Privacy Policy
Effective Date · September 1, 2026
This Privacy Policy explains how FourMeasure, Inc. ("Four Measure", "we", "us") collects, uses, shares, and protects information when you use the Four Measure mobile application and related services (the "Service"). By using the Service, you agree to this Policy. If you do not agree, do not use the Service.
1. Who We Are
The data controller responsible for your information is FourMeasure, Inc., 500 Oleander Drive, Hallandale Beach, FL 33009. For any privacy question or request, contact support@fourmeasure.com.
2. Information You Provide
- Account information: an email address or a phone number. A password is optional and depends on how you sign up — accounts created with a phone number or with Google/Apple have no password unless you add one. You may also add a recovery email address, or link a Google or Apple account, so you have more than one way back in.
- Your phone number, if you provide one. A verified phone number is stored as a sign-in identity for your account. We also store a one-way keyed hash of it (a scrambled form that cannot be reversed back into the number), which is what lets the "find friends" feature below work. See the note on being found by phone number below.
- Profile information: username, display name, bio, profile photo/avatar, your "top items" (favorite songs/albums), and your favorite genres.
- Date of birth (to confirm you meet our minimum age and for age-appropriate features).
- Content you create: posts, reviews, ratings, comments, reactions, and the contents of direct messages (including any images or media you attach).
- Photos you upload: if you add a photo background to a review, we collect and store the image you capture. Review backgrounds are taken with the in-app camera, and we do not support video. Profile pictures and images you attach to direct messages can also be chosen from your photo library, which the app asks your permission to open — we receive only the specific images you pick, never your library as a whole. We strip embedded metadata, including EXIF location (GPS) data, from every image on upload, before it is stored. Uploaded photos are screened automatically for explicit content and may be rejected. If you turn on saving reviews to your camera roll, the app writes a copy of the finished review card — your photo with the song title, artist, rating, and cover art shown on it — to your device's photo library. That copy is made on your device and stays there: turning this on sends us nothing and creates no new information we hold about you. You can turn it off at any time in Settings. (See our Community Guidelines.)
- Reports and communications: reports you submit about content or users, and messages you send to support.
- Contacts — only if you choose to. On the "find friends" step you can ask us to check whether people already in your phone's address book are on Four Measure. This is optional: you can skip the step, decline the permission, or turn it off later in your device settings, and the rest of the app works either way. If you do turn it on, the app sends us the phone numbers from your address book. We convert each one to a one-way keyed hash, compare those hashes against the phone numbers of existing accounts, and show you the matches. We use the numbers only for that comparison — we do not store the numbers you send us, we do not keep the hashes, and we do not create a record of, or send anything to, people in your contacts who are not already Four Measure users. We never sell or share contact data, and we do not use it for advertising. Contacts are not shared with any third party.
- Being found by your phone number. The "find friends" feature works in both directions. If you have verified a phone number, anyone who has that number in their address book and uses this feature will be shown your account — and there is currently no setting to turn this off. Only people who already have your number can find you this way; your number is never shown to them, and it is never revealed to anyone who does not already have it. If you would prefer not to be discoverable this way, do not verify a phone number, or contact us at support@fourmeasure.com.
3. Information We Collect Automatically
- Device and instance identifiers: a Firebase Cloud Messaging push token (to deliver notifications) and a first-party Firebase analytics app-instance identifier, both associated with your account. We do not collect advertising identifiers (Apple's IDFA or Android's Advertising ID).
- A device identifier we generate. The app creates a random identifier for your phone and stores it on the device. We receive it when your device registers for notifications, and we use it for one purpose: if more than one account signs in on the same phone, it lets us send a notification once instead of once per account. Unlike the identifiers above, it is stored on your device independently of any account — it is not cleared when you log out, and on iOS it can survive reinstalling the app. On our servers it is attached only to the notification settings of whichever account is currently signed in: it is deleted when that account is deleted, and when another account signs in on that phone. We do not use it for advertising, analytics, or tracking you across other apps.
- Your device's time zone (for example, "America/New_York"), sent when your device registers for notifications. We use it to send time-sensitive notifications at a sensible hour where you are, and to work out daily streaks. It tells us roughly what part of the world you are in; it is not precise location.
- Log and usage data: IP address, device/user-agent information, timestamps, and actions taken in the app (e.g., posts viewed, features used).
- Approximate location (no GPS): we do not collect precise or GPS location, and the app does not request location permission. Our analytics provider (Google/Firebase) derives an approximate location (such as country or city) from your IP address for analytics. We also use and retain your IP address to secure your account, manage your active sessions, and help prevent fraud.
- Analytics and diagnostics (mobile SDKs):
- Firebase Analytics (Google) — a fixed set of product-interaction events (such as sign-up, login, post created, follow) keyed to your internal account identifier, not your name, email, or phone.
- Firebase Crashlytics (Google) and Sentry — crash and error diagnostics (stack traces and device state) tied to your internal account identifier.
- No advertising or cross-app tracking: the app contains no advertising or attribution SDKs, does not display ads, does not present Apple's App Tracking Transparency prompt, and does not track you across other companies' apps or websites.
4. Information From Third Parties
- Single sign-on: if you sign in with Google or Apple, we receive basic profile information from them (such as your email, name, and avatar) per your settings with that provider.
- Connected music providers: if you connect a music account (e.g., Spotify, Apple Music), we receive information needed to provide the integration, which may include your now-playing/listening activity (when you enable that feature) and access tokens. We store provider access and refresh tokens encrypted and use them only to provide the features you enabled.
