Privacy Policy
Effective 7 October 2026.
This policy covers the SceneSat website, apps and related account and community services. It explains what information we use, why we use it, who receives it and how to exercise your rights. You can listen and browse without creating an account; account, community, notification and payment features involve additional information when you use them.
Who is responsible
SceneSat ideell förening, organisation number 802517-7323, is the data controller for the SceneSat services described here.
Registered address: c/o Mattias Bergsten, Hästhagsvägen 7, 448 36 Floda, Sweden. Contact: info@scenesat.com. More information is on The Association; practical app help is on App support.
Information we process
Accounts and sign-in
SceneSatID holds account identifiers, username/display name, email address and the profile information you provide. Authentication also involves credentials, sessions, tokens, linked service identities and security events. We use these to authenticate you, provide account features, protect accounts and administer access. We do not include passwords, active tokens or other credentials in a data export.
SceneSatID is shared across SceneSat services. If you use additional contributor, artist, event or administrative features, their submissions, roles, permissions and relevant operational records may also be associated with your account.
Profile avatars
Current versions of the SceneSat apps load profile avatars from SceneSat’s own servers, with initials or a fallback when no image is available. You can upload or change your avatar in account settings. We store the image and its account association to display your profile.
Older versions of the Android phone, iOS and macOS apps may still load avatars directly from Gravatar, operated by Automattic. Those requests send a hash derived from your email address and expose device connection information such as your IP address and client details to that provider. The hash is an identifier, not anonymous data. Update to the current app version to avoid automatic Gravatar requests. Gravatar processes these older-version requests under Automattic’s privacy policy.
Listening, preferences and saved items
Depending on the features you use, we process playback positions and completion state, listening history, track requests, ratings and mood votes, saved lists and their entries, preferences and download or purchase entitlements. These support resume, synchronization, saved content, programming, voting and service statistics.
Apps and the website also keep local settings, playback state, downloaded media and related information on your device. Some account features synchronize with our servers; local files are separate from the server copy. Removing an app or clearing browser storage does not automatically delete server-held account data.
Even without signing in, requests for pages, audio, video and APIs reach servers with technical information such as an IP address and client details. Listening statistics can include show/stream identifiers, times, platform information and device or session identifiers. A record without a username is not necessarily anonymous.
Community content and media
We process public posts and chat, private messages, reactions, uploaded images/audio/video, file metadata, and the identifiers and timestamps needed to deliver and manage them. An uploaded file may exist before it is posted; not posting it does not necessarily remove the uploaded copy.
Public chat may be relayed between SceneSat and connected services such as IRC, Discord or Twitch. Messages associated with shows can appear in recorded chat replay. Public contributions may be searchable or copied by other people. Private messages are intended for their participants; authorized operators may access relevant records when necessary for support, security or moderation.
Forum. The forum is for signed-in SceneSatID members. Your thread titles and posts are shown with your display name to every signed-in member and may be searched or copied by others. We process the text of your posts, earlier versions of posts you edit, the discussions you watch and what you have read, and any reports you file. Staff can open a snapshot of a reported post only through a recorded access. Forum posts are not end-to-end encrypted, and the people who run the service can technically access stored data. You can download your own forum text and watch data from the Forum page.
Notifications and email
Where notifications are enabled, we process device/installation identifiers, push tokens, platform and app version, notification preferences and delivery records. Apple Push Notification service and Google Firebase Cloud Messaging deliver notifications on supported platforms. A registration can be device-bound without being linked to a SceneSatID.
We use email addresses and message/delivery records for account and security messages, support, export/deletion responses and subscriptions you choose. SceneSat's mail infrastructure uses Google services. Optional subscribed communications can be stopped through the unsubscribe or preference route provided; essential responses to your requests and account/security messages are separate.
Donations and purchases
If you donate, become a patron or buy something, we may receive donor/buyer identifiers, contact or receipt details, transaction references, amount/currency, payment status, refunds and relevant entitlements. The information depends on the payment method and what its provider supplies. It is used to fulfil purchases, acknowledge support, reconcile payments, resolve disputes and keep required financial records.
Payment services, including PayPal or Patreon when you choose them, process payment information under their own terms and privacy policies. Do not send payment-card details to SceneSat support. Public donor or patron acknowledgements use the display information and visibility choices recorded for that acknowledgement; payment records themselves are not a public donor list.
Support, safety and technical records
Support correspondence, reports and deletion/export requests may include your account/contact details, the issue or reported content, supporting evidence and the actions taken. Access is limited to people who need it to handle the matter.
