Skip to document
Zene
Home All documents Contact Zene

Review draft — not yet effective

These revised documents are awaiting confirmation of the legal operator, launch territories, source permissions, and implemented privacy and safety controls. They do not certify compliance or replace existing terms until properly finalised and issued.

Revision: September 6, 2026

All legal documents

Contents

  1. 1.Scope and contact
  2. 2.Account information and material you provide
  3. 3.Activity, device information, and approximate location
  4. 4.Purposes and applicable legal grounds
  5. 5.Recipients and service providers
  6. 6.Public information and discovery sources
  7. 7.Advertising, analytics, and privacy choices
  8. 8.Purchase records
  9. 9.Retention and deletion
  10. 10.Security and international handling
  11. 11.Requests, objections, and complaints
  12. 12.Children and young people
  13. 13.Changes to this notice

Privacy Policy

Information handled by Zene, the purposes for which it is used, recipients, storage, and available privacy rights.

1. Scope and contact

This Policy concerns personal information handled in connection with Zene’s website, applications, accounts, discovery services, and communications. It distinguishes information provided by a user, information generated by use, and information received from other services. Third-party websites and applications also have their own privacy notices.

Zene, C-108, Cuffe Parade, Colaba, Mumbai, India – 400005. Email: work@zenemusic.co.

The operator’s full legal identity, applicable registration status, responsible privacy contact, and any legally required representatives must be confirmed before this draft is issued as a final notice. The trading name and contact address are not evidence that Zene is a corporation or that a data-protection officer has been appointed.

2. Account information and material you provide

Account functions handle your email address, display name, username, profile photograph, and authentication-provider identifiers. The profile model also supports an optional telephone number and communication preferences. Sign-in providers may supply the profile fields and authentication assertions authorised by their sign-in flow; Zene does not need the password for your Google or Apple account.

Library features handle playlist names and covers, imported track information, saved items, likes, and listening history. Uploading a selected photograph transmits that file for storage and delivery. Choosing a photograph does not grant permission to use every image in your device library. Imported lists can reveal listening preferences even when the original file is parsed on your device, because matching searches and saved playlist records are sent to the service.

If a community or sharing feature is enabled, the information submitted through it and its audience determine what is disclosed to others. Correspondence, privacy requests, complaints, and supporting information are also personal information when linked to an individual. Avoid sending passwords, payment-card details, identity documents, or unnecessary sensitive information in an ordinary support email.

3. Activity, device information, and approximate location

Zene handles requests for pages and media, search and playback activity, saves and other interactions, and technical information associated with those requests. This can include an IP address, browser or operating-system details, device and installation identifiers, language and country settings, timestamps, and diagnostic events. Playback and page analytics can describe how features are used and whether errors occur.

The web sign-in flow includes an IP-based location lookup through ipwho.is. The response can include an IP address, city, region, country, and coordinates estimated from that IP address; the browser may cache the result and submit location-related account metadata. This is distinct from GPS permission and should not be described as collecting only a country code.

Push-notification registration can associate a device token with your account, platform, device metadata, locale, and delivery or engagement state. Notification providers and the operating system handle delivery. Notification permission can be changed in system settings, and a notification may be visible on a lock screen or shared device.

4. Purposes and applicable legal grounds

Account and session information supports authentication, continuity of access, account settings, and security. Library records and selected activity support saved content, playback continuity, and relevant discovery. Purchase information supports entitlement validation, restoration where available, family access, and billing-related support. Reports and correspondence support assistance, rights requests, abuse review, and dispute handling.

Where the EU or UK GDPR applies, processing genuinely necessary to deliver a requested account or paid feature may rely on contract; proportionate security, fraud prevention, service diagnostics, and ordinary support may rely on legitimate interests, subject to necessity and balancing against individual rights. Records required by law rely on the relevant legal obligation. These grounds do not automatically justify optional advertising or analytics tracking.

Consent is required for optional processing where applicable law requires it, including relevant tracking technologies. It must be specific, informed, freely given, and capable of withdrawal. Reading a policy, signing in, or paying for Premium does not by itself provide all necessary consents. In countries with a different legal framework, the available grounds and rights must be assessed under that framework rather than importing GDPR terminology indiscriminately.

5. Recipients and service providers

Google/Firebase supports authentication, analytics, and push messaging in the relevant builds. Apple supports Apple sign-in and iOS purchases. Google Play supports Android billing. Sentry receives configured error and performance reports. Bunny infrastructure is used for uploaded image storage and delivery. Hosting, database, email, and operational providers may handle information needed for their functions; their locations and contractual roles require a current deployment inventory.

Google advertising products, including AdSense on the website and AdMob in supported app builds, can receive online identifiers, device information, ad events, and information about the context in which an advertisement appears. The specific processing depends on deployment, provider settings, permissions, region, and the choices available to the user. Advertising is not equivalent to a disclosure solely to a processor acting on Zene’s instructions.

Search terms and requested media or image identifiers may be sent to content sources. A direct image request, stream, embedded player, or map can disclose your IP address, browser/device information, and request context to the provider or publisher. Server-side retrieval and direct device requests have different recipients; not every source receives every account field.

Where lawful and necessary, information may be disclosed to professional advisers, authorities, or others to respond to binding legal requirements, address serious safety concerns, or establish and defend legal claims. A business transfer would require safeguards and any notices or choices required by law; it is not permission for an unrelated use inconsistent with those obligations.

