Privacy Policy

Last updated: 2026-09-05

  1. Introduction
  2. Data Controller
  3. What Data We Collect
  4. How We Use Your Data
  5. Cookies
  6. Data Sharing
  7. Your Rights Under GDPR
  8. Data Retention
  9. Data Security
  10. International Data Transfers
  11. Changes to This Policy
  12. Contact Us

1. Introduction

KaraokeCrowd ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard personal information when you use our website karaokecrowd.com or our mobile apps — and how we handle publicly available information that appears in our karaoke directory (see Section 3.4).

In short:

  • We collect what's needed to run a community karaoke directory: your account details, your contributions, and basic technical data.
  • We don't sell your data and we don't do cross-site ad tracking.
  • Most processing stays in the EU; the few exceptions are listed in Sections 6 and 10.
  • You can also appear in the directory without an account — as a listed host, or in a photo. Section 3.4 explains what we do and how to object.
  • Questions or requests? Email us (Section 12). That always works.

2. Data Controller

Makerprism UG (haftungsbeschränkt)
Halbergstr. 4
66121 Saarbrücken, Germany
Email: support@karaokecrowd.com

3. What Data We Collect

3.1 Analytics Data

We use Google Analytics 4 to collect aggregated usage data. For visitors in the EU, EEA, Switzerland, and the UK, analytics is off until you consent. For visitors elsewhere, analytics is on by default unless you opt out with the cookie controls below.

  • Pages you visit and features you use
  • Time spent on pages
  • Approximate location (country/city level)
  • Device type, browser, and screen size

Legal basis for EU/EEA, Swiss, and UK visitors: your explicit consent (GDPR Art. 6(1)(a)).

3.2 Contributor Data

Website and chat contributions require sign-in. You can also send venue details, events, corrections or flyers by email. We store:

  • Contributions filed through the site, linked to the account that filed them
  • Email correspondence, including your sender address, so we can respond and ask follow-up questions. If a directory moderator enters your information, the contribution records that it came by email; your sender address is not published
  • Chat-assistant conversations while you work on a contribution; they expire 48 hours after your last activity (see Section 8)
  • If you report a chat problem, a debug copy of that conversation is attached to your problem report and kept with it after the 48-hour chat expiry
  • Text files you attach to the chat assistant (treated like listing text) and flyers you upload (processed only to extract listing facts)
  • Problem reports you file, linked to your account as part of the moderation history

Contributions are publicly visible on the venue/event activity feed. Whether your username is shown depends on your profile visibility setting (see Section 7.1). Guides and directory moderators who are allowed to review the report can identify your account. Legal basis: legitimate interest in maintaining data accuracy, preventing abuse, and attributing contributions (GDPR Art. 6(1)(f)).

3.3 Account Data (When You Sign Up)

If you create an account (via Google sign-in or magic-link email), we store the following:

  • Email address (and, if you sign in with Google, your Google account identifier)
  • If you add a password, a one-way password verifier. We never store the password itself. We store only a hash of a password-reset token; it is valid for 30 minutes and removed by daily cleanup
  • Profile fields you set: username, display name, bio, avatar, public links, language preference
  • Social-graph state within KaraokeCrowd (not from your Google profile): friendships, venues and hosts you follow, saved locations
  • Activity: RSVPs, submitted contributions, technical events while you fill in a submission (to help us fix broken forms), login times, the time when you confirmed you are 18 or older, and the time when you accepted the Terms of Use
  • Images you upload (avatars, venue or event photos). Uploaded photos are re-encoded shortly after upload, which removes hidden metadata such as GPS coordinates (EXIF) from the images we display
  • Content you post for other singers: Memories, photos, replies, compliments, and song lists. Memories, their replies, and Memory photos are visible only to signed-in members; other content may be public depending on the feature
  • A mobile push token for your phone, if you turn on app notifications. We delete it after you sign out on that phone, when it stops working, or when you delete your account
  • Email subscription choices and their consent records (double opt-in); every optional email includes an unsubscribe link. You can also subscribe to event digests without an account; then we store only your email address, language, and chosen area

3.4 Public Listing Data (Venues, Events, Hosts)

Our directory describes karaoke venues, events, and hosts. This section is mainly for people who appear in the directory without ever signing up — for example because you host karaoke nights.

