Privacy Policy
Last updated: 18 September 2026
Jam Jam is built to respect you. The app works on your device and does not require an account. This policy explains the limited data involved when you choose to use the optional online features.
Who is responsible for your data
The controller of the personal data described below is Titouan Wattelet, sole trader, 173 rue de Courcelles, 75017 Paris, France[email protected]. Full publisher details, including the host of this website, are on the legal notice page. No data protection officer has been appointed: at this scale the GDPR does not require one, and the address above reaches a human. We answer in French or in English.
Your songs are yours
Your songbook, chords, lyrics and melodies are saved on your phone and stay usable offline. When you are signed in, they are also backed up to your private account space (including their playlists) so you can restore them on your other devices (web, Android and iOS) if you switch phones or reinstall the app, like a personal cloud drive. You choose what you import, create and publish there: Jam Jam distributes nothing of its own accord, and what other people can see is what you chose to publish.
What we store (only with an account)
- Email: used to sign you back in, to prevent fake accounts, and to send you account emails: a one-off welcome message when you create your account, plus any notification you switched on. We never email you marketing without your explicit opt-in.
- Profile: your chosen username and, optionally, an avatar (moderated for safety). Others can see those two things and any songs you make public, never your email. You can change your username or clear your avatar at any time, and stay anonymous.
- Activity: a “last active” date for optional newsletter preferences, and a device identifier to enforce one active session per environment (web and mobile can be signed in at once).
Ads
The app may show ads to signed-out and non-premium users via Google AdMob. Premium subscribers and beta testers see no ads. This website uses no third-party tracker or analytics tool, and loads no third-party script unless you explicitly ask for one (see “What your browser stores”). To show it in your language, the site detects your approximate country from your IP address via a self-hosted offline database: no third-party service is contacted and your IP is never stored. IP geolocation by DB-IP (CC-BY 4.0). Before the very first ad request, the app asks for your consent through Google’s official consent form (UMP/TCF) and initialises the ad SDK only if you allow it; a refusal loads nothing at all. Ads are restricted to a general-audience rating (G). On Android, they are non-personalised unless you explicitly allow personalisation through that consent form. On iOS, ads are always non-personalised: the app never shows Apple’s App Tracking Transparency prompt. AdMob is operated by Google, which receives an advertising identifier for this purpose. You can review or withdraw that choice from Settings → “Manage ad consent” for as long as your account is eligible for ads; if you have since become Premium or a beta tester, no ad is served to you at all, and you can ask us to reset your choice at [email protected] to reset it.
What your browser stores
This website stores a handful of values in your browser, all of them strictly necessary and none of them used for tracking or advertising: your chosen language and your light/dark theme, so the site opens the way you left it; a marker recording that we already redirected you once to your language, so we do not do it again; and, only if you sign in, your session, so you stay signed in. There is no advertising or analytics cookie on this website, and no third-party script is loaded by default. The content security policy served with every page allows exactly one exception, and only after you ask for it: the Trustpilot review form, on the home page. It stays dormant behind a button; before you press it, nothing at all is requested from Trustpilot. It sets no cookie and writes nothing to your browser. We measured this, but once loaded it does tell Trustpilot your IP address, the page you are on and your browser’s language, which Trustpilot uses for its own audience statistics. Trustpilot A/S is established in Denmark, inside the European Union: this is not a transfer outside the EU, Trustpilot is not one of our processors, it acts as its own controller, and its own privacy policy governs what you write there. The plain link to Trustpilot, next to that button, loads no script whatsoever. These strictly necessary items are exempt from prior consent; clearing your browser data removes them.
Purchases
Optional Premium subscriptions and the lifetime purchase are processed by our payment providers: Google Play Billing (in-app on Android) and Stripe (for direct purchases on jam-jam.org). Your card details are handled by these processors and never stored by Jam Jam.
Where data is stored
Account data is hosted on Supabase (EU region) with row-level security, so you can only ever reach your own data. The website itself is served from a machine rented in France from OVH. Beyond those two, exactly four processors act on our instructions, and no other: Resend sends your sign-in codes and account e-mails (it therefore receives your e-mail address); RevenueCat reconciles your subscription across stores (an account identifier and a purchase status); Stripe and Google Play Billing take the payment; and Google Vision SafeSearch moderates avatars, on the uploaded image only. None of them is allowed to use your data for its own purposes.
