Cooldown — Privacy Policy
Last updated: 31 August 2026
The short version.
- Your journal entries, photos, videos, audio recordings, canvases and collections never leave your device. We cannot see them, and we do not store copies.
- We store only what an account needs: your email address, your profile details, and your subscription status.
- We do not sell your data, we do not show ads, and we do not track you across other apps or websites.
- Anonymous usage analytics help us improve the app. You can switch them off at any time in Settings → Privacy.
- Because your content is stored only on your device, losing the device means losing that content. Use Settings → Your Data → Export everything to keep a backup.
1. Who we are
Cooldown (“the app”) is made and published by Oliver Pope, an independent developer based in the United Kingdom (“we”, “us”). Oliver Pope is the data controller for the personal data described in this policy.
For any privacy question or to exercise your rights, contact privacy@cooldownmusic.com.
2. What stays on your device
Cooldown is a local-first app. The following is written to a database and to files in the app's private storage on your device, and is never uploaded to us or to anyone else:
- Journal entries, including notes, dates, ratings and venues
- Any location you attach to an entry
- Photos, videos and audio recordings you add as memories
- Canvases and their layouts
- Collections, collection items and any images you add to them
- Ranks, filters, and your app preferences
We have no ability to read, recover or restore this content. Two consequences follow, and we want to be direct about both:
- We cannot access your journal, even if you ask us to or if we are compelled to try.
- If you lose your device, delete the app, or reset your device, that content is gone. Export a copy regularly if it matters to you.
3. What we collect, and why
Everything that does leave your device is listed here in full.
| What | Why | Processor |
|---|---|---|
| Email address | To create your account and sign you in with a one-time code. We do not store passwords, because the app does not use them. | Supabase |
| Apple ID identifier and, if you allow it, your email or Apple's private relay address | To sign you in when you choose Sign in with Apple. | Apple, Supabase |
| Username, display name, bio, profile picture | To build the profile you see in the app. You choose all of these and can change or clear them at any time. | Supabase |
| Subscription and purchase status, including which plan you hold and whether it is active | To unlock paid features, to restore purchases on a new device, and to handle renewals and cancellations. | RevenueCat, Apple, Supabase |
| Product analytics events — small records of actions such as opening the app, creating a journal entry or collection item, viewing a screen, changing a setting, viewing the paywall or completing a purchase. Each carries an anonymous identifier (a random ID that is never linked to your account, email address or name), the app version, the platform, your subscription tier, your display preferences, and a coarse location (city and country) estimated from your internet connection — never from your device's GPS. | To understand which features are used so we know what to improve. These events record that something happened, never the content of what you created — no journal text, no media, no search terms, no venue or crew names. You can turn this off at any time in Settings → Privacy → Anonymous Usage Analytics. | PostHog (hosted in the EU) |
| Crash reports and diagnostics: error messages, stack traces, device model, OS version, app version, and a sample of performance traces | To find and fix crashes and performance problems. | Sentry |
| Metadata about failed network requests, such as the endpoint and status code | To detect outages and broken integrations. | Sentry |
4. Error session replay, explained plainly
Our diagnostics tool is capable of capturing a short replay of the app's user interface from the moments before an error, to help us reproduce bugs we could not otherwise diagnose. This is currently switched off across the app — no replays are being recorded — while we investigate a performance issue the feature caused. We want to be explicit about this because, if we turn it back on, it is the one thing in this policy that might surprise you. If we do, the “What we collect” table above will list it again, and it will work like this:
- Triggered by errors only. We do not record ordinary sessions where nothing goes wrong.
- Text and images are masked by the recorder, so it captures the shape and flow of the screens rather than the content of your entries.
- It captures the app only, never other apps or your wider device.
- The app is configured not to attach screenshots to error reports in released builds.
5. Device permissions
The app asks for these only at the point you use the relevant feature, and it works without them:
- Microphone — to record audio memories. Audio is saved to your device only.
- Photo library, read — to let you pick photos and videos to attach to entries. We also read the date a video was filmed so the memory lands on the right day.
- Photo library, add — only when you explicitly save something back to your library.
The app does not request camera access, and does not request access to your contacts, calendar, health data, or precise background location.
6. What we do not do
- We do not sell or rent your personal data.
