Service data notice · August 10, 2026
Privacy & YouTube Notice
Mople is an account-free music room for listening together. This page explains what information Mople and its service providers handle.
1. Information Mople handles
- Rooms and playlists
- Room title and access type; YouTube video ID, URL, title, channel, thumbnail, and duration. A public room’s title, current track, and listener count may appear in the public-room discovery feed.
- Anonymous participation
- A random member ID per room, alias, color, role, and current listening mode
- Chat and notes
- Message body, anonymous author details, time, linked track, and playback position
- Access and security
- Short-lived HttpOnly room sessions and room-scoped network-derived identifiers for abuse prevention
The Mople application does not store original IP addresses in Supabase. Cloudflare, which carries internet requests, may process IP addresses and traffic information to provide and secure the service.
2. Information stored in your browser
- Room sessions are stored in Secure, HttpOnly cookies that JavaScript cannot read.
- A guest link may be kept in sessionStorage so it can be shared from the current tab.
- A host recovery link is kept in localStorage only when you explicitly choose that option.
- Theme and language preferences are kept in localStorage.
Mople doesn't store your personal volume or YouTube watch activity outside Mople. Chat and notes in a room are visible to other people who can access that room.
3. Retention
- Regular chat expires 7 days after it is posted and is removed by a scheduled job.
- Track notes, moment notes, and playlists are kept while the room exists.
- The entire room, its playlist, and all notes are permanently deleted 30 days after the last valid activity.
- Live presence and playback position are processed while needed to operate and synchronize the room.
- Remembered host access can be removed manually from the room footer.
Because Mople has no accounts or email addresses, we cannot send individual deletion notices or recover deleted data. Provider backups and physical media may follow their own later destruction schedules.
4. Reports and moderator access
Mople does not continuously monitor rooms. When spam, harassment, exposed personal information, or illegal content is reported, an operator may use server-only access to review only the reported room and relevant scope, then hide messages or delete the room when necessary.
General content and user reports are submitted through public GitHub Issues. Don't include a complete guest link, access key, password, or personal information—submit only the room publicId from the URL path. Reports are not copied into Mople's database, and GitHub's policies apply to the reporting account and content.
Copyright-owner reports may contain evidence of rights and personal information, so do not submit them through a public Issue. Privately report links or records within Mople to copyright@mople.app, and use the official YouTube copyright process for the source video itself.
5. YouTube use
Mople does not transmit audio or video itself. Content plays through the YouTube IFrame Player API. When you enter a room, the embedded player connects to prepare playback. Basic request information such as the page URL and IP address may be sent to Google and cookies may be used. Additional playback information may be processed after playback starts.
- YouTube provides the content, advertising, and player features.
- Mople doesn't request YouTube account access or download video or audio.
- Google's and YouTube's policies also apply when you use YouTube.
6. Service providers
Cloudflare delivers the web app and handles the Worker API and live room state. Supabase stores rooms, playlists, chat, and notes. Each provider applies its own privacy policy to its processing.
7. Questions and changes
You can open a GitHub issue with questions about this notice or data handling. If our processing changes, we will update both the date and content of this page.