Transfers outside the European Union
Your songbook, your profile and your account stay in the European Union. Four of the processors above are established in the United States, so a transfer does take place when they are used, and only what each one needs: your e-mail address to Resend, an account identifier and a purchase status to RevenueCat, your billing data to Stripe, the avatar image to Google Vision. Plus the advertising identifier to Google when ads are served. Those transfers rely on the European Commission’s standard contractual clauses and, where the provider is certified, on the EU–US Data Privacy Framework. The web lookups described under “Online correction” are not transfers of personal data: nothing that identifies you accompanies them.
Analysing an audio file on our server
Analysing an audio file (chords, rhythm, lyrics) runs either on your device or on our server. This is true of the mobile app as well as the web app, and you are the one who decides. The setting lives in Settings → Listen & detect → “Where audio analysis runs”, and it has three positions. On my phone: nothing is ever sent. Online: the analysis is handed to our server. Depending on my connection, the default: in the mobile app, the analysis goes online when you are on Wi-Fi or a wired link and the connection answers properly, and stays on your phone in every other case (no connection, mobile data, slow link, server unreachable, saturated, or unable to perform the requested analysis); in the web app, which does not measure link quality yet, it sends the analysis to our server. The app always shows where the computation is happening, and you can switch from one side to the other while it runs.
When the analysis runs on our server, what is sent is the audio file itself. It goes to jam-jam.org, which runs on our own machine rented in France from OVH (100 MB and 12 minutes of music at most). There it is converted, analysed, then deleted as soon as the processing ends, whether it succeeded, failed or was interrupted. If you cancel, it is deleted straight away.
Concretely: retention = the time of the processing, and nothing beyond it. No backup copy, no temporary file left behind. The file is not kept, not reused, not attached to your account, not shared, and it is never used to train a model. No processor is involved: the work happens on our own server, in France, and the file is passed to no third party. Only the result (chords, tempo, sections, lyrics) comes back to you, and it is you who then decides whether to save it in your songbook. That result. Never the audio. Waits in the server’s memory for 15 minutes at most, so a slow connection can still collect it; it is erased as soon as your app or your browser has read it, and in any case at the end of those fifteen minutes. Nothing is written to a log. Two technical details, so that nothing is hidden: your request carries a header saying only “premium”, “signed in” or “anonymous”. It decides your place in the queue and nothing else, and carries no identifier of any kind, and your IP address is held in memory for sixty seconds to enforce a rate limit against abuse, then forgotten; it is never stored and never logged.
Legal basis: your consent (Article 6(1)(a) GDPR), given through the setting above. This upload is optional and never silent: the screen states where the analysis is running before and during the processing. You can refuse: choose “On my phone”, and no audio file will leave for an analysis again. The feature still works, it is only slower and your device warms up more. You can also refuse one analysis at a time, by switching back to local computation while it runs. Withdrawing your consent leaves nothing to delete, since nothing is kept.
Exporting your karaoke as a video (optional)
From the mobile app as well as the web app, you can ask for a video of your karaoke. The editing is done by our server, in France, on our own machine: your soundtrack is therefore sent to jam-jam.org for the time it takes to make the video. Along with the optional server analysis described above, it is one of the two features that send an audio file off your phone, it never leaves on its own, and the screen says so before the first byte goes out.
Legal basis: your consent (Article 6(1)(a) GDPR). Nothing is sent unless you started the export, export by export; not starting one has no consequence anywhere else in the app. What goes up: the song’s audio file, the time-stamped lyrics and the chords that make up the picture, and your display settings. What does not go up: your songbook, your email address, your username. An export requires an account (that is what carries your export quota); the server then receives a derived, non-reversible identifier, used only so that two people are never served each other’s video.
Retention, and three rules decide it, whichever comes first: the finished video is deleted 24 hours after you asked for it, one hour after you first download it, or as soon as a fourth export replaces your oldest: we keep at most three exports per account. The audio file you sent is erased as soon as the editing ends, whatever happens (success, failure or cancellation), and cancelling an export erases the video straight away. That video contains a copy of the sound track: that is why these limits exist, and why they are short. Rendering happens on our own server in France; no processor is involved, nothing is logged, and nothing is ever used to train a model.
Detection error reports (opt-in audio)
This is the one and only case in which an audio file of yours is kept: the optional server-side analysis described just above keeps nothing at all. If you report a detection error and explicitly tick the consent box, the analysed audio and its detection results are uploaded to your private space on our EU-hosted infrastructure (Supabase, EU region) and kept for up to 90 days to improve our detection model, then deleted. That box is never pre-ticked; without your consent, no audio of yours is ever stored by us.
