Komirka Privacy Policy

This Privacy Policy explains how Komirka collects, uses, stores, shares, and deletes personal data when you use the Komirka iOS app, backend services, subscriptions, music-provider connections, backups, exports, notifications, and support channels.

This document is intended to be a practical privacy notice for users and for App Store review. It is not legal advice. The controller/operator for Komirka is Andrii Minikh, Poland. For privacy questions or requests, email privacy@komirka.me.

1. Who We Are

Komirka helps you connect Apple Music and/or Spotify, back up music library metadata, view backup history, export backup files, and manage a monthly or yearly Komirka Pro subscription.

For the purposes of privacy laws such as the GDPR, UK GDPR, and similar laws, Andrii Minikh is the controller of personal data processed by Komirka unless another party is identified as an independent controller for its own services.

2. Age Requirement

Komirka is not directed to children under 13. Do not create an account or use Komirka if you are under 13. If we learn that we collected personal data from a child under 13, we will take reasonable steps to delete it.

3. Personal Data We Collect

Account and authentication data

We collect your name, email address, password hash, email verification status, account creation and update timestamps, email confirmation code metadata, password reset code metadata, backend session identifiers, session expiration time, and normalized user-agent/device information used to manage sessions.

We do not store your plain-text password. Passwords are hashed before storage.

Subscription and purchase data

Komirka uses RevenueCat to manage subscription entitlements for monthly and yearly Komirka Pro subscriptions. We process subscription status, entitlement status, RevenueCat app user ID, latest RevenueCat event metadata, subscription expiration information, RevenueCat sync timestamps/errors, and RevenueCat webhook payloads needed to validate and reconcile subscription access.

Apple processes App Store purchases under Apple's own terms and privacy policy. Komirka does not receive your full payment card details.

Apple Music data

If you connect Apple Music, Komirka stores your Apple Music user token so the backend can access Apple Music data you authorized. Komirka may store Apple Music backup snapshots containing library songs, playlists, playlist tracks, track names, artist names, album names, artwork URL templates, Apple Music library resource IDs, raw provider attributes, backup status/history, counts, timestamps, durations, and error information.

Komirka uses Apple Music data to provide backups, history, exports, reconnect notices, and scheduled Pro backups. Komirka does not store audio files.

Spotify data

If you connect Spotify, Komirka stores Spotify access and refresh tokens, token expiration time, granted scopes, token update/invalidation timestamps, and your Spotify user ID when available. Komirka may store Spotify backup snapshots containing liked songs, saved albums, playlists, playlist tracks, track names, artist names, album names, playlist names/descriptions, owner names, artwork URLs, Spotify resource IDs, raw provider attributes, backup status/history, counts, timestamps, durations, and error information.

Komirka uses Spotify data to provide backups, history, exports, reconnect notices, and scheduled Pro backups. Komirka does not store audio files.

Backup exports

When you request an export, Komirka generates CSV files packaged as a ZIP download. Export files can contain the music metadata described above. The iOS app may temporarily store downloaded export files on your device so you can save or share them.

Analytics and product usage data

Komirka uses PostHog EU for analytics and event tracking. We may send your Komirka user ID, email address, screen names, selected provider, button/action names, paywall events, purchase/restore success or failure events, and similar product usage events. This helps us understand feature usage, improve reliability, and prioritize product work.

PostHog is configured with the EU ingestion host. Analytics are not used for targeted advertising or cross-context behavioral advertising.

Push notification data

If you allow notifications, Komirka stores your APNs push token, push environment, and update time. Komirka uses push notifications for service messages such as backup completion or reconnect-required notices. You can disable notifications in iOS settings.

Support and communication data

If you contact us by email, we process the email address, message content, and any information you choose to include. Komirka also sends service emails such as confirmation codes and password reset codes through Resend.

Logs and security data

Komirka may process request IDs, timestamps, route information, response status, sanitized headers, outbound provider request metadata, errors, rate-limit information, user email in request context, and similar logs needed to operate, debug, secure, and protect the service. Sensitive authorization headers and provider tokens are intended to be redacted from logs.

4. How We Use Personal Data

We use personal data to:

  • create and authenticate accounts;
  • verify email addresses and reset passwords;
  • manage backend sessions and protect accounts;
  • connect, disconnect, and maintain Apple Music and Spotify integrations;
  • create manual and scheduled music-library backups;
  • provide backup history, backup status, and CSV/ZIP exports;
  • validate subscriptions, enforce Pro entitlements, and prevent subscription fraud;
  • send service emails and push notifications;
  • provide support and respond to requests;
  • analyze product usage and improve Komirka;
  • monitor reliability, debug issues, prevent abuse, and enforce rate limits;
  • comply with legal obligations and respond to valid legal requests;
  • process privacy requests and manage deletion, access, correction, and portability requests.

5. Legal Bases for GDPR / UK GDPR

Where GDPR or UK GDPR applies, we rely on the following legal bases:

  • Contract: to create your account, provide the app, process subscriptions, connect providers, run backups, provide exports, and manage account features.
  • Consent: where you authorize Apple Music or Spotify access, allow push notifications, or where consent is otherwise required by law.
  • Legitimate interests: for security, fraud prevention, service reliability, product analytics, debugging, abuse prevention, and improving Komirka.
  • Legal obligation: where we must keep or disclose information to comply with applicable law.

You may withdraw consent where processing is based on consent, but doing so may prevent related features from working. For example, disconnecting Apple Music or Spotify stops future provider access.

