Resonate

Privacy Policy

Version 1.0. Effective 28 September 2026.

This policy covers Resonate at resonatefm.app and the Resonate mobile app, which loads the same site. It describes what the service actually does, not what a template says a service might do.

Who is responsible

Resonate is built and run by one person: Melih Onat, in Ontario, Canada. There is no company, no team, and no support department. When this policy says "we", it means one individual.

For anything about your privacy, email hello@melihonat.dev. That address reaches the person who can actually do something about it, and it is the same address used for support and for safety reports, so you never have to guess which one to write to.

Because Resonate is open to people in the European Economic Area and the United Kingdom, this policy is written to the GDPR standard, and Canadian federal privacy law (PIPEDA) applies to it as well. Where those differ, the stricter one is what we follow.

What we collect, and why

The account you create

To sign in at all, Resonate needs an email address and either a password or a Google sign-in. Passwords are handled by our authentication provider and are never visible to us. If you sign in with Google, Google tells us your email address and basic profile details, and nothing about the rest of your Google account.

Why: we cannot give you an account without it. Under GDPR this is necessary to perform our contract with you.

The profile you fill in

A username, a display name, and optionally a bio, a profile picture, a banner image, social handles, an accent colour, and a pinned list or album. Everything in this list is visible to anyone who visits your profile, including people who are not signed in. That is the point of a profile, but it is worth saying plainly.

A small number of account fields are not public and are readable only by the service itself: your role, your email preference, and how you first found Resonate.

Why: contract, for the parts that make the service work, and your own choice for everything optional.

What you write and share

Ratings, reviews, comments, lists and the albums in them, Listening Club picks and curator notes, likes, follows, and reports you file. Public content is public. It is readable by anyone, signed in or not, and by search engines.

Why: contract. Publishing what you write is the service.

Direct messages

Messages you send to other members, and the conversations they belong to. These are private between the participants, but they are not end-to-end encrypted. They are stored in our database in a form the service can read, which means that in principle we can read them. In practice we do not, except where we have to act on a report.

Why: contract, and our legitimate interest in keeping the service safe when a message is reported.

Connecting a music service

If you choose to import your saved albums, we send your Resonate account identifier to the music service as part of the sign-in handshake, and we receive back a list of saved albums, their artists, and their artwork. We keep that list only long enough to show you the import preview: at most two hours, swept automatically every hour. You can clear it yourself at any time from Settings, Privacy and safety. We never store a long-lived token, so we cannot reach your music account again once the import is done.

Why: your consent, given by starting the import. You do not have to do this, and nothing else in Resonate depends on it.

Searching for music

When you search for an album or an artist, the text you typed goes to our music catalogue provider, and the results are cached for one hour so that repeated searches are fast. The cache is keyed by the search text, not by your account.

Why: contract. Search is how you find the album you want to log.

Things that happen automatically

Why: our legitimate interest in running a service that works, stays up, and is not abused. You can object to this, and the Your rights section explains how.

Who else sees your data

Resonate does not sell your data and does not share it for advertising. We do rely on a small number of service providers who process data on our behalf:

ProviderWhat it handles
SupabaseAuthentication, the database, and profile image storage
VercelHosting, analytics, performance measurement, and server logs
UpstashRate limiting, and the one-hour search cache
ResendSending email: sign-in links, password resets, and announcements
GoogleOnly if you choose to sign in with Google
SpotifyThe music catalogue, album artwork, search, and the optional library import
MusicBrainzMatching editions of the same album. No account data is attached to these lookups

We may change music catalogue providers. If we do, this table is updated and the version number at the top of this policy changes with it.

Beyond those providers, we will disclose personal data only where the law requires it, or where it is necessary to act on a child-safety report as described in our Child Safety Standards.

Where your data is

Resonate is operated from Canada. Our providers process data in Canada, the United States, and the European Union. Where that means personal data leaves the European Economic Area, we rely on the transfer safeguards set out in each provider's data processing terms.

How long we keep it

While your account exists, we keep your account data and your content for as long as you keep it, because that is what the service is for. You can delete any individual piece of content at any time.

When you delete your account, the windows are these:

WhatHow long
Your account and everything in itImmediately, as you confirm
Residual copies in backupsUp to 30 days
Moderation records, if you were reported12 months from the report
Records held by our email providerUp to 30 days

Short-lived technical records age out on their own: the search cache after an hour, the music import preview within two hours, rate-limit counters within two hours, the analytics visitor identifier after 24 hours, and the referral cookie after 30 days.

What we can promise is that we delete everything we hold, and that our email provider ages its own copies out. We cannot promise erasure from systems we do not control.

Deleting your account

You can delete your account yourself, from Settings, then Account, or from resonatefm.app/delete-account. Deletion is immediate and cannot be undone. That page explains exactly what is destroyed and the few things that survive, and this policy does not add anything to it.

Two accounts cannot be deleted in the app: the last remaining administrator, and the sole curator of a Listening Club pick. Both are refused with a message pointing to hello@melihonat.dev, and both are handled by hand.

Four things outlive your account on purpose, all of them because deleting them would take other people's content with them:

There is one true retention: if somebody reported you, that report is kept for 12 months with the reporter's identity removed, so that a pattern of harm does not disappear the moment an account is deleted. This is the only case where keeping data beats erasing it, and we rely on our legitimate interest in the safety of other members to do it.

Your rights

You can ask us to:

Email hello@melihonat.dev and we will answer within 30 days. There is no charge.

If you are in the EEA or the UK, you also have the right to complain to your national data protection authority. If you are in Canada, you can complain to the Office of the Privacy Commissioner of Canada. You are welcome to raise it with us first, but you are not required to.

Cookies and local storage

Resonate sets a session cookie so that you stay signed in, and a 30-day referral cookie if you arrived through a tagged link. Your browser also stores small amounts of data locally so the interface remembers your preferences. We do not use advertising cookies, and there are no third-party trackers to consent to.

Email you receive from us

Sign-in links, password resets, and replies to something you contacted us about are part of running your account, and cannot be turned off while the account exists.

Listening Club announcements are a product email, and they arrive by default. Every one has an unsubscribe link that works in one click without signing in, and unsubscribing stops all future announcements.

Children

Resonate is not for anyone under 13, and we do not knowingly collect data from anyone under 13. If you believe a child under 13 has an account, email hello@melihonat.dev and we will remove it. Our approach to child sexual abuse and exploitation is set out separately in our Child Safety Standards.

Security

Traffic to Resonate is encrypted. Passwords are hashed by our authentication provider and never stored by us in readable form. Access to the production database is restricted to the operator. Private data is kept behind server-side boundaries rather than being filtered in your browser.

No service is perfectly secure, and Resonate is run by one person rather than a security team. If you find a vulnerability, email hello@melihonat.dev and we will take it seriously.

Changes to this policy

When this policy changes, the version number and effective date at the top change with it. If a change materially affects your rights or how your data is used, we will tell you in the app before it takes effect, and we will keep the previous version available.

Contact

Melih Onat Ontario, Canada hello@melihonat.dev