Online lyric and chord search (optional)
Chord detection and lyric transcription run on your device or on our server, according to the setting described above. Whichever you pick, the option below is a separate matter: it never sends audio. If online lyric and chord search is enabled (on by default. It is presented during onboarding and can be turned off there, or at any time in the settings), Jam Jam can query a search engine and lyrics sites to find or complete the lyrics and chords of your songs, both during an audio analysis and from your songbook. In that case only anonymous text metadata is sent. The song title, the file name and short lyric excerpts. To third-party services (MusicBrainz, a web search engine and Wikipedia). Your audio is never sent, and no user identity or account information is attached. You can turn this option off at any time; when it is off, no online lookup ever happens. The web search goes through DuckDuckGo, and the lyric or tab pages it points to are then read, a handful at most per analysis. In the web app those requests first go through our own relay on jam-jam.org (browsers cannot call those sites directly): we therefore see your session at that moment, but nothing about you is passed on to DuckDuckGo or to the sites consulted. Legal basis: our legitimate interest in finding and completing the lyrics and chords you ask us to look up. Which is precisely why the option can be switched off in one tap, at any time, without losing anything else in the app. Because none of your identifiers travels with these lookups, MusicBrainz, DuckDuckGo and Wikipedia cannot attach them to you.
Converting a file
Some formats cannot be read on your phone or in your browser: a photo or PDF of sheet music, a scanned songbook, a video, or any format that needs one of our own conversion engines. In those cases, on mobile, on the web and through our API, the file itself is sent to our own conversion service at jam-jam.org, running on our machine in France. It is never sent to a third party. The source file is deleted the moment the conversion ends; the result is kept for at most 24 hours, so you can still collect it if you closed the app, then it is erased too. Nothing is attached to your account unless you choose to import the result, and it is never used to train a model. If you would rather nothing left your device at all, import the melody another way: MIDI, MusicXML, plain text, or by playing it.
Every conversion, whether started from an account, anonymously or through the API, adds one line to a technical usage log: the pair of formats involved, the size of the file, how long the computation took, the platform and, if you are signed in, an account reference. Never the file name, its content, an online address you submitted, or your IP address. This log lets us know which conversions are used and where they fail; it is kept 90 days.
This conversion tool is also available on our website without an account, within a limit of 3 conversions per rolling 24 hours. To enforce that limit without creating an account for you, our server computes an irreversible, salted hash of your IP address (salted with a key that changes every day), a technical fingerprint of your browser and a token stored in your browser, keeps only the most restrictive of the three, and deletes it after 48 hours. Your IP address, your fingerprint and that token are never stored in clear and never linked to an account. Legal basis: our legitimate interest in preventing abuse of a feature open without an account. Past that limit, a one-off Cloudflare Turnstile challenge may be shown before you can try again; it runs in your browser and is not used to profile you.
If you use this conversion service through our public API, you authenticate with a personal API key that we never store in clear: only its irreversible hash and the date it was last used are kept, so you can tell whether it is still active and revoke it at any time from your account.
Import improvement statistics
When you import a song or a melody, Jam Jam records one anonymous line to find out where imports break: the kind of source (link, PDF, photo, file, paste…), whether it succeeded or the reason it failed, the bare host of the online source (for example ultimate-guitar.com, never the full address), the number of songs produced, the app version and your interface language. Nothing else: no account, device or session identifier, no file, no lyrics, no chords, no file name. These lines are not linked to any user and are deleted after 180 days. Legal basis: legitimate interest in keeping the import engine working. You can switch this off at any time, for free and with no effect on the app, in Settings → Songbook, or in the app’s Privacy screen.
Reports and anomaly reports
When you report a problem from the app or the web app (always a voluntary action, and one that requires being signed in) a diagnostic context is automatically attached to your report so that it can actually be acted on. None of it is collected outside a report you trigger yourself.
- What you tell us: the kind of problem, the boxes you ticked and, if you write one, your free-text message. That message is sent exactly as you wrote it, so please do not paste sensitive information into it.
- The build you are running: the app version, the platform and its system version, the brand and model of the device (never the name you gave it) or, on the web, your browser and its major version plus the screen format, where the install came from, the interface language, the light/dark theme and the interface scale.
- Where the problem is: the screen or page you are reporting from, the element you pointed at (a chord, a diagram, a sound, at most a single line of lyrics) and the settings of the feature involved (instrument, capo, transposition, style… and, on the web, the size of the browser window).
