Privacy Policy
Last updated 21 August 2026
RoundTable It runs private clubs for music, films, television and books. This policy explains what we collect when you use the website at roundtableit.app or the RoundTable It mobile app, why we hold it, and what you can do about it. The two are the same service — the app is a native wrapper around the same account and the same data.
The short version. We collect what we need to run your account and your clubs, and nothing else. We do not sell your data, we do not run advertising, and there is no third-party analytics or tracking SDK in the site or the app. You can export everything we hold, or delete your account outright, from your account settings at any time.
1. What we collect
Information you give us
| Account | Username, email address, and a password stored only as a bcrypt hash — we never hold your password itself. Optionally a profile picture, display details and favourite artists, albums, films, shows, books and people. |
|---|---|
| Club activity | The clubs you create or join, the picks you queue, your ratings and reviews, live-chat messages, forum threads and replies, reactions, and direct messages to other members. |
| Uploads | Images you upload for your avatar, club artwork and cover images, files and images you attach in club chat, and any screenshots you attach to a bug report. |
Information we collect automatically
| Session | A session cookie that keeps you signed in, and a record of when you were last active so club members can see who is around. |
|---|---|
| IP address | Recorded against failed sign-in attempts only, so we can rate-limit brute-force attacks on your account. It is not used to build a profile of you and is not retained once the attempts expire. |
| Club moderation log | Administrative actions inside a club — members added or removed, settings changed, cycles advanced — recorded so club owners can see what happened. |
Mobile app only
| Push token | If you allow notifications, the anonymous device token issued by Apple or Google, so we can send you a notification. It identifies a device, not a person, and it is deleted when you sign out or turn notifications off. |
|---|---|
| Camera & photos | Only the specific image you choose, and only at the moment you choose it. The app has no background access to your camera roll and does not scan, index or upload anything you have not explicitly picked. |
| Face ID / fingerprint | If you switch on biometric unlock, the check happens entirely on your device through the operating system. We never receive your biometric data, and it never leaves the device. |
2. Why we hold it
- To run the service — signing you in, showing your clubs, delivering messages, keeping the pick rotation moving.
- To keep the service safe — rate-limiting sign-in attempts, acting on reports of abusive content, enforcing our Terms.
- To contact you — account emails such as verification, password resets and club invitations. We do not send marketing email.
Where the UK GDPR or EU GDPR applies, our lawful bases are performance of a contract (running the account you signed up for), legitimate interests (security and abuse prevention), and consent where you have given it — for example, push notifications, or connecting a Spotify account.
3. Other services we talk to
RoundTable It pulls catalogue information from third parties so you can pick and discuss things. Unless listed below, these requests are made by our servers and do not identify you to the third party.
- Spotify — only if you choose to connect your Spotify account. We store your Spotify user ID and display name so we can build club playlists on your behalf. You can disconnect it at any time from your profile, which deletes those details.
- Google Sign-In and Sign in with Apple — only if you use them to sign in. We receive your email address and a stable identifier for your account, and nothing else. If you use Apple's Hide My Email, we only ever see the relay address.
- TMDB, OMDb, Google Books and The New York Times Books API — catalogue data for films, television, books and bestseller lists. These are server-side lookups about media, not about you.
- Apple Push Notification service and Firebase Cloud Messaging — deliver notifications to your device. They receive the notification and your device token, not your account details.
- Our email provider — sends account emails such as verification and password resets.
We do not sell or rent personal data to anyone, and we do not share it for advertising.
4. Cookies
We use one strictly necessary cookie: the session cookie that keeps you signed in. It lasts up to 30 days so that closing the app or the browser tab does not sign you out. We set no advertising or analytics cookies, so there is nothing here to opt out of.
5. Who can see what you post
Clubs are private. Chat messages, forum posts, reviews and picks inside a club are visible to the members of that club. Your profile, username, avatar and favourites are visible to other signed-in members. Direct messages are visible to you and the person you sent them to. Club owners can see the club's administrative log.
Content you post can also be seen by us when it is reported, so that we can act on it — see our Terms for how reports are handled.
6. How long we keep it
- Account details and content: for as long as your account exists.
- Failed sign-in records: cleared once the rate-limit window has passed.
- Push tokens: until you sign out, disable notifications, or the token is retired by Apple or Google.
- Reports of abusive content: kept after resolution so that repeat behaviour can be recognised.
When you delete your account we remove your profile, your uploads and your direct messages. Messages you posted in a shared club conversation may remain in that club's history, shown as from a deleted account, because removing them would tear holes in other members' conversations.
7. Your rights
You can do the first two of these yourself, immediately, from your account settings:
- Export — download everything we hold about you as a single file.
- Delete — delete your account and its data outright. There is no waiting period and you do not need to email anyone.
- Correct — edit your profile details at any time.
- Object or restrict — write to us at privacy@roundabout.live.
If you are in the UK or the EEA and think we have handled your data badly, you can complain to your data protection regulator — in the UK, the Information Commissioner's Office.
8. Children
RoundTable It is not intended for children under 13, and you must be at least 13 to create an account. If you believe a child has given us personal data, write to privacy@roundabout.live and we will remove it.
9. Security
Traffic is encrypted in transit with HTTPS. Passwords are stored only as bcrypt hashes. Sign-in attempts are rate-limited. Sessions are stored server-side. No system is perfectly secure, and we will tell you promptly if a breach affects your data.
10. Changes to this policy
If we change this policy we will update the date at the top, and we will tell you in the app or by email if the change is significant.
11. Contact
Privacy questions:
privacy@roundabout.live
Anything else:
support@roundabout.live
Report abusive content:
report@roundabout.live