BANDRY
Privacy Terms

Privacy Policy

Last updated: July 20, 2026

Bandry ("we," "us") helps musicians and music-industry people find each other and link up for projects. This page explains what we collect, how we use it, and the choices you have.

We wrote it in plain English. If anything is unclear, write us at support@bandry.app.

What we collect

Account. When you sign in with Apple or Google, we receive an account identifier and, if you choose to share it, your name and email. If you use Apple's "Hide My Email" option, we never see your real email; we only see the relay address Apple provides.

Profile. Whatever you fill in: display name, avatar, bio, the music-industry roles you select (drummer, producer, mixing engineer, etc.), the genres you're into, the credibility badges you self-declare (the badges, and any proof links you attach to them, appear publicly on your profile), and the city label and approximate location you set. Your "approximate location" is rounded to roughly a one-kilometer grid before it's stored; we never store your precise GPS coordinates.

Photos you upload. Your avatar, photos on Market gear listings, and press-kit photos. Location metadata (EXIF) is stripped on your device before upload, and images are stored in access-controlled storage.

Contact methods. Whichever you add. These come in two tiers, and the difference matters:

  • Private: your phone number and email address (and any direct-messaging handle, like WhatsApp). Other members never see these unless you link up with them, see Your contact info stays private below.
  • Public: your social and music links (Instagram, Spotify, Apple Music, SoundCloud, Bandcamp, YouTube, TikTok, X, Facebook, website, and the rest). These appear on your profile for other subscribed members to see, which is how someone checks out your work before deciding to link up. Only add a handle here if you're comfortable with other members seeing it.

Posts you create. Title, body, intent (seeking or offering), local-or-remote scope, radius preference, your approximate location for local posts, and any showcase links you attach (a Spotify track, a YouTube video, a portfolio site).

Showcase-link previews. When you attach a link to a post, our server fetches the linked page to pull a preview image, title, and favicon (the same kind of preview iMessage and Discord show). We store the preview metadata on your post; we don't store anything else from the page.

Boards content. Market listings (item details, price, condition, photos), Showcase tracks (a link to your track on a streaming service) and the reviews you write (shown to the track's artist without your name attached), and Mixtapes (a link to a public playlist you share).

Press kits. Everything you put in a press kit. When you publish it, the kit becomes a public web page (and a downloadable PDF) that anyone on the internet can view, so treat its contents as public. You can unpublish at any time. We count views of your published kit and show you totals and approximate viewer regions. If a signed-in member views your kit we record their account on the view row (so we can leave your own views out of your totals and catch abuse), but we never show viewer identities to you; views from logged-out visitors are anonymous.

Endorsements and link-ups. Which posts you've tapped 🔥 on (visible to everyone, like an upvote), which posts you've tapped 🔗 on to link up (visible only to you and to the poster you connected with), and what you've hidden with "Not interested" (visible only to you).

Blocks and reports. If you block someone, we record that to filter their content from your view; only you can see your block list. If you report someone, the report goes to our moderation queue.

Subscription state. Whether you're on the free trial, an active subscription, or expired. Apple bills subscriptions bought on iPhone and iPad; Stripe bills subscriptions bought on the web. In both cases the payment processor handles your card, your card number never touches our servers. For web billing we store a Stripe customer reference alongside your subscription state.

Push notification token. If you allow notifications, we store the device token Apple issues so we can deliver them. Settings → Notifications has a toggle for each notification type.

Device info. Standard technical data that any app or website receives, your OS version, device model, app version, browser type. We don't use a third-party analytics SDK in the app and we don't track you across other apps or sites. The analytics you see on your own posts, tracks, mixtapes, and press kits are first-party, computed from the interactions described above, and visible only to you. Our marketing site (bandry.app) uses standard Google Analytics page metrics; the app itself does not.

How we use it

To run the service:

  • Show you a feed of relevant posts (local posts get a two-sided radius check so you only see roles near you).
  • Let you create posts, endorse posts, and link up with people you want to reach.
  • Let posters and linkers exchange contact information at the moment a link-up happens, and only then.
  • Moderate the community when someone reports content.
  • Show you private analytics about your own content, views, endorsements, link-ups, plays, and press-kit views, visible only to you.
  • Keep your subscription state in sync with Apple's and Stripe's billing.

We don't sell your data. We don't use it for advertising. We don't share it with third-party brokers.

Your contact info stays private

This part is the load-bearing rule of Bandry. Your phone number and email address are never displayed on your profile, in posts, or anywhere in the feed. (Your social and music links are a separate, public tier, see Contact methods above.)

