Privacy Policy
Last updated: February 21, 2026
Cymbal ("we", "our", or "the app") is a social music-sharing app. This policy explains what information we collect, how we use it, and your choices.
Information We Collect
Account information. When you create an account we collect your email address, a username you choose, and a password (which is securely hashed and managed by Firebase Authentication — we never see or store your plain-text password).
Profile content. You may upload a profile photo, add a bio, and add a website link. Profile photos are stored in Firebase Cloud Storage.
Posts and activity. When you share a song ("cymbal"), we store the song metadata (track name, artist, album, and album art URL sourced from Spotify), any caption or hashtags you add, and engagement data such as likes, comments, saves, and follower relationships.
Comments. Comments you leave on posts are stored alongside your user ID and a timestamp.
Third-Party Services
We use the following third-party services:
- Firebase (Google) — authentication, database (Firestore), and file storage. Google's privacy policy: policies.google.com/privacy
- Spotify Web API — we search Spotify's catalog to let you find and share songs. We use Spotify's public API with app-level credentials; we do not access your Spotify account. Spotify's privacy policy: spotify.com/legal/privacy-policy
How We Use Your Information
- To create and maintain your account
- To display your profile, posts, and activity to other users
- To enable social features (following, likes, comments, notifications)
- To show trending songs and hashtags
Data Sharing
We do not sell your personal information. Your data is shared only in the following ways:
- Public profile and posts. Your username, profile photo, bio, and posts are visible to other Cymbal users.
- Service providers. We use Firebase (Google) to store data and Spotify to retrieve song information, as described above.
Data Retention and Deletion
You can delete your account at any time from the Settings screen in the app. When you delete your account, we permanently remove your profile, all your posts, comments, likes, saves, follower relationships, and notifications. This action cannot be undone.
Security
All data is transmitted over HTTPS. Passwords are hashed by Firebase Authentication. We do not use any custom or non-exempt encryption.
Children's Privacy
Cymbal is not intended for children under 13. We do not knowingly collect information from children under 13.
Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes through the app or by updating the date at the top of this page.
Contact
If you have questions about this privacy policy, please contact us at support@cymbal.fm.