- The state of the app: whether you were online or offline (and, on the web, the connection type reported by your browser), the date of the last successful songbook sync, how many uploads were still pending, how long the app had been open, and your account tier (standard, premium, beta, admin).
- A technical trace: the list of the last screens you visited, the error message if there was one, and the last 80 lines of the app’s technical log.
- Triage markers: the send date, how many taps it took you, and a technical fingerprint used to group identical reports together.
Screenshots. On mobile, the quick report (long-press an element, then pick a symptom) sends no image at all. Only the detailed form attaches a picture of the screen as it was at the moment of your gesture: it is shown to you as a thumbnail and can be removed with one tap before you send. No image ever leaves your device without having been shown to you, and the capture is refused outright on sign-in, verification-code and payment screens, or whenever a password field is on screen. In the web app nothing is captured automatically: only an image you attach yourself is sent.
The technical log is filtered on your device before it is sent: session tokens, API keys, authorisation headers, passwords, email addresses and phone numbers are replaced by a marker. Including when they are split across two lines. The same filter is applied to the settings attached to the report. It deliberately errs on the safe side: better to erase something useful than to let something leak. Your free-text message, by contrast, is transmitted as written.
The following is never sent with a report: audio from your microphone (the one exception being the detection error report described above, with your explicit consent), the full lyrics of a song (at most one bounded line, the one exception being the detection error report described above, with your explicit consent), the list of your songs or your songbook, your email address, username or avatar (we reach you through your account), your location, an advertising identifier, your contacts, the content of your conversations with friends, and (on the web) your browser’s full identification string, your extensions, your installed fonts or the content of your input fields.
Retention. The diagnostic context is erased 90 days after the report is sent, or 30 days after the report is processed if that comes sooner. Concretely, what is erased on that clock is the technical trace, the app state, the device model, the system version, where the install came from and your interface language: everything that describes your phone rather than the problem. Attachments (screenshots and images) are deleted 30 days after the report is processed. What survives is the report itself and only the report: your description, its category, the screen concerned, the platform, the app version, and the follow-up. Kept for as long as your account exists so you can read the answer, and deleted together with your account. Legal basis: your consent, given by voluntarily sending the report, and our legitimate interest in fixing defects in the app. To have a report deleted sooner, write to [email protected].
Beta programme: measurement bench
If you are a beta tester, you can start a measurement bench from the app settings: a short series of automated tests, 5 to 10 minutes, run only on audio and text files we supply ourselves. Never on your songbook. Its purpose is narrow and it is the only one: detecting defects specific to each phone model (which chord engine actually loads, what transcription really costs on an older device, how the screen behaves). A bench that only ever runs on the developer’s handset only ever measures the best case. It never starts without your explicit consent, it is never proposed to anyone outside the beta programme, and no box is ever pre-ticked.
When the run ends, a report is sent through the ordinary reporting channel, so it is attached to your account and hosted on Supabase (EU region). Its content is a closed list, built field by field, not “the whole report minus what we thought to remove”. Exactly these twelve items leave your phone:
- the commercial model of the phone (e.g. “Google Pixel 6a”);
- the Android version;
- the processor architecture (e.g. “arm64-v8a”);
- the screen dimensions and its density;
- the version of Jam Jam installed;
- a random campaign identifier, its duration and its verdict;
- which test ran, on which file from our own corpus;
- the outcome of each test: completed, failed, timed out, not run;
- the durations measured, stage by stage;
- the thermal state of the phone and the processor throttling;
- the numeric quantities measured (real-time ratios, recognition rates…);
- on failure, an error category: never the message itself.
And here is what, explicitly, never leaves your phone with a bench report:
- the app’s internal log;
- the titles, lyrics or chords of your songs;
- not a single screenshot: the screen-capture scenario is banned by name from the beta bench, because no whitelist of fields protects an image;
- your username, your email address, your avatar;
- your location, your address book, your files;
- any advertising identifier or device identifier.
Legal basis: your consent (Article 6(1)(a) GDPR). Deliberately not legitimate interest: this measurement is in no way necessary to provide the Service, and refusing it changes nothing about what Jam Jam does for you. Purpose: detecting defects specific to each phone model, and nothing else. Retention: a bench report is kept at most 180 days, then deleted. Withdrawal: you can withdraw your consent at any time from the app settings. The effect is immediate. Consent is re-read from storage just before any upload, so a withdrawal made during a run also cancels the upload of that run, and nothing more leaves your phone until you grant it again. To have reports already sent deleted sooner, write to [email protected].
