← Tornamesa

Privacy Policy

Last updated: August 18, 2026

1. Who we are

Tornamesa is a personal music logging service. You can record albums you listen to, rate and review them, keep a diary, build lists, and optionally share activity with other users.

2. Data we collect

  • Account: email, password (handled by our auth provider), username, and optional profile fields (display name, bio, avatar URL, pronouns, website, country, favorite albums).
  • Activity: listens, ratings, reviews, lists, follows, and monthly listening summaries you generate through the product.
  • Technical: basic request metadata needed to run the service (e.g. approximate IP for rate limiting and abuse prevention).
  • Optional integrations: if you connect Last.fm, we store the link needed to show “now playing” on your profile.

3. How we use data

We use your data to operate Tornamesa: authentication, profiles, diaries, social features you choose to use, spam and abuse protection, and service reliability. We do not sell your personal data.

4. Visibility and privacy controls

You can mark your profile as private, hide your diary, or hide recent activity from your public profile. Private content is not shown to other users through normal product views. Do not post sensitive personal information in bios or reviews.

5. Third parties

  • Hosting / auth / database: infrastructure providers (e.g. Vercel, Supabase) process data to run the app.
  • Music metadata: album titles, artists, and cover art may come from Spotify and related catalog sources. Tornamesa is not affiliated with Spotify.
  • Bot protection: signup may use Cloudflare Turnstile.

6. Retention and deletion

We keep your data while your account is active. You can delete your account from Settings; that removes your profile, listens, reviews, lists, and related social data from our application database. Some backups or logs may persist for a limited time for security and recovery.

7. Security

We use industry-standard practices (encrypted transport, access controls on write APIs, rate limiting). No online service is perfectly secure; use a strong unique password.

8. Children

Tornamesa is not directed at children under 13. If you believe a child has created an account, contact us so we can remove it.

9. Changes

We may update this policy as the product evolves. Material changes will be reflected on this page with a new “Last updated” date.

10. Contact

Questions about privacy: use the contact channel listed on the site or reach the project maintainer via the public repository / community where Tornamesa is shared.