Privacy Policy

Effective September 16, 2026

Bad Rap is a free music platform showcasing Christian hip hop artists, including Lowery. The app is designed so users can stream featured music, view lyrics, and download tracks for offline listening without creating an account.

Information We Collect

Bad Rap does not require an account and does not ask for your name, email address, phone number, contacts, photos, location, or payment information to listen to music.

When the app contacts our service to load the catalog, stream audio, download artwork, or play music, routine technical request data may be processed, such as IP address, device or browser user agent, requested file or endpoint, response status, and timestamps. On Apple apps and the public web player, playback analytics may include the track being played, playback state, approximate playback position, platform, device family, operating system, browser, app version, and approximate location derived from request metadata, such as city, region, postal code, and country. On supported Apple devices, Apple MetricKit performance and diagnostic reports may include launch, responsiveness, CPU, memory, disk-write, hang, and crash information. MetricKit reports are sent to our first-party service with app version and device/OS context; raw source IP address and user agent are retained with the report. Apple TV sends app-collected CPU, sampled memory, foreground time, startup, responsiveness, memory-warning, and app-network measurements with the same device/OS and request context. These app observations are labeled separately and do not include Apple OS hang or crash diagnostics. We use this information for app functionality, security, troubleshooting, abuse prevention, catalog insight, and service reliability.

On the public website, first-party usage analytics may include normalized page paths, internal navigation destinations, active engagement time, scroll-depth milestones, referrer hosts, limited campaign parameters, platform, device family, operating system, browser, viewport size, network type, raw IP address, browser user agent, and approximate location derived from request metadata. These events use a random per-tab session identifier and do not include form values, page text, or arbitrary URL query values. Web usage event IP addresses and browser user agents are retained with the event record under the configured analytics retention period. The website honors Global Privacy Control and Do Not Track for this usage analytics, and blocking the analytics endpoint does not prevent pages, navigation, or playback from working.

If you contact support, we receive the information you choose to send, including your email address, message, and any app or device details you include.

Android App Data

Android version 1.1 uses daily aggregate counts to help improve Bad Rap. The app reports play starts, completed downloads, and playback or download failures with the UTC day, app version, a broad device category, network category, and, when available, catalog track and album identifiers. It does not send listening position, duration, song titles, raw error messages, a date of birth, or an installation identifier with those counters. A fresh random event identifier prevents a retry from being counted twice; it does not link separate listening events to a person or installation.

Counters can wait on the device for up to seven days when delivery is unavailable. Bad Rap combines them into daily totals without storing the original event identifiers or adding request IP address, user agent, or IP-derived location to that aggregate store. Separate infrastructure and delivery logs may still process technical request information, including IP addresses. The aggregate totals measure reported actions, not unique listeners.

Earlier Android versions used an installation-persistent random identifier and sent more detailed playback and download events, including content titles, positions, durations, app/device context, and error details. Our legacy service could add IP address, user agent, and approximate location derived from the request. Version 1.1 removes the old identifier and unsent detailed events from the device rather than uploading them. Updating or uninstalling does not itself remove historical server records. The app does not request GPS location.

Optional Android Notifications

Music, lyrics, downloads, and in-app News do not require a Bad Rap account, an age entry, a parent email, or notifications. New music and News & updates notifications are separate choices, both off by default. The phone and tablet app asks only for Android notification permission when needed. It does not ask you to enter an age or a parent email, send a parent notice, or complete an approval flow.

On supported devices, Bad Rap silently checks whether Google Play already provides an age signal. Bad Rap does not launch Google's age-sharing prompt. Only a current Google result establishing an adult age range, with no unresolved protection restriction, can enable Google Firebase Cloud Messaging after you opt in. A self-declared Google range is not verified proof of age. If an adult range is not established, including for children, teens, unavailable checks, or expired checks, opted-in announcements use local notifications based on the public announcement feed. Older local age answers do not authorize push delivery. Google Play and Family Link can independently restrict app access.

Google's raw age range, assessment source, approval signals, and supervised-install identifier are not sent to Bad Rap's servers or listening analytics. The app keeps limited protection state and check validity locally. An adult push registration identifies its adult authorization route, which can imply an age category. This information is used only to choose and enforce notification delivery, not for analytics, advertising, marketing, or a listening profile. Google Play's own processing is governed by Google's terms.

For local notifications, the app fetches the same public announcements without sending a notification token, installation identifier, parent contact, age signal, category preference, or account credential. Category choices and the record of announcements already considered stay on the device. Routine technical request data, such as IP address, user agent, and request time, may still be processed by our hosting and traffic providers. The app checks when opened and requests background checks about every 15 minutes while local notifications are enabled. Android may delay or stop those checks because of battery settings, connectivity, background limits, or a force-stop; alerts are not guaranteed to arrive immediately. This delivery method does not initialize Firebase Cloud Messaging.