Usage measurement and crash reports
To know which tools actually get used and where the app breaks, Jam Jam records usage events: the mobile app and the web app send them to our own infrastructure, hosted in the European Union (Supabase, EU region). No third-party measurement tool is involved, nothing is sold or shared, and none of it is used to profile you or to target advertising at you.
What gets recorded fits into three closed categories, picked in advance from a list written into the code: the screens you open and the time you spend on them, the actions you trigger (opening a song, starting an analysis, creating an account…), and the technical errors you run into. Each event carries a name taken from that list, the platform, the app version, the interface language and a session identifier. Never any free text: no song title, no lyrics, no chords, no file name, no full address, no search term. The values attached to an event are themselves picked from closed lists or rounded into brackets.
Jam Jam works without an account, so the measurement exists before there is one. It then relies on a random install identifier, generated locally on your device or in your browser, which contains nothing about you. We would rather write this plainly than let you find out later: if you then create an account, the history carried by that identifier is attached to that account. That is what lets us understand the path that leads to a sign-up, and it is also why this data leaves with your account when you delete it.
Once you are signed in, these events are attached to your account. They are therefore part of your data export (Profile → Export my data) and are deleted with your account, including the ones recorded before it existed, for the installs linked to it.
Two pieces of information come from your connection and deserve a precise description. We derive a two-letter country code from your IP address (for example FR), to know where the app is used from: the IP address itself is neither kept nor attached to the events, only the country code is. And because a sending channel open without an account can be flooded, an anti-abuse quota relies on an irreversible fingerprint of the IP address, short-lived, used only to count submissions and never matched against the events.
Retention: the event detail is deleted after 90 days; sessions and the daily activity summary are kept for 400 days, because it takes a full year to know whether people come back. Beyond that, all that remains are anonymous daily totals (numbers, screen names, platforms and versions: no identifier, no account, no install), which we keep with no time limit and which survive the deletion of your account, because they no longer describe anyone.
Legal basis: our legitimate interest (Article 6(1)(f) GDPR) in knowing what is used and what breaks in our own app. That is why the measurement is on by default, and why opting out has to be simple: the Usage statistics switch sits in the mobile app (Privacy screen) and in the web app (Settings → About, help and privacy). It is free, tied to no subscription, available without an account on both sides, and takes effect immediately: nothing further is sent from that moment on, within the current session. Rows already recorded expire on their own schedule; to have them deleted sooner, write to [email protected].
Automatic crash reporting, on the other hand, remains switched off: the app ships without any crash-reporting key, and no crash is ever reported behind your back. The only detailed technical information that reaches us is what you send yourself when you report an anomaly, as described in the section above. This website itself uses no third-party tracker or analytics.
Your public profile
As long as your profile is private, only the people whose request you accepted see what you publish on it. If you make it public, your username, your display name, your picture, your bio and the songs you chose to publish there, with their comments and their number of likes, become visible to any Jam Jam account. Your profile picture stays visible even to a visitor without an account; you can reserve it to your followers in settings. Your profile page also becomes readable on the web without an account, but a visitor who is not signed in does not see the lyrics. Legal basis: your consent (Article 6(1)(a) GDPR), given by the 15 or older box you tick to make your profile public. You can withdraw it at any time by switching back to private, without losing anything else in the app. Those pages carry a header that forbids indexing: they do not appear in search engines.
What you do on the social surfaces is visible within the same limits: who you follow and who follows you, the comments you write under someone else’s song, and your likes. The number of times one of your songs was imported stays private: you are the only one who sees it.
Your declarations and your reports
Two records concern you specifically. Your rights declarations: before a song goes beyond the circle of accounts you accepted, we record the date, the version of the accepted text and the song concerned. They serve to establish our diligence as a host and to handle a takedown request, nothing else; you can read them again, our administrators can too, and they are deleted with your account. Your reports: what you report is read by our administrators in order to decide, and the record of the decision stays 24 months in our moderation log, without the removed content and without the name of the person who reported. We never disclose your identity to the person targeted.
Answering a report
When you report content, you can leave an email address: it is used only to send you the acknowledgement of receipt and the reasoned decision that the European regulation on digital services requires from us (art. 16(4) and (5) of Regulation (EU) 2022/2065). Legal basis: our legal obligation. It is never shown to the person targeted, never used for anything else, and it is erased 6 months after the report. Without an address, the report is handled in exactly the same way, but we cannot answer you.
