Reverb

Privacy Policy

Last updated 29 September 2026

The short version

Reverb lets you send a song to someone straight from Spotify's or Apple Music's share sheet. They get an SMS, and if they use Reverb the song is added to their playlist automatically. This page explains exactly what that requires us to collect, what we do with it, and what we don't do.

It is written against how the app actually works rather than from a template. If you find something here that doesn't match what you see in the app, please tell us.

What we collect

Information you give us

WhatWhy we need itRequired?
Your phone number It is your account. It's how you sign in, and it's how other people address a song to you. Yes
Your name So a song you send says who it's from instead of showing a bare phone number. No
Your handle and bio Your handle is your name on Reverb — how people find you, mention you and reach your profile. A bio is a line about yourself, if you want one. Both are shown on your profile. A handle, yes; a bio, no
What you post and say Songs you post and their captions, comments, likes, saves and the people you mention. They're shown to whoever your account lets see them (see below), and the For You tab is ordered from them. No
A profile photo Shown on your profile in the app. If you add one, we rebuild the image from its pixels before storing it, so none of the hidden information a phone puts in a photo file — including where it was taken — is kept or published. No
An email address Only if you sign in with Apple, which tells us one. There is nowhere in Reverb to type an email address, and we never send anything to it. If you chose Apple's "Hide My Email", what we hold is Apple's relay address and not your real one. No
Your Sign in with Apple connection Only if you sign in with Apple: the anonymous identifier Apple assigns to you for Reverb alone (it identifies you to us and to nobody else), and the token Apple gives us so that deleting your account can also tell Apple to forget the connection. Neither appears anywhere in the app. No
A password, if you set one Stored only as a one-way hash, so nobody — us included — can read it back. Signing in still works with a texted code whether or not you set one. No

Your contacts

Reverb asks for permission to read your contacts, and uses it to show you its own list: searchable, with checkboxes so you can pick several people at once, and with a small Reverb mark beside anyone whose number already belongs to a Reverb account — so you can see, before you send, who will get the song in the app instead of as a text message. You can grant or revoke this at any time under Contacts in iOS Settings.

The same list appears when you share a song into Reverb from Apple Music or Spotify, so you can tick a few people without leaving that share sheet. It reads your contacts the same way and sends the same nothing: that sheet does not even do the account check described below, so it shows no Reverb marks. If you have not granted contacts access, it falls back to the picker iOS draws itself, which needs no permission and hands back only the one person you tap.

This section changed, and we would rather say so than quietly reword it. Earlier versions of Reverb used a contact picker that iOS ran outside the app, and this page said Reverb never read your address book at all. That is no longer true: Reverb now reads it, because a list drawn by iOS cannot show you which of your contacts are on Reverb. What we do with what we read is below, and it is narrower than the permission itself allows.

What stays on your phone. Everything except phone numbers. Names, nicknames, email addresses, street addresses, photos, birthdays, notes, company names — none of it is ever sent anywhere. The app takes a name and a number off each card and drops the rest on the spot; the name is used to label the row you are looking at and is never transmitted.

What is checked, and what happens to it. To put the Reverb mark next to the right people, the app sends phone numbers to our server and asks which ones have accounts. That check writes nothing: there is no table, no log and no cached copy of your contacts' numbers on our side — they exist for the length of one request and are then gone. The answer comes back listing only the numbers that matched.

We still don't tell you how many of your contacts use Reverb. The answer to that check contains the people who are here and no trace at all of the people who aren't — not a count, not a total, not a placeholder. Neither you nor we can work out from it how many of your contacts are not on Reverb.

Recent recipients. Reverb remembers who you sent songs to lately so they're easy to reach again. People with Reverb accounts come from your own send history on our server. People without one are remembered on your phone only — we have nowhere to keep them, because we never store the phone number of someone who isn't a user (see below). Both lists are cleared when you sign out.

You can say no. If you decline, Reverb does not nag you and nothing stops working: you can still type any phone number and send a song to anyone on earth, exactly as before. The contact list is a convenience, not a gate.

Following someone from your contacts works the same way, and you can also find one person by typing their number — a single lookup that tells you only about that number.

Who you follow

When you follow someone we record that you follow them, and when. You can unfollow at any time, which deletes the record rather than hiding it.