  • Where the information comes from: the person or business themselves, community contributions, or publicly available sources such as venue websites and public social-media announcements. When a host or venue announces a karaoke event publicly (for example in a public Facebook group), we may keep a copy of the announcement — the text, any flyer image, a link to the source, and the advertising host's or venue's name — as evidence for the listing. We do our best not to keep the names of other people, such as group members commenting on a post; if your name still appears in stored evidence and you want it removed, email us and we will redact it. We may use automated tools, including AI services, to find and sort such public announcements; a person reviews them before they become listings.
  • What we publish: only information that is relevant to finding and attending karaoke — such as a host's stage name, links to public social-media profiles, and the business contact details shown on a host page.
  • Invitations: if we have verified that you run a venue or host shows, we may store your business email address and send you a one-time invitation to take over your listing, even if you have no account. You can simply ignore it; tell us if you don't want to be contacted again.
  • Photos: photos posted by other singers may show you. If you appear in a photo on KaraokeCrowd and want it taken down, email us — we remove such photos on request.
  • What you can do: claim and manage your listing, ask us to correct it, ask us to redact your name from stored evidence, or object to appearing in the directory at all (see Sections 7 and 12).
  • Your account and your host listing are separate things: a host listing is a directory record, not part of your account. Deleting your KaraokeCrowd account removes the account and your account's control of the listing; the listing itself stays in the directory, including the host name shown on it, which is often a real person's name or stage name, along with any contact details published on that page — such as a phone number, a contact email address, or links to public profiles — and the profile photo and banner image, even where you uploaded them yourself. Deleting your account is not a way to take a host page down — we cannot remove it as part of that request, even if you are the only person managing it. To ask us to take a host page down, or to remove personal details from one, email support@karaokecrowd.com — we work that mailbox and a person handles it by hand, so it is a request we answer, not something that happens automatically; this is the same route open to anyone listed in the directory. Your formal data-protection rights, including your right to object, are in Section 7.

Legal basis: legitimate interest in running a public directory of karaoke events (GDPR Art. 6(1)(f)). If you object, we stop unless we have compelling legitimate grounds.

3.5 Technical Data and Logs

Like every website, we process your IP address and basic browser and device information to deliver pages, keep sign-ins secure, prevent abuse (for example, through rate limiting), and diagnose errors. Sign-in session records include the IP address and browser used. We look up the country of your IP address (on our own servers or via our CDN) to apply the correct analytics-consent default for your region and similar region-level defaults. Error reports contain technical context about what went wrong, with sensitive details such as email addresses redacted. Legal basis: legitimate interest in operating the service securely (GDPR Art. 6(1)(f)).

3.6 Location Data

"Near me" features use your device location only after you allow it in your browser or phone. We use those coordinates to find karaoke around you. The mobile Check In feature compares your device location with show candidates on your phone; it does not transmit device coordinates with your show confirmation. Saved locations can be a city or area. If you explicitly save a private map pin, we store its coordinates rounded to three decimal places and send that rounded point to our geocoding providers to generate its place name. The pin remains private to your account. Venue and host locations shown on our maps are business addresses, not data about you. Legal basis for precise device-location processing by server-backed "near me" search: your consent through the browser or phone permission (GDPR Art. 6(1)(a)). Legal basis for a private map pin: performing the saved-location feature you request (GDPR Art. 6(1)(b)). You can refuse or revoke location permission at any time and remove a saved pin in your settings.

4. How We Use Your Data

  • Provide the product: accounts, contributions, RSVPs, follows, Memories, and notifications
  • Send sign-in links, service messages, and the emails you have opted into
  • Improve website usability and features
  • Understand which content is most useful
  • Verify and attribute community contributions
  • Keep the platform safe: moderation, abuse prevention, and error diagnosis

Legal bases: performing our contract with you for account features (GDPR Art. 6(1)(b)), your consent for analytics and optional emails (Art. 6(1)(a)), and our legitimate interests in accurate listings, security, and improving the service (Art. 6(1)(f)).