Diligence log of website reports
The report form on this website records, when you send it, the timestamp, the reason you chose, the address you reported and the language of the page. Neither your name, nor your text, nor your IP address is recorded. That record serves only to prove that we handle reports within a reasonable time, and it is erased after 12 months.
Your rights (GDPR)
You can access, export and delete your data at any time from the app (Profile → Export my data / Delete my account). The export is machine-readable JSON: it is how you exercise your right to data portability (Article 20 GDPR), and (like backing up your whole songbook) it is free, unlimited and outside every usage quota. You also have the right to rectification, restriction and to object, and wherever a processing rests on your consent you may withdraw it at any time, without affecting what was lawfully done before. Deletion is permanent and removes your profile, avatar and account. Requests: [email protected]. If you think we are mishandling your data, you may lodge a complaint with your national supervisory authority: in France, the CNIL. We would rather you told us first, but that right does not depend on us.
Retention
We keep account data while your account exists. When you delete your account, the associated server-side data is removed: songbook backup, profile, avatar, shared songs, reports and settings. Three things outlive the deletion, and we would rather write them down than let you discover them: entries in our administrative action log (which support or moderation action was taken, and on which account identifier) are kept 24 months so that a decision can still be audited, then purged automatically; a message you wrote inside someone else’s report thread stays in that thread so the other person keeps their answer, but it is detached from your account and can no longer be traced back to you; and accounting records of a purchase are kept for 10 years as French commercial law requires. Those are held by Stripe or by the store, not inside the app. Deleting your account also carries away what you had published: public profile, published songs, comments and likes go with it. The audio files in your vault are removed by a clean-up task: their actual erasure takes a few days, not a few seconds, and we would rather write it down.
Children
The Service is not directed to children under 13 (or the minimum age in your country). Do not create an account if you are under that age. Making a profile public requires being 15 or over: below that, French law asks for the agreement of those holding parental authority before an open publication. We ask you to confirm it with a tick box at the moment you make the profile public, and we never ask you for your date of birth.
Soundtracks shared with accounts that follow each other
When you attach an audio file to a song, Jam Jam converts it to a lightweight format (Opus mono, 24 kbps, roughly 0.7 MB for four minutes) and stores it in a private bucket hosted in the EU, so that the song works the same on your phone and in your browser. As long as the song stays in your own songbook, you are the only person who can hear that file. It becomes available to the accounts you follow and who follow you back when you publish the song to your profile, and to nobody else: neither a mere follower nor a visitor without an account can reach it, and no download link is ever generated. A file is capped at 2.5 MB, and each account may store 50 MB in total.
Your rights declaration. Before one of your soundtracks becomes audible to anyone else (when you publish the song, or when you suggest that soundtrack to another account), we ask you to declare that you have the right to share the recording. We keep the date, the version of the text you accepted and the song concerned: without those three, a declaration proves nothing later on. Its purpose is to establish our diligence as a host and to handle takedown requests, nothing else. You can read your own declarations, our administrators can read them, and they are deleted with your account.
Someone who imported one of your songs may suggest a soundtrack for it. Nothing is published until you accept it. Every shared soundtrack can be reported from the app, and we can withdraw it. If you delete your account, a suggestion that was never accepted is deleted with its file; a soundtrack that people already depend on stays in place, but the link to you is severed (it is then shown as coming from “a user”). We warn you before you confirm the deletion. If you want the content itself removed rather than merely unattributed, write to [email protected] and we will handle it through the withdrawal procedure.
Notification log (administrators)
Every notification the Service sends is recorded: sender, recipient, type, channel (push, email, in-app), outcome, and the body of the message. Purpose: diagnosing “I never got it” and detecting abuse: nothing else. Retention: 30 days, then automatic deletion by a scheduled job. It is readable by administrators only, and it is erased in both directions (as sender and as recipient) when an account is deleted.
YouTube addresses
A song may carry a YouTube address. Since 24 August 2026 that address is information only: Jam Jam no longer embeds any YouTube player, loads nothing from YouTube, and sends nothing to YouTube while you use the app. Nothing at all leaves for Google unless you tap the address, at which point your browser opens YouTube as it would for any other link, and Google is the controller: see the Google Privacy Policy.
To play a song inside Jam Jam, you attach an audio file. A copy goes to your own private bucket so the song behaves the same on every device you use, and it becomes audible to your friends only once you publish that song, as explained above.
Changes & contact
We may update this policy; changes appear here with a new date. Questions or requests: [email protected].