Privacy Policy
Effective September 30, 2026
Draft. This document is being reviewed and is not yet in effect.
This policy explains what Let’s DJ (“Let’s DJ”, “we”, “us”) collects, why, who sees it, and what you can do about it. Let’s DJ is run by Appology Labs LLC, which is responsible for the personal data described here. You can reach us at legal@appology.dev.
Let’s DJ has two parts: this website at lets.dj, and the app at app.lets.dj where parties happen. This policy covers both.
The short version
- Guests do not need an account. Joining a party takes a code and, if you like, a name.
- We collect only what the service needs to run a party: names people type, the songs they queue, and, for people with accounts, an email address and the things they choose to save.
- Your music and video files never reach us. A bridge you run on your own network sends us only the names and durations of your files.
- We do not sell personal data, we do not show ads, and we do not currently use analytics or advertising trackers.
- This website sets no cookies. The app keeps a few settings on your device, described below.
What we collect
If you join a party as a guest
- A device identifier. The first time you use the app, it creates a random identifier and stores it on your device. It is how the app knows which songs in the queue are yours and whether you hold the host role. It is not tied to your name or identity, and it is never shown to other people at the party.
- A display name, if you choose one. Names are visible to everyone in the same party, and the app keeps them unique within a party.
- What you do at the party: songs you add, the order of the queue, and the reactions you send. Reactions are stored as running totals per song, not as a record of who sent what.
- The party you are in, so that leaving the page and coming back does not mean typing the code again. This and your chosen language are stored on your device.
If you start a party
We store the party itself: its join code, its name if you gave it one, its queue, the libraries attached to it, and its appearance settings. If you upload a background image or other artwork for a party, we store that image.
If you create an account
Accounts exist so that you can own a library and keep settings between parties. We store:
- your email address, which we verify with a one-time code, and a password, which is stored in hashed form, never as plain text;
- a nickname, and a profile image if you add one;
- themes and appearance settings you save;
- the libraries you have connected, described below.
If you connect a library
A library is where a party’s songs come from. There are two kinds.
- A bridge, which is software you run on your own network. It sends us a catalogue: file names, artists and titles read from them, durations, and artwork images. It also sends us its local network address. A secret token proves the library is yours; we keep only a hash of it, and the separate token your screen uses to load files is stored encrypted. The media files themselves are served directly from your network to the screen showing the party. They do not pass through us.
- Cloud storage, if you connect an S3-compatible bucket. We store the connection details you give us. The access key and secret are encrypted before they are saved, and we use them only to read the catalogue of your library and to create the signed links your screen loads files from, directly from your storage. Files do not pass through us. Removing the library deletes the stored keys.
Technical data
Our hosting providers, described below, process technical data such as IP addresses, browser type and request times in order to deliver the service and keep it secure. We do not use this data to build profiles or to advertise.
Cookies and local storage
This website sets no cookies. The app does not use cookies to track you. It stores a small number of items in your browser’s local storage, and they stay on your device:
- the random device identifier described above;
- the display name you chose;
- the party you are currently in, and tokens that let a device keep its host role for a party it started;
- your language and appearance preferences.
If you clear your browser’s site data, these are removed, and you will look like a new guest.
If you use an account, the app also keeps a sign-in session on your device.
Who we share data with
- People at your party see your display name, the songs you add, and any reactions you send. Anyone who has a party’s code can join it, so share codes with care.
- Our service providers, who process data for us under their own terms: Convex, which hosts our database and backend; Cloudflare, which hosts this website and the app and delivers them to you; and Resend, which sends the verification and password-reset emails (it receives your email address and the code in the message). They process data only to provide those services.
- Authorities, if the law requires it, or to protect the rights, safety and security of our users or the service.
We do not sell personal data and we do not share it for advertising.
Where your data is processed
Our providers operate in the United States and other countries, so your data is likely to be processed outside the country where you live, including in the United States. Where the law requires safeguards for that, such as standard contractual clauses, we rely on them or on our providers’ equivalent measures.
How long we keep data
- Parties. A party and its queue are deleted after it has been idle for a day.
- Accounts and what they hold (profile, saved themes, libraries and their stored credentials) are kept until you delete your account. You can do that yourself in the app, under your profile: sign-in stops at once and the rest is deleted in the background, usually within minutes and longer only for very large libraries. If you cannot sign in, write to legal@appology.dev. Names you used at a party stay in that party until it expires.
- Verification and password-reset codes expire after 20 minutes.
- Data on your own device stays until you clear it.
- Technical logs are kept by our hosting providers for the periods in their own policies.
Your choices and rights
Depending on where you live, you may have the right to ask us to give you a copy of your personal data, correct it, delete it, limit or object to how we use it, or move it to someone else, and to complain to your local data protection authority. Write to legal@appology.dev. We reply within two working days and carry out your request within 20 days, unless the law gives us longer. You can also delete your account yourself, in the app.
Because guests are identified only by a random identifier on their own device, we may not be able to connect a request to a particular guest. Clearing your browser’s site data removes that identifier from your device.
California residents. We do not sell or share personal information as those terms are defined under California law, and we do not use or disclose sensitive personal information for purposes beyond running the service. You have the rights described above, and we will not treat you differently for using them.
Vietnam. If you are in Vietnam, you have the rights set out in the Personal Data Protection Law (Law 91/2025/QH15) and Decree 356/2025/ND-CP, which you can exercise by writing to us. By using Let’s DJ you understand that your data is processed outside Vietnam as described above.
European Economic Area, United Kingdom and similar. Where those laws apply, we process your data to provide the service you asked for (performance of a contract), for our legitimate interests in keeping it secure and working, and, where needed, with your consent.
Security
We use reasonable measures to protect data, including encrypted connections, hashed passwords, encrypted storage credentials, and hashed pairing tokens. No service can promise perfect security. Treat a library token or a party code as you would any other secret, and tell us straight away if you think one has been exposed.
Children
Let’s DJ is not for children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has given us personal data, write to us and we will delete it. For people under 18, we recommend that a parent or guardian supervise use of the service.
Changes to this policy
We may update this policy as the service changes. The date at the top of the page tells you when it last changed. If a change is significant, we will say so in the app or on the website before it takes effect.
Contact
Appology Labs LLC
legal@appology.dev