Privacy Policy
Introduction
Last updated: September 6, 2026
This policy covers the LankaFM mobile app, website and preference service. LankaFM lets you listen without creating an account. Contact the operator at milan@findmilan.ca for privacy questions.
Listening preferences work locally. Compatible app releases can sync a small preference record after setup or a settings change. If the protected service is unavailable or the app cannot complete its security checks, changes stay on the device for later retry.
Information Stored On Your Device
Your selected languages and location, favorite station IDs, recent listening history and quick-resume station are stored on your device. Favorites, listening history and quick-resume information are not submitted to the preference service.
Your district or country is chosen manually. The app does not use GPS, device Location Services or precise location APIs.
Preference Information We Receive
The preference service receives a pseudonymous installation identifier, selected languages, one selected district or country (or no location while setup is incomplete), platform, app version and update time. It keeps the latest preference snapshot rather than a history of each settings change.
A pseudonymous identifier distinguishes installations without a name, email address or user account. It is not proof that the data cannot identify a person when combined with other information.
Preferences are submitted after setup, when selected options change, and when a pending update is retried. Playing a station, changing tabs or reopening the app with no pending update does not require a preference database request. This record supports app preference functionality and aggregate audience planning.
Security And Abuse Prevention
The protected service verifies supported iOS app requests directly with Apple App Attest and supported Android requests with Google Play Integrity. An installation-specific credential authorizes changes to that installation. This credential is sent over HTTPS and is not stored in our preference database.
Apple and Google process app and device integrity information for these security checks. For iOS, our service stores the attested public key, key identifier, environment and assertion counter. The private App Attest key stays on the device. We do not store raw attestation receipts, Android integrity tokens or raw device integrity responses in the preference database.
Our service uses short-lived, keyed hashes of network addresses and installation identifiers for rate limiting. Raw IP addresses are not copied into preference records or our API application logs. Hosting and security providers may process request metadata under their own policies. API application logs contain a generated request ID, route name, response status and duration, without preference bodies, installation IDs or credentials.
Information Not Sent To The Preference Service
- Names, email addresses or phone numbers
- GPS coordinates or precise location
- Contacts, photos, microphone recordings or camera data
- Advertising identifiers
- Favorite stations, listening history or quick-resume station
The app does not require account registration. The preference service does not create advertising profiles or sell preference records. If you choose to email support, we receive the information you include in that message.
Providers And International Processing
Supabase provides PostgreSQL storage for the preference service. The selected database project is in the United States. Website hosting, support email, security checks and third-party radio streams may involve processing in other countries.
Apple App Attest and Google Play Integrity process security information under their respective privacy terms. Firebase is not used by this preference service.
If you download the app through Apple or Google, the store provider processes downloads, reviews and other store interactions under its own policy.
Live Radio Streams And Third-Party Hosts
When you press play, audio connects directly to external station or streaming hosts. Those hosts may receive your IP address, request metadata and stream request timing.
Broadcasters control their content, availability, geographic restrictions and privacy practices. Station logos are bundled with the app rather than requested from separate logo hosts.
Device Permissions
The app does not request microphone, camera, contacts or precise location permissions. Internet access and operating-system audio/background-playback capabilities support radio streaming. App integrity checks may be required for server preference sync.
Retention And Reset App Data
Preference records are eligible for deletion after 12 months without an accepted newer preference update. Daily database maintenance removes expired records while the database is available; a paused or unavailable database delays that cleanup until service resumes. Identical retries do not extend retention.
Reset App Data requests hard deletion of the server preference row. A separate deletion marker contains only the pseudonymous installation identifier and an expiry time for 30 days to prevent delayed requests recreating the deleted preferences. It is then removed by cleanup. Repeated deletion requests do not extend that period.
An offline reset must keep the old installation credential with its pending deletion until the deletion succeeds. A new setup uses a new installation identifier. Simply uninstalling the app does not reliably notify our server; if no deletion request arrives, the inactivity retention period applies.
Rate-limit hashes expire after their request window, no later than about 24 hours and one minute. Daily cleanup removes expired hashes. A paused service delays cleanup. Provider-managed logs and any backups follow the provider or backup configuration; restoring a backup requires reapplying later deletion requests before reopening the service.
Apple public-key verification records are removed after 12 months without use. Following a successful reset deletion, the verification record is retained for up to 30 days so authenticated deletion retries can complete. One-time challenge hashes expire after five minutes. Daily cleanup removes expired records; service outages can delay cleanup.
Your Choices And Privacy Requests
Change your selected languages and location in the app. Use Reset App Data to clear local preferences and request removal of the server preference record. Listening remains available when preference sync is unavailable.
For access, correction or deletion questions, contact milan@findmilan.ca. Because records are identified by installation rather than an email address, we may need information that establishes which record is yours. Do not email your installation secret, database credentials or security tokens. Applicable privacy rights depend on your location.
Children's Privacy
LankaFM does not seek children’s contact information or create personal accounts. Pseudonymous preference and security information may still be processed as described above. If you believe a child has supplied personal information that should be removed, contact milan@findmilan.ca.
Using This Website
Website favorites are stored in your browser’s local storage and are not sent to the preference API. You can remove them individually or clear this website’s browser storage. Website audio connects to third-party streaming hosts only when you press play.
The support form prepares an email in your email application. It does not submit its contents to the website. If you send the email, we receive the details you choose to share and use them to respond.
Changes To This Policy
We will update this page when features, providers or data practices change, and revise the date above. Material changes will be communicated through the app or website as appropriate. App-store privacy disclosures must match the release actually distributed.
Contact
For privacy questions, corrections, deletion requests or support, contact milan@findmilan.ca.
