Last updated: 30 April 2026
Setline ("we," "us," "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains what information we collect when you use the Setline mobile application ("App") and website at setlineapp.com ("Website"), how we use it, and what choices you have. By using the Service, you agree to the collection and use of information as described in this policy.
| Data type | When collected |
|---|---|
| Name and email address | When you create an account or join the Android waitlist |
| Phone number (optional) | When you choose to add your phone number from Edit Profile. We never store the phone number itself, only a one-way private code derived from it (see section 2C below) |
| Profile information | When you set up your profile (display name, profile photo) |
| Festival schedules | When you add artists and build your personal timetable |
| Friend connections | When you add friends or accept friend requests |
| User Content | When you post reviews, comments, photos, or other content |
| Data type | Purpose |
|---|---|
| Device information | Device model, operating system version, and unique device identifiers to ensure compatibility and diagnose issues |
| Usage data | Features you interact with, screens viewed, and actions taken within the App to help us improve the experience |
| Crash and performance data | Error logs and performance metrics to identify and fix bugs |
| Push notification tokens | Device tokens used to deliver set reminders, live updates, and friend activity notifications |
| Precise location data | GPS coordinates collected only when you opt in to share your location with friends at a festival (see section 2A below) |
| Anonymous location data | At festivals that use Setline safety features, your device contributes to a crowd density map shown to the festival organisers. The data is anonymised and cannot be linked back to you (see section 2A below) |
| Health and fitness data | Step count and distance data read from your device's built-in motion sensors (via Apple CoreMotion on iOS or the hardware step counter on Android) only when you opt in to Festival Steps (see section 2B below) |
If you choose to connect your Apple Music or Tidal account, we access your listening history and library data to provide personalised artist recommendations and help you discover acts in festival lineups. We do not store your Apple Music or Tidal credentials, and you can disconnect either service at any time from the App settings. Tidal integration uses OAuth authentication, meaning you authorise access directly through Tidal's login flow and can revoke it at any time.
Setline offers a friend location sharing feature that lets you share your real-time position with selected friends on a festival map. This section explains how location data is handled.
Location data is collected only when you explicitly opt in to share your location. You must actively enable sharing each time — location sharing does not persist between sessions and is never enabled automatically. You choose which specific friends can see your location.
When sharing is active, we collect your precise GPS coordinates (latitude and longitude), accuracy data, and a timestamp. On Android, a foreground service notification is displayed while location sharing is active.
If you opt in to the festival-wide leaderboard (see section 2B), your approximate location is included with each step sync (approximately every 5 minutes) so we can verify you are physically at the festival. This is an anti-cheat measure to keep the leaderboard fair. Your coordinates for this purpose are stored only on the most recent leaderboard entry, are not shared with other users, and are deleted along with the leaderboard entry within 7 days of the festival ending.
To help festival organisers improve crowd safety and site operations, we may aggregate and anonymise location data from users who have opted in to location sharing to produce crowd-level insights such as density heatmaps, movement flow patterns between stages, peak congestion areas, and emergency egress analysis. This data is fully anonymous — it is stripped of all personal identifiers before processing and cannot be used to identify, track, or re-identify any individual user. These insights are shared only with the organisers of the specific festival and only for the purpose of improving safety and the attendee experience. Anonymous crowd insights are never sold to third parties, used for advertising, or shared with anyone other than the relevant festival organiser.
Friend-sharing location data is ephemeral — it is removed from our systems when you stop sharing or when sharing automatically ends. Festival Leaderboard verification location is retained only on the most recent leaderboard entry and deleted with the entry. We do not build location history profiles or retain individual movement patterns. Anonymous, aggregated crowd safety data (which cannot identify any individual) may be retained for a reasonable period to allow festival organisers to use the insights for safety planning. Location data is not used for analytics, advertising, or any purpose other than delivering the friend sharing feature, verifying festival leaderboard entries, and generating anonymous crowd safety insights for festival organisers as described above.
Setline offers an optional Festival Steps feature that tracks your step count and distance walked during festivals. This section explains how health and fitness data is handled.
Health data is collected only when you explicitly opt in to Festival Steps. On iOS, you must grant Motion & Fitness permission. On Android, you must grant Physical Activity permission. We read step count and distance data directly from your device's built-in motion coprocessor (via Apple CoreMotion on iOS or the hardware step counter sensor on Android). We do not use Apple HealthKit, Google Health Connect, or any third-party health platform. We do not access heart rate, sleep, nutrition, weight, or any other health categories.
