Privacy Policy
EFFECTIVE 7 SEPTEMBER 2026 · LAST UPDATED 7 SEPTEMBER 2026
The short version. Punk-Records reads your Apple Music listening history so it can draw it for you. By default that reading stays on your iPhone. If you choose to sign in, a copy is kept on our server so your history survives a new phone. We have no advertising business, no analytics SDKs and no third party we sell to. You can delete everything from inside the app, permanently, at any time.
01Who we are
Punk-Records ("we", "us") makes the Punk-Records iPhone app. We are the data controller for the information described here. You can reach us at [email protected].
This policy covers the Punk-Records iPhone app, its home-screen widget, and this website.
02Two modes, two different answers
Punk-Records works in two modes, and the honest answer to "what do you collect" is different in each.
- Local mode (the default). You do not sign in. Your listening history, your scores and every chart are stored only on your iPhone, in the app's own storage. We receive nothing about you and we cannot identify you. Uninstalling the app destroys the data.
- Signed-in mode (your choice). You sign in with Apple. From then on your listening history is also stored on our server so that it survives a reinstall or a new iPhone, and so that plays can be collected while the app is closed.
Signing in is never required to use the app. You can sign out at any time, and you can delete the server copy without uninstalling the app.
03What we collect
Only in signed-in mode. In local mode, none of the following leaves your device except as described in section 5.
| Category | What, exactly | Where it comes from |
|---|---|---|
| Account identifier | The opaque user identifier Apple issues for our app, and the email address you chose to share. If you used Apple's Hide My Email, we only ever see the relay address. | Sign in with Apple |
| Listening history | For each play: the track, the time it was played, how confident we are in that time, and how we learned about it. Track records hold title, artist, album, genres, duration, ISRC and the artwork URL. | Apple Music, via your device and via our scheduled polling |
| Derived scores | Your daily Record Score and its four sub-scores, plus the one-line read shown with it. | Computed from your listening history |
| Apple Music access token | The user token that lets us read your recently-played tracks while the app is closed. Stored encrypted (AES-GCM); we never see your Apple ID password. | MusicKit, when you link Apple Music |
| Service state | When we last polled, how many polls have run, how many plays were ingested, and the last error if one occurred. Account creation and last-seen timestamps. | Our own service |
What we do not collect. No advertising identifier (IDFA). No location. No contacts, photos, calendar or health data. No device fingerprint. No third-party analytics or crash-reporting SDK is present in the app — you can verify this in the app's privacy manifest, which Apple publishes alongside the listing. We do not track you across other companies' apps or websites, and we have never asked for permission to.
04Why we collect it
- To provide the app. The charts are your listening history; without it there is nothing to draw.
- To keep your history across devices. This is the entire reason signed-in mode exists.
- To collect plays while the app is closed. Apple only exposes a short recently-played window, so our server polls it on a schedule to avoid gaps.
- To keep the service working. Service state exists so a broken link can be detected and reported to you in Settings.
Where the GDPR applies, our legal basis is performance of a contract (Article 6(1)(b)) for everything above — you asked us to keep and draw your listening. We do not rely on legitimate interests to process your listening history, and we do not process it for marketing.
05Who else sees it
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done either. The complete list of others involved:
- Apple. Sign in with Apple authenticates you; Apple Music provides your listening. Your use of those services is governed by Apple's own privacy policy.
- Cloudflare, Inc. Our server, database and cache run on Cloudflare's platform. Cloudflare processes this data on our instructions as our processor, and does not use it for its own purposes.
- ReccoBeats. To place a song on the mood map we need its musical characteristics — how bright it is, how energetic. We look these up by recording code (ISRC), sometimes with the track title and artist to disambiguate. We never send your identity, your account, your timestamps or your history. The lookup is about the song, not about you, and the answer is cached and shared across all users so the same song is only ever looked up once.
In local mode, the ReccoBeats lookup is the one request that leaves your device, and it carries the same song-only information.
We will disclose data if legally compelled by valid process, and we will tell you unless we are prohibited from doing so. If the app is ever sold or transferred, we will give you notice and the chance to delete your data first.
Our servers are in the United States. If you are in the EEA or the UK, your data is transferred there under the Standard Contractual Clauses that form part of our agreement with Cloudflare.
06How long we keep it
- Listening history and scores: until you delete them. They are the product; they are not aged out.
- Your Apple Music token: until you unlink Apple Music, delete your account, or it is revoked by Apple.
- Sign-in sessions: 180 days, then you sign in again.
- Audio characteristics of songs: kept indefinitely, because they describe recordings rather than people and are not linked to any account.
07Deleting your account and data
Open the app, go to Settings, and tap Delete account & data. Confirm, and we erase your account record, your entire listening history, your scores, your service state and your stored Apple Music token. The deletion is immediate and permanent — there is no deactivated state, no grace period and no archived copy to restore. We cannot undo it, and neither can you.
To remove only the local copy, sign out, or delete the app from your iPhone.
If you cannot reach the app for any reason, email [email protected] from the address on your account and we will delete it for you within 30 days.
08How it is protected
- Every request travels over TLS.
- Your Apple Music token is encrypted with AES-GCM before it is written to the database. The key is held only as a server secret, never in our source code or this repository.
- Sessions are signed tokens with a fixed expiry, checked on every request.
- Every query is scoped to your account. There is no social layer, no shared feed, and no way for one account to read another's history.
- On your iPhone, credentials are held in the iOS Keychain.
No system is perfect. If you find a security problem, please write to [email protected] — we would much rather hear from you than not.
09Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your data, to object to or restrict processing, and to withdraw consent. In practice:
- Access and portability: email us and we will send you your data in a machine-readable format.
- Deletion: use Settings, as in section 7. No email needed.
- Correction: email us. Most of what we hold is a factual record of plays, which we will correct if it is wrong.
We do not discriminate against anyone for exercising these rights — there is no paid tier, so there is nothing to withhold. If you are in the EEA or the UK and we have not resolved your concern, you may complain to your local supervisory authority.
California residents. In the twelve months before the date of this policy we did not sell or share personal information, and we do not knowingly sell or share the personal information of anyone under 16.
10Children
Punk-Records is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us data, write to [email protected] and we will delete it.
11Changes to this policy
If we change this policy we will update the date at the top. If the change is material — new data collected, a new recipient, a new purpose — we will tell you in the app before it takes effect, and where the law requires consent we will ask for it rather than assume it.
12Contact
Questions, requests, or a correction to something we got wrong: [email protected]. A person reads it.