privacy.
clockit is operated by Ashok Baniaas an individual (“we”, “us”). This policy describes what personal information we collect when you use clockit.space, how we use it, and the rights you have over it. For any privacy question, write to support@clockit.space.
1. what we collect
account information
- Your email address (required to sign up; used to authenticate you and send transactional email).
- A password hash (if you sign up with email) or your Google identity (if you sign in with Google), both managed by our authentication provider, Supabase.
profile information
- Your handle (username), display name, optional bio, optional location, optional “era” tag, and optional avatar.
user-generated content
- The drops you publish (a track plus your commentary), the drops you like, who you follow, and your profile customizations. All of this is public-by-default to other clockit users. clockit is a social platform, and that is how the service is meant to work.
music track data
- Track metadata (titles, artists, albums, artwork, 30-second preview URLs) for any tracks you reference in drops. This metadata is sourced from Apple’s public iTunes Search API and stored in our database after you publish a drop.
Google data (if you sign in with Google)
- Your Google email address, name, and profile picture, via the “openid”, “email”, and “profile” scopes.
technical data
- Server logs from our hosting providers (IP address, user agent, request paths). We use these only to operate, secure, and debug the service.
- We do not use third-party analytics or tracking pixels at this time. If we add any in the future, we’ll update this policy.
2. how we use information
- To authenticate you and maintain your session.
- To provide the service: display drops, follows, and likes; search tracks via the iTunes Search API for composing drops; surface your public content to other users.
- To send transactional emails (sign-up confirmation, password reset).
- To send service-related notification emails about activity on your account (likes you’ve received, new followers). Every such email carries a one-click unsubscribe link, and you can manage your preferences any time from settings → email preferences.
- To show you anonymous in-app notifications when other signed-in users view your clockit profile. We record the view so we can deduplicate repeat visits from the same person within an hour, but the bell entry reads “someone viewed your profile” and never reveals the viewer’s identity in the app or anywhere else.
- To detect and prevent abuse, fraud, and security issues.
We do not use your data for advertising or ad-targeting, and we do not sell your data to anyone.
email we send you
We send two kinds of email, both delivered through Resend (a US sub-processor, see §5):
- Transactional email(sign-up confirmation, password reset). Required to operate your account; can’t be opted out of, because they are how you regain or verify access.
- Engagement notification email (likes on your drops, new followers). Opt-in by default. Two ways to opt out: flip the toggle in Settings, or click the one-click unsubscribe link in any such email. We honor unsubscribe requests immediately.
We do not send broadcast marketing, “new feature” announcements, or promotional content. If we ever introduce another email category, we’ll add it to this list and to the Settings toggle before turning it on.
3. music search and previews, specifically
clockit uses the iTunes Search API, Apple’s public, no-authentication endpoint, to search for tracks during composition and to fetch the 30-second preview clips that play on drops.
- You do not connect any music account to use clockit. There is no OAuth handshake, no token storage, no listening-history access.
- When you type a search query, the query is sent to Apple’s iTunes Search API server-side. Apple receives only the search text, not your clockit identity.
- Track metadata returned by the API (title, artist, album, artwork URL, preview URL, Apple Music deep link) is cached in our database when you publish a drop. We do not cache results you searched but didn’t pick.
- Every drop with an Apple-sourced preview shows a “courtesy of iTunes” attribution near the play controls and a “Listen on Apple Music”deep link, in line with Apple’s iTunes Search API terms.
- clockit is not affiliated with Apple. Apple’s use of any data is governed by Apple’s own policies.
Pre-29-May-2026 drops were composed against the Spotify Web API (the V1 corpus before the pivot). Those drops keep their Spotify-sourced metadata; no new Spotify data is collected.
4. Google integration, specifically
If you choose to sign in with Google, clockit uses Google OAuth to authenticate you. We request only the “openid”, “email”, and “profile” scopes, which give us your Google email, your name, and your profile picture.
We do not access Gmail, Google Drive, Google Calendar, Google Contacts, or any other Google service. We do not request any sensitive or restricted scopes.
clockit’s use of information received from Google APIs adheres to Google’s API Services User Data Policy, including the Limited Use requirements applicable to the scopes we use.
5. how we share information
other clockit users
Your public profile information (your handle, display name, bio, drops, follows, and likes) is visible to anyone who can see your profile. clockit is a social application; that visibility is the point.
sub-processors we use
We rely on a small number of third-party services to operate clockit. Each receives only the data they need to perform their function:
- Supabase handles authentication and database hosting (US region).
- Vercel handles web hosting, DNS, and CDN.
- Resend handles outbound transactional email delivery.
- Google receives only the data you have authorized clockit to access via OAuth (your email, name, and profile picture).
- Apple receives only the text of the search queries clockit sends to the public iTunes Search API on your behalf when you compose a drop. No clockit identity is sent.
We do not share your data with advertisers, data brokers, or third parties for marketing purposes.
legal requests
If we receive a valid, legally compelled request (subpoena, warrant, or equivalent), we may disclose data to the extent required. We push back on requests that appear overbroad.
6. data retention and deletion
We retain your data while your account is active.
You can permanently delete your account at any time from settings, under “danger zone.” Deletion takes effect immediately and removes your authentication record, your profile, your drops, your follows, and your likes.
Deletion is irreversible. If you want a copy of your data, email support@clockit.spaceto request export before you delete. We can’t export data that has already been removed.
If you can’t sign in (lost access, account dispute, or anything else), email support@clockit.space from the address associated with your account, and we will process the deletion within 30 days.
7. your rights
You can request to access, correct, or export your data by emailing support@clockit.space. Account deletion is now self-serve in settings, under “danger zone” (email is still available as a fallback if you can’t sign in). We respond to email requests within 30 days.
If you are in the European Union, EEA, or United Kingdom, you have additional rights under the GDPR (UK GDPR / EU GDPR), including the right to object to processing, the right to portability, and the right to lodge a complaint with your national data protection authority.
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what categories of personal information we collect, the right to deletion, and the right to non-discrimination for exercising those rights. Use the same email address above.
8. security
We use industry-standard measures to protect your data: HTTPS for all traffic, encrypted credentials at rest, restricted administrative access, and security review of our code. No system is perfectly secure. If we become aware of a material breach affecting your data, we will notify affected users in accordance with applicable law.
9. children
clockit is intended for users aged 13 and older (in the United States, per COPPA). If you are in the European Union, the EEA, or the United Kingdom, you must be at or above the age of digital consent in your country (typically 16, lower in some member states). We do not knowingly collect personal data from anyone below the applicable age. If you believe a child has provided us their data, email support@clockit.space and we will delete it promptly.
10. international data transfers
clockit’s data is hosted in the United States. If you access clockit from outside the United States, your data will be transferred to and processed in the United States. By using clockit, you consent to this transfer.
11. changes to this policy
We will post material changes to this page and update the “last updated” date at the top. For significant changes, we will attempt to notify you in-app or by email.
12. contact
Questions, requests, or concerns related to this policy or your data: support@clockit.space.