Privacy Policy
Last updated: 22 July 2026
1. Introduction & Data Controller
This Privacy Policy explains how TONIVO LTD (“Tonivo”, “we”, “us”, or “our”) collects, uses, stores, and protects your personal data when you use our platform at tonivo.co.uk.
TONIVO LTD is the data controller responsible for your personal data. We are a company registered in England and Wales.
- Company number: 17117959
- Registered address: The Bank Main Street, Tingewick, Buckingham, England, MK18 4NN
- Data protection contact: hello@tonivo.co.uk
This policy is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Information We Collect
a) Information you provide directly
- Account registration: Email address and password (your password is cryptographically hashed and never stored in plain text).
- Onboarding: Username, display name, roles (e.g. Producer, Vocalist, Mixer), and genre preferences.
- Profile information: Avatar image, banner image, bio (up to 800 characters), location (up to 100 characters), external links (up to 5, HTTPS only), availability status and date, and external music profile URLs (Spotify, YouTube, SoundCloud).
- Tracks: Audio files you upload (MP3 or WAV format, up to 50 MB per file, 500 MB total storage limit, maximum 50 tracks) along with title, description, and tags.
- Comments: Comments you leave on other users' profiles and tracks (up to 500 characters each).
- Posts and replies: Posts you share on the feed and replies to other users' posts (up to 500 characters each).
- Messages: Text messages (up to 1,000 characters) and optional attachments (images up to 5 MB; audio files up to 60 MB) sent through our messaging system.
- Social actions: Users you follow and users you block.
- Reports: If you report another user or piece of content, we store the reason, the target of the report, and any optional photo attachments you provide (up to 3 photos, 5 MB each, JPEG/PNG/WebP/GIF) for administrator review.
- Terms consent record: When you create an account, we record the date and time you accepted our Terms of Service and the version of the Terms you agreed to.
- Account deletion feedback: If you delete your account, we ask for an optional reason and details (up to 1,000 characters).
b) Information collected automatically
- Authentication cookies: Essential session cookies to keep you logged in (see Section 5 for details).
- Activity timestamps: We record when you were last active on the platform (updated approximately every 5 minutes).
- Activity log: A record of your actions on the platform, including tracks uploaded, comments made, follows, message reactions, and profile changes. This log is visible to you in your account settings.
- Product analytics events: A first-party record of product events (e.g. signups, logins, uploads, searches, follows, and which pages are viewed) used to measure platform health. These events are stored in our own database, never shared with third parties, and contain no raw content (no message text, comment bodies, or search queries). Page addresses are reduced to a general pattern before they are stored — a visit to someone’s profile is recorded as “a profile page”, never as whose profile it was. Where associated with an account, events are anonymised when you delete your account.
- Performance measurements: How quickly pages load and respond on your device (standard web performance timings), recorded against the general page pattern rather than the exact address. We use these to find and fix slow parts of the service. They contain no content and no personal detail beyond being linked to your visit.
- Visit identifier: A random value stored in the
tonivo_sidcookie that groups the above within a single visit, so we can tell one visit from another and see what led up to an error. It identifies nothing about you, expires after 30 minutes of inactivity, and is never used for advertising. See Section 5, including how to opt out. - Browser identifier (abuse prevention): A random value stored in the
tonivo_didcookie, recorded against your account so we can tell when a new account is created on the same browser as one we permanently suspended. It identifies the browser, not you, and is not derived from your device. We keep the record while your account is active and delete it when your account is deleted — except where the browser itself is subject to a ban, which we keep so the ban cannot be undone by deleting the account. See Section 5. - Error diagnostics: When something goes wrong we record the error, the page it happened on, and your browser or app version, so we can fix it. Where you were signed in, this is linked to your account so we can tell whether a problem is widespread or specific to you.
- Acquisition source (UTM tags): If you arrived at our signup page from a link that included UTM tags (e.g.
?utm_source=...), we store those tags on your profile so we can understand which campaigns bring us new users. These are marketing-source strings chosen by campaign operators, not user-identifying data, and are never used for advertising. - Notification data: Records of events that trigger notifications to you (e.g. new followers, comments on your tracks, new messages).
