Privacy Policy
Last updated: March 2026
1. What We Collect
FocusHouse.fm collects the minimum data necessary to provide our service:
- Account data: Name, email address, and hashed password when you create an account. If you sign in with Google or GitHub, we receive your name and email from those providers.
- Subscription data: Stripe manages all payment processing. We store your Stripe customer ID and subscription status. We never see or store your card number.
- Listening analytics: We record anonymized listening events (channel played, duration, quality) to improve the service. IP addresses are HMAC-hashed with a weekly rotating key and are never stored in raw form.
- Session data: Encrypted authentication cookies for login sessions. No marketing cookies or tracking pixels.
2. What We Do Not Collect
- No third-party analytics or tracking scripts
- No advertising identifiers
- No cross-site tracking
- No sale of personal data to third parties
3. How We Use Your Data
- Authenticate your account and manage subscriptions
- Gate premium channels for paying subscribers
- Send transactional emails (welcome, subscription changes)
- Improve channel curation based on aggregate listening patterns
4. Data Storage & Security
All data is stored on self-hosted infrastructure in the EU (Hetzner, Germany). Data is encrypted in transit (TLS 1.3) and at rest. Database backups are encrypted and stored in AWS S3 with server-side encryption.
5. Third-Party Services
- Stripe — Payment processing (PCI DSS Level 1 compliant). See Stripe's privacy policy.
- Sentry — Error tracking for application stability. No personally identifiable information is sent to Sentry.
- Resend — Transactional email delivery. Only your email address is shared for the purpose of sending account-related emails.
6. Your Rights (GDPR)
If you are in the EU or EEA, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and all associated data (via Dashboard → Settings or by contacting us)
- Export your data in a machine-readable format
- Withdraw consent at any time
7. Data Retention
- Account data is retained while your account is active and deleted upon account deletion request.
- Anonymized listening events are retained for 90 days, then archived.
- Subscription records are retained as required by financial regulations.
8. Cookies
We use only essential cookies for authentication sessions. No marketing, analytics, or third-party cookies are used. No cookie consent banner is required because we do not use non-essential cookies.
9. Contact
For privacy-related inquiries or to exercise your rights, contact us at privacy@focushouse.fm.