We do not make decisions about you based solely on automated processing that would have legal or similarly significant effects on you (GDPR Art. 22).

5. Cookies

We use cookies for keeping signed-in users logged in and optional analytics. We also use local storage for display and interface preferences, sign-in status hints, analytics consent, and short-lived draft and chat recovery. We do not use cookies or local storage for cross-site tracking or targeted advertising. Where cookies or local storage are not strictly necessary for a feature you asked for, we ask for your consent first (§ 25 TDDDG, GDPR Art. 6(1)(a)).

Cookie Purpose Required? Duration Control
kc_session Keeps you signed in Yes, if you sign in 30 days Sign out to end the session
_ga, _ga_<measurement-id> Google Analytics usage statistics No Cookies: up to 2 years; analytics data: up to 14 months Use the controls below to accept or decline analytics

If you are in the EU, EEA, Switzerland, or the UK, analytics stays off unless you accept it. In other regions, analytics may be on by default, but you can turn it off here at any time.

Manage Cookie Preferences

Current choice:

6. Data Sharing

We use the following processors. We do not sell or rent personal data and we do not share personal data with advertisers.

  • Google Analytics 4: aggregated usage statistics, consent-gated for EU/EEA, Swiss, and UK visitors and default-on elsewhere unless you opt out. Google Sign-In (when you choose it) returns your email and name so we can create your account.
  • Google Maps Platform: the map in the Android app loads map content directly from Google. Google receives your IP address; request metadata such as OS version, device name, model, brand and form factor, Maps SDK version, result counts and an internal usage-attribution identifier; Maps SDK stack traces and crash metrics; and a Maps-specific pseudonymous identifier. The SDK may also collect map interactions such as panning and zooming. If you choose to use your device location, the map area shown can reflect that location.
  • Amazon SES (AWS, Frankfurt): sends sign-in emails, account notifications, and digest emails you've opted into.
  • Expo Push Service: delivers mobile push notifications to devices where you have enabled app notifications.
  • Mobile platform push services (Google FCM or Apple APNs, depending on your device): complete delivery of app notifications sent through Expo.
  • Cloudflare: runs the content delivery network in front of our site (which processes request data such as IP addresses) and provides R2 object storage for uploaded images and encrypted database backups.
  • AWS Rekognition (Frankfurt): automated moderation of uploaded images.
  • Geocoding providers (LocationIQ, with HERE and geocode.xyz as fallback): turn addresses or place names into map coordinates and back — including your device coordinates when you use "near me" search and a rounded private-map-pin point when you ask us to save one.
  • OpenStreetMap (OpenStreetMap Foundation): maps on venue pages load directly from OpenStreetMap servers, which receive your IP address and the map section you view.
  • LLM provider for the chat assistant (currently xAI/Grok, USA; we may switch to another provider such as OpenAI or Anthropic): processes chat-assistant messages, attached text file contents, uploaded flyer images, and the listing details under discussion, so the assistant can draft contribution details. See our AI transparency page for the full picture.
  • AI classification (currently xAI/Grok, USA): sorts public social-media announcements by whether they contain karaoke information before a person reviews them (see Section 3.4).

