Version 1.0. Effective 28 September 2026.
This policy covers Resonate at resonatefm.app and the Resonate mobile app, which loads the same site. It describes what the service actually does, not what a template says a service might do.
Resonate is built and run by one person: Melih Onat, in Ontario, Canada. There is no company, no team, and no support department. When this policy says "we", it means one individual.
For anything about your privacy, email hello@melihonat.dev. That address reaches the person who can actually do something about it, and it is the same address used for support and for safety reports, so you never have to guess which one to write to.
Because Resonate is open to people in the European Economic Area and the United Kingdom, this policy is written to the GDPR standard, and Canadian federal privacy law (PIPEDA) applies to it as well. Where those differ, the stricter one is what we follow.
To sign in at all, Resonate needs an email address and either a password or a Google sign-in. Passwords are handled by our authentication provider and are never visible to us. If you sign in with Google, Google tells us your email address and basic profile details, and nothing about the rest of your Google account.
Why: we cannot give you an account without it. Under GDPR this is necessary to perform our contract with you.
A username, a display name, and optionally a bio, a profile picture, a banner image, social handles, an accent colour, and a pinned list or album. Everything in this list is visible to anyone who visits your profile, including people who are not signed in. That is the point of a profile, but it is worth saying plainly.
A small number of account fields are not public and are readable only by the service itself: your role, your email preference, and how you first found Resonate.
Why: contract, for the parts that make the service work, and your own choice for everything optional.
Ratings, reviews, comments, lists and the albums in them, Listening Club picks and curator notes, likes, follows, and reports you file. Public content is public. It is readable by anyone, signed in or not, and by search engines.
Why: contract. Publishing what you write is the service.
Messages you send to other members, and the conversations they belong to. These are private between the participants, but they are not end-to-end encrypted. They are stored in our database in a form the service can read, which means that in principle we can read them. In practice we do not, except where we have to act on a report.
Why: contract, and our legitimate interest in keeping the service safe when a message is reported.
If you choose to import your saved albums, we send your Resonate account identifier to the music service as part of the sign-in handshake, and we receive back a list of saved albums, their artists, and their artwork. We keep that list only long enough to show you the import preview: at most two hours, swept automatically every hour. You can clear it yourself at any time from Settings, Privacy and safety. We never store a long-lived token, so we cannot reach your music account again once the import is done.
Why: your consent, given by starting the import. You do not have to do this, and nothing else in Resonate depends on it.
When you search for an album or an artist, the text you typed goes to our music catalogue provider, and the results are cached for one hour so that repeated searches are fast. The cache is keyed by the search text, not by your account.
Why: contract. Search is how you find the album you want to log.
Why: our legitimate interest in running a service that works, stays up, and is not abused. You can object to this, and the Your rights section explains how.
Resonate does not sell your data and does not share it for advertising. We do rely on a small number of service providers who process data on our behalf:
| Provider | What it handles |
|---|---|
| Supabase | Authentication, the database, and profile image storage |
| Vercel | Hosting, analytics, performance measurement, and server logs |
| Upstash | Rate limiting, and the one-hour search cache |
| Resend | Sending email: sign-in links, password resets, and announcements |
| Only if you choose to sign in with Google | |
| Spotify | The music catalogue, album artwork, search, and the optional library import |
| MusicBrainz | Matching editions of the same album. No account data is attached to these lookups |
We may change music catalogue providers. If we do, this table is updated and the version number at the top of this policy changes with it.
Beyond those providers, we will disclose personal data only where the law requires it, or where it is necessary to act on a child-safety report as described in our Child Safety Standards.
Resonate is operated from Canada. Our providers process data in Canada, the United States, and the European Union. Where that means personal data leaves the European Economic Area, we rely on the transfer safeguards set out in each provider's data processing terms.
While your account exists, we keep your account data and your content for as long as you keep it, because that is what the service is for. You can delete any individual piece of content at any time.
When you delete your account, the windows are these:
| What | How long |
|---|---|
| Your account and everything in it | Immediately, as you confirm |
| Residual copies in backups | Up to 30 days |
| Moderation records, if you were reported | 12 months from the report |
| Records held by our email provider | Up to 30 days |
Short-lived technical records age out on their own: the search cache after an hour, the music import preview within two hours, rate-limit counters within two hours, the analytics visitor identifier after 24 hours, and the referral cookie after 30 days.
What we can promise is that we delete everything we hold, and that our email provider ages its own copies out. We cannot promise erasure from systems we do not control.
You can delete your account yourself, from Settings, then Account, or from resonatefm.app/delete-account. Deletion is immediate and cannot be undone. That page explains exactly what is destroyed and the few things that survive, and this policy does not add anything to it.
Two accounts cannot be deleted in the app: the last remaining administrator, and the sole curator of a Listening Club pick. Both are refused with a message pointing to hello@melihonat.dev, and both are handled by hand.
Four things outlive your account on purpose, all of them because deleting them would take other people's content with them:
There is one true retention: if somebody reported you, that report is kept for 12 months with the reporter's identity removed, so that a pattern of harm does not disappear the moment an account is deleted. This is the only case where keeping data beats erasing it, and we rely on our legitimate interest in the safety of other members to do it.
You can ask us to:
Email hello@melihonat.dev and we will answer within 30 days. There is no charge.
If you are in the EEA or the UK, you also have the right to complain to your national data protection authority. If you are in Canada, you can complain to the Office of the Privacy Commissioner of Canada. You are welcome to raise it with us first, but you are not required to.
Resonate sets a session cookie so that you stay signed in, and a 30-day referral cookie if you arrived through a tagged link. Your browser also stores small amounts of data locally so the interface remembers your preferences. We do not use advertising cookies, and there are no third-party trackers to consent to.
Sign-in links, password resets, and replies to something you contacted us about are part of running your account, and cannot be turned off while the account exists.
Listening Club announcements are a product email, and they arrive by default. Every one has an unsubscribe link that works in one click without signing in, and unsubscribing stops all future announcements.
Resonate is not for anyone under 13, and we do not knowingly collect data from anyone under 13. If you believe a child under 13 has an account, email hello@melihonat.dev and we will remove it. Our approach to child sexual abuse and exploitation is set out separately in our Child Safety Standards.
Traffic to Resonate is encrypted. Passwords are hashed by our authentication provider and never stored by us in readable form. Access to the production database is restricted to the operator. Private data is kept behind server-side boundaries rather than being filtered in your browser.
No service is perfectly secure, and Resonate is run by one person rather than a security team. If you find a vulnerability, email hello@melihonat.dev and we will take it seriously.
When this policy changes, the version number and effective date at the top change with it. If a change materially affects your rights or how your data is used, we will tell you in the app before it takes effect, and we will keep the previous version available.
Melih Onat Ontario, Canada hello@melihonat.dev