Overview
This Privacy Policy explains how Lido Nation Foundation Inc. (“we”, “us”) collects, uses, and shares information when you use Qaoki, our real-time karaoke platform, through the Qaoki apps (iOS, Android, and web) and www.qaoki.app (together, the “Service”).
Qaoki is a real-time karaoke platform: one shared song queue per room, lyrics synced to the screen, a cheers economy, and one profile that works across every venue. Using the Service means you agree to this policy and our Terms of Service.
Information we collect
Account and profile. Your email address, display name, @handle, optional profile photo, and your role (singer, fan, star, DJ, host, manager, or owner).
Sign-in information. When you sign in with Google or Apple, we receive basic profile details (such as your name and email) from that provider. If you use phone sign-in, we collect your phone number to send a one-time code.
Location at check-in. When you check in to a venue, we use your device’s approximate location once, at that moment, to verify you are at the venue (within roughly 150 metres). We do not track your location continuously or in the background.
Activity and content. Songs you add to a queue, cheers you send and receive, posts to an event feed, messages, follows, favorites, and recent searches.
Performances and recordings. If a venue records performances and you have given consent, audio or video clips you appear in. This is governed by your recording-consent / “do not film” setting, which you control in your profile.
Device and usage data. Device type, operating system, app version, IP address, and diagnostic information used to keep the Service reliable.
Payments (future). If and when paid features launch, payment details are handled by a third-party payment processor. We do not store full card numbers.
How we use your information
- Run the live queue, sync lyrics to the room, and notify you when you’re on deck, on next, and up.
- Operate the cheers economy, Stars leaderboards, and Supafan status.
- Verify venue check-ins and prevent location spoofing.
- Maintain your single, universal profile across venues.
- Send service notifications and (with your permission) updates.
- Keep the Service safe — detecting abuse, fraud, and violations of our terms.
- Analyze and improve features and performance.
Mobile messaging (SMS)
If you provide your mobile number, we use it to send transactional text (SMS/MMS) messages only — one-time passcodes for sign-in and verification, and venue check-in verification codes. We do not send marketing or promotional text messages. Message frequency varies and message and data rates may apply. You can opt out at any time by replying STOP, or get help by replying HELP or emailing [email protected]. The full messaging terms are in our Terms of Service.
No sharing or sale of mobile information for marketing. We do not share or sell your mobile phone number or SMS opt-in (consent) information to third parties or affiliates for their marketing or promotional purposes. We share mobile information only with service providers (such as our SMS delivery vendor) strictly to send messages you have requested, and as otherwise described in this policy for legal or operational reasons.
Location data
Location is used only at check-in to confirm you’re physically at the venue. We compare your coordinates against the venue’s once, at the moment you check in, and we do not retain a continuous location history — we don’t track you before an event, after it, or between events.
You can use Qaoki without granting location access. RSVP to the event, then ask the host, DJ, or venue staff to check you in when you arrive. They vouch for your presence in place of the location check, and it unlocks exactly the same things a self check-in does — your free cheers, the Fan role, venue loyalty credit, and the ability to sing. A host who gives you a join code can admit you that way too, once the party is live. If you decline the permission, or your GPS simply won’t cooperate, that staff check-in is the supported route rather than a workaround.
Recordings and consent
Recording is opt-in. Your recording-consent / “do not film” setting controls whether performances you appear in may be captured or shared to a feed. You can change this setting at any time in your profile; changes apply going forward.
How we share information
- With venues you check in to: your presence, queue entries, and cheers at that event, so hosts and DJs can run the night.
- With other users: your public profile, queue position, feed posts, and leaderboard standing are visible to others in the room or, where you’ve made your profile public, more broadly.
- With service providers: hosting, storage, authentication, and analytics vendors who process data on our behalf under appropriate safeguards.
- For legal reasons: to comply with law, enforce our terms, or protect the rights, safety, and security of users and the public.
- In a business transfer: as part of a merger, acquisition, or sale of assets.
We do not sell your personal information.
YouTube and Google services
Qaoki uses YouTube API Services to search for and play back songs. By using these features you are also agreeing to the YouTube Terms of Service, and the information Google and YouTube collect or receive through the embedded player is handled in accordance with the Google Privacy Policy.
When you sign in with Google, Google shares basic profile and account information (such as your name, email, and Google account identifier) with us, and that exchange is likewise governed by the Google Privacy Policy. We use this data only to create and maintain your Qaoki account; we do not use it for advertising or sell it. You can review and revoke Qaoki’s access to your Google account at any time via Google’s security settings.
Cookies and on-device storage
Qaoki stores, accesses, and recognizes information directly on your device and in your browser. Some of this we place ourselves; some is placed by third parties we embed. This happens on every platform we ship — web, Android, iOS, and desktop.
What we store ourselves
- Authentication tokens — kept in your device’s secure keystore (iOS Keychain, Android Keystore) on the apps, so you stay signed in between sessions.
- A local database cache — song, queue, event, and profile data mirrored to an on-device SQLite database so the app works offline and starts quickly.
