This notice covers Nightflat.com and the official Nightflat Android app. We use the data and storage needed to keep accounts, protected playback, rooms, radio, fair use, sponsored messages, payments, safety, and support working. Google Analytics is optional on the website and only uses analytics storage when you allow it.
Nightflat.com is operated by Madeliz, registered with the Dutch Chamber of Commerce under KvK number 77510194, The Netherlands.
When this notice says "Nightflat", "we", "us", or "our", it means the Nightflat.com service operated by Madeliz.
Tracking
No marketing or advertising tracking.
Nightflat does not use marketing cookies, advertising identifiers, personalized ad tracking, or cross-site profile tools.
We may use Google Analytics to understand broad website usage, such as which pages and features are visited. Analytics storage is denied by default and is only enabled on that browser after you choose "Allow". The Android app does not load Google Analytics or an advertising SDK.
Android app
The app uses the same Nightflat account and protected service.
The official Android app sends credentialed requests to nightflat.com. These requests can include session and CSRF cookies, account and membership identifiers, app version, Android platform information, request metadata such as user agent and IP address, search terms, selected moods, favorites, queue changes, room and radio actions, podcast activity, and playback or fair-use events.
Music and podcasts stay behind Nightflat's protected authorization flow. The app requests a short-lived signed stream URL and does not receive a permanent direct audio-file path. The app may keep a limited temporary playback cache in its private app storage so an approved loop can continue smoothly; this is not an offline download and remains bound to server permission.
The app can show track or episode metadata in Android media notifications and on the lock screen. That metadata remains on the device and may be visible while the device is locked, depending on Android notification settings.
Analytics consent
Your analytics choice.
Nightflat saves your analytics choice in this browser's localStorage as nightflatAnalyticsConsent. Choosing "No thanks" keeps Google Analytics storage denied. Choosing "Allow" lets Google Analytics use analytics storage for this browser.
No analytics choice has been saved yet.
Account data
What we process when you join.
If you create an account, we process account details such as your email address, display name, password hash, profile settings, avatar, public profile choices, saved playlists and ordered playlist tracks, favorites, podcast follows and favorites, rooms, achievements, Flat Coins, and premium status.
We use this data to provide the account features you choose, protect login security, show public profile details only when you allow them, and keep your listening space available across visits.
Rooms, radio, and community safety
Shared messages need visible rules and moderation.
Room messages and radio call-in notes are shared with other listeners in that space. Nightflat processes the message, account and room or station identifiers, display name, timestamps, votes, blocks, report reasons, and limited technical abuse signals to deliver the feature and keep it safe.
When a listener reports a room message, station message, or another listener, Nightflat stores a safety report with the selected reason and a copy of the evidence needed for review. The reported listener is not told who submitted the report. Blocking another listener hides their room and station messages for the blocker.
Listening and fair use
Playback needs a little operational memory.
Nightflat processes playback attempts, server-confirmed audio delivery, bounded player heartbeats, completion and skip signals, room or radio context, a short device label, track and episode IDs, estimated audio bandwidth, and fair-use counters so playback can work reliably and the service can stay fair for Visitors, Residents, Night Owls, and Rooftop members.
A play becomes a qualified play only after Nightflat has both server-side delivery proof and enough bounded playback time. Seeking, refreshing a signed URL, or retrying a Range request does not create another play. Playback quality events are limited to small fields such as a failure code, time to first audio, rebuffer duration, playback position, delivered bytes, and completion.
Private-session plays may still be counted for delivery operations, fair use, rights administration, and aggregate service reporting. They are excluded from listening history, recommendations, Taste Mix, Artist Alerts, public activity, and recaps. Taste feedback such as completed, skipped, or disliked remains a separate preference signal and does not rewrite whether a play qualified.
The playback lifecycle does not store a raw IP address. Fair-use actor keys and IP-based abuse controls are stored as hashed technical identifiers where the app uses them. They are used for quota, security, and abuse prevention, not for advertising or profiling.
Sponsored messages
Listener ads do not use an advertising identifier.
Visitors and free accounts may hear clearly labelled sponsored audio messages. Nightflat processes eligibility, reservation, completion, session and daily cap data so a message is not played too often and paid tiers remain ad-free. This is first-party delivery: the Android app does not send an advertising ID or build a cross-service advertising profile.
Essential cookies
The cookies Nightflat may set.
