Your information
Privacy Policy
Last updated September 9, 2026
Cutty is a music discovery and review app. We use information to run the app, support its social features, keep the community safe, and improve reliability. We do not sell personal information or serve third-party ads. Optional Meta ad measurement is off by default and requires your separate choice and iOS tracking permission, as described below.
Scope
This policy applies to the Cutty iOS app and Cutty-operated web pages, including sign-in callbacks, public share pages, and legal and support pages. It explains what information we collect, why we use it, when it is shared, and the choices available to you.
Information we collect
- Account and profile information: email address, sign-in provider, account and profile identifiers, display name, handle, bio, avatar, and profile links you choose to add.
- User content and community activity: ratings, notes, reviews, comments, reactions, playlists, follows, blocks, reports, and the music identifiers connected to that activity. Reports may include the reason, the reported content or account, and information needed to investigate the report.
- Music and catalog activity: Apple Music song and album identifiers, catalog searches needed to return results, playback starts, and requests you make to save music to your Apple Music library or a playlist.
- Push notifications: if you enable notifications, an app installation identifier, Apple push-delivery token, notification preferences, and delivery records linked to your account. These deliver the social alerts you select and open their conversations.
- Community participation: account-linked contribution dates and activity records, such as ratings, replies, and conversation returns, used to produce aggregate reports about participation and whether people receive responses and return to the community.
- Anonymous product analytics: feature interactions, recommendation interactions, campaign labels, and a fresh random session identifier. Anonymous analytics excludes account IDs, email addresses, search terms, review or comment text, authentication URLs, tokens, and persistent device IDs.
- Optional account activity: if you choose Share, a separate session identifier, session and sign-in times, a first observed session flag, and the app version linked to your Cutty account when you sign in. This helps measure account creation, ratings, reviews, and return visits. Searches and writing are excluded.
- Optional Meta ad measurement: if you separately opt in and grant iOS tracking permission, app opens and confirmed account creation, together with your device's advertising identifier, device information, and network request metadata, as described below.
- Technical and diagnostic information: app and build version, plus bounded outcome, duration, and failure-reason events needed to operate, secure, and troubleshoot the service.
Cutty does not request access to your iPhone contacts or address book. Connections such as follows and blocks are created inside Cutty.
How we use information
- Authenticate accounts and provide profiles and account settings.
- Provide ratings, reviews, comments, reactions, playlists, follows, and personalized music discovery.
- Search the music catalog, start playback, and complete Apple Music actions you request.
- Apply blocks, investigate reports, moderate content, prevent abuse, and protect users and the service.
- Diagnose failures, measure product performance, and improve accessibility and reliability.
- Comply with law, enforce our Terms of Use, and respond to valid legal requests.
Apple Music and MusicKit
If you allow Media & Apple Music access, Cutty uses MusicKit to search Apple's catalog, match activity to the correct music, play available songs or previews, and complete library or playlist actions you request. Full-length playback may require an active Apple Music subscription. Apple Music access is optional, and public browsing remains available if you decline it.
Apple provides the catalog, artwork, previews, playback, subscription status, and library services under Apple's own terms and privacy policy. Cutty does not redistribute full-length Apple Music audio.
Public content, reports, and blocks
Public profiles and content you choose to publish—such as ratings, reviews, comments, reactions, and public playlists—can be seen and shared by other people. Review your content before publishing it and do not include information you do not want to make public.
Blocks and reports are not displayed publicly. Blocking is used to limit interactions and visibility between accounts. Reports are made available to authorized moderators so they can investigate possible violations, protect the community, and take appropriate action.
When information is shared
We share information only as needed for the following purposes:
- Service providers: Supabase provides authentication services; Railway hosts the application programming interface and supporting service infrastructure; and Vercel hosts public callback, share, and legal pages. Hosting providers may process IP addresses and request metadata as part of operating and securing their services.
- Apple, Google, and email providers: Apple supports Sign in with Apple, MusicKit, TestFlight, and push-notification delivery; Google may provide sign-in when you choose it; and an email provider sends one-time sign-in messages. Each provider handles information under its own privacy terms.
- Public features: information you deliberately make public is shown according to the feature and visibility settings you select.
- Safety and legal obligations: we may preserve or disclose information when reasonably necessary to investigate abuse, protect rights and safety, enforce our terms, comply with law, or respond to valid legal process.
- Business changes: information may be transferred as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to this policy and applicable law.
We do not sell or rent personal information. The optional Meta measurement described below can associate app activity with activity across other apps and websites only after your separate choice and iOS tracking permission.
Analytics, diagnostics, and TestFlight
Account-linked community activity and contribution dates separately support aggregate participation reports. Turning off optional product analytics does not remove these records, which are also used for community features. The reports help us evaluate contribution, responses, and returns to conversations.