Website, streaming, identity and operational systems also process request/access logs, IP addresses, device/client information, timestamps, errors and security/audit records. These help us deliver the service, diagnose faults, prevent abuse and investigate incidents. Information you send in a crash report or support attachment is also processed for that request.
Why we may process it
Under the GDPR, we rely on the basis applicable to the particular purpose:
- Providing a service you request: processing necessary for your account, synchronized features, submitted content, purchases and related fulfilment is needed to perform our agreement with you.
- Legitimate interests: operating and securing the public service, maintaining reliable streams and archives, preventing abuse, handling ordinary support and moderating the community. We must balance these purposes against your rights and interests; you may object to processing based on this ground.
- Consent: optional subscribed communications and other processing for which we ask your permission. Where consent is the legal basis, you can withdraw it without affecting earlier lawful processing. Device notification permission can also be withdrawn in device settings.
- Legal obligations: records and disclosures required for accounting, legal compliance and responding to applicable data-protection obligations.
We do not sell personal data. We do not use your account data for advertising profiles. Programming and ranking features may use requests, votes and listening information; these are different from decisions with legal or similarly significant effects about you, which we do not make solely by automated processing.
Recipients and international processing
Authorized SceneSat staff and volunteers receive access according to their responsibilities. Service providers may receive the information needed to host or deliver a feature, authenticate users, send email or notifications, process payments, or investigate technical issues. Public content is also received by the audiences and connected platforms described above. We may disclose information where legally required or necessary to establish or defend a legal claim.
Core SceneSat infrastructure is operated in the European Union. This does not mean every recipient or copy stays there: global email, push, payment, app-store and community-platform providers can process data in other countries. Third-party websites, guest streams, external links and embedded players may receive connection information when you use them and may set their own cookies or identifiers. Their processing is covered by their policies as well as any obligations they have to SceneSat.
Relevant provider information includes Apple, Google, PayPal, Patreon, Discord and Twitch. IRC networks and guest stations are independently operated. Contact us for the recipients and applicable international-transfer safeguards relevant to your data; safeguards must follow applicable data-protection law, such as an adequacy decision or appropriate contractual safeguards where required.
Cookies and information on your device
The website and apps use cookies or local storage for functions such as sign-in, security, preferences, player state and account synchronization. The browser and operating system provide controls to clear this information or revoke permissions. Clearing it may sign you out or remove local preferences and downloads. Third-party services you open or embed can have separate storage and consent settings.
Turning off notifications in SceneSat initiates device unregistration where supported. An offline device may need to reconnect to complete that request. Turn notifications off on each device as needed: deleting an account cannot identify every anonymous device registration, and changing operating-system permission alone does not necessarily erase a server registration immediately.
Retention
Retention depends on the record, its purpose and any legal obligation. Deletion of a visible profile is not the same as immediate removal of every operational or backup copy.
- Account features and private content: retained while needed to provide the account and features, then removed or reviewed when you delete content or request account deletion. We handle related media, service identities and copies as part of that review.
- Forum: posts and threads stay until you remove them, ask us to remove them, or your account is deleted (see below). Removing a post hides it from the discussion; its text is kept for 30 days for abuse review and then erased. Earlier versions of an edited post are kept for 90 days and then erased. Reports, and the snapshots attached to them, are kept for 12 months after the case is closed, and so is the record of which staff opened them. Your watches and read state are kept while your account exists; short-lived keys that prevent a duplicate post are kept for seven days.
- Shared play/request history and votes: retained to preserve the station's historical record and consistent totals. On fulfilled account deletion, we remove the account connection and identifying details rather than erase those shared records. Data that still identifies a person is still treated as personal data.
- Financial records: retained for the applicable bookkeeping, tax, transaction and legal-claim purposes. Unnecessary personal attribution is removed or anonymized; identifying evidence that must be retained is restricted. We explain relevant retention when responding to a deletion request.
- Support, safety and security records: retained as needed to investigate, resolve and document the matter, meet legal obligations or handle a related dispute. Open matters require review. We minimize completion evidence instead of preserving erased content in case notes.
- Notifications: registrations and delivery records remain while needed for notification delivery and its administration. Successful unregistration removes the registration and associated delivery rows. A permanently rejected token can be marked unusable before its stored record is removed; invalidity alone is not deletion.
- Technical logs: rotated according to the relevant system's operational configuration and investigation needs. Retention varies between systems; records needed for an incident investigation can be kept until that investigation and any related dispute are resolved.
