Privacy Policy
Radijo Privacy Policy
Effective date: [publication date] Version: 1.0
This policy explains what personal data the Radijo service collects, why, how long it is kept and what your rights are. It is written to match what the software actually does; the technical basis is the data inventory kept with the source code.
1. Who we are
The service is operated by Dream Agency d.o.o., Božidara Magovca 54, 10000 Zagreb, Croatia (OIB [to be filled in]). We are the data controller for the processing described here.
- Privacy requests: privacy@aboutdream.io
- Everything else: support@aboutdream.io
2. What this policy covers
- the Radijo mobile app for iOS and Android, including its CarPlay and Android Auto interfaces;
- the Radijo API at
api.radijo.app, which the app talks to; - the Radijo website at
radijo.aboutdream.io.
Radio stations you listen to are operated by third parties. When the app plays a station, your device connects to that broadcaster's own streaming server; see section 6.
3. The short version
- Radijo has no user accounts. The app identifies your installation with a random device identifier, not with your name, e-mail address or phone number.
- We store the data needed to run the app: which stations you favourited, your listening history, the token used to send you notifications, and any bug reports you choose to send.
- We use no advertising, no tracking and no analytics SDKs, and we do not sell data.
- Diagnostics (crash reports) are processed on our own servers in the European Union.
- You can ask us to delete everything linked to your device identifier at any time.
4. How your installation is identified
When the app starts for the first time it creates a device identifier:
- on iOS, Apple's "identifier for vendor" (
ios-…), which Apple resets when all our apps are removed from the device; - on Android, a random identifier (
android-…) generated by the app and stored in the app's private settings.
The app registers this identifier with our API and receives a random device token that authenticates its requests. Neither value contains information about you, your phone number or your Apple/Google account.
The app lets you enter another installation's device identifier to continue using its favourites and history ("import device ID"). Anyone who knows an identifier can do this, so treat yours like a password. We cannot tell the difference between you and someone who has your identifier.
5. What we collect, why, and on what legal basis
| Data | Why we process it | Legal basis (GDPR Art. 6(1)) |
|---|---|---|
| Device registration: device identifier, device token, platform (iOS/Android), app version and build, operating-system version, device brand/model, first and last time the app contacted us | Running the app: authenticating requests, keeping your favourites and history together, supporting the app version you use | (b) providing the service you asked for |
| Favourites: the stations and songs (artist and title as broadcast) you marked as favourites | Showing them to you; counting how many installations favourited a station or song | (b) providing the service |
| Listening history: which station you played, when you started and stopped, for how long, the app version, and the IP address your device used at the start of a session | Showing your recently listened stations; computing which stations are popular; understanding usage and detecting abuse | (b) for your history; (f) our legitimate interest in understanding usage and keeping the service secure |
| Push notification token (issued by Google Firebase to your device) | Sending the app a notification when artist artwork it asked for is ready | (f) legitimate interest in completing a request the app made; you can withdraw the token from the app or by denying notification permission |
| Bug reports you send: your description, report type, app version, device model and OS version, technical device facts (physical device or emulator, language and time-zone settings, network type, dark mode) and, if you attach them, the app's log files of the last seven days | Investigating and fixing the problem you reported | (b) handling your support request; (f) legitimate interest in fixing defects |
| Crash and performance diagnostics: crash reports, app hangs, unexpected terminations, failed network requests to our API, the sequence of screens and actions before a crash, device model, OS and app version, and a sample of performance measurements | Finding and fixing crashes and slowness | (f) legitimate interest in keeping the app working |
| Server logs: for every API request, the time, the requested endpoint, the outcome, the response time and your IP address; security events (for example a rate limit being hit) record your device identifier and IP address | Security, abuse prevention, troubleshooting | (f) legitimate interest in security |
| E-mail correspondence with privacy@ or support@ | Answering you | (b)/(f) handling your request |
Log files attached to bug reports are written by the app on your device and contain technical events: the stations you played and their stream addresses, the "now playing" artist and title the station broadcast, your device identifier, requests made to our API and their results, and error details. Please do not write personal information about yourself or others in the description field.
We do not collect your name, e-mail address (unless you write to us), phone number, contacts, precise or approximate location (other than what an IP address implies), microphone or camera data, or advertising identifiers, and we do not build profiles for advertising.
