Updated: 18 September 2026

This policy covers Surf City Apps websites, language sites, the MP3 store and mobile apps. The following summary describes website choices; the full policy below also explains app data processing. Website cookie choices do not control app SDKs.

Your choice is shared across these sites for 180 days. Necessary cookies support consent preferences, security, sign-in, the cart and requested payments. Optional analytics and external content stay off until you agree. Rejecting optional cookies does not prevent purchases.

Google Analytics is currently used by the MP3 store only. Advertising tags remain disabled. Third-party embedded content is optional. Fonts are served from our own server. Stripe loads for checkout and other requested payment functions.

Use Privacy settings to change or withdraw consent at any time. Withdrawal stops future optional loading and removes accessible analytics cookies; it does not erase earlier server records. Global Privacy Control keeps analytics blocked. Clearing browser data or changing browsers may require a new choice.

We store a random consent identifier, choices, time, site, language and the policy version on our own server. Consent receipts do not store your IP address or browser user-agent. The website and security infrastructure may separately process connection and security logs.

Surf City Apps LLC is responsible for these websites. For privacy requests: privacy@surfcityapps.com, 440 N Barranca Ave #2975, Covina, CA 91723, USA. Depending on applicable law, you may request access, correction, deletion or portability, object to or restrict processing, withdraw consent and complain to your data protection authority. We may verify your request. We do not charge or discriminate for exercising applicable rights.

1. Who we are and what this policy covers

Surf City Apps LLC is responsible for the personal information described in this policy. It covers our Surf City Apps websites, language sites, MP3 store, mobile apps and related customer support. Website cookies and app SDKs are different: your website cookie choice does not change data collection within an app. The services available and providers used can vary by app, version and platform.

Contact us at privacy@surfcityapps.com or Surf City Apps LLC, 440 N Barranca Ave #2975, Covina, CA 91723, USA. Our EU representative is BizLegal Ltd, trading as EU Rep, 27 Cork Road, Midleton, Co. Cork, Ireland (company number 635921), eurep.ie.

2. Information we process

The following describes the categories, sources, purposes and recipients of information processed through our services. A provider receives only the information relevant to its function; the table does not mean every provider receives every category.

Category and source Examples and purpose Recipients for these functions
Identifiers and contact information, from you and your browser or device Name and email supplied for orders or support; IP address, app installation and device identifiers, store/customer identifiers and a random website consent identifier. Used to deliver services, manage purchases, respond to requests, protect systems and remember choices. Hosting and security providers; payment and app-store providers; support and email providers; app diagnostics and purchase-management providers as described below.
Commercial information, from you, our store and app stores Products purchased, order and transaction identifiers, purchase or restoration status and entitlement records. Used for delivery, unlocking purchases, support, fraud prevention and business records. Hosting providers, Stripe, Apple or Google Play, and Superwall in apps that use it.
Internet or app activity and technical diagnostics, from your browser, device and service providers Pages or screens viewed, feature and playback interactions, session counts, paywall interactions, device model, operating system, app version, errors, crash reports and performance information. Used for permitted analytics, product improvement and troubleshooting. Google Analytics/Firebase; Superwall for paywall and purchase-related activity; Sentry in supported app versions; hosting/security providers; optional embedded-content providers when loaded.
Approximate location, derived by providers from connection information Country or region associated with an IP address or app-store/device configuration, used for service operation, aggregate reporting and appropriate purchase offers. This is different from precise GPS location. Relevant analytics, hosting, app-store and purchase-management providers.
Support communications, supplied by you Your message, contact details and any attachments or order details you choose to send. Used to answer your request, investigate problems and resolve disputes. Please do not send health records or payment-card details. Our support, email and hosting providers, and a relevant service provider when needed to investigate your request.

The apps do not require you to enter your name or email to listen. This does not make device identifiers, usage events or purchase records anonymous. App and MP3 titles and listening or purchase activity may reveal interests in wellness topics; they are not medical diagnoses. Settings such as volume and reminders are stored on your device, although related feature interactions or session counts may be included in app analytics.