For opted-in adults with Android notification permission and a current eligible Google result, Firebase Cloud Messaging provides push delivery. Google processes a Firebase installation identifier, notification registration token, app version, and technical app/device information. Bad Rap stores the notification token, registration/update times, permission state, app version, device family, adult authorization route, and category choices with their update revision. These records remain separate from listening counters and are not used for advertising or a listening profile. Wear OS and Android Automotive builds do not include Firebase Cloud Messaging.

The updated app retires earlier parent-notice and parent-approval notification setup. It stops using those permissions, requests deletion of any previous parent request and associated notification registration, and retries cancellation when a connection is available. Switching from push to local delivery also requests removal of the old push registration. These requests do not mean historical server records have already been deleted. Private links from earlier parent emails can still remove associated legacy records; they do not control the updated app's local notification choices.

Turn both notification categories off inside the app to stop local checks and alerts and request removal of its push registration. Failed server deletion requests are retried when possible. Android's separate system notification control affects display and is not itself a request to delete server records. Already delivered alerts cannot be recalled.

Apple Announcements

If you enable announcements in an Apple app, it sends a push-notification token, platform, app version, device family, delivery environment, and announcement preference to our service. We retain this registration to deliver announcements, including Home Screen badges on Apple TV. Turning announcements off stops that delivery by updating your preference; it does not delete the registration record. Apple registration records are stored separately from playback analytics and do not have automatic age-based expiry. We do not use these tokens for advertising or tracking. Android's notification delivery options do not change the Apple app's current controls.

Google Play Reviews

If you choose to rate or review Bad Rap through Google's in-app review prompt, Google Play processes your rating and review. Reviews may be public; feedback on a closed test is shared privately with the developer. The in-app review API does not return your review text to Bad Rap. You can delete your review through your Google Play or Google Account.

Offline Downloads

Downloaded tracks, cached artwork, playback state, and app preferences are stored on your device so the app can work smoothly and play content offline. Removing the app or deleting downloaded content from the app removes that local copy from the device.

How We Use Information

What We Do Not Do

Service Providers

We may use service providers to host the app service, deliver website or media traffic, process support email, and maintain security. Google Firebase provides eligible adult Android push delivery, Postmark handles support email and earlier parent-notification correspondence, and our hosting and traffic providers process technical requests, including public announcement feed requests. Provider operational records are governed by their applicable service and privacy terms. Bad Rap does not enable Firebase Analytics, advertising trackers, or notification engagement exports in the Android app.

Children's Privacy

Children, teens, and adults are among Bad Rap's intended audience. Core content does not require an account or personal contact details. Children and users without a current eligible adult Google result can choose app-related music and News alerts delivered locally from the public feed. The updated app does not collect a parent email or register these users for Firebase push delivery. Category choices and announcement history for this delivery stay on the device, separate from aggregate listening counters. These choices do not authorize advertising, personalized marketing, or a listening profile.

A parent or guardian can help manage the app's notification choices or Android's system notification settings and can contact us about information a child provided through support. Existing private parent email links remain available for deletion of legacy parent and notification records. Notifications are optional and do not unlock or restrict music. Bad Rap does not override Google Play or Family Link controls.

Retention and Deletion

Android aggregate daily counters have a 90-day retention window. Hashed retry identifiers expire no later than eight days after the event day and are not linked to the counters. The updated app requests cancellation of legacy parent requests and removal of their associated notification registrations. Until deletion completes, the existing legacy limits remain: unanswered requests or notices without confirmed delivery expire after 48 hours, and approval or delivered-notice eligibility expires after 180 days without silent renewal. Scheduled hourly cleanup removes expired parent contacts, notices, approvals, associated registrations, and token copies from Bad Rap's configured announcement queues and archives. Legacy email delivery identifiers are retained for up to seven days while their request remains active; delivery status may remain with that record until removal. Security rate-limit hashes expire within 24 hours. A canceled-request hash is kept for 48 hours to prevent delayed requests from restarting it; it contains no contact or device details. Parent emails are not retained for newsletters or marketing.

The legacy analytics service is configured with a 90-day cleanup window for event records. Its cleanup runs as new events are processed, so records may remain longer when processing is inactive. Playback session summaries use their last activity time. These periods do not apply to separate server or CDN logs, backup copies, Apple push registrations, support correspondence, or records held by service providers.

Removing downloads removes those device copies. Clearing app data or uninstalling removes local settings, local announcement history, and any saved cancellation credentials, but is not a remote deletion request. A parent can still use a private link from an earlier email to delete its associated legacy records. Bad Rap cannot recover lost private credentials or identify an individual listener from aggregate counters. For privacy questions or deletion requests involving identifiable records, use the Support form. Provider operational records, backups, and alerts already delivered are outside the immediate notification-deletion flow.

Your Choices

You can use the app without creating an account. You can remove downloaded tracks inside the app, delete the app from your device, or contact us to request deletion of support messages associated with your email address.

Changes

We may update this policy as the app changes. If we make material changes, we will update the effective date and publish the revised policy at this URL.

Contact

Dickens Technologies LLC
8605 Santa Monica Blvd PMB 212899
West Hollywood, California 90069-4109 US
Telephone: (213) 679-0732
Privacy email: support@badrap.app

For privacy questions or support requests, use the Support form.