Who is responsible
Shared Noise Ltd, of Saxon House, Main Street, Southwick, Peterborough, PE8 5BL, United Kingdom, operates Shared Noise and is the controller of personal information used to run it. For privacy questions or requests, contact sharednoise@tmlabs.co.uk. This notice covers the invitation-only private beta for people aged 18 or over who live in the United Kingdom. It explains our own processing; Apple, Google and other services also give their own privacy notices for their services.
Account and profile information
Google or Apple sign-in and Firebase Authentication supply and manage your account identifier, sign-in details and associated profile information, which may include your name, email address and profile image. Shared Noise uses a stable account identifier to associate your data and social interactions with you. You may upload a profile image. Apple sign-in lets you choose a private relay email address and does not supply a profile image. We do not receive your Google or Apple password or your Apple Music payment details.
Your library, activity and contributions
We store albums you save or archive, crate names and contents, favourites, track selections, ratings and written reviews. We record listening progress, track and album play events, session position, and discovery interactions such as albums shown or dismissed and social cards you dismiss. We store photos, bursts, videos and voice notes that you upload, associated album and playback information, share recipients and notes, follows, likes and feed comments. Blocks record the two account identifiers and when the block was made. Reports record the reporter, reported account, identified content, reason, any details you provide, and the review outcome. Direct and group messaging stores conversation identifiers and names, participant identifiers, invitations and roles, message text and content references, private photos and voice notes, timestamps, send-retry identifiers and read positions. Optional AI testing stores its enable/pause setting, generated profiles and contributions, reply jobs, error status, daily request counts and cached voice transcripts linked to their source messages.
Device data, local storage and service logs
The app keeps local library and playback caches, pending uploads, saved media and account-specific unsent messages and their attachments to support its interface and offline behaviour. Delivered messages are stored on the API server. The app keeps the currently displayed conversation in memory and verifies access when loading it. Unsent messages and attachments are saved on the device for retry and removed from that outbox after delivery or discard. Hosting and service logs can include network addresses, request paths, timestamps, account identifiers, status codes and diagnostic information. Apple may supply TestFlight feedback and diagnostics under its own testing arrangements. This build does not integrate a dedicated third-party crash-reporting or advertising analytics service.
Why we use information and our legal bases
We use account details to sign you in and maintain your account, library and listening data to supply the features you request, and contribution and recipient information to publish your chosen contributions and deliver record shares and private messages. Our legal basis for these uses is performance of our agreement with you. We rely on legitimate interests to operate the shared community, including making activity visible to other members; diagnose failures and secure the service using limited operational logs; and protect users and handle abuse using blocks and reports. We also rely on our legitimate interest in useful music discovery to organise recommendations using your musical interactions. You can object to these uses as explained below. We may process information where necessary to comply with a specific legal obligation. Where a use requires consent, we will explain it and obtain consent separately before that use. We do not seek to infer health, religion, political views or other sensitive characteristics from your music choices. Sign-in information is needed to provide an account; you can choose whether to contribute reviews, recordings or other content. For the optional AI test community, we ask the enabling tester to agree to the described processing before activation. They can withdraw that choice by pausing the feature in Messages; this stops future model requests but does not undo processing already completed. Existing generated contributions can remain until removed or the associated account is deleted.
What is visible to other people
This beta has broad community visibility. Other signed-in users can view profiles, collections, reviews, moments and listening activity even without following you. Likes and feed comments identify their authors. New record shares deliver a private message and a recipient shelf record. Their notes and voice attachments require conversation access and do not appear in the global feed. Older public shares can still appear there with their recipient and written note. A received shelf record remains after its message is deleted or conversation access ends; the private note and source context no longer remain accessible through that delivery. Reviews and moments forwarded into a conversation retain their original public visibility. Public contribution photos, video, voice and avatar files are served at unguessable URLs without a sign-in check. Anyone who receives such a link may access or forward it. Blocks hide account-based interactions in both directions and prevent new record shares, but cannot revoke an existing media link or remove independent copies. Do not upload confidential information or sensitive information about yourself or others. Direct and group conversations are accessible only to authorised participants through the app, and to the operator where needed to administer the service or handle a report. They are not end-to-end encrypted. Private message attachment downloads require sign-in and current access checks. Blocks prevent direct messages and hide the two accounts’ messages from each other in shared groups; group membership remains visible. New or returning members see messages sent after joining. Leaving or removal revokes server access to conversation history, but does not remove independent copies already saved by a participant.
Device permissions and your choices
Camera and microphone access are used when you choose to capture moments or voice notes. Music access enables the Apple Music features you request; playback availability depends on Apple. Notifications support app reminders where enabled. The settings interface can also request contacts permission, but the beta does not upload your address book. The app does not request tracking permission or collect an advertising identifier. Granting an operating-system permission does not mean every related use is taking place, nor is it blanket consent to future processing. You can decline or change permissions in iOS Settings, although related features may not work. Device storage permissions and music-provider data remain subject to the platform’s controls.