Payment-card details are handled by Stripe or the applicable app store. We receive transaction and purchase-status information rather than your complete card details. If you do not supply information needed for an order or a support request, we may be unable to complete that transaction or answer the request.

3. Website cookies and your choices

Necessary storage supports security, consent preferences, sign-in, carts and requested payment functions. Optional analytics and third-party content remain blocked until you allow the relevant category. You can reject optional cookies and still browse and buy MP3s. Google Analytics is currently enabled only on the MP3 store and only after permission. Advertising tags are disabled.

Use the floating privacy icon to change or withdraw your choice. Withdrawal stops future optional loading and removes analytics cookies accessible to our site; it does not itself delete information already received by providers. Your choice is shared for 180 days across surfcityapps.com and its active language and MP3 subdomains in the same browser. It does not carry to mobile apps, another browser or device, bubblz.ai or successminds.com. A parent-domain cookie is also sent to Surf City Apps subdomains hosted by our service providers. Clearing browser storage can require another choice.

We honor Global Privacy Control by keeping website analytics blocked. We do not separately interpret the older Do Not Track header; optional website tracking still requires your permission. Details of storage, purposes, providers and expiry appear in our Cookie policy.

Our self-hosted consent service records a random identifier, choices, time, site, language and policy version. Consent receipts do not store IP addresses or browser user-agent strings. Separate hosting and security systems may process connection logs.

4. Mobile apps and their providers

  • Google Analytics for Firebase: app usage, device and installation information and interaction events, used to understand app use and improve features.
  • Firebase Crashlytics and, where included, Performance Monitoring: crash reports, device/app context and performance diagnostics, used to find and fix failures. Firebase Remote Config supplies app configuration and can process installation identifiers.
  • Superwall, in apps that include it: pseudonymous app-user/device identifiers, device and country information, paywall and app interactions, session counts and purchase/entitlement information, used to present purchase offers, manage access and measure purchase flows.
  • Sentry, in selected app versions: errors, crashes, hangs, release/session health and limited events preceding an error, used for troubleshooting. Our current Sentry configuration disables session replay, screenshots and profiling, does not supply a named user profile, and applies IP scrubbing.
  • Apple App Store and Google Play: purchases, restoration and transaction records. These stores also process information under their own privacy notices.

Our apps currently do not display an in-app consent prompt before initializing their analytics and purchase-management SDKs. These SDKs operate independently of the website consent service. Browser cookie rejection does not disable them. A link to this policy is provided in the app-store listing; the policy describes our practices and is not itself a request for consent. You can contact us about app information using the details below; tell us the app, platform and nature of your request so we can identify the relevant records. We may not be able to associate a device-only identifier with your email without additional information.

Older app versions used Flurry, Apsalar or Crittercism. They are not included in current versions; older installations or records held by those providers may still be subject to their policies. System sharing buttons send information to a chosen service only when you use the sharing function.

5. Apple Health and sensitive information

In iOS apps with Apple Health integration, you can choose to allow mindful-session start times and durations to be written to HealthKit. We do not receive the HealthKit record on our servers or use it for advertising. Apple Health storage and any synchronization follow your Apple settings. You can manage access and delete records through Apple Health. Android apps do not connect to a health or fitness platform. Ordinary app usage and session-count analytics described above are separate from HealthKit records.

6. Purposes and legal bases

Where the GDPR or a similar law applies, we rely on contract performance to deliver requested purchases and restore access; legitimate interests to operate and secure our services, investigate errors, prevent misuse and answer support requests; and legal obligations for required accounting, regulatory and legal records. Our interests include understanding app use and improving reliability and purchase flows, subject to the protections and consent requirements of applicable law.

Optional website analytics and embedded content rely on consent. Where applicable law requires consent for optional device access or app analytics, providing this notice or continuing to use an app does not by itself provide that consent. HealthKit access requires your device permission. Where processing relies on consent, you can withdraw it without affecting the lawfulness of earlier processing. Where we rely on legitimate interests, you may object.

7. Disclosures and international processing

Our websites and consent records are hosted with Amazon Web Services in the United States. We use the providers above for payment, app operation, analytics and diagnostics, and support/email providers to communicate with you. Optional website support or media embeds receive connection information when you allow them to load. Those providers may also process information for their own purposes as explained in their notices.

