privacy policy
Effective: May 2026 · This is a beta-stage policy and will be updated as dawdle launches publicly.
The short version: dawdle stores only what we need to make the chat work. Your handle, profile, friends, messages, samples, and which Spotify artist you've claimed. We don't sell or share your data with advertisers. We don't run ads. We use industry-standard providers (Supabase, Cloudflare) to host the service.
1. who runs dawdle
dawdle is operated as an independent project. Contact: hello@daw-dle.com. Once a legal entity is registered, this section will list the company name and address.
2. what we collect
account data
- email address (used for sign-in and password reset)
- chosen handle, display name, and profile fields you fill in (bio, status line, city, links)
- password (stored as a salted hash by our auth provider; we never see the plaintext)
activity data
- messages you send (in global, club, room, and DM channels)
- samples you upload to your beat pad
- profile sound, photo, and animated waveform
- club / room creation, membership, and invites
- friend graph and block list
- online / AFK / offline status (presence)
spotify artist claim
- the public Spotify artist page you claim, plus the cached display fields (name, monthly listener count, avatar) we read from that public page
- if you complete cross-verification via a social platform, the handle on that platform you used to verify
technical data
- basic request logs (IP address, user agent, timestamp) retained by Cloudflare for abuse prevention
- error logs (no message content) for debugging
3. how we use it
- to operate the service: deliver messages, render profiles, sync your friend list across devices
- to display your public profile fields to other users (bio, links, claimed artist)
- to compute features like listener tier, "heating up" indicator, and DAW loyalty
- to prevent abuse: rate-limit spam, enforce blocks, take down content that violates our terms
- we do not use your data to train AI models, sell to data brokers, or run targeted advertising
4. who we share it with
We use a small number of subprocessors to run the service. Each one only sees the data needed for its job:
- Supabase. Postgres database, file storage, realtime, and auth.
- Cloudflare. Site hosting, DDoS protection, request logs, edge compute.
- Spotify (read-only public data). When you claim an artist, we fetch that artist's public Spotify page. We do not send Spotify any data about you.
We do not sell personal data. If we're ever required to disclose data due to a valid legal request (court order, subpoena), we'll comply only to the extent required and will notify you unless legally prohibited.
5. how we secure it
- all traffic over HTTPS
- passwords stored as salted hashes by Supabase Auth (we never see plaintext)
- row-level security policies in our database limit access to data you own or that's explicitly public
- operational secrets are stored in Cloudflare Workers Secrets, not in our codebase
6. retention
- account + profile data: kept while your account is active. Deleted within 30 days of account deletion
- chat messages: free tier keeps the last 7 days; paid tiers keep the last year. Global chat retains the most recent 1,000 messages and rolls older ones automatically
- request logs: ~30 days at our hosting providers
7. your rights
- view, edit, or delete your profile fields directly in the app
- delete your account from the settings panel. this removes all your messages, samples, claims, and friend connections
- request a copy of your data by emailing hello@daw-dle.com
- if you're in the EU/UK, you have GDPR rights including access, rectification, erasure, restriction, portability, and objection. Contact us to exercise any of them
- if you're in California, you have CCPA rights including the right to know what we collect and the right to delete
8. cookies
We use a small number of cookies/local storage entries strictly to keep you signed in and remember your preferences (favorite rooms, mono-color toggle, etc). We don't use third-party tracking cookies.
9. children
dawdle is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has signed up, contact us and we'll delete the account.
10. changes to this policy
We'll update the "Effective" date above when this policy changes materially. For significant changes, we'll notify users in-app or by email.
11. contact
Questions, requests, or concerns: hello@daw-dle.com