Legal

Privacy Policy

Effective Date: July 14, 2026 Last Updated: July 14, 2026 Applies to: Duoplay for Android

Introduction

Welcome to Duoplay. This Privacy Policy explains how Vam Studio ("we," "us," or "our") approaches the collection, use, and disclosure of information in connection with the Duoplay mobile application for Android (the "Application").

Duoplay is a shared music-listening application that allows users to create or join a listening room using a room code, chat with other users inside the room, and enjoy synchronized music and video playback with everyone connected. The Application does not require account creation, login, email registration, or any form of personal identity verification.

By downloading or using the Application, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this policy, please discontinue use of the Application.

Developer Note: Before publishing, replace every [PLACEHOLDER] throughout this document with your actual information. This policy is a legally structured template; consult a qualified legal professional for advice specific to your jurisdiction and circumstances.

Information We Collect

2.1 Information We Do Not Collect

The Application is designed with a minimal data footprint. We do not intentionally collect, store, or process any of the following categories of personal information:

  • Full name or display name
  • Email address
  • Phone number
  • Postal or physical address
  • Date of birth or age
  • Government-issued identification numbers
  • Financial or payment information
  • Device contacts or address book data
  • Photos, camera data, or image library contents
  • Video content stored on your device
  • Audio recordings or microphone data
  • Precise or approximate GPS location
  • Biometric data of any kind
  • Health or fitness data

2.2 Information That May Be Processed

To deliver core functionality, the Application may process the following categories of information. This processing is strictly limited to what is necessary for the Application to operate correctly:

  • Anonymous device information — Technical details such as device type and operating system version, required to ensure compatibility and stable operation. This information is not linked to any identifiable individual.
  • Temporary room identifiers — A randomly generated code used to create or join a listening session. These identifiers are ephemeral and exist only for the duration of the session.
  • Temporary chat messages — Text messages sent within a room while users are connected. Messages are held in memory solely to relay them to other participants and are not persisted after the room ends.
  • Synchronization data — Playback state information (e.g., play, pause, seek position) exchanged between connected users to keep playback in sync. This data is transient and not stored.
  • Network information — IP address and connection metadata required to establish and maintain a real-time connection between participants. IP addresses may appear in server operational logs (see Section 4).
  • Advertising identifiers — The Android Advertising ID (AAID) and related device signals may be accessed by our third-party advertising partner, Google AdMob, to serve advertisements. See Section 6 for full details.

How We Use Information

The limited information processed by the Application is used exclusively for the following purposes:

  • Providing core functionality — Enabling users to create and join rooms, synchronize music and video playback, and send temporary chat messages within a session.
  • Service reliability and diagnostics — Generating operational logs to detect errors, investigate service disruptions, and maintain infrastructure security.
  • Displaying advertisements — Working with Google AdMob to display advertisements within the Application. Advertising identifiers are used by AdMob; we do not use them ourselves for any other purpose.
  • Legal obligations and security — Retaining minimal data as required by applicable law or to investigate and respond to security incidents.

We do not sell, rent, trade, or share any information we collect with third parties for their own marketing purposes. We do not build user profiles, engage in behavioral tracking, or combine session data with external data sources to identify individual users.

Data Storage & Retention

4.1 Ephemeral Session Data

The Application is architected around temporary, session-scoped data:

  • Room information exists only while the room is active. Once all participants leave or the session expires, the room and its associated data are deleted automatically.
  • Chat messages are held in memory for the duration of the session. They are not written to persistent storage and are not recoverable after the session ends.
  • Synchronization state (playback position, track metadata) is transient and not stored beyond the active session.
  • No permanent user profiles are created at any point.
  • No long-term chat history is maintained by us.

4.2 Operational Logs

Our server infrastructure may generate operational logs for security, diagnostics, and service reliability purposes. These logs may contain:

  • IP addresses (in anonymised or pseudonymised form where technically feasible)
  • Timestamps of connection events
  • Error and exception details
  • Aggregate traffic metrics

Operational logs are retained only for as long as necessary to fulfil their diagnostic and security purpose — typically no longer than 30 days — after which they are automatically purged unless a specific legal obligation requires a longer retention period.