- We do not show advertising.
- We do not track you across other apps or websites, and we do not use advertising identifiers.
- We do not use your content to train machine learning models — your content never reaches us in the first place.
- We do not build advertising or marketing profiles about you.
7. Anonymous accounts
You can use much of the app without giving us an email address. In that state we hold only a randomly generated account identifier and the analytics events described above, flagged as anonymous. If you later sign up, that identifier is linked to your new account so your subscription and profile carry over. Your content is unaffected either way, because it was on your device all along.
8. Legal bases for processing
Where UK and EU data protection law applies, we rely on the following bases:
- Performance of a contract — account creation, sign-in, profile, and subscription entitlements. Without these we cannot provide the app.
- Legitimate interests — crash reporting, diagnostics and product analytics, so the app is stable and improves. We keep these minimal, pseudonymous, and never use them to target you — and you can object to product analytics at any time with the Anonymous Usage Analytics switch in the app's settings, which takes effect immediately on that device.
- Consent — device permissions such as microphone and photo library access, which you grant or refuse at the OS level and can withdraw at any time in your device settings.
- Legal obligation — where we must retain records, for example for tax purposes relating to a purchase.
9. Who we share data with
We use a small number of service providers, each processing data on our instructions under a data processing agreement:
- Supabase — authentication, profile storage, subscription records
- PostHog — product analytics, stored and processed in the European Union
- RevenueCat — subscription and entitlement management
- Sentry — crash reporting and diagnostics, processed in the European Union
- Apple — app distribution, Sign in with Apple, and all payment processing. We never see your card details.
- Cloudflare — hosting for this page
We may also disclose data where we are legally required to, or to establish or defend legal claims. Given that your content is device-only, there is very little for us to disclose.
10. International transfers
Some providers process data outside the UK and the European Economic Area. Where they do, transfers are covered by the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, together with additional safeguards where needed.
11. How long we keep things
- Account and profile data — for as long as your account exists, then deleted when you delete your account.
- Analytics events — retained in aggregate for product analysis. Once your account is deleted, the identifier the events carry no longer connects to anyone; to have the events themselves erased, email us and we will delete them from our analytics provider.
- Crash reports — retained on our diagnostics provider's standard schedule, currently 90 days, then deleted automatically. Session replay is currently switched off (see section 4), so no replay data exists to retain; if it is turned back on, that provider's standard schedule is 30 days.
- Purchase records — retained as long as tax and accounting law requires.
- Your content — kept on your device until you delete it or remove the app. We hold no copy and therefore no retention period applies.
12. Your rights
You have the right to access, correct, delete, restrict and object to our processing of your personal data, to withdraw consent, and to data portability. Three of these are built directly into the app:
- Stop analytics — Settings → Privacy → Anonymous Usage Analytics. Switch it off and this device stops sending product analytics events immediately. The app works exactly the same either way.
- Export your data — Settings → Your Data → Export everything. This produces a zip of your journal database, photos, videos, audio and collection images, and opens the share sheet so you can keep it wherever you like.
- Delete your account — Profile → Account → Delete account. This permanently removes your account and the profile and subscription records associated with it, and it cannot be undone. Analytics events were never linked to your account in the first place, so nothing there identifies you after it goes.
For anything else, email privacy@cooldownmusic.com and we will respond within one month. If you are in the UK you may complain to the Information Commissioner's Office; if you are in the EU, to your national supervisory authority.
13. Children
Cooldown is not directed at children, and we do not knowingly collect personal data from anyone under 13, or under the minimum age of digital consent in your country if that is higher. If you believe a child has given us personal data, contact us and we will delete it.
14. Security
Your content benefits from your device's own protections, including device encryption and the app's private storage area. Data in transit to our providers is encrypted with TLS. Access to our systems is restricted and authenticated, and profile pictures are held in a private storage bucket rather than a public one. No system is perfectly secure, but keeping your content off our servers entirely removes the single largest category of risk.
15. Changes to this policy
If we change this policy we will update the date at the top of this page. Where a change materially affects your rights, we will tell you in the app before it takes effect.
16. Contact
Oliver Pope
privacy@cooldownmusic.com
Email is the fastest way to reach us and is the contact channel we monitor. If you need a postal address for a formal request, ask and we will provide one.