Privacy Policy
Starling Radio · dj.vagabondstudio.dev · Effective August 1, 2026
Starling Radio collects only what it needs to be your DJ — never to sell, and never for advertising. Starling Radio is an AI radio host that curates listening sessions from your real music taste. It is operated by Vagabond Studio (vagabondstudio.dev). This policy covers the web app at dj.vagabondstudio.dev and the Starling Radio mobile apps.
What we collect
- Account. Your email address, a hashed password (we never store the password itself), your email-verification status, and your credit balance and purchase history.
- Music taste from services you connect. Only what is needed to learn your taste: liked songs and channel/library data from YouTube, library and favorite artists from Apple Music, favorites from TIDAL, and the artist/album/track index of a personal music server (Subsonic/Navidrome) or Bandcamp collection you connect. Connecting is always your choice, per service.
- Connection credentials. Access tokens for services you connect, stored server-side and used only to read your taste or play your music. For a personal music server we store its URL, your username, and a salted authentication token — never your server password.
- Listening activity. The sessions we generate for you, what was played or skipped, and your track ratings. This is what makes curation improve.
- Payments. Purchases are processed by Stripe (web) or by Apple and Google (in-app purchases). We never see or store card numbers; we keep the transaction records needed to credit your account.
We do not use analytics or advertising trackers, and the apps never use your microphone — the host's voice is generated, nothing is recorded.
How we use it
Your taste and listening data are used for one thing: curating your sessions and writing the host's spoken commentary. To do that, music data (artists, tracks, and listening patterns — not your email or identity) is processed by AI model providers via OpenRouter, and the commentary text is converted to speech by Google Cloud Text-to-Speech. Standard server logs (including IP addresses) may be kept briefly for security and operations.
YouTube API Services
Starling Radio uses YouTube API Services to read the music you have liked and to play music. By connecting YouTube you agree to the YouTube Terms of Service; Google's handling of your data is described in the Google Privacy Policy. We store the liked-music and library data retrieved from the API on our server to build your taste profile, for as long as your account exists or until you disconnect YouTube. You can revoke Starling Radio's access at any time from your Google security settings. Starling Radio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The web player embeds YouTube's own player, which operates under Google's privacy policy.
Who we share data with
We never sell your data and never share it for advertising. It is handled only by the service providers that run the product: Google Cloud (hosting and text-to-speech), OpenRouter and its underlying AI model providers (music data only), Stripe, Apple, and Google (payments), and our email provider (verification and sign-in email only).
Retention and deletion
We keep your data while your account is active. You can disconnect any connected service in the app, which removes its stored credentials.
You can delete your account — and with it all associated data: your email, taste profile, listening history, sessions, credentials for connected services, and remaining credit balance — at any time, from inside the product:
- Web: sign in at dj.vagabondstudio.dev, open the account menu (top right), choose Account, then Delete account.
- Mobile apps: open the ☰ account menu, choose Account, then Delete account.
Deletion is immediate and cannot be undone. Payment transaction records are retained by our payment processors (Stripe, Apple, Google) as required for financial compliance; we keep no copy tied to a deleted account. If you can't sign in, email vagabondstudio9@gmail.com from your account address and we will erase the account within 30 days.
Deleting some of your data, without deleting your account
You do not have to delete your whole Starling Radio account to remove data from it.
Disconnect a music source. Open Integrations — in the web player, the account menu (top right); in the mobile apps, the ☰ menu — and choose Remove on the source you want gone. Everything we hold for that source is deleted at once: its stored credentials, the taste profile built from it, and the account identifier that connected it. For YouTube that is your liked artists and songs, the connection timestamp and your channel id; for Apple Music or TIDAL, the stored taste snapshot and account id; for a music library, the server address, its username and password, and the catalog snapshot. Nothing about that source is kept, and you can connect it again later.
Removal takes effect immediately and cannot be undone. Your account, credit balance and listening history are unaffected — to delete those, delete the account (above). Payment transaction records are retained by our payment processors (Stripe, Apple, Google) as required for financial compliance.
Security
All traffic between the apps, the web player, and our server is encrypted in transit with HTTPS (TLS). Server-side data is stored on encrypted disks (Google Cloud encryption at rest). On your device, the app stores only your sign-in token, in the platform's encrypted storage. Credentials and tokens are never shared with other users, and each account's data is stored separately.
Children
Starling Radio is not directed at children under 13, and we do not knowingly collect data from them.
Changes
If this policy changes, the new version will be posted at this address with an updated effective date.