6. Who receives data
| Recipient | What and why |
|---|---|
| Radio broadcasters | When you play a station, your device connects directly to that broadcaster's streaming server. The broadcaster (or its streaming provider) sees your IP address, the player's identification and how long you stayed connected, and applies its own privacy practices. We do not sit between you and the stream and cannot control what broadcasters collect. |
| Google (Firebase Cloud Messaging) | Delivers our push notifications to your device. Google receives the notification token and the notification content (the artist whose artwork became available). Google Ireland Ltd.; data may be processed in the United States under the EU Standard Contractual Clauses and Google's Data Privacy Framework certification. |
| Cloudflare (Turnstile) | If you use the station-submission form on our web application, Cloudflare's Turnstile check verifies that you are not a bot and receives technical signals from your browser. Cloudflare, Inc.; EU Standard Contractual Clauses. |
| Slack | Our team receives internal notifications about new bug reports and station submissions; these include the report identifier, app version, device model and an excerpt of the description you wrote. Slack Technologies; EU Standard Contractual Clauses. |
| Service providers | Companies that host our infrastructure and tools that help us analyse and fix problems act on our instructions under data-processing agreements. |
| Public authorities | Only where the law obliges us. |
TheAudioDB, the database from which we fetch artist images, receives only artist names as broadcast by stations, never any data about you.
We do not sell personal data and do not share it for advertising.
7. Where data is stored and international transfers
Our servers, including the crash-reporting and log systems, are located in Croatia (European Union). The transfers to Google, Cloudflare and Slack described above may involve processing in the United States; they are covered by the EU Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework.
8. How long we keep data
| Data | Kept for |
|---|---|
| Device registration and favourites | Until the installation has not contacted us for 24 months, then deleted; or earlier on your request |
| Listening history, including the IP address recorded with each session | 12 months from the session, then deleted |
| Push notification token | Until you remove it from the app, deny notification permission, or the device record is deleted |
| Bug reports and attached log files | Until 12 months after the report is resolved or closed; reports still open are kept while we work on them |
| Crash and performance diagnostics | 90 days |
| Server request and security logs | 20 days |
| Abuse-prevention counters (requests per IP address or device) | At most 1 hour |
| E-mail correspondence | As long as needed to handle your request, and up to 12 months afterwards |
| Website access logs | 20 days |
Aggregated statistics that no longer identify an installation (for example how many devices listened to a station in a month) may be kept longer.
9. Your rights
Under the GDPR you may ask us for access to your data, its rectification, erasure, restriction of processing, portability, and you may object to processing based on our legitimate interests.
Because Radijo has no accounts, the only way we can find your data is by your device identifier, which the app shows in its settings/diagnostics screen [confirm exact path]. Send it to privacy@aboutdream.io and tell us what you want. Possession of the identifier is how we verify the request. We answer within 30 days.
To delete your data yourself, note that uninstalling the app removes everything stored on the device but not the data linked to your identifier on our servers; for that, write to us.
You may lodge a complaint with a supervisory authority, in particular in the EU member state where you live. In Croatia this is the Agencija za zaštitu osobnih podataka (AZOP), Selska cesta 136, 10000 Zagreb, www.azop.hr.
10. Security
Traffic between the app and our API is encrypted (HTTPS). Device tokens are random and unique. Our servers are accessible to a small number of our staff, protected by individual accounts and rate limits. Bug-report archives are stored in access-controlled object storage, and the device and notification tokens are removed from log files before we work with them.
Radio streams are delivered by the broadcasters over whatever protocol they offer; many use unencrypted HTTP.
11. Children
Radijo is a general-audience radio app and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has sent us personal data (for example in a bug report), write to privacy@aboutdream.io and we will delete it.
12. Automated decision-making
We make no decisions about you by automated means that have legal or similarly significant effects.
13. Website
The website at radijo.aboutdream.io is a static site. It sets no cookies and uses no analytics. Its
web server keeps standard access logs (IP address, requested page, browser type, time) for security, deleted
after 20 days.
14. Changes to this policy
When we change how the app or the API processes data, we update this policy, change the effective date at the top and, for material changes, tell you in the app or on the website before the change takes effect.
15. Contact
Dream Agency d.o.o., Božidara Magovca 54, 10000 Zagreb, Croatia — privacy@aboutdream.io