The only way someone receives your phone number or email is if you tap 🔗 on a post they wrote. At that moment, and only at that moment, they're revealed to that poster, so they can reach you off-platform. The poster cannot mass-broadcast their contact info to people who haven't actively reached out.

This rule is enforced in our database, not just the app. A request to our API for someone else's phone number or email address is refused unless a link-up between the requester and that user exists.

Approximate location, never precise

For local posts to work, "drummer wanted within 25 miles", we need to know roughly where you are. We use the lowest accuracy iOS offers (kCLLocationAccuracyReduced), and we round your coordinates further on your device, so what we receive is approximately a one-kilometer grid square. We never store fine-grained GPS.

You can also set your location manually, a city or ZIP in Settings, which we geocode using Apple's services and store at the same approximate, city-level precision. On the web, where there is no device GPS, this is how local posts work. When a manual location is set, it's used instead of your device location.

You can deny location permission entirely. If you do, either set a city or ZIP manually, or the feed shows only remote posts (mixing, mastering, design, work that happens anywhere).

Who we share with

We use a small set of vendors to run the service. Each receives only what it needs to do its job:

  • Apple, Sign in with Apple identity verification; App Store billing for subscriptions bought on iPhone and iPad; and Apple Maps, which powers the Resources map and location search (Apple receives the map and place queries needed to serve results).
  • Google, Sign in with Google identity verification.
  • Stripe, payment processing for subscriptions bought on the web. Stripe receives your email and your payment details directly; we store only a customer reference and your subscription state.
  • Supabase (data hosting, US region), stores everything in the What we collect list above on secure, access-controlled databases.
  • Vercel, hosts our web apps; request data passes through it briefly while requests are in flight.
  • Cloudflare, DNS, edge caching, the small services that send your moderation reports and unfurl link previews. Cloudflare receives the same data Supabase does, briefly, while requests are in flight.
  • Sentry, crash and error monitoring. When something breaks, the error report includes your account id and email so we can find and fix the problem you actually hit.
  • Resend (transactional email), when a user reports content, we use Resend to email the report to our moderation inbox. No other emails go through Resend right now.

We do not share your data with advertisers, data brokers, or any party not listed above.

Your choices

  • Edit your profile, Profile → Edit.
  • Set or change your location, Settings → Location on iOS, or Settings → Distance & search on the web.
  • Change your local radius, Settings → Distance.
  • Turn notification types on or off, Settings → Notifications.
  • Unpublish a press kit, open the kit's editor and unpublish; its public page stops resolving.
  • Block someone, tap the ⋯ menu on their post → Block. They disappear from your feed and link-ups; you disappear from theirs.
  • Report someone, tap the ⋯ menu on their post → Report. Reviewed within 24 hours.
  • Delete your account, Settings → Account → Delete Account. This permanently removes your profile, posts, link-ups, contact methods, endorsements, blocks, reports, and subscription state from our databases. The deletion is immediate and cannot be undone.

If you signed in with Apple, deleting your account in Bandry will also revoke our access to your Apple ID token, so we can no longer authenticate as you.

To request a copy of your data, write us at support@bandry.app with the subject line "Data Request." We'll respond within thirty days.

Children

Bandry is not for users under 13. We don't knowingly collect information from children under 13, and we don't market to them. If we discover an account belongs to a child under 13, we delete it.

Data retention

We keep your data while your account exists. When you delete your account, your data is removed within minutes, there is no soft-delete or grace period. Two exceptions, both bounded: operational logs (e.g., a record that a deletion took place) may persist for up to 30 days for security and audit purposes, and crash or error reports held by our monitoring provider include your account id and email and are retained for up to 90 days before they age out.

Security

Data in transit is encrypted via TLS. Data at rest is held in Supabase's encrypted Postgres. Access to user data is gated by row-level security policies that enforce our privacy rules at the database layer, meaning even a bug in our app code cannot expose another user's private data.

Links to other services

Posts can include showcase links to other services (Spotify, YouTube, Instagram, etc.). When you tap one of those links from inside Bandry, you're leaving us and entering that other service, which has its own privacy practices. We don't control them.

International users

Bandry's servers are in the United States. If you use Bandry from outside the US, your data will be transferred to and stored on US-based servers. By using Bandry you consent to that transfer.

If you're in the EU, UK, or California, you have rights under GDPR, UK-GDPR, and CCPA respectively, including the rights of access, correction, deletion, and (where applicable) data portability. To exercise any of those, write us at support@bandry.app.

Changes to this policy

When we change anything material in this policy, we'll update the "Last updated" date at the top and, for changes that affect your privacy meaningfully, announce them on bandry.app. Your continued use after a change means you've accepted the new version.

Contact

For any privacy question, write us at support@bandry.app.

← Back to bandry.app
support@bandry.app