4.3 Where Data Is Stored

The Application's server-side infrastructure is operated using cloud hosting services. Data may be stored and processed in data centres located outside your country of residence. See Section 11 (International Users) for more information.

Third-Party Services

The Application integrates third-party services that may collect and process data independently according to their own privacy policies. We do not control and are not responsible for the data practices of these third parties. We encourage you to review their privacy policies before using the Application.

Google AdMob

Provides in-app advertising. AdMob may collect device identifiers, IP address, and usage data to serve personalized or non-personalized advertisements. See Section 6 for a detailed description of AdMob's data practices within this Application.

Google Privacy Policy ↗

Google Play Services

Provides core Android runtime services required by the Application, including certificate transparency, app integrity verification, and other system-level APIs. Google Play Services may collect device and diagnostic information as part of its standard operation.

Google Privacy Policy ↗
Note: By using the Application on an Android device, you agree to Google's Terms of Service and Privacy Policy to the extent they apply to Google Play Services and related Google components.

Advertising (Google AdMob)

6.1 How Advertising Works

The Application uses Google AdMob, provided by Google LLC, to display advertisements. AdMob may use the Android Advertising ID (AAID) — a resettable, non-permanent device identifier — along with general device information (such as device model, operating system version, and coarse location derived from IP address) to serve advertisements.

6.2 Personalized vs. Non-Personalized Ads

Depending on your consent and the laws applicable in your jurisdiction, you may be shown:

  • Personalized advertisements — Ads tailored using interest signals derived from your AAID and device information by Google's advertising systems.
  • Non-personalized advertisements — Ads that are contextually or randomly selected without the use of cross-app interest profiling. These may still use your AAID for frequency capping and fraud prevention.

Where required by law (e.g., in the European Economic Area, United Kingdom, or other regulated jurisdictions), AdMob will prompt users for consent before processing data for personalized advertising purposes, via the Google User Messaging Platform (UMP).

6.3 Managing Your Ad Preferences

You can reset or opt out of interest-based advertising at any time through your device settings:

  • Android 12 and later: Settings → Privacy → Ads → "Delete advertising ID" or toggle "Opt out of Ads Personalization."
  • Earlier Android versions: Settings → Google → Ads → "Opt out of Ads Personalization."

For more information on how Google uses advertising data, visit How Google uses data when you use our partners' apps or sites ↗ .

App Permissions

The Application requests only the Android permissions necessary to deliver its core features. The following permissions are declared in the Application's manifest:

  • INTERNET
  • ACCESS_NETWORK_STATE
  • INTERNET — Required to connect to the Tunely backend servers to establish real-time listening rooms, relay synchronization data, and deliver chat messages between participants. Also required for AdMob to fetch and display advertisements.
  • ACCESS_NETWORK_STATE — Allows the Application to check whether a network connection is available before attempting to connect to the server, enabling graceful handling of offline scenarios without unnecessary connection attempts.

The Application does not request permissions to access your camera, microphone, contacts, precise location, storage, or any other sensitive device resource.

Children's Privacy

The Application is not directed toward children under the age of 13 (or the minimum digital age of consent applicable in your jurisdiction, which may be higher — for example, 16 in certain European Union member states).

We do not knowingly collect, solicit, or process personal information from children. If you are a parent or guardian and believe that your child has provided personal information through the Application, please contact us immediately at duoplayapp@gmail.com . We will take prompt steps to investigate and, where confirmed, delete any such information from our systems.

Because the Application integrates Google AdMob, and in compliance with the Children's Online Privacy Protection Act (COPPA) and Google AdMob's policies, we have not designated this Application as a child-directed app in AdMob settings. If we become aware that the Application is being used by children under the applicable minimum age, we will take appropriate measures, which may include restricting access.

