Privacy policy
Last updated: 6 October 2026
This policy explains what Musikboxen (the app and the box) does with personal data, in plain words.
Who is responsible
The data controller is [legal name to be filled in], a sole proprietorship in Denmark, CVR [CVR number to be filled in], [address to be filled in].
Contact: info@musikboxen.app. If the business later moves into a company, we will update this policy and name the new controller.
Who Musikboxen is for
The app is meant for adults. A grown-up signs in, pairs the box and writes the cards. We do not create accounts for children and we do not knowingly collect personal data from children through the app.
Children use the box by tapping cards on it. The box has no screen and no account of its own, but it does report each tap to the grown-up’s account (see “Plays” below). That can show what a child listens to, so we treat it as personal data of the household.
What we collect and why
Account
You sign in with Google or Apple. We receive your account ID and your email address (Apple may give us a private relay address instead). We use this to sign you in and to keep your data separate from everyone else’s. Basis: performing our agreement with you (GDPR art. 6(1)(b)).
App settings and phone details
Your language, whether you have paired a box before, which speaker system you use, and whether you allowed Bluetooth, notifications and Wi-Fi during setup. We also store your phone’s operating system and version and, on Android, its make and model. We use this to run the app and to work out why something fails on a particular phone. Basis: performing our agreement with you, and our legitimate interest in a working product (art. 6(1)(b) and (f)).
Cards
For each card you write we save which song, album or playlist it holds (its Spotify ID, name, artists and cover image link) and when you wrote it, so the app can show your cards. We also keep a count of how many different users have written each song. That count, with the song’s name and cover, is shown to other users as a list of popular cards. It does not say who wrote them. Basis: performing our agreement with you.
Your box
When you pair a box we register its ID (the hardware address of its Wi-Fi chip), its software version and a link to your account, plus a secret that the box uses to prove it is yours. The secret is stored only as a hash. We use this to accept reports from your box and to offer software updates. Basis: performing our agreement with you.
Plays
Each time a card is tapped on your box, the box tells us which box, which song, album or playlist, and when. We link it to your account. We use this to understand which music families use and to build features such as listening summaries. Basis: our legitimate interest (art. 6(1)(f)). You can object to this at any time, see “Your rights”.
Notifications
If you allow notifications we store which notification topics you subscribed to and when. Delivery uses a push token managed by Firebase Cloud Messaging. Basis: your consent, which you can withdraw in your phone’s settings.
Diagnostic logs
The app sends short log lines about what it is doing, such as pairing steps and errors, together with your user ID. Pairing lines can include the name of the Wi-Fi network your phone is on and the name of the speaker or box involved. They never include your Wi-Fi password. The box also sends technical logs, identified by its device ID. Basis: our legitimate interest in finding and fixing faults.
Bug reports
If you send a bug report we store what you wrote, the screen you were on, your recent actions in the app, an optional screenshot you chose to attach, your email address, the app version, your phone details and, where available, the ID of the box you were connected to. Basis: your request to us, and our legitimate interest in fixing problems.
Searching for songs
The words you type when you search for a song are sent to our server and on to Spotify to find matching music. We do not use your Spotify account and receive nothing from it.
What stays on your side
The Wi-Fi name and password you enter for the box are sent to the box over Bluetooth and stored on it. The password is never sent to us. The app finds your speaker on your home network and plays through it directly. A card holds only a link to a song, not any personal data. The app asks for location permission only because the phone operating system requires it to read the name of the Wi-Fi network and to scan for Bluetooth devices. We do not collect your location.
What we do not do
We do not sell personal data, show advertising or use advertising or third-party analytics software in the app.
Where data is stored
Our database is located in [database region to be filled in] and our server functions run in Belgium (europe-west1). Google and Axiom may process data outside the EU/EEA, for example in the United States. Where they do, the transfer relies on the EU Commission’s standard contractual clauses or the EU–US Data Privacy Framework.
How long we keep data
Account, card, box and play data is kept for as long as you have an account, and deleted when you ask us to delete your account (see Delete your account). Diagnostic logs are kept for [log retention period to be decided]. Bug reports are kept for [bug report retention period to be decided]. Backups are overwritten within [backup period to be decided].
Your rights
You can ask us for access to your data, to correct it, to delete it, to restrict how we use it, or to receive it in a portable format. You can object to processing that rests on our legitimate interest, including the play history above. Where we rely on consent you can withdraw it at any time.
Write to info@musikboxen.app. We answer within one month. You can also complain to the Danish Data Protection Agency, Datatilsynet, or to the authority in your own country.
Security
Data travels over encrypted connections. Each signed-in user can read and write only their own data in our database, and the secret a box uses is stored only as a hash. No system is perfectly secure, and if a breach puts your rights at risk we will tell you and the Danish Data Protection Agency as the law requires.
Changes to this policy
If what we collect or why changes in a way that matters to you, we update this page and the date above. For significant changes we will also tell app users directly.