  • Google Privacy Policy
  • Apple Privacy Policy
  • Sentry Privacy Policy
  • Bunny Privacy Policy
  • Provider references

6. Public information and discovery sources

Profile and playlist information shared publicly can be seen by other people and may be linked from public pages. A person who receives a link may copy or redistribute it. Review the audience shown by the feature before uploading; if no private audience is offered, do not treat that surface as private.

Entertainment features retrieve information about artists, public figures, concerts, films, and styles from third-party sources. Some information is collected by automated retrieval and cached. Public-source material can still be personal information, inaccurate, sensitive, or subject to copyright. A person affected by an inaccurate or inappropriate listing can request correction or removal and identify the relevant Zene and source URLs.

7. Advertising, analytics, and privacy choices

The website contains Firebase analytics and Google advertising integrations, while supported applications have their own analytics and advertising integrations. Analytics identifiers derived from account details are pseudonymous, not necessarily anonymous. Error reporting and analytics are different processing activities and can have different purposes and retention settings.

This draft does not claim that Zene has verified an absence of sale or sharing under every privacy-law definition, or that a Global Privacy Control signal currently blocks all relevant collection. The terms “sale”, “sharing”, and “targeted advertising” can cover disclosures without a cash payment. Current provider contracts, settings, consent controls, and actual requests must support the final classification.

Use any privacy controls actually displayed by the service or provider, system advertising/tracking settings, and the contact route below. An email request does not itself prevent requests already sent by a device, and clearing cookies does not erase information held on a server. Premium affects the advertised Zene ad experience; it does not mean authentication, diagnostics, or every form of processing stops.

  • Cookies and Device Storage
  • Advertising Privacy Choices

8. Purchase records

For supported store purchases, the store handles the payment instrument. Zene receives or processes the purchase identifiers, verification information, product, entitlement, status, and account associations needed to recognise access. These records are personal information even when they do not contain a complete payment-card number.

A family plan can involve membership and invitation records. The person paying for a plan is not thereby entitled to another member’s private account data. Cancelling store renewal, leaving a family group, and deleting a Zene account are separate actions with separate effects.

9. Retention and deletion

Account, library, and preference records are used while needed to support the account and requested features. The in-app account-deletion process schedules a purge after a fifteen-day cancellation period. A scheduled date does not establish the exact time every database record, uploaded file, processor copy, and backup is erased.

Final retention periods must be set by data category and deployment. Relevant criteria include whether an account is active, whether a record remains necessary for a requested feature, applicable accounting and claims periods, documented safety or fraud needs, contractual provider limits, and a valid preservation obligation. Retention must not become indefinite simply because a backup exists or a future use is possible.

The current implementation does not establish a verified universal backup expiry or complete erasure from all external systems. Zene must confirm processor deletion, uploaded-media cleanup, legacy records, and any retained categories before publishing a complete-erasure guarantee. You may request deletion or an explanation of a retention decision through the contact route.

  • Account and Data Deletion

10. Security and international handling

Account access uses authentication and session controls; production communications and storage require appropriate technical and organisational safeguards. No service can promise absolute security. Zene does not claim independently audited encryption of every data store or end-to-end encryption of all contributions on the basis of this notice.

Providers may process information outside your home country. The final notice must identify relevant processing locations and the legal mechanism used for restricted transfers, where required. A statement that standard contractual clauses exist cannot substitute for executed agreements, a transfer assessment, and any necessary supplementary safeguards. Contact Zene to request information about applicable safeguards.

11. Requests, objections, and complaints

Depending on your location and applicable law, you may have rights to learn what information is processed, obtain access or a copy, correct inaccuracies, request deletion, restrict processing, receive portable information, object to certain uses, withdraw consent, and complain to a regulator. Some jurisdictions provide rights concerning targeted advertising, sale or sharing, sensitive information, and appeals of a refused request.

Send a request to work@zenemusic.co and identify the right you wish to exercise and enough information to locate the relevant account or content. Access or deletion requests may require proportionate identity verification to protect your information; an advertising opt-out should not require unnecessary identity documents or creation of an account. An authorised representative may submit a request subject to applicable authority requirements.

Requests must be handled within the deadlines imposed by the applicable law. Any permitted extension or refusal should be explained, together with available complaint or appeal routes. An ordinary deletion cancellation period does not suspend a statutory response deadline. You should not be penalised for exercising a protected privacy right. Withdrawal does not retrospectively invalidate processing that was lawful before withdrawal.

12. Children and young people

The proposed service minimum is thirteen, subject to higher local thresholds and required parental authorisation. Names and email addresses are personal information even when received through Google or Apple, and Zene also processes the activity, device, location, and other categories described above. No verified parental-consent programme is established by this notice. Store ratings or an account statement do not replace duties arising from the actual audience or knowledge of a child’s use.

If a child has supplied personal information or is at risk through Zene, contact work@zenemusic.co with a safe description and relevant account or content identifiers. Do not attach abusive material or unnecessary identity records. Child-safety reports and privacy requests must be handled through appropriate procedures, including restrictions, deletion, preservation, or authority reporting where the circumstances and law require.

  • Child Safety Standards

13. Changes to this notice

When processing materially changes, the notice and collection-time disclosures must change accordingly. New purposes may require fresh consent or another valid legal basis before use begins. The revision date records the drafting revision; final publication and any effective date must be supported by confirmed practices and appropriate user notice.

All legal documents Back to document title

Correspondence and requests

For account, privacy, copyright, or safety matters, identify the relevant document or item and the action requested. Do not send passwords or unlawful material.

Zene
C-108, Cuffe Parade, Colaba, Mumbai, India – 400005
work@zenemusic.co

Statutory rights remain unaffected. The revision date is not an acceptance or effective date.