, and copyright issues. Records may be used to comply with tax, accounting, lawful requests, and other legal obligations.
Optional marketing, new analytics uses, or materially different processing should be explained separately and should use any consent or opt-out required by law. This draft does not assert that marketing campaigns or every possible vendor integration are already active.
Legal bases where applicable
Some regions require an identified legal basis for processing. Depending on the information, purpose, and applicable law, relevant bases may include performing a contract or taking steps you request before a contract; legitimate interests such as securing the service, addressing fraud, and improving reliability; your consent for uses that require it; and compliance with legal obligations.
A legitimate-interest basis requires consideration of your interests and rights and is not permission to disregard them. Where processing depends on consent, you may withdraw it for future processing without making earlier lawful processing unlawful. If information is required for a requested service or a legal obligation, not providing it may prevent that service from being delivered.
The specific controller, applicable regional notices, and purpose-by-purpose legal-basis details must be confirmed before adoption. This section is a general explanation, not jurisdiction-specific legal advice or a claim that every listed basis applies to every activity.
The boundary around creator analytics
Creators need to understand how their work performs, but listening should not automatically reveal who a private listener is. The intended rule is that creator analytics should use aggregated or appropriately privacy-protected information and should not expose private listener identities unless the listener expressly chooses to share them.
A listener’s decision to follow, purchase, or play music is not by itself consent to disclose a private email address, account identity, or individual listening history to a creator. Where a feature offers identifiable sharing, the choice and its audience should be clear. Public interactions or profile information you intentionally make visible may still be visible independently of analytics.
Data retention
Information should be kept for as long as reasonably needed for the relevant purpose, including operating an active account, fulfilling purchases and payouts, resolving disputes, protecting security and rights, and meeting legal requirements. Retention depends on the record, its purpose, applicable law, and any unresolved dispute; this draft does not invent a universal deletion deadline.
When information is no longer needed, the intended approach is to delete it or make it no longer identify a person, subject to lawful retention and technical constraints. Backup copies may remain for a limited operational cycle and should not be used as an excuse to keep information indefinitely. Detailed schedules and provider deletion arrangements must be verified before adoption.
Security
Undiscovered One’s intended approach is to use reasonable technical and organizational measures appropriate to the information and risk, including controlled access, authentication safeguards, and monitoring for abuse. No online service, transmission, or storage system can be guaranteed completely secure. This policy is not a claim of a particular certification, audit, or implemented security control.
Use a secure account sign-in method, keep recovery information current, and report suspected unauthorized access through the existing support channel. Do not share passwords, verification codes, or payment details in public posts. Where a security incident triggers a legal notification duty, the applicable notification requirements must be followed.
Children and eligibility
The service is not intended for children where their use or the processing of their information is legally prohibited. Age and account eligibility requirements are addressed in the Terms of Service and must be finalized for supported regions before public adoption. This draft does not set or imply a specific minimum age.
If you believe a child has provided information contrary to applicable requirements, contact support so the situation can be reviewed and appropriate action taken. Verification should avoid collecting more personal information than reasonably needed to address the concern.
International processing and transfers
Infrastructure and service providers may process information in countries other than the one where you live. Those countries may have different privacy laws. Provider locations and actual transfer routes must be assessed rather than assumed from a provider’s name.
Where law requires safeguards for an international transfer, appropriate permitted safeguards must be used, such as recognized adequacy arrangements or approved contractual protections, together with any further measures required. This draft does not claim that a particular transfer mechanism or regional hosting commitment has already been implemented. You may request information about applicable safeguards through support.
Your privacy rights and choices
Depending on where you live and the circumstances, you may have rights to access information, correct inaccurate information, request deletion, receive portable information, restrict or object to certain processing, withdraw consent, or opt out of uses covered by local law. Rights can have exceptions, including records needed for legal obligations or a dispute. You may also have a right to complain to a relevant privacy regulator.
Use available account settings for changes they support, or make a request through the existing Undiscovered One support/contact channel. Identify the request and relevant account without sending your password or full payment details. Reasonable identity or authority verification may be needed to protect your account; any verification should be proportionate. Requests should be addressed within the applicable legal period, with an explanation when an exception applies.
Available settings for personalization, communications, or storage may vary by feature. Where legally required, applicable opt-outs and consent withdrawal must be respected. This document does not claim that a specific self-service privacy portal, recommendation toggle, or consent manager is already available.
Account closure and ownership records
Closing an account and deleting all records are not always the same action. Some purchase, ownership-entitlement, payout, tax, accounting, fraud-prevention, chargeback, copyright, and legal records may need to be retained after account closure. Access should be limited and retained records should not be reused for unrelated purposes simply because they remain available.
Before requesting closure, consider access to music tied to the account and any unresolved purchases or payouts. Platform-based ownership depends on identifying a valid entitlement and an authorized account or device; irreversible removal of identifying information can affect the ability to restore that access. Support should explain the consequences and available options. There is no claim here of an unrestricted file export or an already implemented post-deletion recovery mechanism.
Ordinary enforcement should not automatically confiscate legitimately purchased music. Necessary record retention supports that distinction, subject to narrow fraud, chargeback, legal, and copyright exceptions described in the Terms and foundational rights. Voluntary closure should not be treated as a hidden sale of personal data or a way to evade lawful retention duties.
AI and transparency
Recommendations, discovery, or review may use automated or AI-assisted technology. Relevant information may be processed for those purposes where appropriate and permitted. Such processing is distinct from using a creator’s music to train a generative model.
Uploading music does not automatically grant permission for generative-AI training. Any proposed training use would require a separate, clearly explained permission or other lawful basis that respects creators’ rights; the ordinary platform upload license is not a blanket training authorization. AI-generated or AI-assisted music may be allowed with appropriate labels and rights checks. Important decisions should have appropriate transparency and review rather than treating an automated signal as infallible.
Changes and draft history
October 7, 2026: this comprehensive draft was prepared to replace the Privacy Policy placeholder. This is a drafting milestone, not public adoption or an effective date. The operating practices, formal entity details, required regional disclosures, and applicable safeguards must be checked before finalization.
When adopted policies change, the intended approach is to publish the revised date, explain meaningful changes, and provide appropriate notice or obtain consent where required. Material reductions in established rights should not occur silently. The Policy Change Log is currently a placeholder; this draft entry does not assert a publicly adopted change there.
Contact and related documents
For privacy questions or requests, use the existing Undiscovered One support/contact channel in the service or on the main website. Formal contact details remain [Privacy contact] and [Company mailing address], to be confirmed before public adoption. Do not send sensitive identity or banking documents unless a verified process requests them.
Read this draft alongside the Cookie Policy, Terms of Service, and Digital Bill of Rights. All remain unadopted drafts; none is represented as attorney-reviewed or as evidence issued by another platform.