Cutty's anonymous product analytics uses a fresh random session identifier and is designed to exclude identity, private writing, search terms, authentication data, and persistent device identifiers. You can turn anonymous analytics off in Privacy choices on Home or in Settings; doing so clears events still queued on your device. Anonymous analytics events are retained for up to 90 days.
Account activity sharing is a separate optional choice and is off until you choose Share. It connects session information to your Cutty account when you sign in. Every feature remains available if you decline. Turning this choice off in Privacy choices on Home or in Settings stops new collection locally and clears queued sessions. When your choice reaches Cutty, we delete the linked session history. An offline revocation waits until you sign in to that account and reconnect; the app shows when it still needs to be saved. Your ratings and reviews remain.
With account activity sharing enabled, Cutty also supplies engagement milestones to Apple's privacy-preserving ad attribution system. Apple may send campaign and conversion statistics to the ad network and a copy to Cutty, without your Cutty identity, email address, or advertising identifier. Apple controls which fields are included and may delay, limit, or omit reports. We also receive aggregate App Store download and campaign reports from Apple. We do not join these reports to individual Cutty accounts. Turning sharing off cannot recall statistics Apple has already received or delivered.
During beta testing, Apple's TestFlight may provide installation, session, device, operating-system, crash, and voluntarily submitted feedback information. Apple's handling of that information is governed by Apple's TestFlight terms and privacy disclosures.
Optional Meta ad measurement
Meta ad measurement is a separate choice, off by default, available in Privacy choices on Home or in Settings. It requires your permission in both Cutty and the iOS tracking prompt. Enabling anonymous analytics or account activity does not enable Meta measurement. Every Cutty feature works with Meta measurement off.
If you opt in, Cutty uses Meta's SDK to share app opens and confirmed account creation, together with your device's advertising identifier, device information and network request metadata, to measure which ads bring people to Cutty. Meta may associate this information with activity across other apps and websites under its own privacy policy. Cutty does not send Meta your Cutty account ID, email address, searches, listening selections or writing as event parameters. Account creation can be measured only when Share account activity is also enabled; these choices remain separate. We do not replay account creation that occurred before your Meta choice and tracking permission were enabled.
Turning this choice off or withdrawing iOS tracking permission stops new event sharing. Pending local registration events are cleared when you turn it off or change accounts. Requests already sent and information Meta has received cannot be recalled by this setting; Meta's retention and privacy controls apply to that information. Learn more in Meta's Privacy Policy.
Retention
We keep account information and content while your account is active and as needed to provide the service. Safety and moderation records may be kept for as long as reasonably necessary to investigate abuse, prevent repeat violations, protect the service, resolve disputes, or meet legal obligations. Backups and operational logs may retain limited information for a short period after it is removed from the active service.
Account deletion removes account-linked contribution records and push installations. Push-delivery queue records are pruned after seven days. A registration-status record containing an installation identifier and revision, without an account link or delivery token, may remain to prevent delayed requests from restoring a revoked registration.
Optional linked session records and Apple campaign postback copies are retained for up to 90 days. Queued linked sessions expire from the device after 30 days. Your account's consent choice and revision remain until account deletion so delayed requests cannot undo revocation. Account deletion removes this choice and linked session history. Apple's aggregate reports and its retention are governed by Apple's policies.
For an eligible Meta registration event, Cutty retains a one-time claim with your account's consent record until account deletion to prevent duplicate registration claims across devices and retries. Revoking sharing does not reset this claim. The device stores a hashed account reference solely to avoid sending the registration event again; account deletion removes that reference and any pending registration event. This local reference is never sent to Meta.
Account deletion
You can delete your account in the app from Profile → Settings → Delete Account. This removes application-owned account data and starts deletion of the associated authentication identity. Limited records may remain temporarily in backups or when retention is required for security, abuse prevention, dispute resolution, or law.
If you cannot access the app, contact Cutty Support for deletion help. We may need to verify that you control the account before acting on a request.
Your choices and rights
- Edit your profile information and playlist visibility in the app.
- Decline or revoke Apple Music access in iOS Settings and continue using public browsing.
- Change anonymous analytics, optional account activity sharing and Meta ad measurement in Privacy choices on Home or in Settings.
- Control iOS tracking permission in iOS Settings.
- Choose social notification categories or turn notifications off in Cutty settings, and control notification permission in iOS Settings.
- Block accounts and report content or accounts through the relevant menu.
- Delete your account in the app.
Depending on where you live, you may also have rights to access, correct, delete, or receive a copy of certain personal information, or to object to or restrict certain processing. Contact us to make a request. We will respond as required by applicable law.
Security
We use safeguards designed to protect information, including encrypted network connections, authenticated access, scoped authorization, and secure device storage for sign-in sessions. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
Children
Cutty is not directed to children under 13. If you believe a child has provided personal information without appropriate permission, contact us so we can investigate and take appropriate action.
Changes to this policy
We may update this policy as Cutty changes. The date above shows when it was last revised. If a change materially affects how we use personal information, we will provide notice in the app or by another appropriate method before the change takes effect when required.