Privacy Policy
Effective: March 2026
About Jamrz
Jamrz is a multiplayer music party game. Players join a room, listen to song snippets, and compete by guessing details about each track. This privacy policy explains what data the app collects, stores, and how it is used.
Data We Collect
- Account information — when you sign in with Discord or Google, we receive your display name, email address, and profile image from the OAuth provider. This creates your Jamrz account.
- Music service connections — you may optionally link your Spotify or Apple Music account for full song playback. We store OAuth tokens (encrypted) to enable playback on your behalf.
- Game history — scores, rounds played, categories used, and game outcomes are stored to provide your stats, achievements, and leaderboard rankings.
- Friends list — when you add friends by user code, we store the friendship connection to enable game invites and activity feeds.
- Purchase history — in-app purchases are processed through Google Play Billing (Android) or Apple App Store (iOS) via RevenueCat. We store entitlement records to sync your purchased content across devices.
- Device identifier — a locally generated device ID is used for guest play and purchase attribution. This is not linked to your hardware serial number.
How Data Is Stored
Account data, game history, friends, achievements, and entitlements are stored in a PostgreSQL database hosted on Neon (EU region). Spotify OAuth refresh tokens are encrypted with AES-256-GCM before storage. All data is transmitted over HTTPS.
Session data (authentication cookies) is stored in your browser and expires automatically. Game room state (active scores, playback position) is held in server memory and discarded when the room closes.
How Data Is Used
- Account data: display your profile, enable social features, sync across devices
- Music tokens: play songs during game sessions via your own subscription
- Game history: show stats, achievements, leaderboard rankings
- Friends: enable game invites and activity feeds
- Purchases: unlock premium content packs
We do not sell your data or use it for advertising.
Third-Party Services
- Discord / Google — used for account sign-in via OAuth. See their respective privacy policies.
- Spotify — used for music playback. Your Spotify account is accessed via the official OAuth flow. See Spotify’s Privacy Policy.
- Apple Music — used for music playback via MusicKit JS. Authorization is handled client-side by Apple. See Apple’s Privacy Policy.
- RevenueCat — processes in-app purchases and syncs entitlements. See RevenueCat’s Privacy Policy.
- Deezer / iTunes — used to resolve preview audio URLs. No user data is sent to these services.
- Neon — hosts the PostgreSQL database. See Neon’s Privacy Policy.
Data Retention & Deletion
Your account data is retained as long as your account exists. You can request deletion of your account and all associated data by contacting us at the email below. Upon deletion, we remove your account, game history, friends, achievements, and music service links from our database.
Ephemeral game session data (room state, live scores, playback position) is held in memory and discarded when the room closes or the server restarts.
Children’s Privacy
Jamrz does not knowingly collect personal information from children under the age of 13. If you believe a child has provided data through the app, please contact us so we can address it.
Changes to This Policy
We may update this policy from time to time. Changes will be reflected on this page with an updated effective date.
Contact
If you have questions about this privacy policy or wish to request data deletion, contact us at privacy@jamrz.app.