Privacy Policy

RoundTable It runs private clubs for music, films, television and books. This policy explains what we collect when you use the website at roundtableit.app or the RoundTable It mobile app, why we hold it, and what you can do about it. The two are the same service — the app is a native wrapper around the same account and the same data.

1. What we collect

Information you give us

Information we collect automatically

Mobile app only

2. Why we hold it

  • To run the service — signing you in, showing your clubs, delivering messages, keeping the pick rotation moving.
  • To keep the service safe — rate-limiting sign-in attempts, acting on reports of abusive content, enforcing our Terms.
  • To contact you — account emails such as verification, password resets and club invitations. We do not send marketing email.

Where the UK GDPR or EU GDPR applies, our lawful bases are performance of a contract (running the account you signed up for), legitimate interests (security and abuse prevention), and consent where you have given it — for example, push notifications, or connecting a Spotify account.

3. Other services we talk to

RoundTable It pulls catalogue information from third parties so you can pick and discuss things. Unless listed below, these requests are made by our servers and do not identify you to the third party.

  • Spotify — only if you choose to connect your Spotify account. We store your Spotify user ID and display name so we can build club playlists on your behalf. You can disconnect it at any time from your profile, which deletes those details.
  • Google Sign-In and Sign in with Apple — only if you use them to sign in. We receive your email address and a stable identifier for your account, and nothing else. If you use Apple's Hide My Email, we only ever see the relay address.
  • TMDB, OMDb, Google Books and The New York Times Books API — catalogue data for films, television, books and bestseller lists. These are server-side lookups about media, not about you.
  • Apple Push Notification service and Firebase Cloud Messaging — deliver notifications to your device. They receive the notification and your device token, not your account details.
  • Our email provider — sends account emails such as verification and password resets.

We do not sell or rent personal data to anyone, and we do not share it for advertising.

4. Cookies

We use one strictly necessary cookie: the session cookie that keeps you signed in. It lasts up to 30 days so that closing the app or the browser tab does not sign you out. We set no advertising or analytics cookies, so there is nothing here to opt out of.

5. Who can see what you post

Clubs are private. Chat messages, forum posts, reviews and picks inside a club are visible to the members of that club. Your profile, username, avatar and favourites are visible to other signed-in members. Direct messages are visible to you and the person you sent them to. Club owners can see the club's administrative log.

Content you post can also be seen by us when it is reported, so that we can act on it — see our Terms for how reports are handled.

6. How long we keep it

  • Account details and content: for as long as your account exists.
  • Failed sign-in records: cleared once the rate-limit window has passed.
  • Push tokens: until you sign out, disable notifications, or the token is retired by Apple or Google.
  • Reports of abusive content: kept after resolution so that repeat behaviour can be recognised.

When you delete your account we remove your profile, your uploads and your direct messages. Messages you posted in a shared club conversation may remain in that club's history, shown as from a deleted account, because removing them would tear holes in other members' conversations.

7. Your rights

You can do the first two of these yourself, immediately, from your account settings:

  • Export — download everything we hold about you as a single file.
  • Delete — delete your account and its data outright. There is no waiting period and you do not need to email anyone.
  • Correct — edit your profile details at any time.
  • Object or restrict — write to us at privacy@roundabout.live.

If you are in the UK or the EEA and think we have handled your data badly, you can complain to your data protection regulator — in the UK, the Information Commissioner's Office.

8. Children

RoundTable It is not intended for children under 13, and you must be at least 13 to create an account. If you believe a child has given us personal data, write to privacy@roundabout.live and we will remove it.

9. Security

Traffic is encrypted in transit with HTTPS. Passwords are stored only as bcrypt hashes. Sign-in attempts are rate-limited. Sessions are stored server-side. No system is perfectly secure, and we will tell you promptly if a breach affects your data.

10. Changes to this policy

If we change this policy we will update the date at the top, and we will tell you in the app or by email if the change is significant.

11. Contact

Privacy questions: privacy@roundabout.live
Anything else: support@roundabout.live
Report abusive content: report@roundabout.live