Legal

Privacy Policy

Last updated 3 August 2026 · Applies to the varostream mobile app and this website.

The short version. You don't need an account. We don't sell your data, we don't run advertising, and we don't build profiles for anyone else. We store the things the app needs to work — your favourites, your queue, where you got to in an episode — against an anonymous device identifier, and you can wipe all of it from inside the app.

1. Who we are

varostream ("varostream", "we", "us") is operated by {{LEGAL ENTITY NAME}}, {{REGISTERED ADDRESS}}. We are the data controller for the personal information described in this policy. If you have any question about it, write to support@varostream.com.

2. What we collect

Information you give us by using the app

  • Your library. Stations, podcasts and episodes you favourite, the presets and packs you build, and the items in your Up Next queue.
  • Playback state. Recently played items, resume positions in episodes, and playback preferences such as speed.
  • Listening history. What you played and when, which powers Recently Played, your listening Insights, and the "what was that song?" track history.
  • Your settings. App language, content languages, theme, alarms, sleep-mode configuration and notification preferences.

Information collected automatically

  • An anonymous device identifier. When you first open the app it generates a random identifier and issues a token for it. This is how your library follows you between sessions. It is not your name, email, phone number, advertising ID or Apple/Google account.
  • Basic technical data needed to serve requests — device platform and app version, and, transiently, the IP address your requests arrive from (standard server logs).
  • Diagnostic data. If the app crashes or a stream fails repeatedly, we may record the error and the station or feed involved so we can fix it or retire a dead stream.

Information we do not collect

We do not ask for your name, email address, phone number, date of birth, contacts, photos, calendar, microphone or camera. Because there is no sign-up, we have no credentials to lose.

3. Why we collect it

We process the data above to provide the service you asked for — syncing your library across launches and devices, resuming episodes where you left off, firing your alarms on time, showing your listening insights, and keeping the catalogue healthy by detecting streams and feeds that have gone dead. Our legal bases, where the GDPR applies, are performance of a contract (providing the app you subscribed to) and our legitimate interests in keeping the service working, secure and accurate.

4. Device permissions

  • Location (optional). Only used if you tap into the "near you" / local radio features on the Discover tab. We use an approximate location to find nearby stations at the moment you ask; we do not track your location in the background and we do not store a location history. Deny it and everything else in the app still works — the near-you row simply disappears.
  • Notifications (optional). Required for alarms, show reminders and bedtime prompts to reach you. Alarm content is prepared on your device.
  • Local network / casting (optional). Used to find AirPlay, Chromecast and Sonos targets when you open the output picker.

5. What we never do

  • We do not sell or rent personal information to anyone, for any purpose.
  • We do not serve advertising in the app, and we embed no advertising SDKs or cross-app trackers.
  • We do not share your listening history with broadcasters, podcast publishers, data brokers or ad networks.
  • We do not use your data to train third-party advertising or profiling models.

6. Who we share data with

Only the parties needed to run the service:

  • Apple and Google handle all subscription billing. They tell us whether a subscription is active; they do not give us your payment details, and we never see your card.
  • Our hosting and infrastructure providers ({{CLOUD PROVIDER — e.g. Amazon Web Services}}), who store the data on our behalf under contract and may not use it for their own purposes.
  • Music metadata lookups. When the track-history feature identifies a song, we query public catalogue services (such as the iTunes Search API) for the artwork, genre and a link. Those requests contain the song and artist name — never your device identifier or any information about you.
  • Radio stations and podcast hosts. When you play something, your device connects directly to that broadcaster's or host's server, exactly as a browser would. Their own logging is governed by their privacy policies, not ours.
  • Legal requirements. We may disclose information if we are legally compelled to, or to protect the rights and safety of our users or ourselves.

7. How long we keep it

Library and settings data is kept for as long as your device identifier is in use, so that your app keeps working. Listening history is retained to power Recently Played and Insights, and you can clear it at any time from within the app. Server logs are kept for a short operational window and then discarded. If you delete the app and don't return, the data associated with your device identifier is deleted after {{RETENTION PERIOD — e.g. 24 months}} of inactivity.

8. Your rights and choices

Inside the app you can clear your track history, empty your queue, remove favourites and packs, turn off notifications, and revoke the location permission at the OS level. Deleting the app removes the local copy of everything.

Depending on where you live — including the EU/UK under the GDPR and California under the CCPA — you may also have the right to access, correct, export or delete the information we hold, and to object to certain processing. To exercise any of these, email support@varostream.com. Because we deliberately don't know who you are, we will ask you for the device identifier shown in the app's Settings screen so we can locate the right records. We will not discriminate against you for making a request. If you are in the EU or UK and are unhappy with our response, you may complain to your local data protection authority.

9. Children

varostream is not directed at children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect information from them. The catalogue contains live radio and podcasts from third parties, which may include content intended for adults. If you believe a child has provided us with information, contact us and we will delete it.

10. International transfers

Our infrastructure is hosted in {{PRIMARY REGION — e.g. the United States}}. If you use the app from elsewhere, your data will be transferred there. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

11. Changes to this policy

If we change this policy we will update the date at the top of this page, and for material changes we will notify you in the app before the change takes effect.

12. Contact

Questions, requests or complaints: support@varostream.com, or by post at {{REGISTERED ADDRESS}}.