PHPSESSID keeps your session alive while you move through the site, including access checks, login state, CSRF protection, flashes, checkout state, and other essential session features. It is a first-party session cookie.
nightflat_remember is used only when a logged-in user chooses remember-me style login. It stores a selector and token value, with the real token checked against a hashed database value. It lasts up to 30 days and is cleared when you log out.
nightflat_fair_use gives guest listeners a stable first-party visitor key for audio fair-use limits. It lasts up to 180 days and helps avoid relying only on IP addresses for bandwidth protection.
Google Analytics cookies may be set by Google only after you allow analytics on this browser. If analytics is off, Nightflat keeps analytics storage denied through Google's consent mode.
Browser storage
Storage on your own device.
localStorage may store comfort settings such as your selected neon theme, whether the sidebar is collapsed, and interface preferences for your own browser. These values stay on your device until you clear them or change browser storage.
sessionStorage may store short-lived interface state such as the player, focus timer, and current interface tab during the current browser session. This helps the room feel continuous while you browse.
Service-worker asset cache may be used by the browser to keep Nightflat interface files available and refreshed efficiently. Protected audio is deliberately not cached by the service worker, and old Nightflat audio caches are removed when the worker activates.
Android app storage may keep interface preferences, autoplay and repeat choices, update-check timestamps for direct-distribution builds, listener-ad cap state, WebView cookies, and the limited private playback cache described above. Clearing the app's storage removes these local values and signs the app out.
Payments
Mollie may handle payment details.
If you buy a paid Nightflat pass, payment handling may be processed by Mollie and the payment method you choose. Nightflat stores payment status, order references, plan details, and activation information needed to provide the paid feature.
Nightflat does not need to store full card numbers or banking credentials. Mollie's own privacy and legal information is available at mollie.com/legal.
Support
Messages sent to the flat.
If you contact Nightflat, we process the name, email address, subject, message, account link when available, and limited request metadata you provide so we can read, route, secure, and answer your request. Please avoid sending sensitive personal information unless it is truly needed for the question.
Legal basis
Why this processing is allowed.
Under GDPR, Nightflat may process data to perform the service you request, protect the service and its users, comply with legal obligations, handle payment records, answer support messages, and maintain legitimate operational interests such as security, abuse prevention, and fair-use controls.
Essential service storage is used to provide and protect Nightflat. Optional analytics is based on your consent and can be turned off from this page.
Retention
Short-lived activity expires; legal records may last longer.
Room messages normally expire after 60 minutes, and radio call-in notes after no more than 2 days.
Room, station-message, and listener reports expire after 90 days. Account identifiers inside report evidence are anonymized when an account is deleted.
Playback quality events expire after 30 days. Playback lifecycle records expire after 400 days so annual operations, rights administration, and recap eligibility can be supported. Private-session rows remain subject to their exclusions during that period. On account deletion, the direct user link is removed from retained lifecycle rows. The temporary legacy track-listen table expires after 90 days and is not used to reconstruct older lifecycle events.
Short-lived signed-stream reservations expire and are cleaned after 7 days. Broader bandwidth totals are kept only for the active fair-use and operational reporting periods.
Remember-login tokens last up to 30 days, password and email-verification tokens follow their own short expiry, and active sessions end on logout, expiry, security revocation, or account deletion.
The guest fair-use cookie lasts up to 180 days unless you clear it earlier.
Payment and order records are retained for no more than 10 years to cover the Dutch seven-year accounting period and the longer period that can apply under European VAT schemes. Nightflat does not keep full card or banking credentials.
Support correspondence may remain while a case or related legal dispute is open. On account deletion, Nightflat removes the direct account link, supplied account name and email, and stored technical metadata. Closed support cases are removed after 90 days unless a legal dispute is still open.
You can clear localStorage, sessionStorage, service-worker storage, cookies, and Android app storage from your device settings. Clearing essential storage may log you out or reset local Nightflat preferences.
Your rights
You can ask about your data.
Depending on your situation and applicable law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. You may also have the right to complain to the Dutch data protection authority or another relevant supervisory authority.
Logged-in users can start a JSON data export or delete their account from the profile privacy controls. The public account deletion page explains the browser flow and limited retention. For manual privacy requests, use the official contact page and include enough detail for us to understand the account or message involved.
Updates
This notice can change with the building.
Nightflat may update this privacy notice when the service, storage, payment setup, legal requirements, or safety needs change. The latest version lives on this page.