Privacy Policy
This policy describes what WaveSphere collects, why, and how you can control it. It is written for this product as it actually works—not a generic template.
1. Summary
- Most listening preferences stay in your browser (local storage / similar).
- Admin and backend features use Google Firebase (Auth, Firestore, and optionally Messaging) when configured.
- Third-party radio directories and stream servers receive requests when you browse or play stations.
- We do not sell personal data.
2. Information stored in your browser
Typical client-side data includes:
- Favorites and recently played station identifiers
- Volume, mute, theme (light/dark), era/style preference
- Optional API keys you paste yourself (e.g. OpenRouter) for optional AI features—these stay local unless you clear storage
- UI state such as collapsed panels
Clearing site data in your browser removes this. WaveSphere cannot “see” these values on our servers unless a feature explicitly syncs them (current public player primarily keeps them local).
3. Analytics and logs
If analytics (e.g. Firebase Analytics / Measurement ID) is enabled in the project configuration, aggregate usage events may be collected. Server or CDN logs (Netlify or similar) may record IP address, user agent, referrer, and request paths for security, abuse prevention, and reliability.
We do not invent public “listener counts” for marketing. Any internal play counters used in the admin dashboard (e.g. total plays document) are operational metrics, not a promise of real-time global audience size.
4. Accounts and admin
Admin login uses Firebase Authentication (email/password when enabled). Only authorized accounts should access the dashboard. Feedback submissions and announcement documents are stored in Firestore when those features are active.
If you create or are given an admin account, you are responsible for keeping credentials secure.
5. Push / messaging
If Firebase Cloud Messaging is configured, notification permission is requested in the browser. Tokens and notification content are handled according to Firebase and the admin “push” documents you publish. You can deny or revoke notification permission at any time in browser settings.
6. Third-party services
- Radio directory APIs (e.g. radio-browser style endpoints): station lists and metadata.
- Station stream servers: audio is requested from the station’s URL; those operators have their own policies.
- Firebase / Google: auth, database, optional analytics and messaging.
- Fonts / CDNs: e.g. Fontshare, Google Fonts, gstatic Firebase scripts.
- Optional AI: if you supply an OpenRouter (or similar) key, requests go to that provider under your key.
- Proxy helpers: Netlify functions or CORS proxies may be used for stream metadata (ICY) when available.
WaveSphere does not control third-party privacy practices. Review their policies if you need detail.
7. Cookies
Essential and preference storage is primarily localStorage rather than tracking cookies. Third-party scripts (Firebase, fonts, analytics if enabled) may set their own cookies or identifiers according to their documentation.
8. Data retention
- Browser storage: until you clear it or uninstall data for the site.
- Firestore documents (feedback, announcements, maintenance flags, optional analytics counters): retained until deleted by an admin or project cleanup.
- CDN/server logs: typically short-term, subject to host defaults.
9. Deletion and access requests
For browser data: use your browser’s clear-site-data tools.
For feedback or account-related records stored in Firebase, contact the project via the channels listed on the About page and identify the relevant email or submission details. We will process reasonable requests consistent with technical ability and legal obligations.
10. Children
WaveSphere is a general audience radio player. It is not directed at children under 13 (or the equivalent age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has submitted data through feedback or admin systems, contact us to request deletion.
11. International users
Infrastructure may be located in multiple regions (e.g. Netlify, Google Cloud). By using the service you understand data may be processed outside your country, subject to the safeguards of those providers.
12. Changes
We may update this policy as features change. The “Last updated” date will be revised. Continued use after changes constitutes acceptance of the updated policy for the public product.
13. Contact
Privacy questions: use the contact path described on the About page, or the in-app feedback form for product-related notes.