Legal
Privacy Policy
Last updated: 25 May 2026
1. Who we are
Chorus Club is operated by Chorus Club Ltd, a company registered in England and Wales. We are registered with the Information Commissioner's Office (ICO) as a data controller.
If you have any questions about this policy or how we handle your data, contact us at chris@chorus.club.
2. What data we collect
Account data
When you create an account we collect your email address and the display name and username you choose. If you sign in via Google or Apple we receive only the name and email address that provider shares with us.
Performance submissions
When you submit a performance to a JAM we store the audio or video file you upload, the JAM and backing track it relates to, and the AI-generated feedback and scores produced for that submission.
Usage data
We collect standard server logs including your IP address, browser type and pages visited. We use this only to operate and improve the service - we do not use it for advertising or tracking.
Votes and interactions
We record the votes you cast on other performers' submissions so we can prevent duplicate voting and maintain leaderboard integrity.
Email preferences and consent
We record your email notification preferences and, where you have given consent to marketing emails, the date and method of that consent.
3. Why we use your data (lawful bases)
| Purpose | Lawful basis |
|---|---|
| Creating and managing your account | Contract |
| Processing and displaying your performance submission | Contract |
| AI analysis of your submission | Contract |
| Sending transactional emails (feedback, results, milestones) | Contract |
| Maintaining the leaderboard and vote integrity | Legitimate interests |
| Preventing fraud and abuse | Legitimate interests |
| Sending marketing emails (news, features, offers) | Consent |
| Complying with legal obligations | Legal obligation |
4. Who we share your data with
We use a small number of carefully selected third-party services to operate Chorus Club:
- Supabase - database, authentication and file storage (EU/US data centres with Standard Contractual Clauses where applicable).
- Google Gemini - AI analysis of your audio and video submissions. Submission files are sent to Google's API for analysis and are not retained by Google beyond the request.
- Resend - transactional and marketing email delivery.
- OpenAI (DALL·E) - used to generate JAM cover artwork. No personal data is included in these requests.
- Vercel - web hosting and deployment.
We do not sell your personal data to third parties. We do not use your data for advertising purposes.
5. AI analysis of your performance
When you submit a performance, your audio or video file is analysed by Google's Gemini AI model. This analysis scores your performance across dimensions including pitch accuracy, rhythmic timing, dynamics and overall feel. The score determines whether your submission reaches the public leaderboard.
This automated analysis does not make legally significant decisions about you. You can request a manual review of any AI decision by emailing chris@chorus.club.
6. How long we keep your data
- Account and profile data - kept for as long as your account is active. If you delete your account, your personal data is anonymised immediately.
- Submission files - kept while your account is active. Deleted when you delete your account or request removal.
- Anonymised leaderboard data - vote counts and ranks are retained indefinitely to preserve JAM history, but are not linked to any identifiable individual after account deletion.
- Server logs - retained for up to 90 days for security purposes.
- Email consent records - kept for 7 years to demonstrate compliance with ICO requirements.
7. Your rights under UK GDPR
You have the following rights regarding your personal data. To exercise any of them, email chris@chorus.club. We will respond within 30 days.
- Right of access - you can request a copy of all personal data we hold about you. You can also export it directly from Settings → Download your data.
- Right to rectification - you can correct inaccurate data via your profile settings or by contacting us.
- Right to erasure - you can delete your account and all associated personal data at any time from Settings → Delete account.
- Right to restrict processing - you can ask us to pause processing of your data while a dispute is resolved.
- Right to data portability - you can download your data in machine-readable JSON format.
- Right to object - you can object to processing based on legitimate interests. You can also withdraw marketing consent at any time from Email Settings.
- Rights related to automated decision-making - you can request human review of any AI-generated score.
If you are not satisfied with our response you have the right to lodge a complaint with the ICO at ico.org.uk.
8. Cookies
Chorus Club uses the following cookies:
- Authentication cookies - set by Supabase to keep you signed in. These are strictly necessary for the service to function. They are session cookies and expire when you sign out, or after 7 days.
- Preference cookies - we store your cookie consent choice in your browser's local storage so we don't ask again.
We do not use advertising cookies, tracking pixels or third-party analytics cookies.
9. International transfers
Some of our service providers (including Supabase, Google, and Vercel) may process data outside the UK or EEA. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the UK ICO.
10. Security
We use industry-standard measures to protect your data, including encrypted connections (HTTPS), encrypted storage, and role-based access controls. Submission files are stored in private Supabase Storage buckets that are not publicly accessible without a valid signed URL.
Despite these measures, no system is completely secure. If you believe your data has been compromised, contact us immediately at chris@chorus.club.
11. Age requirement
Chorus Club is an 18+ platform. You must be 18 years or older to use the service. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has created an account, please contact us at chris@chorus.club and we will delete it promptly. At launch, age will be verified at signup using a Highly Effective Age Assurance method in line with the UK Online Safety Act.
12. Changes to this policy
We may update this policy from time to time. If we make material changes we will notify registered users by email at least 14 days before the changes take effect. The "Last updated" date at the top of this page will always reflect the most recent version.
13. Contact
Chorus Club Ltd
Email: chris@chorus.club