| Data type | Details |
|---|---|
| Step count | Number of steps recorded by your device's motion sensors during festival dates |
| Distance walked | Estimated distance in metres derived from your device's step counter |
| Per-set breakdown | Steps attributed to individual performances in your schedule, calculated by correlating step data timestamps with your scheduled set times |
| Hourly breakdown | Per-hour step totals used to detect implausible spikes for leaderboard fairness |
| Approximate location (festival leaderboard only) | If you opt in to the festival leaderboard, your last known coordinates are sent with each sync to verify you are at the festival. See section 2A. |
Aggregated daily step and distance data is stored in your user profile on our servers (Firebase Firestore). We retain this data for as long as your Setline account is active so you can revisit your stats from past festivals and, over time, compare your activity year-on-year at the same event. You can permanently delete every saved festival recap at any time using the Delete Movement History action in Privacy settings, and all movement data is removed when you delete your account. Festival leaderboard entries are deleted within 7 days after the festival ends. Raw step data from your device's motion sensors remains on your device and is governed by your operating system's privacy policies. Setline does not modify or delete data on your device.
Festival Steps powers two separate, independent leaderboards. Each is opt-in and can be toggled on or off at any time from the App settings:
To keep the festival leaderboard fair, we apply automated anti-cheat checks server-side. Entries where the device location does not match the festival, or which contain implausibly high step counts within a short period, may be excluded, capped, or removed without notice. We do not guarantee that any particular entry will appear on the leaderboard. Aggregated, anonymised step data may be shared with festival organisers as part of overall attendance insights — this data does not identify individual users.
We do not use health or fitness data for advertising, marketing, data brokerage, or any purpose other than providing the Festival Steps feature and related leaderboard functionality. Health data is never sold to third parties.
Setline lets you optionally add a phone number to your account to help friends find you and to support account recovery. This section explains exactly how phone numbers are handled, because we hold them to a stricter standard than most apps.
A phone number is collected only if you choose to add one from Edit Profile in the App. It is never required to use Setline. You can remove it at any time from the same screen.
When you add a phone number, we send a 6-digit verification code by SMS using Firebase Authentication, Google's identity service. You enter the code in the App to confirm you control the number. Standard message rates from your carrier may apply. We do not use your number for any purpose until verification is complete.
We never store your raw phone number in our database. After verification we generate a one-way cryptographic code derived from your number using HMAC-SHA256 with a secret key held only on our servers, and we store only that code. Your verified phone number itself is held by Firebase Authentication on Google's servers as part of the standard authentication record, in the same way as your email address; it is not visible to us in our application database, never appears in logs, and is never shown to other users.
We do not use your phone number for marketing, advertising, profiling, or sale to third parties. We do not run lookups against external phone-number databases.
Setline offers an optional feature that helps you find friends already on the app by checking your phone's address book against our user base. This section explains exactly how it works, because contact data is sensitive and we treat it accordingly.
Your address book is read only when you explicitly opt in to "Find friends from contacts" and grant the system contacts permission. We do not access contacts at any other time or for any other purpose. You can deny or revoke the permission in your device settings at any time, and the feature is fully optional — the rest of the app works without it.
When you trigger a contact sync, the App sends the phone numbers and email addresses from your address book to our server over an encrypted connection (HTTPS/TLS). The server immediately:
The matches we return contain only the publicly-visible parts of a user's profile (display name, username, profile photo) and respect each user's privacy settings — anyone who has set their search privacy to "Hidden" will never appear in contact-match results, even if their contact info is in your address book.
Contact data has zero retention on our servers. Phone numbers and email addresses arrive in a single function call, are processed in memory, and are discarded when the call returns. Only the matches you see in the App are produced. We retain only an aggregate counter of sync requests per day for product diagnostics — that counter contains no contact data, no individual identifiers, and no per-user information.
We use the information we collect to:
We do not sell your personal information. We may share your information in the following limited circumstances:
We retain your personal information for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal, accounting, or legitimate business purposes. Anonymised and aggregated data that cannot identify you may be retained indefinitely.
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These measures include encryption in transit and at rest, access controls, and regular security assessments. However, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
Depending on your location, you may have certain rights regarding your personal information:
If you are located in the European Economic Area (EEA), United Kingdom (UK), or another jurisdiction with applicable data protection laws, you may also have the right to restrict or object to certain processing, and to lodge a complaint with your local data protection authority.
The Service is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us at [email protected].
Setline is based in Australia. If you access the Service from outside Australia, your information may be transferred to, stored, and processed in Australia or other countries where our service providers operate. These countries may have data protection laws that differ from those in your jurisdiction. By using the Service, you consent to the transfer of your information to these countries. Where required by law, we will ensure appropriate safeguards are in place to protect your data.
The Service may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access through the App.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the App or by other reasonable means before the changes take effect. The "Last updated" date at the top of this page indicates when the policy was last revised. Your continued use of the Service after the changes take effect constitutes your acceptance of the revised policy.
If you have any questions about this Privacy Policy or how we handle your personal information, please contact us at [email protected].