Privacy Policy
What Afterglow collects, what becomes public, and what the current controls can—and cannot—delete.
1. About this notice
Afterglow is a radio service presented as Afterglow by dollhouse. This notice describes the owned Afterglow application, including its connection to the original ChatGPT Site. The operator’s legal name, jurisdiction and applicable privacy-rights contact details must be confirmed before this draft takes effect.
The proposed privacy and deletion-request contact is divanny@dollhouse.ai, the support address currently configured for the application. Do not send passwords, sign-in codes, session cookies or API keys.
2. What Google sign-in supplies
Afterglow requests only openid, email and profile. It verifies Google’s sign-in response and stores your stable Google account identifier, email address and display name with an Afterglow account ID. Your Google password is handled by Google, not Afterglow. The application does not request Gmail, Drive, contacts, calendar or Spotify access through Google sign-in.
Google may include other standard profile claims in its sign-in response. The current application does not fetch or store a Google profile photo. It processes the temporary authorization code and ID token to authenticate you; it does not request offline access or save Google refresh tokens. Temporary sign-in state and verification information are stored to complete the login safely.
Google identifiers and email addresses are used for sign-in and account administration, not as music-generation prompts or public profile fields. Ownership is linked by the verified Google identifier and, for an original account, a separate signed handoff—not by matching an email address or display name.
3. Station, profile and listening information
We store the station names, genres, colors, descriptions, musical direction, reference points, energy/discovery settings and feedback you provide; your chosen display name; station visibility and sharing identifiers; and recordings, titles, lyrics and associated generation metadata.
Account activity includes favorites and ratings, followed stations and DJs, station requests, playback bookmarks, and preferences. Listening features record station/track identifiers, browser-generated listening-session identifiers, playback position and duration, timestamps, and events such as plays, likes, follows, skips, shares and playback failures. Operator dashboards use these records to understand usage and diagnose problems.
Cloudflare processes network requests, including IP addresses and HTTP request information. The application uses the incoming IP address for authentication rate limiting, and Workers logs/traces can contain request and error metadata. This is separate from the listening records stored by the application.
4. What other people can see
New stations are public by default. A public station can appear in discovery and shared links with its name, genre, color/artwork, public description, DJ display name, broadcasting status, and aggregate listener/follower information. Public station archives expose available recordings, titles, lyrics, duration and download links, including older completed recordings.
Until you choose a display name, a new station’s DJ byline can use the first part of the name supplied at sign-in. Chosen display names are not unique and do not establish account ownership. Changing your display name updates your station bylines.
The application does not publish your Google email/identifier, private musical-direction fields, reference notes, or your complete favorites/following list as public profile fields. A station request is visible to its DJ. A description or generated song may still reflect information you put into a prompt; avoid sensitive personal information in station text or lyrics.
Making a station private restricts subsequent access through Afterglow’s public station, archive and media endpoints. It does not retrieve recordings someone already downloaded or remove copies, links, screenshots or search-engine records held elsewhere.
5. Providers, processing and storage
Cloudflare Workers serves the owned app and its media/composer services. Cloudflare D1 stores accounts, Google identity mappings, session records, account-link receipts/audit, station and profile data, favorites, listening records and operational metadata. Cloudflare R2 stores archived audio and generated artwork. These services are in the operator’s Cloudflare account; this notice does not promise a particular storage country or regional residency.
The planned canonical address is https://afterglow.dollhouse.ai. Its proposed Bunny HTTPS front end would process network requests, IP addresses, request paths and authentication traffic before forwarding them to Cloudflare. The proposed configuration bypasses caching for the application and preserves its secure cookies; the engineer must confirm the actual logging, retention and security settings before this notice is adopted. Account and recording storage remains in D1/R2 rather than being moved to Bunny Storage.
When enabled, OpenAI’s API provides songwriting, station-brief/public-description assistance and cover generation. Songwriting requests contain musical preferences, relevant previous song titles/styles/lyrics, feedback and sequencing context. Cover requests use station name, genre, public mood and an edition identifier. Private station direction can therefore be processed by a provider even though it is not shown as a public field. The current application does not include your Google identity or email in those generation payloads.
Audio generation uses operator-managed GPU workers running the configured music model. Worker jobs carry station/composition identifiers, generated lyrics, musical direction and technical parameters; workers store durable job history and audio artifacts. The project has also used Runpod GPU/storage infrastructure, and retained worker artifacts or backups may remain there. The planned archive-playback launch keeps new generation disabled; listening to an existing recording does not require a new model run.
The original ChatGPT Site and operator-held migration snapshots/backups also retain data during this migration. Some backups are encrypted, but that does not establish a deletion schedule. Removing an item from the owned app does not automatically erase the source Site, worker files, retained cloud volumes or backup copies.
The optional Spotify setup opens ChatGPT, where you may choose to connect Spotify. Afterglow itself does not receive a Spotify access token or directly query your Spotify library in this workflow. It receives the station directions you review and save, including any text you choose to paste or import. Google, OpenAI/ChatGPT, Spotify, Cloudflare and Runpod have their own applicable terms and data practices. No unverified promise about a provider’s training or retention settings is made here.
6. Cookies and browser storage
Afterglow uses a secure, HttpOnly sign-in session cookie and a short-lived OAuth-flow cookie. The application session currently expires after seven days and the login/handoff flows after ten minutes. These are access-validity limits, not promises that all corresponding database rows or logs are deleted at those times.
Local storage remembers selected stations and playback positions; session storage holds import drafts and listener sequence information. Clearing site data removes those browser copies and may sign you out, but does not delete server-side accounts or recordings. Google manages its own sign-in cookies. The audited app uses its own listening telemetry and does not embed a third-party advertising or Google Analytics tracking script.
7. Your controls and deletion requests
When application writes are enabled, you can change your display name and station settings, make a station private, remove favorites/follows, and delete a station through its settings. The current migration rehearsal temporarily blocks those changes.
Station deletion removes the station’s database record and related records covered by its database relationships, and attempts removal of referenced audio and cover objects. It is not a complete account-erasure feature: separately stored originals, worker artifacts, historical copies and backups can remain, and cleanup can fail or require operator review.
There is currently no self-service Delete account or erase-all-copies endpoint. To request deletion, email divanny@dollhouse.ai with the account you use and what you want removed, plus station or recording links if relevant. The proposed operator workflow is to verify that you control the account, identify the affected stores and backups, review any applicable retention obligations, and report what was removed or remains. The operator must approve and operate that workflow; this draft does not promise an automated deletion process, a fixed turnaround or immediate erasure of every copy.
Signing out revokes that Afterglow session. Disconnecting an original account revokes its account sessions and disconnects its mapping; it does not delete the original stations or recordings. Removing Afterglow’s access in your Google Account is also not an Afterglow data-deletion request. Contact the operator to discuss any access, correction or deletion rights that apply to you.
8. Retention and changes
The current implementation has no comprehensive automatic retention/deletion schedule for account, listening, linkage, worker or backup data. Some records expire for access or playback purposes while their rows can remain stored. A documented retention schedule and backup handling process are operator decisions still required before adopting this notice. We do not claim that data is deleted after a particular number of days.
This page is an approval draft, not an effective policy. Before publication, the operator must confirm its identity/contact information, data-handling practices and unresolved decisions. Future material changes should be reflected in an updated notice before the changed practices are used.