Following is one-way, and public accounts can be followed by anyone. If your account is public, somebody can follow you and see what you post without your approval, and your name and photo can appear in Reverb's suggestions to people you've never met. Your phone number is never shown there.

You can turn on Private account in Profile at any time. Follows then need your approval, and you stop appearing in suggestions. Existing followers stay — turning it on closes the door, it doesn't remove the people already through it.

You can block anyone. Blocking is mutual in effect: neither of you sees the other's posts, and any follow between you is removed. You can report a post or an account from the menu on any post. Reports are read by a person; nothing is hidden or suspended automatically.

On the For You tab — posts by people you don't follow — you can ask to see more or less of somebody. We store who you asked about, which way, and when, so we can honour it; it changes the order of that one tab, only for you, and never hides anyone. You can undo it from the same menu or from Settings, which deletes the record. The other person is never told.

Your music accounts

If you connect Spotify or Apple Music, we store the access token those services issue us, along with its refresh token and expiry. We use them for three things, all of them yours to ask for: reading your playlists so the app can list them and you can choose where shared songs land, adding songs to the playlist you chose, and writing a playlist you made in Reverb into your library when you ask it to.

If you connect Apple Music we also store the country of your Apple Music account, because Apple's catalog is different in each country and a song has to be looked up in the right one.

We never receive your Spotify or Apple Music password — the sign-in happens with those companies directly. You can disconnect either service from inside Reverb at any time, which deletes the stored tokens.

Songs and shares

When a song is shared between two Reverb users we record who sent it, who received it, which song it was, any short message attached, and when. We also keep basic public details about the song itself — title, artist, album, genre, artwork, and the platform's ID for it — so we don't have to re-fetch them.

There are two kinds of share, and they're visible to different people.

A song you post is not added to anyone's playlist. Posting shows people a song; it doesn't put anything in their library.

Jukeboxes

A jukebox is temporary. Its queue lives in memory with an expiry and is deleted when the jukebox ends; nothing you play in a jukebox is posted anywhere. There is no record afterwards of who was in the room with you or what they queued.

The one thing that leaves a jukebox is a song you choose to save, which goes to your own Reverb playlist exactly like any other save — with no note of where you heard it.

Inviting somebody who is already on Reverb writes them one notification, carrying the jukebox's six-character code and nothing else about the room — no queue, no roster, no history. It is the only lasting record a jukebox produces, and it appears in no feed.

Jukeboxes with people who don't have Reverb

There are two ways in, and they hold different things about you. A shared link holds no phone number at all; a texted invitation holds one, hashed, for as long as the room lives. Both are below.

Opening a link somebody shared with you. If your host sends you the jukebox's link — in a message, a group chat, or by reading you the code — you can join from your browser, and:

Being texted an invitation. A host can text a jukebox invitation to a phone number. If your host does that, here is everything that happens to your number, and everything that does not:

One exception, and only if your host's version of Reverb has it switched on: your number in its ordinary form can be shown to the host of that jukebox and to nobody else, so that their phone can put your name to it from their own contacts. That match happens on their device — we never see their address book and never learn what they call you. Like everything else here, the number is gone when the jukebox ends. If they have no contacts permission, or don't have you saved, they see the number.

Broadcast

Broadcast is off unless you turn it on, and it is temporary. With it on, the song you're playing in Reverb is held in memory for a couple of minutes so your friends — people you follow who follow you back — can see it at the top of their feed. It expires on its own. Nothing is written down: there is no record afterwards of what you played, and no way for anyone, us included, to look back at it.

Turning broadcast off clears it at once rather than waiting for it to expire. Only friends ever see it — somebody who follows you but whom you don't follow back sees nothing — and nothing you play in a jukebox is ever broadcast.

We never tell you, or anyone, who looked at it. There is no "seen by" list, no count, and no notification when a friend starts a song.

Notifications

If you allow it, we store a notification token for each iPhone you sign in on, along with whether that install is a test or App Store build. It's what lets us notify you without a text message: when somebody sends a song to your number and one of your phones can take a notification, we send that instead of a text, and comments, mentions and follow requests arrive the same way. A phone that has stopped answering is forgotten and the text comes back — the text is the floor. We delete the token when you sign out of that device.