- IP addresses: Your IP address is used for rate limiting (abuse prevention) and, when you create an account on the web, to estimate an approximate city to prefill your profile location (see “Approximate location” below). For rate limiting, IP addresses are stored temporarily in our rate-limiting system and automatically expire within seconds to minutes. We never store the raw IP address on your account — only, in the web signup case, the coarse city estimate derived from it.
- Approximate location: When you join our pre-launch waitlist, we record an approximate country and region (e.g. “GB / ENG”) derived from your IP address at the moment of signup, used to plan launch markets. Separately, when you create an account on the web, we estimate an approximate city (e.g. “Manchester, United Kingdom”) from your IP address at signup and use it to prefill the location field on your profile. This is a coarse, city-level estimate only — never a precise location, address, or device — and you can edit or remove it at any time from your profile. In the mobile app you can instead choose to add your location: with your permission, we read your device’s location once, convert it to a coarse city, and store only that city — never the underlying coordinates. We rely on our legitimate interest in helping nearby musicians find each other as the basis for this, and you remain in full control of the field.
- Acquisition source (waitlist signups only): When you join the waitlist, we record the referring URL your browser sent (e.g. the social post or page you clicked from) and any UTM campaign tags present in the link. This helps us understand which channels and content are reaching new musicians. It is not linked to any external profile.
- Device summary (waitlist signups only): When you join the waitlist, we record a coarse device summary (mobile / tablet / desktop, broad OS family such as iOS or Windows, and browser language) parsed from standard request headers. We do not collect a device fingerprint or precise hardware information.
- Self-reported genres (waitlist signups only, optional): If you tick genre tags or type a custom genre when joining the waitlist, we store these on your row. Helps us plan onboarding and matching. You can leave this blank.
c) Information we do not collect
- We do not use advertising cookies, or any cookie that follows you across other websites or apps. The one analytics cookie we do set is first-party, expires within 30 minutes, and is described in Section 5.
- We do not use any third-party analytics that track you across sessions or websites, such as Google Analytics, Facebook Pixel, or similar cross-site trackers. We do not use tracking pixels or fingerprinting scripts.
- We do not collect device fingerprints — we never derive an identifier from your hardware, screen, fonts, or browser characteristics. The one browser identifier we do set is the
tonivo_didsecurity cookie described in Section 5: a random value we generate and store in a cookie, used solely to stop permanently suspended users returning. You can delete it like any other cookie. - We do not store precise geographic coordinates (GPS latitude/longitude). The optional mobile location prompt described above is converted to a coarse city before anything is saved.
- We do not collect your date of birth.
3. Lawful Bases for Processing
Under UK GDPR, we must have a lawful basis for each way we process your personal data. Here are the bases we rely on:
| Processing Activity | Lawful Basis |
|---|---|
| Account creation, authentication, and email verification | Contract (Art. 6(1)(b)): necessary to provide the service |
| Profile data, tracks, comments, and messages | Contract: core platform features you signed up to use |
| Session and authentication cookies | Contract: necessary for the service to function |
| Transactional emails (verification, password reset) | Contract: necessary for account security |
| Activity logging, product analytics, acquisition tracking, and notifications | Legitimate interests (Art. 6(1)(f)): platform integrity and user experience |
| IP address storage for rate limiting | Legitimate interests: security and abuse prevention |
| Account deletion feedback | Legitimate interests: service improvement |
4. How We Use Your Information
- To provide, maintain, and improve the Tonivo platform.
- To authenticate your identity and manage your account.
- To enable you to create a profile, upload music, and showcase your work.
- To facilitate discovery of other users and communication between collaborators.
- To deliver notifications about activity relevant to you (e.g. new followers, comments, messages).
- To enforce our Terms of Service and protect against abuse, spam, and harassment.
- To rate-limit requests and prevent misuse of the platform.
- To send you transactional emails (account verification, password resets).
