Attorney review required
This policy is a launch-ready draft for product planning and must be reviewed by a qualified attorney before public launch.
Overview
CypherClub helps rappers practice, record, join rooms, use beats, complete challenges, and share creative work. This Privacy Policy explains what information we collect, how we use it, and what choices users have.
Information we collect
We may collect account information such as email address, username, display name, avatar, membership tier, referral codes, onboarding answers, settings, and authentication metadata.
We may collect content and activity such as saved takes, highlights, lyrics, transcripts, room activity, chat messages, beat usage, challenge history, saved sessions, shared links, reports, support tickets, feedback, and moderation records.
We may collect technical data such as device type, browser, IP address, logs, crash data, route activity, approximate location from IP, cookie data, local storage data, and analytics events.
We may collect billing and entitlement metadata through Stripe, RevenueCat, Apple, Google Play, or other authorized payment and entitlement providers, such as customer ID, subscription ID, app user ID, product ID, plan, billing interval, subscription status, current period end, cancellation status, renewal status, and payment status. We do not store full card numbers.
We may collect Cypher Credits and rewards data such as wallet balance, credit grants, credit transactions, daily rewards, streak rewards, rewarded ad events, referral reward status, storage usage, AI usage metadata, soft-cap status, and admin corrections.
Advertising, cookies, and consent
CypherClub may use Google AdSense on approved web pages and Google AdMob in future native iOS or Android builds. Advertising providers may process device identifiers, IP address, approximate location, browser or app information, consent signals, ad interactions, fraud-prevention signals, and contextual information according to their own policies and the choices available to you.
We keep advertising disabled by default until the relevant provider, consent, and placement requirements are configured. Ads are blocked during recording, active performance, beat playback, checkout, support, safety reporting, and beside unmoderated user content. Pro, Admin, active remove-ads entitlements, and compatible legacy paid entitlements suppress eligible CypherClub display placements.
The web cookie controls let you accept optional analytics and ads, choose non-personalized ads, or use essential cookies only. Where required, production Google advertising in the EEA, United Kingdom, or Switzerland also requires a Google-certified consent management platform. Native apps require the Google User Messaging Platform or an equivalent compliant consent flow before requesting ads when consent is required.
Optional rewarded ads are initiated by the user. A reward is recorded only after the server verifies provider completion. Display ads never grant credits. You can report an inappropriate advertisement through the Report an Ad page.
Audio, lyrics, and transcripts
Audio recordings, transcripts, and lyrics can be personal creative work. We use them only to provide features such as playback, storage, sharing, analysis, moderation, support, safety review, and user-requested AI feedback.
When you explicitly request transcription, CypherClub may send the selected saved audio to ElevenLabs, OpenAI, or another provider identified in the product before confirmation. The provider may return transcript text, word timing, language confidence, audio-event labels, and speaker labels for full-room recordings. A transcript request is separate from Ranked judging and does not send camera footage. Provider processing and retention are also subject to that provider's applicable terms, privacy commitments, and CypherClub account configuration.
Do not upload private third-party information, secrets, payment information, passwords, or content you do not have rights to use.
Optional player cameras
Player cameras are off by default and require a persistent verified account, an adult age declaration, current camera-policy acceptance, eligible account standing, a local device preview, and a separate opt-in for each session. We may process the private age declaration, eligibility decision, account standing, camera suspension, policy version, per-session consent, device/session metadata, and safety events needed to control access and investigate reports.
Normal game camera tracks are transmitted through LiveKit only after opt-in and are not recorded by default. Camera footage does not influence Ranked judging, rating, matchmaking, skill progress, community reputation, or access to gameplay. Spectators may view shared player cameras but cannot broadcast a camera. Disabling camera falls back to the player's avatar and activity indicators.
Selected adult performers in an official CypherClub show must separately accept a session-specific recording release. Official-show video may be recorded, edited, published, clipped, promoted, streamed, and distributed as described in that release. Public official-show camera access remains subject to legal, moderation, and operational review.
Legacy collaborative-session data
Some users created collaborative media under an earlier Recording Studio feature. For lawful existing archive access, we may process room metadata, beat selections, participant roles, mute and recording-inclusion settings, segment assignments, consent choices, LiveKit session metadata, Egress recording IDs, storage paths, timestamps, and recording status. We use this information to preserve consent records, support authorized playback or export, enforce permissions, resolve disputes, and comply with safety, copyright, and legal obligations. New collaborative song creation is not exposed to new users.
Only participants who were marked for inclusion and consented should appear in existing collaborative media. Consent records may be retained even if media is later deleted, where needed for safety, audit, disputes, legal compliance, or abuse prevention.
Profile image uploads and moderation
When you upload a profile image, we process the original file, file type, file size, dimensions, a normalized copy, storage path, moderation status, provider response, rejection reason, and upload timestamps. We use this information to resize and secure the image, detect prohibited or unsafe content, display approved images, investigate abuse, support appeals, and operate profile and community features.
Profile images are stored in private storage. Pending and rejected images are not displayed publicly. Approved images may be visible to other users across profiles, rooms, records, friends, messages, comments, leaderboards, and related community features. We may use Supabase for private storage and OpenAI or another disclosed safety provider to evaluate uploads. Those providers process the image only as needed to provide their services under their applicable terms and privacy commitments.
