Meloduels (“we”, “us”) runs the Meloduels mobile app and related services at meloduels.net / api.meloduels.net. This policy explains what we collect, why, and the choices you have.
1. What we collect
- Account — email, password (stored hashed), display name, optional avatar preset.
- Gameplay — Offline and Duels session results, scores, streaks, Elo / rank, energy balance.
- Friends & social — friend requests, invites, lobby participation.
- Connected music accounts — if you link Spotify (and later SoundCloud), we store OAuth tokens and library metadata needed to build quiz packs (playlist names, track titles, artists, artwork URLs, preview URLs, play counts where available). We do not download or permanently store full audio files.
- Catalog / Daily packs — public preview metadata we seed so you can play without linking a library.
- Device & push — FCM device tokens for duel invites and similar notifications when you allow them.
- Purchases — subscription status via RevenueCat / Google Play (we receive entitlement state, not your full payment card details).
- Diagnostics — basic server logs (IP, user agent, request path, error traces) to keep the service reliable and secure.
2. How we use data
- Run quizzes, lobbies, scoring, and ranks.
- Sync and resolve playable packs from your library or catalog.
- Proxy short preview streams so mobile players can hear clips.
- Send optional push notifications you enable (e.g. lobby invites).
- Unlock Premium features and enforce freemium energy limits.
- Prevent abuse, debug outages, and improve the product.
We do not sell your personal data. We do not use your library to train third-party generative AI models.
3. Processors & partners
We rely on infrastructure and product partners under their own terms:
- Hosting — VPS / edge providers that serve the API and this site.
- Spotify — OAuth and library APIs when you connect; Spotify’s privacy policy also applies to data Spotify holds.
- Preview sources — official preview URLs (e.g. Spotify or catalog partners such as iTunes Search metadata) streamed through Meloduels.
- RevenueCat + Google Play Billing — subscriptions and entitlements.
- Firebase Cloud Messaging — push delivery.
Meloduels is not affiliated with, sponsored by, or endorsed by Spotify or SoundCloud.
4. Retention
Account and gameplay data are kept while your account is active. Preview audio may be cached briefly on our servers to improve playback reliability, then expire. Server logs are rotated on a short operational schedule. You can request account deletion via [email protected].
5. Your choices
- Play Offline on Daily / Catalog without linking Spotify.
- Disconnect Spotify in-app (where available) or revoke Meloduels in your Spotify account settings.
- Disable notification permission on your device.
- Manage or cancel Premium through Google Play.
- Email us to correct profile data or delete your account.
6. Security
We use HTTPS, hashed passwords, and access controls on production systems. No method of transmission or storage is perfectly secure; please use a unique password.
7. Children
Meloduels is not directed at children under 13 (or the minimum age required in your country). If you believe a child provided data, contact us and we will delete it.
8. International transfers
Servers and processors may be located outside your country. By using Meloduels you understand your data may be processed where we or our providers operate, with appropriate safeguards where required.
9. Changes
We may update this policy as the product evolves. Material changes will be reflected by the “Last updated” date on this page. Continued use after an update means you accept the revised policy.
10. Contact
Questions or requests: [email protected]
Site: https://meloduels.net