Privacy notice
Your private workspace is not your public page.
What Tagg collects, what becomes public, who processes it and the controls you have.
Effective 15 July 2026Who is responsible
Tagg is responsible for the personal data described in this notice. Tagg is currently an early-access service. We have not named a separate data protection officer because one has not been appointed.
Use Contact support and choose a general product question for a privacy request or complaint. We may ask for enough information to verify that the account or data belongs to you.
Data Tagg handles
Account and session
Email address, account ID, sign-in and confirmation events, plan and entitlement. Password credentials and authentication are handled by Supabase Auth. Tagg uses session tokens in cookies so signed-in pages work on the server and in your browser.
Profile, library and social activity
Handle, display name, bio, status, optional location, profile visibility, links, badges, profile design settings and soundtrack details. We also store media saved to your library, status and progress, ratings, reviews, lists, Top 4 picks, friend requests, friendships, blocks and account preferences.
Uploads
Avatar, background, soundtrack artwork and profile audio files, with technical details such as file path, type and size. Profile files are stored privately and served through short-lived links after Tagg checks that the viewer may open the page. A link can keep working until it expires, so remove an upload when it should no longer be hosted.
Support, reports and moderation
Support and report forms can collect your email, Tagg handle, subject, affected URL, issue details and selected context such as device, plan or rights-owner relationship. These records are stored in private operational tables. The current web form does not upload evidence files; if evidence is requested later, it is handled separately and privately.
Catalog search
Search words, media type and the item you choose. Tagg searches its canonical catalogue first, then may ask Wikidata, TheTVDB or IGDB for additional results from protected server code. External search results stay temporary unless a meaningful action or catalogue supply job resolves them to a Tagg media ID, so profiles do not depend on a live provider request every time they load.
To prevent automated catalog abuse, Tagg gives anonymous visitors a random identifier in a strictly necessary, HttpOnly cookie. The server turns that identifier, or your account ID when signed in, into a keyed one-way hash. It also makes a separate keyed network hash. The catalog limiter does not store raw network addresses, browser details, cookie values or account IDs. Inactive limiter records are deleted after seven days.
Privacy-safe profile view counts
When someone opens a published profile, Tagg may record a view for the profile owner. A signed-in viewer is represented by their account ID. For an anonymous viewer, the server issues a random visitor token in a strictly necessary, HttpOnly cookie. Page scripts cannot read that token. Tagg also creates a keyed one-way fingerprint from the network address and browser user-agent. The raw address and full user-agent are not stored in the view event.
The account ID or random visitor token is converted to a keyed hash on the server. It prevents the same viewer and profile being counted again for 30 minutes. Self-views are excluded. Owners receive totals, today and seven-day counts, not a list of individual anonymous visitors.
Why we use it
- Provide the service
- Create accounts, save private workspace data, publish what you choose, connect friends and deliver paid features. The usual lawful basis is performance of our contract with you.
- Protect Tagg and its users
- Authenticate requests, prevent abuse, deduplicate views, investigate reports and enforce the rules. We rely on legitimate interests in a safe and reliable service, and legal obligations where they apply.
- Support and billing
- Respond to requests, resolve account access, apply entitlements and keep records needed for transactions or disputes. This uses contract, legitimate interests and legal obligations depending on the request.
- Optional email
- Product-update email is controlled by your preference and uses consent where required. You can switch it off. Service and security messages are not marketing.
Tagg does not sell personal data and does not use it for third-party behavioural ads.
What other people can see
Creating an account and claiming a handle do not publish the profile. When you publish, profile visibility can be public, friends-only or private. Library entries, including status and rating, start in your private workspace. Supported links, reviews and lists have separate visibility controls. Blocking can remove access and the friendship connection.
Taste Match has its own audience control and starts as Friends only. You can make it public or hide it completely at any time. A pending request does not count as a friend; only an accepted friendship can see a Friends-only Taste Match.
Public profile content may be copied, indexed or shared by visitors outside Tagg. Profile image and audio files are stored privately and delivered through short-lived signed links after a visibility check. A signed link can still work until it expires, so hiding a block is not the same as deleting its file. Remove the asset if it should no longer be hosted.
How long data is kept
- Account, profile and library: while the account is active, then deleted or anonymised after closure unless a limited record is needed for law, payment or safety.
- Public uploads: until you remove or replace them, the account is deleted, or moderation removes them. Cached copies may take a short period to expire.
- Support tickets: until the request is resolved and no longer reasonably needed for follow-up, service quality, billing records or a dispute.
- Safety, copyright and moderation records: for as long as reasonably needed to investigate, prevent repeat abuse, establish what action was taken or meet a legal obligation.
- Profile-view events: while needed to provide counts, prevent duplicate counting and investigate abuse. They are removed if the viewed profile account is deleted. Tagg reviews this early-access period and will shorten or anonymise it when the identifiable event is no longer needed.
- Catalog metadata: while the item remains active or used in libraries, reviews, lists or profiles.
We do not keep personal data indefinitely just in case. Exact periods may be extended when a legal hold, active investigation or unresolved transaction requires it.
Your data rights
Depending on the data and lawful basis, UK data protection law may give you rights to be informed, access a copy, correct inaccurate data, request deletion or restriction, receive portable data, object to processing and withdraw consent. These rights are not all absolute.
Signed-in members can download a copy of their Tagg data or permanently delete their account from Settings. Use Contact support for correction, restriction, objection or any request the self-service controls do not cover. We may ask for enough information to verify the request.
We aim to resolve concerns directly. You can also complain to the UK Information Commissioner's Office. Start with the ICO's current data protection complaint guidance.
People under 18 and changes
Tagg accounts are for people aged 13 and over. Tagg does not currently ask for a date of birth. If we learn that an account belongs to a child under 13, we will close it and remove the child's personal data unless a legal or safety reason requires limited retention.
People under 18 deserve clear information and privacy-protective defaults. Tagg begins with an unpublished profile, keeps the private workspace separate from the public page, and provides visibility, blocking and reporting controls. We will review these protections as the service develops.
We will update this notice when data use, providers or law materially change and will bring significant changes to account holders' attention before the new use begins where required.