We do not use advertising cookies or these integrations to sell personal information or share it for cross-context behavioral advertising. We may disclose relevant records where legally required, to protect rights or security, to professional advisers subject to confidentiality, or in connection with a business transfer subject to applicable privacy protections.

Information may be processed in the United States and other countries where our providers operate. These countries can have different privacy laws. AWS incorporates Standard Contractual Clauses in its service terms for covered transfers. Other providers describe safeguards such as Standard Contractual Clauses, applicable UK terms or participation in an applicable Data Privacy Framework in their data-protection terms. The applicable mechanism depends on the provider, data and transfer. Contact us for information or a copy of safeguards relevant to your information.

Provider information: AWS, Google, Firebase, Stripe, Apple, Superwall, Sentry.

8. How long information is kept

Retention depends on the information and purpose. Browser expiry is different from retention of data already received by a service.

  • Website consent: the browser preference lasts 180 days; consent evidence is retained for up to three years. Daily consent-database backups rotate after 30 days. Separate infrastructure recovery snapshots follow their backup lifecycle.
  • Orders and entitlements: kept while needed to deliver or restore a purchase, handle refunds or disputes, and satisfy applicable accounting, tax and legal requirements. A continuing right to restore a purchase can require keeping a purchase record after active use ends.
  • Support and security: kept according to the time needed to resolve the request or incident, detect recurring faults or abuse, and address related legal claims. A legal hold can extend retention of relevant records.
  • Analytics and diagnostics: retention varies by provider, service and configured reporting period. Firebase states that Crashlytics begins removing crash traces and associated identifiers after 90 days. Other analytics, performance, Sentry and Superwall records follow their applicable service and account retention settings and deletion processes; contact us for information about a particular app or record.
  • Local settings and HealthKit: retained until removed through app/device controls, subject to your device backup and Apple Health settings. Uninstalling an app does not necessarily delete provider-side records or Apple Health data.

9. Your privacy rights and requests

Depending on where you live and which laws apply, you may have rights to know or access the information we hold, obtain a portable copy, correct inaccurate information, request deletion, restrict or object to processing, withdraw consent, or opt out of sale, sharing, targeted advertising or certain profiling. Exceptions can apply, for example where records must be kept for legal obligations or to establish legal claims. We do not use the described services to make solely automated decisions with legal or similarly significant effects on you.

Send requests to privacy@surfcityapps.com, or write to our postal address above. Include the website or app involved and what you want us to do. Do not send a password or complete payment-card number. We may ask for proportionate information to locate records and verify your identity. An authorized agent may act for you where permitted; we may verify their authority and, where allowed, your identity directly. You do not need to create an account to submit a request.

We respond within the time required by applicable law and explain any applicable extension or refusal. We do not discriminate against you for exercising applicable rights. Requests are normally free; any lawful exception will be explained. If an applicable US state law gives you an appeal right, reply to our decision at the same email address with “Privacy appeal.” You may also contact your state attorney general or privacy regulator. EEA/UK residents can complain to their supervisory authority, including where they live or work or where a suspected infringement occurred; Swiss residents may contact the FDPIC.

California: the categories in section 2 include identifiers, customer/contact records, commercial information, internet or electronic activity, approximate geolocation and information you provide in support communications. HealthKit records are handled as described in section 5. We disclose the relevant categories to the recipients identified in sections 2, 4 and 7 for the stated business purposes. Where the CCPA applies, your rights include knowing the categories and specific information collected, sources, purposes and recipient categories; correction and deletion; and opting out of sale or sharing. We do not use sensitive information to infer characteristics for advertising. Contact us using the request methods above, including for information about the preceding 12 months.

10. Children, security and changes

Our apps are intended for adults aged 18 and over. We do not knowingly collect personal information from children under 16. If you believe a child has provided information, contact us so we can investigate and address it.

We use technical and organizational measures appropriate to the information, including access restrictions and protected connections. No service can promise absolute security. We update this page when our practices change and show the revision date above. Where required, we provide an additional notice or request a new consent before introducing a materially different purpose.