You may remove or replace your profile image through account settings. Removed and rejected files are scheduled for deletion from active storage, subject to reasonable processing time, backups, security records, legal holds, and safety obligations. Limited moderation and audit records may be retained to prevent abuse, resolve disputes, and comply with law. Severe suspected child exploitation or other illegal content may be restricted, preserved, or reported when legally required.
How we use information
We use information to operate CypherClub, provide accounts, save recordings, play beats, run rooms, process memberships, provide support, investigate reports, prevent abuse, enforce rules, improve product quality, analyze usage, personalize experiences, send permitted emails, and comply with law.
Product analytics
CypherClub may use PostHog or similar analytics tools to understand product usage, funnels, retention, feature performance, and crashes. We do not intentionally send raw audio, full transcripts, passwords, payment card details, API keys, or private message content to analytics tools.
Session replay, if enabled, should be configured to mask sensitive inputs and avoid private recording details. Legal and privacy review is required before broad replay use.
Analytics events may include credit earning, credit spending, reward claims, ad reward outcomes, upgrade prompts, AI feature usage, storage limit events, and subscription state changes.
Email communications
CypherClub may use Resend or similar email providers for transactional emails, account notices, billing updates, support replies, safety notices, recording reminders, product updates, and marketing emails where permitted.
Security, billing, account deletion, and legal service emails may be sent even if marketing is disabled. Marketing emails require consent where required and should include unsubscribe or preference options.
Service providers
CypherClub may use service providers such as Supabase for authentication, database, and storage; Stripe for payments; Vercel for hosting and infrastructure; PostHog for analytics; Resend for email; LiveKit for real-time rooms; ElevenLabs for selected music, voice, and user-requested transcription features; and OpenAI or other AI providers if AI features are enabled.
These providers process information to help us operate CypherClub.
If ads are enabled, CypherClub may use Google AdSense, Google AdMob, or similar advertising providers to serve ads, measure impressions, verify rewarded ad completion events, prevent fraud, enforce frequency caps, respect consent choices where required, and grant eligible in-app rewards. Paid members and admin users should not receive CypherClub ad placements where ad removal is supported.
RevenueCat may be used to manage cross-platform subscription entitlements for future iOS and Android apps. RevenueCat may receive app user IDs, product identifiers, entitlement status, renewal status, store information, and webhook events needed to keep membership access accurate across platforms.
Sharing and public visibility
Some information becomes visible when you choose to share a public highlight, join rooms, chat, share links, appear on leaderboards, create a producer or host profile, or participate in public features.
Private recordings and shared links should follow the visibility settings and permissions available in the product. Do not share links with people who should not access the content.
Safety and legal disclosures
We may disclose information if needed to comply with law, respond to legal process, protect users, investigate safety issues, enforce policies, prevent fraud, address security incidents, or protect the rights and property of CypherClub and others.
Retention
We retain information for as long as needed to provide the service, comply with law, resolve disputes, enforce agreements, prevent abuse, process billing, provide support, and maintain records. Recording retention may depend on membership tier, user settings, storage limits, and legal holds.
Takes and highlights data
When you save takes or share highlights, we may process titles, descriptions, tags, visibility settings, audio metadata, duration, file size, playback activity, props, favorites, shares, reports, downloads, producer attribution, beat-rights labels, and estimated bandwidth usage. We use this information to provide playback, profiles, discovery, moderation, analytics, storage management, abuse prevention, and membership features.
Public highlights are visible to other users. Unlisted highlights are visible to people with the link. Private takes are intended for owner access and administrative or legal review where required.
Watch creator data
When you use Watch or apply to be listed as a creator, we may process creator display names, bios, categories, platform links, stream titles, live status, schedules, follows, notification preferences, reports, moderation status, and admin notes. Twitch, YouTube, TikTok, and other third-party platforms may process information under their own policies when you open or watch embedded or linked streams.
We use Watch notification preferences to send in-app alerts, and email alerts where enabled and configured. Users can opt out of optional creator notifications in product settings where available.
Account deletion
Users may request account deletion through the app where available. Some information may be deleted, anonymized, retained for legal or safety reasons, or retained in backup systems for a limited period.
Children
CypherClub accounts are not available to users under 13. We do not knowingly create accounts for users under 13. COPPA, teen privacy, and state privacy obligations require final legal review before public launch.
Security
We use reasonable technical and organizational measures to protect information. No system is perfectly secure. Users should use strong passwords and protect their accounts.
International users
CypherClub may process and store information in the United States and other locations where service providers operate. By using CypherClub, you understand that information may be transferred and processed outside your location.
Your choices
You may be able to update profile settings, notification settings, privacy settings, email preferences, membership settings, saved content, and account deletion requests in the app.
Profile image controls let you upload, replace, or remove an image. Removing an image returns your account to the default silhouette; it does not automatically erase legally required safety or audit records.
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing. Contact support to make a privacy request.
Changes
We may update this Privacy Policy as CypherClub changes. The current version and last updated date will be shown on this page.
Contact
For privacy questions, contact support through the Support page or the support email shown in the app.
