Version 2.1, September 30, 2026
Privacy policy
This English translation is here to help. If the two versions differ, the French version prevails.
This policy covers the Dundu app (Android and iPhone) and the Dundu website. It explains what we collect, why, who we share it with, how long we keep it, and how to have it erased.
Dundu was created by BABA Faycal, who publishes the app and is responsible for your data. To reach him, see section 10.
1. What we collect, and why
| Data | Why | Legal basis |
|---|---|---|
| Email address, display name | Recognise your account, write to you | Performance of the contract |
| Password (Argon2 hash) | Sign you in | Performance of the contract |
| Identifier sent by Google or Apple (if you choose "Continue with Google" or "with Apple"), with the email and name they give us | Create your account and sign you in without a password | Performance of the contract |
| Profile photo, short bio (if you add them) | Your public profile | Performance of the contract |
| Phone number (if you give it) | Paying by mobile money | Performance of the contract |
| Listening history | Working out what each artist is owed, applying listening limits, showing you "My listening" | Performance of the contract |
| Favourites, "dislikes" (private), playlists, artists and people you follow | Your library, and not suggesting what you dislike again | Performance of the contract |
| Written comments, likes, reactions | Conversations around songs | Performance of the contract |
| Recordings of your voice: voice comments, shout-outs in a live, a DJ's voice messages | Playing them where you sent them | Performance of the contract |
| Taking part in a live, live messages | Running the live | Performance of the contract |
| App language, the song language you prefer | Speaking to you in your language and suggesting songs | Performance of the contract |
| Phone notification token | Sending you the notifications you accepted | Consent |
| Sign-in attempts, IP address | Spotting password attacks; limiting preview plays on the website | Legitimate interest |
| Payments, subscriptions, redeemed gift cards | Billing, keeping our accounts | Legal obligation |
| Identity document (artists) | Knowing who we pay and on whose behalf we sell rights | Legal obligation and contract |
| Payout details (artists) | Paying earnings | Performance of the contract |
| Artist profile prepared by the team: stage name, phone number that gave consent | Publishing their songs with their consent, and sending them the code that hands their profile back | Artist's consent |
The microphone is only used while you record (a voice comment, a shout-out, a DJ message), and only if you have allowed it. Outside those moments, nothing is listened to.
Your password is never kept as it is. We only keep an Argon2 hash, which cannot be turned back into your password.
Payout details are stored separately, apart from the artist profile. That way, an account number cannot show up by mistake with the profile.
What everyone can see: your display name, photo and bio, your written and voice comments, your playlists if you make them public, and your shout-outs during the live where you send them. Everything else is private.
2. What we do not do
- we do not sell any data;
- we do no targeted advertising and do not follow you from one app to another;
- the website uses no cookies and no trackers;
- we only share your data with the providers the service needs (section 4).
3. Listening history
This is the most sensitive data, because it says a lot about you. It exists for one precise reason: it decides what is paid to each artist. Without it, the split would be guesswork.
We keep it for as long as it takes to calculate and justify that split. After that, it is grouped: for a finished period, only totals remain, with no detail per person.
4. Our providers
- Railway: hosting, database and file storage (sounds, images);
- Google: "Continue with Google" sign-in, and Firebase Cloud Messaging for notifications;
- Apple: "Continue with Apple" sign-in;
- Brevo: service emails (address check, new password);
- a mobile money provider, when a payment is offered: it receives your name, your email address and the amount, never what you listen to;
- an error tracking service, when it is switched on: it receives the description of an error, without your listening.
5. How long we keep your data
| Data | How long |
|---|---|
| Active account | As long as the account exists |
| Deleted account | Erased within 30 days, except what follows |
| Detailed plays | Until the payout period ends, then grouped into totals |
| Written and voice comments | Until you delete them (or the song's artist does), or until the account is deleted |
| A live's shout-outs, messages, reactions and replay | Erased 24 hours after the live ends |
| A DJ's voice messages | Erased a few minutes after they are played |
| Accounting records (payments, licences) | As long as the law requires |
| An artist's identity document | As long as they are a member, then 12 months |
| Sign-in attempts | 12 months |
| Preview play counters on the website | One hour |
| Log of sensitive actions | Never erased (see section 7) |
6. Your rights
You can see your data, correct it, have it erased, take a copy, object to a use of it or limit it. Do this from the app or by writing to us (section 10).
Deleting your account: in the app, or on the website's "Delete my account" page, even if you have uninstalled the app. Your personal data is erased; what is kept, and why, is explained in sections 5 and 7.
We reply within one month.
7. Two limits, to be honest with you
The log of sensitive actions cannot be erased. Every moderation decision, every payout and every sanction leaves a trace in it that nobody can change or delete, not even an administrator. A log that could be edited would prove nothing. It holds who did what and when, not what you listen to.
A licence that has been sold stays valid even if the artist deletes their account. The buyer paid for a precise right; taking it away because the artist leaves would mean taking back what they bought.
8. Security
- all exchanges are encrypted (HTTPS);
- passwords are protected with Argon2;
- sessions expire, and refresh tokens change every time they are used;
- an account locks after too many sign-in attempts;
- downloaded songs are encrypted (AES-256-GCM), with keys tied to the phone;
- website previews are encrypted and served with a short-lived token;
- only a few people can reach production data, and every access is logged.
9. Children
Dundu is not meant for children under 13. If we learn that an account belongs to a child under 13, we delete it.
10. Writing to us
For a question, or to exercise your rights, write to us at the address given on the website's "Help" page, or from the app.
11. Changes
Every change is published with a new version and a new date. If a change is important, we let you know in the app.