The short version: your phone listens, sends a fingerprint rather
than the sound, and keeps audio only where it will ask you to judge it.
Accounts are optional, and your audio stays on your device. If you have
friends on Catchy, a finished night goes to them unless you switch that
off — that and everything else that leaves are listed below.
What stays on your phone
Your sets, catches, timelines, and library — the names, the venues, the
artwork, the words. Stored locally. Two things derived from them leave
unless you switch them off: the capture diagnostics described below
(catalog identifiers and times, never names), and a finished night going
to your friends, described under Friends.
Short clips (~20 seconds) for anything that still needs your ear —
the moments nothing matched, and the songs Catchy named but wasn't sure of.
They exist so you can listen back and decide during review. They live on
your device and are never uploaded anywhere.
Those clips delete themselves when you finish reviewing the set, and
after a retention window even if you never do. That window is 30 days by
default and you can set it to 7, 14, 30 or 60 in Notifications &
timing.
The one exception is a clip you tap Keep clip on. That one is
yours until you delete it.
What never exists
No recording of your night. The microphone feeds a rolling ~20-second
buffer that is continuously overwritten. The only audio written to disk is
the clips above, and the stretches still waiting to be identified when
you're offline — those go the moment they are, or with the rest when the
set's window runs out.
The one exception is Concert Mode — the
“at a show?”
toggle, off unless you flip it for a night. Turn it on and that night is
recorded on this phone so the review can take a second pass at what
nothing caught live. The recording never leaves the phone, skips your
backups, stops after 4 hours, and deletes itself when you finish the
review — or after 7 days if you never do.
No password. An account is Sign in with Apple or Google — nothing to fill
in, and no email or phone number we ask you for. It is never needed to
catch, review, keep your library, or export, and never needed to open a link
someone shares with you. It backs your friend code, your friends list and
your share links so they survive a new phone — and adding a friend is the
one thing that asks for it.
No third-party analytics SDK, no advertising, no location, no
contacts.
What leaves your phone, and when
While capturing: your phone turns what it hears into an acoustic
fingerprint on the device and sends only that — never the audio itself —
to Apple's Shazam service, the same way the Shazam app works. It identifies
songs, not you.
Also while capturing: the lock-screen banner's updates (current
song, catch count) pass through Catchy's server on their way to Apple's
push system so the banner stays fresh. Passing through — our server logs
counts, never songs.
If you share a night as a link: a separate, deliberate act —
nothing ever creates a link on its own. Exactly what the page shows —
the tracklist, times, and the name you gave the set — is hosted until you
revoke it. Revoking deletes it.
After a set is reviewed: capture diagnostics — exactly what the
in-app Capture health
panel shows — are shared with the developer to fix
capture bugs. Two things travel: the counters (windows sent and matched,
pauses, battery, device model), and the night's per-window recognition
events — which catalog songs were recognized and when, sent as catalog
identifiers (Shazam / Apple Music / ISRC) and numbers. Never audio, never
a recording, never song titles or artist names, never the set's name.
They exist to fix how the app merges and presents what it recognizes.
The switch in Profile → Privacy & FAQ turns it off and deletes what
was already sent, and deleting a night deletes that night's rows too.
With no signal, or if recognition fails: that stretch of audio
waits on your phone until there is a connection to identify it, and is
deleted the moment it is.
If you export to Spotify: the set's name and its song names.
What happens next depends on whether you have connected your own Spotify.
With your own account connected, the playlist is created in your
library and is public, so the listen link on your share page works
for everyone; you can make it private in Spotify, but exporting that night
again turns it public once more. Nothing else is sent either way.
Without it, we do
run one small server: it creates the playlist on Catchy's own Spotify
account and gives you a link to follow — that playlist is public, so
whatever you named the set is visible to anyone with the link — and a random
identifier for this installation goes with the request so the shared account
cannot be abused. That identifier is tied to nothing about you, we cannot
connect it to a person, and it resets if you reinstall the app.
If you export to Apple Music: the playlist is created in your own
library, with your permission, on your device.
If you open Insights on a song or artist: that name goes to our
server, which looks it up in public sources (MusicBrainz, Wikipedia,
Discogs, Apple's catalog) and writes the short piece you read. The same
piece is shared by everyone who asks about that artist — nothing about
you, your account, or your night goes with the request.
Song titles are looked up against Apple's public catalog for artwork and
previews.
Friends and your profile — what your friends see
When a night ends it goes to your friends on its own: the
tracklist, the times, and what you called the set, in their Friends tab.
That is a switch in the app, on to begin with; the first time it happens
Catchy stops and asks, and you can stop sharing any single night from its
own menu. With no account, or with no friends, there is nobody for this to
reach and nothing is sent.
Adding a friend just links two random IDs on the server — no
names, no contact info, nothing readable. The nicknames you give friends
are typed on your phone and stay on it.
If you claim a @username, the server holds it — it's how friends
find you. Same for the display name if you add one. You
are findable by search unless you turn that off in the app; either way,
someone finding you only ever sends a request you approve. This is the one
place we hold a name, and only because you chose one.
Your profile carries counters (sets, songs, hours, favourites) and
they are visible to friends unless you switch them off, which also deletes
what was published. The Top sets you pin ride the profile too — they are
nights you already chose to share, so their pages are hosted the same way.
The audio and the full record of each night stay on your phone.
A set shared with friends — whether it went on its own or you
shared it yourself — puts exactly what the shared page shows (the
tracklist, times, and the set's name) in their app until you unshare it.
Your profile shows friends only the name, venue, and date of the sets that
are shared.
Adding friends to a set sends each one an invitation, as IDs only;
accepting places that set in their app. Declining leaves no trace.
Reactions and song IDs on a shared set live on the server while it
is shared: a tap, or the title and artist a friend typed. Anyone who can
open a shared set sees who reacted to it — names, never counts — and your
@username can appear there to people who follow the same night without
being your friend. Reactions disappear with the set when it is
unshared.
If you allow notifications, this phone's push address is stored so
a night you follow can reach you. Storing it does not send you anything:
only following a set makes you a recipient. The pushes carry no songs and
no names. Turning off Following in the app removes the address.
Letting friends see you are out is off unless you turn it on for
that set. They see only that — no venue, no place — and it disappears when
the set ends. If a friend asks to join you and you accept, the venue you
type goes to that one friend alone and dies with the set too.
Changes
If what the app does with your data changes, this page changes with it.
It is kept in the same repository as the app and reviewed against the
code.