In a browser, if you switch notifications on, we store the push subscription your browser hands us for the same purpose, and delete it when you switch them off or sign out. The notification's text is handed to Apple's, Google's or Mozilla's push service to deliver, depending on the phone or browser — see the table under "Who we share information with".

Signing in

To sign you in we text you a six-digit code. The code is held in temporary storage for five minutes and deleted the moment you use it. After that your device holds a login token in the iOS Keychain, which is also what lets the share sheet extension act as you.

For each place you're signed in we keep a label for the device, so Settings can list where you're signed in and let you sign any of them out: from the iPhone app it is just "Reverb iOS"; from a browser it is the description your browser gives of itself (which browser, on which system). It goes when that sign-in ends.

What we do not collect

If someone shares a song with you and you don't use Reverb

You'll get one SMS telling you who sent the song, with links to hear it. Your phone number reaches us only because the sender chose you from their contacts.

If you don't have a Reverb account, we do not create one for you and we do not store your number in our database. It passes through to our SMS provider to deliver that one message. It will appear in our server's operational logs and in our SMS provider's message records, both of which age out — see How long we keep things.

We don't add you to a mailing list, and we don't message you again unless someone shares another song with you. If you'd rather never hear from us, get in touch and we'll block your number from receiving Reverb messages.

Who we share information with

We do not sell your personal information, and we do not share it for advertising. We use a small number of service providers to make the app work:

ProviderWhat they receiveWhy
Twilio Phone numbers and message text Delivering sign-in codes and share notifications by SMS
Spotify Your Spotify authorisation, song identifiers Reading your playlists and adding shared songs to them
Apple (Apple Music) Your Apple Music authorisation, song identifiers Reading your playlists and adding shared songs to them
Apple (push notifications) A device token and the notification's text Delivering notifications to iPhones instead of texts
Your browser's push service (Apple, Google or Mozilla, depending on the browser) A push subscription and the notification's text Delivering notifications to a browser you switched them on in
Sentry Error reports: which request failed and how, with the phone number, message text, cookies and address stripped out before anything is sent Finding out that something broke without waiting for you to tell us
Fly.io Hosts our servers and database Running the service
Upstash (through Fly.io) Short-lived working data — sign-in codes, and the counters that stop the service being abused, some of them keyed by phone number. Each expires on its own; none of it is a lasting record Sign-in and keeping the service from being abused
Apple (the music catalog) Song searches, and — because artwork and previews load straight from Apple — the network address of whoever is viewing them Finding songs, and showing and playing them
SoundCloud A SoundCloud link you share into Reverb Looking up which song the link is
Cloudflare The requests that look up our web address, and email you send us Running our domain name, and forwarding email to our inbox
Google (Gmail) Email you send us, and the text of any report, which is emailed to us so a person reads it quickly Answering you, and reviewing reports

Each of these has its own privacy policy governing what it does with what it receives. We may also disclose information if the law requires it, or to protect someone's safety. If Reverb is ever acquired, personal information would transfer with the service, and we'd say so here before it took effect.

Where your information is stored

On servers in the United States. If you use Reverb from elsewhere, your information is transferred to and processed in the US.

Traffic between the app and our servers is encrypted in transit (HTTPS). Access to the production database is restricted to the people who operate the service. We want to be straight with you rather than reassuring: Reverb is a small, independently run app, and no service can promise perfect security. Please don't put anything in a share message that you'd be harmed by seeing disclosed.

How long we keep things

Your choices

Depending on where you live you may have additional rights over your personal information — to access it, correct it, delete it, or object to how it's used. We apply the choices above to everyone regardless of location. Ask us and we'll act on it; we won't treat you differently for exercising a right.

Children

Reverb is not directed at children under 13, and we don't knowingly collect personal information from them. If you believe a child under 13 has given us information, contact us and we'll delete it.

Changes to this policy

If we change how Reverb handles your information, we'll update this page and move the date at the top. For anything significant we'll give notice in the app before it takes effect rather than quietly editing the page.

Contact

Questions about this policy, requests to delete your data, or anything else:

support@reverbmusic.app

We aim to reply within a few days. Answers to the common questions are on Support.