Catwalk — Privacy Policy

Last updated: 18 July 2026  ·  Applies to version 1.8.x and later

1. Overview

Catwalk ("the App") is an independent internet radio player and music identification app developed by Sahar Okuniev ("we", "us", "our"). This Privacy Policy explains what information the App accesses, how it is used, and your rights.

Short version: the App does not collect, transmit, or store personally identifiable information on our servers. All persistent user data lives exclusively on your device. A pseudonymous device identifier is used for service access control and beta-test usage tracking as described in Section 4.5.

2. Data Stored on Your Device

Favorites & History local only

Favorite stations, listening history, and identified track history are saved to a SQLCipher-encrypted database on your device and never uploaded to any server.

Audio Recordings local only

Recordings are saved to your device's private storage directory, inaccessible to other apps, and never uploaded to any server.

PIN & Biometric Authentication local only

Your PIN is stored as a cryptographic hash. Biometric authentication uses the device's secure enclave / keystore. No credentials leave your device.

Location Tags local only

If you choose to attach a location to a recording or identified track, that location is stored in the encrypted local database only and is never transmitted.

3. Microphone Access

The App requests microphone permission for two purposes only:

4. Third-Party Services

4.1 Google AdMob

The App displays ads served by Google LLC. Google may collect advertising identifiers to serve personalized ads, subject to your ATT consent (iOS) or device settings (Android). Privacy Policy: policies.google.com/privacy

4.2 AudD Music Recognition API

Song identification uses the AudD API (audd.io). A short audio snippet (≤ 5 seconds) is sent to their servers for matching and is not stored by us. AudD's privacy policy governs their handling of this data: audd.io/privacy

4.3 Radio Streams

Radio streams are provided by independent third-party broadcasters. The App does not host audio content. Each broadcaster's own privacy policy applies to their streams.

4.4 Sentry (Crash Reporting)

The App may send anonymous crash reports to Sentry.io containing technical data (device model, OS version, stack trace) — no personal data or audio content. Privacy Policy: sentry.io/privacy

4.5 Beta Access Control & Usage Limits

During beta testing, the App transmits a pseudonymous device identifier (a random UUID generated on first launch, stored in device secure storage) to our backend server on each app start and on each song identification request. This identifier is used solely to:

The device identifier is pseudonymous — it cannot be linked to your name, email address, or any other personal information unless you have provided that information to us separately. It is stored in Cloudflare KV (a key-value store operated by Cloudflare, Inc., subject to Cloudflare's Privacy Policy). It is retained for the duration of the beta programme and deleted when beta access is revoked or the programme ends. Beta testers who bring their own AudD API key (configured in Settings) are not subject to this limit.

5. Permissions Summary

PermissionPurpose
RECORD_AUDIOSong identification (CatEye RadioScan) & in-app recording
ACCESS_FINE/COARSE_LOCATIONOptional geo-tags on recordings & identified tracks
USE_BIOMETRIC / USE_FINGERPRINTLocal biometric unlock for the app PIN screen
POST_NOTIFICATIONSPersistent playback notification with media controls
FOREGROUND_SERVICEBackground audio playback

6. Children's Privacy & Age Recommendation

The App is not directed at children under 13. We do not knowingly collect personal data from children under 13. If we learn that personal data has been collected from a child under 13, we will delete it promptly.

Recommended age: 18+. The App includes features such as content sharing, location tagging, and in-app advertising that are better suited to adult users. Users under 18 should use the App only with parental consent.

The App also includes the following features that involve sensitive personal data and are intended for adult users:

These features require the Android permissions ACCESS_FINE_LOCATION, RECORD_AUDIO, and READ_CONTACTS. You will be prompted to grant each permission before the relevant feature is used.

7. Data Retention & Deletion

All user data is stored locally on your device. You can delete any data within the App at any time. Uninstalling the App removes all locally stored data permanently.

8. Your Rights (GDPR / CCPA)

Because we do not store personal data on our servers, there is no data to access, correct, or delete on our end. All data is under your direct control on your device. For privacy-related questions, contact us at sahar.okuniev@yahoo.com.

9. Changes to This Policy

We may update this Privacy Policy from time to time. The current version will always be available at this URL. Continued use of the App after changes constitutes acceptance of the updated policy.

10. Contact

Email: sahar.okuniev@yahoo.com