Legal
Privacy policy
Last updated 16 September 2026
This policy explains what personal data the eSound app ("eSound", "the app") processes, why, who receives it and what you can do about it. It also covers this website.
Who is responsible
The controller of your personal data is Slavko Josipovic, Stari velikobrdski put 10, 21300 Makarska, Croatia ("we", "us").
For any privacy question or request, write to [email protected]. We have not appointed a data protection officer because the law does not require one for this service.
What we collect
Your account
- Email address and password (stored only as a salted hash).
- First name and last name, which you enter when you sign up.
- Optional profile details you add yourself: gender, date of birth and a profile photo.
- If you sign in with Apple, Google or Facebook: the identifier and the basic profile details that provider shares with us (usually name, email address and profile photo). With Sign in with Apple you can choose to hide your email address.
- Your settings, such as a private profile, private listening sessions and explicit content.
Your library and listening
- Playlists, saved songs, albums, artists, podcasts and radio stations.
- The artists you pick when you set up your account.
- What you play and when, and when you skip a song, used for your history, your recommendations and to keep your library in sync.
- Your recent searches are stored on your iPhone. The text of a search is sent to the services that return results (see "Who receives your data").
Your device and how you use the app
- A device identifier for this app (the iOS identifier for vendor), your iPhone model, iOS version, app version, language, time zone and country setting.
- Your IP address. We use it to estimate your country and city when a session starts; we don't use GPS and we don't ask for your location.
- Events that describe how the app is used, such as screens opened and features used, linked to your account.
- Crash reports and performance data. Crash reports include your account identifier and email address so we can help you when something breaks.
- A push notification token, if you allow notifications.
- When you open eSound for the first time from a link, the device details listed above and your account email once you sign in, so that we can take you to the content the link pointed to.
When you contact us
- Your messages, your email address, your account identifier, your device model, iOS and app version, and any screenshot or video you choose to attach.
Optional connections you turn on
- Last.fm: the songs you play, sent to your Last.fm account.
- Dropbox, Google Drive, OneDrive, Box or Yandex Disk: read-only access to the files you pick, used to import them.
- Playlist imports from Spotify and other services: the playlist links you give us.
- YouTube account: if you sign in to YouTube inside the app, the sign-in cookies stay on your iPhone and are sent only to YouTube.
What we don't collect
We don't access your contacts, microphone or precise location. We access your camera or photo library only when you choose a picture, for example a playlist cover or a profile photo.
Why we use it and our legal basis
- To provide the app and your account (performance of our contract with you, GDPR Article 6(1)(b)): creating and securing your account, signing you in, syncing your library, playing what you ask for, Jam sessions, imports and support.
- To keep the app working and secure (our legitimate interests, Article 6(1)(f)): crash reports, performance data, abuse and fraud prevention, and checking that requests come from a genuine copy of the app.
- To understand and improve the app (our legitimate interests, Article 6(1)(f)): usage events and aggregated statistics. You can object at any time (see "Your rights").
- With your consent (Article 6(1)(a)): push notifications, and the optional connections listed above. You can withdraw consent at any time in iOS Settings or in the app.
- To meet legal obligations (Article 6(1)(c)): for example answering requests from authorities or keeping records the law requires.
We don't sell your personal data and we don't use it to show you personalised advertising.
Who receives your data
We share personal data only with the recipients below, and only what each one needs.
- Hosting and infrastructure providers in the European Union that run our servers, databases, storage, backups, content delivery and network security. They act as our processors under written agreements and may only use the data to provide their service to us.
- Customer support software provider, acting as our processor, which stores the messages you send us.
- Google (Firebase Analytics, Firebase Crashlytics, Firebase Cloud Messaging, Firebase Remote Config and Google Sign-In): usage events, crash reports, push notification delivery and sign-in.
- Meta (Facebook SDK and Facebook Login): sign-in with Facebook. The Facebook SDK included in the app can also send Meta basic app events, such as app installs and app launches, together with device information.
- Apple: Sign in with Apple, push notifications and Siri requests you make.
- Content, catalogue and lyrics services: when you search or play something, the app requests results, audio, artwork and lyrics from third-party services such as YouTube, Deezer, Spotify and lyrics providers. These services receive the search or track details and your IP address and process them under their own privacy policies.
- Podcast publishers and radio stations: when you play an episode or a station, your iPhone connects to the publisher's or station's server, which receives your IP address.
- Services you connect yourself, such as Last.fm or a cloud storage provider, under their own privacy policies.
- Authorities, when the law requires us to disclose data.
International transfers
Some recipients, such as Google and Meta, may process data outside the European Economic Area, including in the United States. Where that happens, the transfer relies on an adequacy decision of the European Commission (such as the EU-U.S. Data Privacy Framework, for certified companies) or on the European Commission's Standard Contractual Clauses.
How long we keep it
- Account, library and settings: for as long as your account exists.
- Usage events and crash reports: for as long as they help us run and improve the app, and no longer than 14 months in identifiable form. After that we delete them or keep them only in aggregated form.
- Support messages: for up to 2 years after your last message.
- When you delete your account, we delete your account, library and settings without undue delay. Copies in backups are overwritten as the backups rotate. We keep data longer only where the law requires it.
Deleting your account
In the app, open Settings, then Profile, Edit profile, Delete account. You can also ask us by writing to [email protected] from the email address of your account.
Your rights
Under the GDPR you can ask us to:
- give you access to your personal data and a copy of it;
- correct data that is wrong or incomplete;
- delete your data;
- restrict how we use it;
- give you the data you provided in a portable format;
- stop processing based on our legitimate interests (right to object).
Where we rely on your consent, you can withdraw it at any time; that doesn't affect what we did before. Write to [email protected]. We answer within one month, and we may ask you to confirm that the account is yours.
You also have the right to lodge a complaint with a supervisory authority. In Croatia this is the Personal Data Protection Agency (AZOP). You can also contact the authority of the EU country where you live or work.
Children
eSound is not meant for children under 16. We don't knowingly collect personal data from children under that age. If you believe a child has created an account, write to us and we'll delete it.
Security
Connections between the app and our servers are encrypted. Passwords are stored only as salted hashes, and access to personal data is limited to the people and providers who need it.
This website
esound.music doesn't use cookies, analytics or third-party scripts, and the fonts are served from our own server. Like any web server, ours records technical logs (IP address, date and time, page requested and browser type) to deliver the site and protect it from abuse. We keep these logs for no more than 30 days.
Changes to this policy
When we change this policy we update the date at the top of this page. If a change affects you in a significant way, we'll also tell you in the app or by email before it takes effect.