- Phone verification: when you verify a phone number, our verification provider (Firebase Phone Authentication) confirms the number to us.
5. How We Use Information
We use information to: create and secure your account; provide and personalize the Service (feeds, profiles, recommendations, messaging); deliver notifications; enable features you turn on (such as music-provider integrations); maintain safety and integrity (moderation, abuse prevention, enforcing our Community Guidelines); analyze and improve the Service; communicate with you about the Service; and comply with legal obligations. Where required by law, we rely on legal bases including performance of our contract with you, your consent (which you may withdraw), our legitimate interests (such as security and improving the Service), and compliance with legal obligations.
6. How We Share Information
We do not sell your personal information for money, and we do not share it for cross-context behavioral advertising. We share information only as follows:
- With other users: your profile and the content you choose to share are visible to others according to your settings. If your account is private, your content is limited to approved followers. Direct messages are visible to participants in the conversation. If a direct message is reported, that message becomes visible to our moderation team so the report can be reviewed; only the reported message is shown, not the surrounding conversation.
- Service providers (sub-processors) who process data on our behalf under contract:
- Amazon Web Services (AWS) — cloud hosting, file/media storage (S3), content delivery (CloudFront), automated image content-safety screening (Rekognition), and transactional email (SES).
- Google / Firebase — push notifications (FCM), phone-number verification (Phone Authentication / SMS), product analytics (Firebase Analytics), and crash diagnostics (Firebase Crashlytics).
- Sentry — crash and error monitoring/diagnostics.
- Spotify and Apple Music — only if you connect those accounts.
- Giphy — GIF search within comments and messages.
- Musixmatch — music metadata.
- For legal and safety reasons: to comply with law or valid legal process, enforce our Terms, or protect the rights, safety, and security of users, the public, or Four Measure.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
7. Your Choices and Rights
- Access, update, and delete: you can view and edit your profile in the app, and you can delete your account at any time from the app, which removes your account and associated personal data (subject to limited retention described below).
- Notifications: you can control push notifications in your device and app settings.
- Connected accounts: you can disconnect a music provider at any time.
- Contacts: finding friends from your contacts is optional. You can skip it, decline the permission, or revoke it at any time in your device settings. Because we do not store the numbers or hashes from your address book, there is nothing left for us to delete when you revoke it.
- Privacy (GDPR/EEA/UK): if you are in the European Economic Area or the UK, you have rights to access, rectify, erase, restrict, or object to processing of your personal data, to data portability, and to withdraw consent. You may also lodge a complaint with your local supervisory authority.
- Privacy (California/US state laws): if you are a California resident (or in a U.S. state with similar laws), you have rights to know, access, correct, and delete your personal information, and to not be discriminated against for exercising them. Because we do not sell or "share" personal information for advertising, no opt-out of sale/sharing is needed.
To exercise any right, contact support@fourmeasure.com. We will verify your request and respond as required by law. You may use an authorized agent where permitted.
8. Data Retention
We keep personal information for as long as your account is active or as needed to provide the Service, and afterward only as necessary to comply with legal obligations, resolve disputes, enforce our agreements, and for reasonable backup/security purposes. When you delete your account, we delete or de-identify your personal data within 30 days, except where a longer retention period is legally required. Application security and server logs (such as IP addresses) are retained for up to 90 days and then automatically deleted. Infrastructure logs held by our hosting provider may be retained separately under that provider's retention settings.
Sign-in and verification records. Signing in, verifying a phone number or email address, and confirming a sensitive change all create short-lived records — such as a one-time code or a confirmation token — so we can check the step was completed. These expire quickly, typically within minutes, and cannot be used again afterward. They are deleted when your account is deleted, and expired ones are cleared automatically.
Moderation and enforcement records. When we take a moderation or enforcement action — for example removing content, or suspending or banning an account — we keep a record of that action, including which staff member took it and why. These records are retained after an account is deleted, for safety, abuse-prevention and legal purposes, so that enforcement history is not erased by deleting and re-creating an account.
Photos. Photos you upload are stored for as long as your account exists. If you replace or remove a photo, the image may remain in our storage and in content-delivery caches for a period afterward. When you delete your account, photos attached to your posts are deleted from our storage; copies may persist in caches for a period after removal.
9. How We Protect Information
We use technical and organizational measures to protect your information, including encryption in transit, hashing of passwords, and encryption at rest for sensitive items such as connected music-provider tokens. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.
Photos are served publicly. Photos attached to posts are delivered from a public content-delivery network. Anyone with the direct link to an image may be able to view it, even if the post it belongs to is later restricted, made private, or removed.
10. Children's Privacy
The Service is for users 16 and older. We do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided us personal information, contact support@fourmeasure.com and we will take steps to delete it. If you are between 16 and the age of majority where you live, use the Service only with a parent or guardian's consent.
11. International Data Transfers
We operate primarily in the United States, and your information may be processed in the United States and other countries that may have different data-protection laws than your own. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers.
12. Third-Party Links and Services
The Service may link to or integrate third-party services. Their use of your information is governed by their own privacy policies, not this one. Review the privacy policies of any music provider or other service you connect.
13. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will provide notice (for example, in the app) and update the "Last updated" date. Your continued use of the Service after changes take effect constitutes acceptance.
14. Contact Us
Questions or requests about this Policy or your information: support@fourmeasure.com, or FourMeasure, Inc., 500 Oleander Drive, Hallandale Beach, FL 33009.
