Privacy Policy
This is a working draft, not yet reviewed by counsel or published. It was written directly from what the Vael app and backend actually do today — no placeholder clauses, no boilerplate copied from another company’s policy.
Vael’s legal counsel should review this before it’s linked from App Store Connect, the Play Console, or vaelinfo.com. It should also be updated the moment the underlying entity is formally incorporated — it currently refers to “Vael” rather than a filed legal name, since that filing hasn’t happened yet.
Updated August 26, 2026: real, optional email/password accounts have now shipped for both drivers and artists. Sections 02, 03, and 04 below reflect this — a driver’s anonymous account is still the default and still requires nothing to use the app, but creating an account is now something the app actually offers, and artists now log into the Portal with their own credentials rather than through shared invite-only access.
In plain language
On this page
01 Who this covers
This policy covers two things Vael operates: the Vael driver app (the iOS and Android app that plays independent artists’ music matched to the highway corridor you’re driving) and the Vael Artist Portal (the web tool independent artists use to submit their music and profile to Vael). If you’re a driver using the app, Section 02 is what applies to you. If you’re an artist using the portal, Section 03 is what applies to you.
Vael is an early-stage, pre-launch product currently in closed testing with a small group of invited testers. This policy describes what the app and portal actually do today, and will be revised as the product grows.
Who we are
Vael is currently operated as a pre-incorporation project — the entity that will hold this policy hasn’t been formally filed yet, so this page refers to “Vael” rather than a registered legal name. There’s no separate data protection officer at this stage; the contact in Section 13 reaches the team directly. Both of these should be updated the moment they change — flagged here rather than glossed over.
02 What the driver app collects
An anonymous account by default
The first time you open the app, it creates an anonymous account for you automatically — a random identifier with no name, email address, password, or phone number attached. You’re never required to sign up or log in to use the app this way. If you never create a real account, this is the only kind of account you’ll ever have.
An optional real account
You can choose to turn that anonymous account into a real one by adding an email address and password. Doing this upgrades your existing anonymous account in place — it keeps the same underlying identifier and everything already recorded against it (your Signal activity, described below), rather than creating a new, separate account and losing that history. Once you’ve done this, that same email and password let you log back in on another session or device instead of starting over as a new anonymous user.
Your password itself is never stored by Vael in readable form — it’s handled by our authentication provider (Supabase Auth, see Section 06), which stores only a cryptographic hash of it. Creating a real account remains entirely optional; the app works fully without one, and an anonymous account still carries no name, email, password, or phone number unless you choose to add them.
When you tap “Use my location,” the app asks your device’s operating system for your current GPS coordinates (or, in a browser, your browser’s estimated location) and sends that single reading to our server to find the nearest active music corridor. We do not save, log, or retain that location. It’s used for that one lookup and then it’s gone — our database has no table or column that stores driver GPS coordinates. You can revoke this permission at any time in your device’s Settings, and the app will simply be unable to auto-detect your corridor until you grant it again.
What you do in the app
When you upvote, downvote, follow an artist, save a song, or open an artist’s card, we record that action against your anonymous account — which artist, which song (if one applies), which corridor, what kind of action, and when. This is what powers Vael’s “Signal” — the live ranking of which artists are resonating on a given corridor. It’s tied to your anonymous identifier, never to your name or any other real-world identity, because we don’t collect one.
Some things aren’t saved to our servers yet, and only exist for the current app session: the artists you’re following, songs you’ve saved to your Library, and playlists you’ve built. Closing or reloading the app currently clears these — that’s a real, known limitation of the current build, not a privacy protection, and it’s expected to change as the app matures.
| Field | What it is | Tied to |
|---|---|---|
| drivers.id | Your account identifier — anonymous by default, unchanged if you later add an email and password | Nothing else, unless you create a real account |
| drivers.email | Only present if you chose to create a real account — used solely to let you log back in | drivers.id |
| drivers.created_at | When that account was created | drivers.id |
| signals.action_type | What you did — upvote, downvote, follow, save, or opened a card | drivers.id, the artist, and the corridor |
| signals.weight | How much that action counts toward an artist’s live Signal score | signals.action_type |
| signals.created_at | When the action happened | drivers.id |
03 What the Artist Portal collects
Artists who submit their music to Vael use a separate web tool. An artist joins by claiming a one-time invite link from Vael and setting a real email address and password for their own account, which then controls only their own profile, tracks, and documents — no shared or admin-level access. It collects real, identifiable information, since artists are credited by name and need to be reachable:
- Account credentials — the email address and password an artist sets when claiming their invite. As with driver accounts (Section 02), the password is never stored by Vael in readable form.
- Profile information — stage name, city, genre, bio, an avatar photo, and any social media links the artist chooses to add.