- Preferences and app state — your theme, sort order, the last screen you were
on, and similar settings, stored in your browser’s
localStorage/sessionStorageon the web and in app preference storage on the apps. - Sign-in handoff data — a short-lived value in
localStorageused to complete a Google or Apple sign-in redirect.
What third parties store
- YouTube. Playing or previewing a song loads YouTube’s embedded player. YouTube and Google may place, access, and read cookies and similar technologies in your browser or on your device through that player — including for measurement and, in some contexts, advertising. This happens under Google’s control, not ours, and is governed by the YouTube Terms of Service and the Google Privacy Policy.
- Google sign-in. Signing in with Google involves Google setting and reading its own cookies on its domains.
- Analytics. We use Fathom Analytics, which is cookieless: it does not set advertising or cross-site tracking cookies and does not build a profile of you across other websites.
We do not use cookies or on-device storage for advertising, ad targeting, or cross-site tracking of our own.
Your controls. You can clear cookies and site data, or block them, in your
browser settings; on the apps, clearing the app’s storage or uninstalling it
removes the local cache and preferences. Blocking storage for youtube.com may
stop song previews and playback from working. Signing out clears your
authentication tokens and the local cache.
Performance monitoring & error tracking
To keep the Service fast and reliable we collect performance and error diagnostics in two complementary systems:
- OpenTelemetry (OTel) traces. Our apps, our backend services, and this
website send timing information — how long a page took to render, how long a
request took — to our own OTel Collector Gateway (
https://otel.qaoki.appfor the live site,https://otel-dev.qaoki.appfor our development site), which feeds Grafana, Tempo, Prometheus and Loki, all operated by Lido Nation rather than a third-party analytics vendor. What this website sends is timings and one size measurement: how long the page took to load, how long its slowest interaction took to respond, how much its layout moved while loading, and how many bytes the page itself weighed. No page URLs, no referrer, no search terms, no description of what you clicked, and nothing that identifies you. - GlitchTip error tracking. When the app crashes or a server request
fails, a minimal error report (stack trace, device/OS/app version, and the
current
trace_idso the error links to its trace in Grafana) is sent to our self-hosted GlitchTip athttps://glitchtip.2lovelaces.com, with separate projects for our production and development environments. No third-party error vendor. - Push notifications carry a trace id. A notification we send you includes
the
trace_idof the request that caused it, so that if a notification is late or wrong we can find the one request responsible instead of guessing. It is a random identifier for that request, it is never shown to you, and it says nothing about who you are.
What we don’t collect here. Spans and error reports never carry your
password, raw email, phone number, or Authorization header. Each app removes
them before anything is sent, and the Collector removes them again at the
gateway as defense in depth. Web addresses attached to an error report have
their query string stripped first, so anything carried in a link — a sign-in
code, a campaign tag — is dropped before the report leaves your browser.
Retention. Diagnostics are kept only for as long as we need them to investigate and fix problems, then deleted on a rolling schedule; development data is pruned more aggressively than production.
Your controls. There is no per-user opt-out toggle; diagnostics are essential to operating the live room.
Third-party services
The Service relies on other third parties whose own privacy policies apply:
- Google sign-in and Google/YouTube API services — see the section above and the Google Privacy Policy.
- Apple sign-in.
- Hosting, object storage, and analytics providers.
- GlitchTip (self-hosted, same operator) and the OTel Collector Gateway (self-hosted) for the diagnostics described above.
Data retention
We keep your information while your account is active and as needed to provide the Service. This includes data we receive through Google sign-in / OAuth (your name, email, and Google account identifier) and through YouTube API Services (such as your search and playback activity within the Service), which we retain only for as long as your account is active or as needed to operate the features you use.
When you delete your account, we delete or anonymize your personal data — including the Google OAuth and YouTube-related data described above — except where we must retain certain records to comply with legal obligations, resolve disputes, or enforce our agreements. You can also revoke Qaoki’s access to your Google account at any time via Google’s security settings.
Your choices and rights
- Access and update your profile in the app (display name, handle, photo, settings).
- Delete your account, which removes your profile and associated personal data as described above.
- Control recordings via your recording-consent / “do not film” setting.
- Manage notifications and marketing preferences.
Depending on where you live (for example, under the GDPR or CCPA), you may have additional rights to access, correct, delete, port, or restrict processing of your data, and to object to certain uses. To exercise these, contact us at [email protected].
Children’s privacy
The Service is not directed to children under 18, and we do not knowingly collect their personal information. Some venues and events may be restricted to adults (18+). If you believe a child has provided us information, contact us and we will delete it.
Security
We use technical and organizational measures — including encryption in transit and access controls — to protect your information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
International transfers
We may process and store information in the United States and other locations where we or our service providers operate. Where required, we use appropriate safeguards for cross-border transfers.
Changes to this policy
We may update this policy from time to time. We’ll revise the “Last updated” date above and, for material changes, provide a more prominent notice.
Contact us
Questions about this policy or your data? Contact Lido Nation Foundation Inc. at [email protected].