- To understand how the service is used and make improvements, using first-party activity logs and aggregate product analytics we host ourselves.
5. Cookies
We use a small number of first-party cookies only. We do not use advertising cookies, third-party cookies, or any cookie that follows you across other websites or apps.
Most of them are strictly necessary — the platform cannot function without them. We also set one analytics cookie (tonivo_sid), which groups your activity within a single visit so we can measure how the service is used and diagnose errors. We want to be straightforward about this rather than stretch a definition: an analytics cookie is not automatically “strictly necessary”, and regulators treat analytics differently from essential cookies.
We keep it as low-impact as we know how: it is a random value that identifies nothing about you, it is never shared with anyone, it is never used for advertising or profiling, it cannot be read by scripts in your browser, and it expires after 30 minutes of inactivity — so it cannot follow you between visits.
Preventing banned users returning. We also set one security cookie, tonivo_did, which holds a random value identifying the browser rather than the person using it. Its only purpose is to let us see when an account has been created on the same browser as an account we permanently suspended, so that someone removed for breaking our rules cannot simply sign up again. It is set only on sign-in and account pages, never on our public pages. This is abuse prevention under our legitimate interests, and is exempt from the analytics opt-out below: allowing it to be switched off would hand anyone evading a ban a one-click way around it. It is never used for analytics, advertising, personalisation, or profiling, is never combined with your activity data, and is never shared with anyone. A match is only ever reviewed by a human — it never automatically suspends or blocks an account. If you believe a decision was wrong, email hello@tonivo.co.uk and a person will look at it.
How to opt out. If you have an account, turn off Share usage dataunder Settings → Privacy. This works on the website and in the mobile app, and applies to your account on every device you sign in on. When it is off, no analytics cookie is set, any existing one is deleted, and nothing is recorded for you.
We also honour the Global Privacy Control signal automatically, with no need to ask us or fill anything in. This is a browser-level setting — built into Brave and DuckDuckGo, and available in Firefox and via extensions — so it applies on the website. Our mobile app does not send it, which is why the Settings switch above exists.
Either way, essential cookies continue to work, so you stay logged in.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
| Supabase auth session | Keeps you logged in and authenticates your requests | HttpOnly, SameSite=Lax | Session (expires on logout or session timeout) |
| last_active_ping | Throttles activity timestamp updates to reduce database load | HttpOnly, SameSite=Lax | 1 hour |
| tonivo_ref | Remembers a creator referral code from a ?ref= link so it survives signup | HttpOnly, SameSite=Lax | 30 days |
| tonivo_did | A random value identifying the browser (not you) so that an account created to get around a permanent suspension can be linked to the suspended one. Set only on sign-in and account pages. Never used for analytics, advertising, or personalisation, and never shared. | HttpOnly, SameSite=Lax, signed | 400 days |
| device_ping | Throttles the above check to once every 5 minutes to reduce database load | HttpOnly, SameSite=Lax | 1 hour |
| tonivo_sid (analytics) | A random value that groups your activity within one visit, so we can measure how the service is used and see what happened before an error. Not linked to advertising. Turn it off under Settings → Privacy, or with Global Privacy Control. | HttpOnly, SameSite=Lax | 30 minutes of inactivity |
| tonivo_no_analytics | Remembers that you turned off usage data sharing, so we keep honouring it. Only set if you opt out. | HttpOnly, SameSite=Lax | 1 year |
6. Data Sharing & Third-Party Processors
We do not sell your personal data to anyone. We share data only with the following service providers who help us operate the platform, and only to the extent necessary for their specific function:
- Supabase (Supabase Inc.): provides our database, user authentication, and file storage. Processes all user data. Data is stored in the EU (Frankfurt, Germany).
- Upstash (Upstash Inc.): provides Redis-based rate limiting. Processes IP addresses and action counts only. Data auto-expires within seconds to minutes.
- SendLayer: provides SMTP email delivery. Processes email addresses for the purpose of sending verification and password reset emails only.
- Vercel (Vercel Inc.): hosts and serves the Tonivo web application. Requests pass through their infrastructure.