Your Rights & Choices

Depending on the laws of your country or region, you may have certain rights regarding personal information that relates to you.

9.1 Right to Request Information

You may request a summary of the categories of information we hold that may relate to you and the purposes for which it is used. Given the minimal-data design of the Application, we typically hold no persistent personal data linked to a specific individual; however, we will respond to any verifiable request within the timeframe required by applicable law.

9.2 Right to Request Deletion

You may request the deletion of any personal information we hold that relates to you. Because session data (room codes, chat messages, sync state) is already deleted automatically at the end of each session, there is generally no persistent personal data to delete. Operational log entries that may contain your IP address are purged on the schedule described in Section 4.2. If you believe specific data about you is being retained, contact us and we will investigate.

9.3 Right to Opt Out of Advertising (CCPA / CPRA)

Residents of California and other jurisdictions with applicable consumer privacy rights may have the right to opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising purposes. We do not sell personal information. Advertising identifiers used by AdMob are processed by Google on our behalf for advertising display; you may opt out through your device-level ad settings as described in Section 6.3.

9.4 GDPR Rights (EEA / UK Residents)

If you are located in the European Economic Area (EEA) or the United Kingdom, you may have additional rights under the General Data Protection Regulation (GDPR) or the UK GDPR, including:

  • The right of access to data held about you
  • The right to rectification of inaccurate data
  • The right to erasure ("right to be forgotten")
  • The right to restrict processing
  • The right to data portability
  • The right to object to processing based on legitimate interests
  • Rights related to automated decision-making and profiling

To exercise any of these rights, contact us at the details in Section 14. You also have the right to lodge a complaint with your local data protection authority.

9.5 Contacting the Developer

To submit a privacy rights request, report a concern, or ask a question about this policy, please contact us using the details provided in Section 14. We aim to respond to all requests within 30 days (or the shorter period required by applicable law).

Security

We implement reasonable technical and organizational measures to protect information processed in connection with the Application against unauthorized access, disclosure, alteration, or destruction. These measures include, but are not limited to:

  • Encrypted transport using TLS/HTTPS for all client-server communication
  • Secure WebSocket connections (WSS) for real-time data relay
  • Server-side rate limiting and abuse mitigation controls
  • Infrastructure hosted on reputable cloud platforms with their own security certifications
  • Access controls limiting server access to authorized personnel only

However, no method of electronic transmission or storage is completely secure. While we strive to protect the information processed by the Application, we cannot guarantee absolute security. In the event of a security incident that affects your rights and freedoms, we will take appropriate steps in accordance with applicable law, including notifying affected users and relevant authorities where required.

You are also responsible for maintaining the security of your device and ensuring that others do not access the Application through your device without your knowledge.

International Users

The Application is available globally and may be used by individuals located in countries other than the country in which we or our infrastructure provider operates. By using the Application, you acknowledge that any information processed in connection with the Application may be transferred to, stored, and processed in countries whose data protection laws may differ from those of your country of residence.

Where such cross-border transfers occur, we rely on the safeguards provided by our infrastructure provider (including, where applicable, Standard Contractual Clauses approved by the European Commission for transfers of personal data from the EEA to third countries).

If you are located in the EEA, UK, or Switzerland and have concerns about cross-border data transfers, please contact us at the address provided in Section 14.

Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the features of the Application. When we make changes, we will:

  • Update the Effective Date and Last Updated date at the top of this page.
  • Post the revised policy at the same URL (/privacy/).
  • Where required by applicable law or the nature of the change, provide additional notice within the Application or through other appropriate channels.

We encourage you to review this Privacy Policy periodically. Continued use of the Application after any modifications have been posted constitutes your acceptance of the updated policy.

Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or the handling of your information, please contact us using the details below. We aim to respond to all inquiries within 30 days of receipt.

Contact Type Details
Developer / Data Controller Vam Studio
Application Duoplay for Android
General Enquiries duoplayapp@gmail.com
Support & Data Requests duoplayapp@gmail.com
Website —