7. Your Rights Under GDPR

Under the EU General Data Protection Regulation (GDPR), you have the following rights. We honor them for everyone who uses KaraokeCrowd, wherever you are:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Delete your account in the KaraokeCrowd app, or at /en/delete-account. After you sign in again and confirm, the account is closed at once: you are signed out everywhere, it can no longer be used to sign in, and your profile and Memories stop being visible. The personal data behind the closed account is kept for 21 days, and erasing it begins after that. We email the account address as soon as a deletion is confirmed, to say the account has been deleted and when its data will be erased. Those 21 days exist so that an account deleted by somebody who was not its owner can be given back: if a person who is not you gets into your account and deletes it, you have three weeks to notice, write to support@karaokecrowd.com and ask us to restore it. We check who owns the account before restoring anything, and we cannot promise a restore in every case. This is not a waiting period you can use from the app or the website: there is nothing to cancel, no link that undoes the deletion, and the account stays closed the whole time. Separately, you can see every image you uploaded and delete it everywhere it is used, including editable public listings. Images retained for moderation, claim evidence, or as the current curated city banner must be handled by our team. Deleting an image removes it from the site but leaves the listing or other item; cached copies such as link previews can take a little longer to disappear. You can also email support@karaokecrowd.com to exercise this or another privacy right. We complete erasure within 30 days of your request. Deleting an account does not remove a host listing about you from the public directory, including the contact details and images published on it. See Section 3.4 for how to ask us separately to take down a host page or remove personal details from it.
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to our processing of your data — in particular to appearing in the directory or to any processing we base on legitimate interest. We then stop unless we have compelling legitimate grounds
  • Right to Withdraw Consent: Withdraw analytics consent anytime from the cookie controls
  • Right to Lodge a Complaint: Complain to a data-protection supervisory authority — for us that is the Unabhängiges Datenschutzzentrum Saarland; you can also contact the authority where you live

To exercise any of these rights, contact us at support@karaokecrowd.com

7.1 Privacy Controls in the Product

If you have an account, you can manage profile visibility, default RSVP visibility, friend-suggestion participation, and active sessions at /settings/preferences. Email subscriptions and location notification cadence are at /settings/notifications.

8. Data Retention

Changes on 28 July, 24 August and 1 September 2026: We added the 365-day deletion rule below for listings we could not verify, clarified the 30-day notification-history period, and documented self-service deletion of uploaded images from editable listings. This does not shorten retention for genuine listings that ended or are paused. Change on 30 August 2026: Account deletion now happens in the app as well as on the website, and confirming it closes the account immediately. The data behind the closed account is then kept for 21 days before erasing it begins, so that an account deleted by somebody other than its owner can still be recovered; we email the account address at the moment of deletion so that the owner finds out. The 30-day limit below still runs from your request, not from the end of those 21 days.

Change on 27 August 2026: We introduced self-service account deletion, a seven-day maximum for application backups, and the limited restore-safety record described below.

Changes on 28 July and 24 August 2026: We added the 365-day deletion rule below for listings we could not verify, then clarified the 30-day notification-history period. This does not shorten retention for genuine listings that ended or are paused.

Two kinds of information sit behind these entries, and deleting an account treats them differently. Account data is personal to you as a member: your email address, name, username, profile, RSVPs, friendships and follows, saved locations, push tokens, and your Memories. A confirmed deletion request automatically removes it. Directory data is what the directory says about karaoke in the world: venues, events, and host listings contributed to a public record other people rely on. It does not disappear because the person who contributed it closed their account. A host listing is directory data, so deleting an account is not a way to take a host page down. Section 3.4 has the separate route for that.