- Google LLC (“Sign in with Google” only): if you choose to create an account or sign in using Google, Google authenticates you and shares your Google account identifier and email address with us so we can create or access your Tonivo account. Google's own privacy policy applies to their handling of this authentication. This processor is only involved if you actively choose the Google sign-in option.
- Apple Inc. (“Sign in with Apple” only): if you choose to create an account or sign in using Apple, Apple authenticates you and shares your Apple ID identifier (and, if you choose to share it, your email address) with us so we can create or access your Tonivo account. Apple's own privacy policy applies to their handling of this authentication. This processor is only involved if you actively choose the Apple sign-in option.
Each processor operates under appropriate contractual safeguards. No processor receives more data than is necessary for its specific function.
All data stored by Tonivo — your profile, tracks, messages, and other platform content — is stored within the EU and UK. If you choose to sign in with Google or Apple, your authentication request passes through those providers' global infrastructure (which may include servers outside the EU/UK) subject to their own cross-border transfer safeguards. We do not ourselves transfer personal data outside the EU/UK.
7. Data Retention
- Active accounts: Your data is retained for as long as your account exists.
- Deleted accounts (soft-delete period): When you delete your account, your profile is immediately hidden from other users. Your data is retained for 30 days in case you wish to reactivate.
- After 30 days (hard delete): All your data is permanently and irreversibly deleted via an automated process, including your profile, tracks, comments, messages, follows, and blocks.
- Deletion feedback: If you provided a reason for deleting your account, this feedback is retained separately after hard deletion for service improvement purposes (lawful basis: legitimate interests). It is not linked to your identity after hard deletion.
- Rate-limiting data (IP addresses): Automatically expires within seconds to minutes in our Redis cache. Not retained long-term.
- Activity log: Retained for the lifetime of your account and deleted when your account is permanently deleted.
- Reports you submit: Retained while your account is active so our moderation team can review them and keep an audit trail of moderation decisions. Deleted when your account is permanently deleted.
8. Your Rights Under UK GDPR
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): you can request a copy of all personal data we hold about you.
- Right to rectification (Art. 16): you can correct inaccurate data. Most data can be updated directly via your profile settings.
- Right to erasure (Art. 17): you can delete your account and all associated data via your account settings, or by contacting us.
- Right to restrict processing (Art. 18): you can request that we limit how we use your data in certain circumstances.
- Right to data portability (Art. 20): you can request your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21): you can object to processing based on legitimate interests. We will stop processing unless we have compelling legitimate grounds.
To exercise any of these rights, email us at hello@tonivo.co.uk with the subject line “Data Request”. We will respond within one month as required by UK GDPR.
If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Website: ico.org.uk
9. Children & Age Restrictions
Tonivo is not directed at anyone under the age of 16. You must be at least 16 years old to create an account and use the platform. If we become aware that a user is under 16, we will terminate their account and delete their personal data promptly.
10. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Row-Level Security on all database tables, ensuring users can only access data they are authorised to see.
- Passwords are cryptographically hashed and never stored in plain text.
- Strong password requirements are enforced (minimum 8 characters with uppercase, lowercase, number, and special character).
- Multi-tier rate limiting to prevent brute-force attacks and abuse.
- File upload validation including MIME type checking, file size limits, and path traversal prevention.
- Session cookies are set with HttpOnly and SameSite=Lax flags to prevent cross-site attacks.
- Email verification is required before you can access the platform.
- Automated decision-making and profiling: we do not use any automated decision-making or profiling that produces legal or similarly significant effects.
While we take all reasonable steps to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. If we make material changes, we will notify you via email or an in-app notification. The “Last updated” date at the top of this page will always reflect the current version. Continued use of Tonivo after changes are communicated constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
- Data controller: TONIVO LTD
- Company number: 17117959
- Registered address: The Bank Main Street, Tingewick, Buckingham, England, MK18 4NN
- Email: hello@tonivo.co.uk
Supervisory authority: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF (ico.org.uk)