Providers and other recipients
Google/Firebase provides authentication; Fly.io hosts the API, database and uploaded media. Uploaded media is stored on the API’s volume, not Firebase Storage. Apple supplies Apple Music playback, music metadata and TestFlight distribution. Music catalogue services, including Spotify, MusicBrainz, Discogs, Last.fm and iTunes, may receive catalogue queries; externally hosted artwork and preview services receive network requests when your device loads their content. We may also receive catalogue material generated using external AI services; this is distinct from sending your personal posts for AI processing. For an enabled AI test community, OpenAI receives the enabling tester’s selected public review text and a limited window of text and display names from dedicated AI conversations, plus catalogue titles and artists. For voice replies, OpenAI also receives the enabling tester’s voice recording from a dedicated AI conversation for transcription. The reply model receives the resulting transcript. Recordings are limited to three minutes and 5 MB, with up to four transcription attempts per day within the shared daily request allowance. Uploaded photos, authentication credentials and ordinary human conversations are not sent to the model. Photo moments created by test accounts reuse copies of the founder’s existing still photos, stored on our own service. We request that responses are not stored as retrievable API responses. OpenAI states that API content is not used for model training by default; abuse-monitoring content may generally be retained for up to 30 days, with longer retention for legal or safety needs, and model prompt caching can retain processing state for up to 24 hours. This is not a zero-retention service. We do not sell personal information or use it for targeted advertising in this beta. We may disclose information if required by law, to protect people or legal rights, or to professional advisers acting under confidentiality obligations.
Where processing happens
Our API, database and uploaded media use a Fly.io volume in London. Firebase Authentication processes account information in the United States. Hosting support, operational services and other providers may also process information outside the UK. Google and Fly.io publish commitments under the EU–US Data Privacy Framework and its UK Extension for covered transfers to the United States. Those arrangements apply only to transfers within their scope; London hosting does not mean all processing stays in the UK. You can request information about the safeguards applicable to your data and a copy of relevant contractual safeguards by contacting sharednoise@tmlabs.co.uk. Provider information is available at firebase.google.com/support/privacy and fly.io/legal/data-privacy-framework/. Optional AI processing uses OpenAI’s API and is not configured for UK-only data residency. It can involve processing outside the UK. Ask sharednoise@tmlabs.co.uk about the applicable provider arrangements and transfer safeguards.
Retention and account deletion
We keep account, library and contributed information while you maintain an account and need the associated features. Supported items can be removed in the app. Reports and their outcomes currently remain until the related account is deleted or the operator removes them; closing a report does not automatically erase it. Unattached public uploads remain until account deletion or operator cleanup. Private message uploads that remain unattached for seven days are queued for deletion. Delivered private messages remain until deleted by their sender, by an authorised group administrator, or through account deletion. There is no other automatic age-based expiry for these records.
Account deletion in Settings removes your active profile, library, listening records, reviews, moments, shares, messages you sent, conversation memberships, owned AI test accounts and their contributions, follows, blocks and associated reports/reactions, and initiates deletion of your Firebase sign-in account and attributable uploaded files. If file or provider cleanup fails, access stays closed and cleanup is retried. We retain the deleted account identifier, deletion timestamps and completion receipt to prevent the old identity regaining access and track cleanup; these records have no automatic expiry.
Fly volume snapshots are configured for five-day retention. Fly currently retains searchable application logs for seven days. These periods do not cover separately retained diagnostic files, manually exported copies or historical application backups. Legacy application backups, where present, keep the latest 14 copies rather than expiring after a fixed number of days. Such copies are not individually edited by account deletion. Google states that Firebase Authentication removes associated authentication data from its live and backup systems within 180 days after deletion is initiated, and retains logged IP addresses for a few weeks.
Local app data is cleared on the device where you complete deletion. Other devices, recipients and device backups may retain independent copies. We assess any additional retention by whether it is needed for an unresolved safety or security incident, a data-recovery task or a specific legal obligation, taking account of the sensitivity of the information and whether less information would suffice. Information kept solely for a legal requirement is restricted to that purpose. Removing a private message queues its attachment for file deletion and removes its cached voice transcript. Other participants’ messages can remain in their conversation after you delete your account. OpenAI’s own retention periods apply to content already processed by that provider.
Your right to object
You can object to our use of your information based on legitimate interests, including community-wide activity visibility and recommendation personalisation. Send your request to sharednoise@tmlabs.co.uk and tell us which use concerns you and, where relevant, your circumstances. We will assess the request and stop that processing unless we can demonstrate overriding compelling legitimate grounds or need it for legal claims. We will explain the outcome and available ways to challenge it. This beta does not use your information for direct marketing.
Your rights and how to exercise them
Depending on the applicable law and processing basis, you may ask for access, correction, erasure, restriction or a portable copy of your personal information. Where we rely on consent, you can withdraw it without affecting earlier lawful processing. Contact sharednoise@tmlabs.co.uk; we may need proportionate information to verify your identity. Automatic export in Settings is not yet available, so requests are handled through that contact. We will respond within applicable legal time limits and explain any lawful exception. You may complain to the UK Information Commissioner at ico.org.uk/make-a-complaint or to your local supervisory authority. Contacting us first is helpful but is not a condition of complaining.
Recommendations and children
Discovery and listening features use your musical interactions to order or suggest catalogue content. We do not use these features to make solely automated decisions with legal or similarly significant effects on you. The private beta is for people aged 18 or over and uses an age confirmation at entry, rather than collecting a date of birth or identity document. Do not register or post information about a child. If you believe an under-18 account is using the service, report it in the app or contact sharednoise@tmlabs.co.uk so we can investigate and remove the account where appropriate.
Updates and contacting us
We will update this notice when our practices change and make the updated version available in the app and on the published policy page. We will draw significant changes to your attention where required. Changes to messaging or AI processing, crash reporting, new analytics or new recipients must be assessed and disclosed before release. Privacy contact: sharednoise@tmlabs.co.uk. General support and safety contact: sharednoise@tmlabs.co.uk. Postal contact: Saxon House, Main Street, Southwick, Peterborough, PE8 5BL.