6. Third Parties and Recipients

We may share or make personal data available to:

  • Apple, App Store, APNs, MusicKit, and Apple Music API for purchases, push notifications, and Apple Music access;
  • Spotify for Spotify authorization and API access;
  • RevenueCat for subscription management, receipt validation, entitlement reconciliation, and subscription analytics;
  • PostHog EU for product analytics and event tracking;
  • Resend for transactional emails such as confirmation and password reset codes;
  • hosting, database, Redis, queue, logging, and infrastructure providers used to run the backend;
  • professional advisors, security providers, legal authorities, or other parties when needed for legal compliance, security, fraud prevention, dispute resolution, or protection of rights.

These providers may process data under their own privacy policies where they act as independent controllers. Where they act as processors or service providers for Komirka, they are expected to process data only as needed to provide their services.

7. No Sale, No Targeted Advertising Sharing

Komirka does not sell personal data. Komirka does not share personal data with data brokers. Komirka does not share personal data for cross-context behavioral advertising or targeted advertising.

If this changes, we will update this policy and provide any legally required choices before using data in that way.

8. International Transfers

Komirka is operated from Poland and is expected to host production backend and database data primarily in the EU/EEA. Some providers, such as RevenueCat, PostHog, Apple, Spotify, Resend, hosting, infrastructure, support, or security providers, may process data in other countries.

Where required, we rely on appropriate transfer mechanisms such as adequacy decisions, Standard Contractual Clauses, Data Privacy Framework participation, data processing agreements, or other safeguards recognized by applicable law.

9. Retention and Deletion

We keep personal data only as long as needed for the purposes described in this policy, unless a longer period is required or permitted by law.

  • Account data is kept while your account exists.
  • Backend sessions expire based on the configured session lifetime and may also be deleted when you sign out or reset your password.
  • Unverified accounts may be deleted after the configured cleanup window.
  • Email confirmation and password reset codes are temporary and expire after the configured code lifetime.
  • Apple Music and Spotify provider tokens are kept while the provider remains connected. Disconnecting a provider removes the provider tokens and stops future provider access.
  • Disconnecting Apple Music or Spotify does not delete existing backups by itself. Existing backups remain available until account deletion or retention cleanup.
  • For each provider and user, Komirka keeps up to 100 successful backup snapshots and up to 50 failed backup snapshots. Older successful and failed snapshots may be deleted during retention cleanup. Running or queued snapshots may be marked failed if stale.
  • Account deletion is intended to permanently delete your account, sessions, provider tokens, push token, linked RevenueCat webhook rows, and stored Apple Music/Spotify backup snapshots and their items from the backend database, subject to lawful exceptions and backup/infrastructure propagation.
  • If we must retain limited information for legal, security, fraud-prevention, accounting, dispute, or compliance reasons, we will retain only what is reasonably needed for that purpose.

10. Provider Disconnect and Revocation

You can disconnect Apple Music or Spotify in Komirka. Disconnecting removes the stored provider token(s) from Komirka and prevents future backups for that provider unless you reconnect.

You may also revoke access through Apple or Spotify account settings. If a provider token expires or is rejected, Komirka may clear the token and ask you to reconnect.

Existing backup data is not deleted by provider disconnect alone. To delete all account-associated backup data from Komirka, delete your Komirka account or contact privacy@komirka.me.

11. Your Privacy Rights

Depending on where you live, you may have rights to:

  • access personal data we hold about you;
  • receive a copy of your data in a portable format;
  • correct inaccurate or incomplete data;
  • delete personal data;
  • restrict or object to certain processing;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with a data protection authority.

If you are in the EEA, UK, or Switzerland, these rights may apply under GDPR, UK GDPR, or related laws. If you are in California, you may have CCPA/CPRA rights to know/access, delete, correct, opt out of sale/share, limit certain uses of sensitive personal information, and not be discriminated against for exercising your rights.

Because Komirka does not sell personal data and does not share personal data for cross-context behavioral advertising, there is no sale/share opt-out to exercise for those activities.

12. How to Exercise Your Rights

You can delete your account in the Komirka app. Account deletion permanently deletes your account and associated backend data as described above.

For access, correction, portability, objections, CCPA requests, provider-specific deletion questions, or any other privacy request, email privacy@komirka.me. We may need to verify your identity before completing a request.

We will respond within the time required by applicable law. If we cannot complete a request, we will explain why unless the law prevents us from doing so.

13. Security

Komirka uses technical and organizational measures intended to protect personal data, including password hashing, Keychain storage for the iOS backend session token, transport security for production services, provider-token handling on the backend, rate limits, session invalidation, and log redaction for sensitive headers.

No system is perfectly secure. You are responsible for keeping your account credentials confidential and for protecting exported backup files after you download or share them.

14. Changes to This Policy

We may update this Privacy Policy when Komirka changes, when providers or laws change, or when we need to clarify our practices. The "Last updated" date shows when the policy was last revised. If changes are material, we will provide notice as required by law.

15. Contact

Controller/operator: Andrii Minikh, Poland

Privacy contact: privacy@komirka.me

16. Reference Materials Used for This Policy

This policy was drafted to align with Komirka's current code paths and with privacy guidance from Apple App Review, Apple App Privacy Details, the European Commission's GDPR information for individuals, California CCPA/CPRA resources, Spotify Developer Policy, RevenueCat privacy/GDPR materials, and PostHog privacy compliance materials.