- Backups and migration sources: routine backups expire according to their backup schedules. Some older migration/recovery copies remain restricted until replacement data has been restored, checked and reconciled; these are separate from routine backup rotation. Restoring a backup must include reapplying completed removals before the restored personal data is made available again.
- Data exports: a released ZIP is downloadable for seven days and then expires. Expired/cancelled request metadata is removed once the original request is more than 30 days old; an unfulfilled request remains pending for review. Temporary review material must be removed separately after fulfilment. An export is not intended to become a permanent additional archive of your data.
Contact us for the period or retention criteria applying to a particular record. We will explain any information retained after a fulfilled request and why it remains necessary.
Access and data export
A single takeout request covers your personal data across all SceneSat services you use. This includes SceneSatID, the website and apps, chat/community services, Foundry, and other SceneSat contributor or administration services associated with you. The service where you submit the request does not limit its scope. You do not need to request each service separately. We review linked identities and legacy records, and the package identifies the services checked and explains any justified exclusions or data that could not be reliably attributed to you.
Sign in at Download my data to request a ZIP. It includes the applicable account data and reviewed records from the services you use, including your donation/purchase data where held. Coverage and exclusions are described in the package. We protect other people's private information and exclude credentials and service secrets.
The first accepted request has a minimum one-hour delay. Further exports within a rolling 30 days have minimum delays of one day, three days and then seven days. Repeated submissions while a request is pending reuse the existing request without moving its scheduled time. An operator reviews coverage, so delivery can take longer than the minimum delay. Large exports may need a separately arranged secure delivery.
We email a link to the account page when the ZIP is ready, not the ZIP or a public download token. Download requires sign-in to the same account. The seven-day download window begins when the package is released. These operational delays do not extend legal deadlines for responding to a data-rights request. Contact us if the online route is unsuitable or unavailable.
Account deletion
A deletion request covers all SceneSat services associated with you, not only the website or app where it starts. We review the shared SceneSatID, connected service accounts, personal records, community content, uploads and retained copies across our services, including Foundry and any contributor or administration services you use. We do not treat removal of a single profile as completion of a service-wide request. We explain any legal retention, anonymized shared records or other justified limitations in the completion response.
Sign in at Delete your account to request deletion. You can choose a seven-day cancellation window or delete without the waiting period. Your account remains available until processing starts. You can cancel a pending request during the cancellation window; once permanent deletion begins, it cannot be undone. Completion can take up to 30 days, including the waiting period. You can also make a deletion or other privacy request by contacting info@scenesat.com. We verify ownership without asking you to email your password. Uninstalling an app is not an account-deletion request.
When fulfilling deletion, we remove the account and identifying profile information, revoke associated access, and remove or anonymize applicable personal records and content under SceneSat's control. Forum posts you wrote stay in their discussions but are detached from you and shown as "Deleted member", and your forum watches and read state are deleted. If you would rather have your posts erased, say so in your request: we then replace them with a removal notice and erase their earlier versions, unless an open report needs them. Shared play/request history, votes and financial records are handled as described above. Deleting SceneSatID also affects access to other SceneSat services using it. Tell us about any other service identities or uploads so we can include them in the review.
We aim to complete verified account-deletion requests within 30 days and send confirmation of the outcome, including any justified retention or limitations. Request any data export you want before deletion is completed: irreversible anonymization prevents us from reconstructing the retained records as your personal history.
Public material may already have reached connected services, recipients or independent copies outside our control. We handle our copies and relevant recipient-notification obligations, but cannot guarantee removal of copies held independently by others. Account deletion does not itself cancel recurring payments held by an external provider; manage those with that provider too.
Your choices and rights
Subject to the applicable legal conditions, you can ask to access or correct your data, obtain a portable copy, erase it, restrict processing, or object to processing based on legitimate interests. You can withdraw consent where processing depends on it. We may need proportionate information to confirm that a request comes from the right person, and must consider other people's rights and lawful retention obligations.
Email info@scenesat.com. We respond without undue delay and normally within one month of receiving a data-rights request. Where the law permits an extension for a complex or numerous request, we explain the reason and extension within that first month. Automated export scheduling does not override this obligation.
You can complain to the Swedish Authority for Privacy Protection (IMY) or your relevant supervisory authority. Contacting us first can help resolve a concern, but is not a condition for making a complaint.
SceneSat is not designed specifically for children. If you believe a child's personal information needs attention, contact us so we can assess and handle it.
Changes to this policy
We update this page when relevant processing or services change and show the effective date above. Where a change requires additional information or a new consent, updating this page alone does not replace that requirement.