  • Account data: kept for the lifetime of your account. Confirming deletion closes the account straight away; this data is then kept for a further 21 days, after which erasing it from active systems begins, and the whole process completes within 30 days of your request. The 21 days are a recovery window for an account deleted without its owner's consent (see Section 7), not a period in which the account still works. When erasing finishes we email you once to say so, and then delete your email address; that mail is the last thing we send you. There is no page that reports the status. Backups made before erasure remain for no more than seven days. A separate minimal receipt makes sure a restored backup cannot bring the account back. We store this receipt as plaintext. It contains only random request and account identifiers, the request time, and how the request reached us. It contains no email address, profile data, copy of the account, or encrypted account envelope. We remove a completed receipt after both retention periods have elapsed: 38 days after the request and eight days after completion. An unfinished request is kept until erasure completes
  • Host listings: kept as part of the public directory, independently of any account, and not removed by an account-deletion request. Deleting an account removes that account's control of a listing, not the listing itself: the host page stays published, including the host name shown on it, which is often a real person's name or stage name, along with any contact details published on that page — such as a phone number, a contact email address, or links to public profiles — and the profile photo and banner image, even where you uploaded them yourself. To ask us to take a host page down, or to remove personal details from one, email support@karaokecrowd.com — we work that mailbox and a person handles the request by hand (see Section 3.4)
  • Notification records and in-app history: kept for up to 30 days after creation. A delivery-only record can remain longer while delivery is still pending
  • Contributions and venue/event history: normally kept indefinitely as part of the public record. One exception applies when we remove a listing because we could not verify it: after 365 days, the listing and its related contributions, review history, evidence, and linked records are eligible for deletion. If a Memory must remain attached, we keep that listing graph with it. Listings that genuinely ended or are paused stay in history. The public attribution to you is removed or anonymized when your account is deleted; your name, or the email address used for a contribution without an account, can also be redacted earlier on request
  • Optional outcome email for a contribution made without an account: removed at the earlier of 30 days after every contribution from the same submission has a final outcome and we have attempted its outcome email, or 12 months after you supplied the address. We remove it sooner if you make a valid erasure request. The contribution stays with generic public credit and no email address
  • Listing evidence (for example a copy of a public announcement): kept while the listing needs it; personal details in it are redacted on request
  • Chat-assistant conversations (including attached text file contents): expire 48 hours after your last activity; raw flyer images uploaded to the chat assistant are not stored by KaraokeCrowd after extraction. If you report a chat problem, the debug copy attached to that report is kept with the report instead
  • Sign-in sessions: browser sessions last 30 days; mobile app sessions last until revoked or for one year after the last token refresh. Expired sessions are removed by daily cleanup, and revoked session records are removed after 30 days. Magic-link tokens: 15 minutes; password-reset token hashes: valid for 30 minutes and removed by daily cleanup; password verifier: until you remove it or delete your account
  • Mobile push tokens: until you sign out on that phone, the token stops working, or you delete your account
  • Email subscriptions: until you unsubscribe; consent records are kept as long as we need to prove the subscription was real
  • Email delivery protection: if an email permanently bounces or is reported as unwanted, we keep a protected identifier for the address and limited delivery details so we can stop sending to it and protect our email service. We use legitimate interests for this. Delivery-event records are kept for up to 12 months; the protected suppression identifier is kept until the block is corrected or no longer needed. If you think an address was blocked by mistake, contact us
  • Claim invitations: the invitation record is kept until it is accepted, revoked, or expired, plus a short audit trail
  • Application backups: kept for no more than seven days. If we restore one, we apply every still-live deletion receipt again before reopening the service
  • Analytics data: up to 14 months
  • Technical audit and error logs: up to 12 months. The contribution review history (submissions, review decisions, problem reports) is part of the public record and is kept like contributions (see above); your name can be redacted from it on request
  • Uploaded images: kept only while needed for the service. You can see every image you uploaded and delete it everywhere it is used, including editable venue, karaoke night, event, and Host listings. The listing or other item stays. Images retained for moderation, claim evidence, or as the current curated city banner must be handled by our team. Cached copies such as link previews can take a little longer to disappear Deleting your account erases the images you uploaded, except an avatar or banner that belongs to an unchanged public host listing. Section 3.4 explains how to request removal of a host image or other personal detail separately

9. Data Security

We apply appropriate technical and organizational measures to protect personal data, in line with GDPR Art. 32. In plain terms: connections are encrypted (HTTPS), backup storage is protected by technical and access controls, and access to production data is restricted to authorized personnel of the controller plus the processors listed in Section 6.

10. International Data Transfers

Most processing happens in the EU: our database, image storage, backups, email sending, image moderation, and error monitoring run in Frankfurt or other EU regions. Some recipients process data outside the EU/EEA: Google (Analytics, Sign-In, and Maps Platform), geocoding providers, mobile push-notification delivery (Expo, Google FCM, Apple APNs), the chat-assistant LLM including the reading of uploaded flyer images (currently xAI/Grok, USA), and the AI model that sorts public announcements by whether they contain karaoke information (also USA). For these transfers we rely on EU standard contractual clauses agreed with the provider, or on the provider's certification under the EU-US Data Privacy Framework where one exists (for example Google, AWS, and Cloudflare). Both are safeguards the EU recognizes for sending personal data to other countries; you can ask us for a copy.

11. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top indicates when changes were made. If we make material changes, we will point them out on the website.

12. Contact Us

For any questions about this Privacy Policy or to exercise your rights, contact us:

Email: support@karaokecrowd.com