- Verification documents — artists submit proof of ownership over the music they upload (for example, a document establishing rights to a master recording). These are stored in a private file location, not publicly accessible.
- Music files — the audio, artwork, and metadata for tracks an artist chooses to submit.
- Agreement records — when an artist accepts Vael’s licensing agreement, we record the timestamp, the version of the agreement accepted, the IP address the acceptance came from, and which ownership warranties were confirmed. This is standard practice for any digital agreement and exists to protect both the artist and Vael if a dispute over rights ever arises.
04 What we don’t collect
It’s easier to list this precisely than to leave it implied. As of today, the driver app does not request or have access to:
- Your name or phone number, ever. We only collect an email address and password if you actively choose to create a real account (Section 02) — using the app anonymously requires none of it
- Your camera, microphone, contacts, or photo library
- Your location in the background, continuously, or at any time other than when you actively tap “Use my location”
- Payment or financial information of any kind
- Advertising identifiers, and it does not run any third-party analytics, advertising, or crash-reporting SDK — there are none integrated in the app today
05 How we use it
We use the information above for exactly the purposes described in Sections 02–03: matching you to a live music corridor when you ask for it, computing which independent artists are resonating on that corridor, keeping the app’s basic functionality working, and — for artists — administering the licensing relationship and paying out where applicable. We do not use driver activity to build advertising profiles, and we do not sell, rent, or trade any of this information to third parties.
07 How long we keep it
Signal activity (Section 02) is kept as long as your account exists — anonymous or real — since it’s what the artist-facing rankings are built from. We don’t currently have a self-service way for you to delete your account or its history from within the app — that’s a real gap in the current beta, not a decision to withhold it. Until it’s built, email us (Section 13) and we’ll delete it by hand.
Artist records (Section 03) are kept for as long as an artist’s music is live on Vael, plus a reasonable period afterward for licensing and dispute-resolution purposes, consistent with the termination terms in the artist agreement itself.
08 Your privacy rights
These apply regardless of where you live — we don’t gate them by region, though some are formally guaranteed only in certain jurisdictions (see below). None of this is self-service yet: every request today is handled by a person, by email (Section 13), not through an in-app control.
Access & know what we hold
Ask what data we have tied to your account and we’ll tell you — for a driver, that’s the fields listed in Section 02’s table; for an artist, the categories in Section 03.
Correct it
If something on your artist profile or account is wrong, email us and we’ll fix it. Drivers can already edit most of this themselves in-app where it applies.
Delete it
Email us (Section 13) with your request. If your account is anonymous, we may ask you to confirm it from within the app so we can locate the right record; if you’ve created a real account, we can locate it by the email address on file.
Restrict or object to processing, and withdraw consent
You can ask us to stop a particular use of your data, or object to it outright. Where something depends on your consent — like an optional real account — you can withdraw that consent at any time; the account reverts to anonymous rather than being deleted, unless you ask us to delete it outright.
Data portability
Ask for a copy of your Signal activity or artist records in a portable format and we’ll put it together and send it to you.
Revoke permissions
Location permission is entirely optional and revocable at any time in your device’s system settings — the app degrades gracefully to manual corridor selection without it.
Region-specific rights
If you’re in the EEA, UK, or Switzerland, the rights above are the ones GDPR names directly (access, rectification, erasure, restriction, portability, and objection), plus the right to lodge a complaint with your local data protection authority. If you’re a California resident, the CCPA gives you the right to know what’s collected, to delete it, and to opt out of the sale or sharing of personal information — we don’t sell or share data for cross-context advertising today, so there’s nothing to opt out of, but we’re naming the right rather than omitting it. We haven’t done a jurisdiction-by-jurisdiction legal review beyond this, and this section should be treated as a starting point for counsel, not a final determination.
09 Children’s privacy
Vael is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If we learn that we’ve inadvertently collected information from a child under 13, we’ll delete it.
10 Security
We use industry-standard practices to protect the information described in this policy, including database-level access controls that restrict who and what can read or write each table. As with any early-stage product, our security posture is still maturing alongside the product itself — no method of transmission or storage is ever 100% secure, and we can’t guarantee absolute security.
11 This website
Separately from the app and Artist Portal (Sections 02–03): the pages you’re reading now, including this one, load type from Google Fonts at render time rather than shipping fonts locally. That means your browser makes a direct request to Google’s servers for those font files, which exposes your IP address to Google the same way any embedded third-party resource would — this site does not otherwise set cookies or run analytics. This hasn’t been evaluated against EU cookie-consent requirements; flagged here as a known open item for counsel rather than left silent.
12 Changes to this policy
We’ll update this policy as Vael’s features change — for example, once account deletion becomes self-service, or once persistent (rather than session-only) follows and saved libraries are added. Material changes will be reflected with a new draft/effective date at the top of this page.
13 Contact us
Questions about this policy, or a request to access or delete your data: