Melo

Privacy Policy

Last updated: 21 September 2026

Melo is a radio directory and player: the Android, Wear OS, Android TV and Automotive apps, and the website at themelo.in. This policy says what each does and does not do with data about you. The short version: there is no account, no cookie, no advertising and no profile, and the little the service does process is listed here in full.

Who is responsible

The data controller is Sudhi S, an individual developer in Kerala, India, reachable at support@sudhi.in. The same address is the grievance contact under India's Digital Personal Data Protection Act, 2023 and the point of contact for data-protection authorities.

What we do not collect

No name, email address, phone number, contacts, precise location, advertising identifier or device identifier. No account and no sign-in exist. No analytics or advertising SDK is built into the apps, and no cookie of any kind is set by the website — which is why it shows no cookie banner: there is nothing to consent to.

What stays on your device

In the apps, and in the website's browser storage, kept only there and never sent to us:

Deleting the app, or clearing the site's data in your browser, deletes all of it. This storage is used solely to provide what you asked for, which is why it needs no consent under the ePrivacy rules.

What reaches our servers, and why

Everything below is processed on Cloudflare's network, which runs our servers (see "Who else is involved" below).

- Catalogue and page requests. Loading the station list, or a web page, sends an ordinary web request. Like any web server ours sees your IP address, the page or language codes requested, your browser's identification string and, on the website, the page you came from. Legal basis: our legitimate interest in running the service. Retention: request logs are kept by Cloudflare for up to 7 days for troubleshooting and abuse prevention, then deleted. They are not used to build a profile of anyone. - Rate limiting. To keep the service up, the number of requests from an IP address in a minute is counted and capped. The count lives only for that minute. Legal basis: legitimate interest in preventing abuse. - "Listening now" counts (website). While you play a station in the browser, the page sends a heartbeat every 30 seconds containing the station and a random token the page made up for itself. The token is the only identity involved — no IP address, no cookie — it is held in memory only, and it is forgotten 90 seconds after the last heartbeat. What is shown to others is a number. Legal basis: legitimate interest in showing which stations are live and listened to. - "Near you" (website). The home page asks our server for stations that match the country the request came from and the languages your browser says it prefers. Both are read from the request, used for that one answer, and not stored. - Page counts (website). The website uses Cloudflare Web Analytics, which counts page views without cookies, without fingerprinting and without storing IP addresses; it tells us how many people visited which pages, not who. If your browser sends the Global Privacy Control signal, the page you receive omits it entirely. Legal basis: legitimate interest in knowing whether the site is used. - Support email. If you write to us, we keep the correspondence for as long as needed to deal with it.

Connections your device makes to other people's servers

A radio directory cannot work without these; read this part.

Playing a station usually connects your device directly to that broadcaster's server. That connection is between you and them: they see your IP address, when you listened and for how long, and what your player sends in its request headers. Each broadcaster is an independent controller with its own privacy policy, which we neither control nor review.

On the website, some streams are relayed through our servers. A browser refuses to play a plain "http://" stream inside an "https://" page, so for those stations the website fetches the stream on your behalf and passes the bytes through unchanged. In that case the broadcaster sees our server's address rather than yours; we store nothing and inspect nothing about the audio. The same is true of the "now playing" title some streams announce, which our server reads and shows for a few seconds and does not record.

Station artwork. The website serves all station logos through our own domain, so browsing it contacts no third-party image host. In the apps, a third of the logos are served from our domain; the rest — and this is most of them — artwork is also loaded directly from other people's servers: the broadcaster's own site, or the public directory a listing came from (for the largest share, the instant.audio content delivery network). Those hosts see your IP address the way any web request does. No identifier of ours travels with those requests.

One third-party script. Streams in the HLS format are played in most browsers with the hls.js library, loaded from the jsDelivr content delivery network the first time such a stream is played, and pinned to its exact contents. jsDelivr sees the request for that file and your IP address, under its own privacy policy.

Opening a station's website leaves Melo. Following the link hands you to that site, under its terms and its privacy policy.

If you would rather not make these connections, do not play a station and do not open a station's website. The catalogue itself can be browsed from our domain alone.

Who else is involved

- Cloudflare, Inc. hosts and delivers the service, keeps the request logs described above, runs the rate limiter, the listener counter and the cookieless page counts, and does so at data centres around the world, including inside and outside the EU and India. Cloudflare acts as our processor under its Data Processing Addendum, which incorporates the EU Standard Contractual Clauses and Cloudflare's certification under the EU-US Data Privacy Framework. - jsDelivr serves one script, as described above. - Broadcasters receive your connection directly when you play their stream and are independent controllers, not our processors.

We sell nothing to anyone and share nothing with anyone else.

App permissions

The Android apps ask only for what playing radio needs: network access and its state; a foreground service so playback continues with the screen off, with a notification for it; a wake lock during playback; an exact alarm and a start at boot, only if you set the radio alarm; and permission to post the playback notification. No location, camera, microphone, contacts, calendar, storage or phone permission is requested, and none is used.

Security

Every connection to our servers is encrypted (HTTPS, with HSTS). The website sends a strict Content-Security-Policy so that only our own code runs on it. Because we keep no database of people, there is no store of personal data to breach; should the request logs described above ever be exposed, we would inform the affected users and the relevant authorities as the law requires.

Automated decisions, profiling, special categories, sale

None. No decision with legal or similar effect is made about you by automated means; no profile is built; no special-category data (health, beliefs, ethnicity and so on) is processed — note that which *station* you play is not recorded by us at all; and no personal information is sold, rented or shared for advertising. For residents of California and other US states with privacy statutes: we do not "sell" or "share" personal information and have not done so in the preceding twelve months, and the Global Privacy Control signal is treated as an opt-out.

Children

Melo is not directed at children and collects no personal data from anyone, of any age. If you believe a child has sent us personal data by email, tell us and we will delete it. We do not control what a third-party station broadcasts — see the Terms of Service.

Your rights

Under the GDPR and the UK GDPR (if you are in the EU, EEA or UK), the Digital Personal Data Protection Act (if you are in India), and comparable laws elsewhere, you have the right to ask what personal data we hold about you, to have it corrected or erased, to object to processing based on our legitimate interests, and to data portability. Because nothing we hold is tied to an identifiable person, in practice there is nothing to hand over or erase — but ask, and we will answer, at support@sudhi.in, within a month.

You also have the right to lodge a complaint with a data-protection supervisory authority, in particular the one in the EU member state where you live or work, the UK Information Commissioner's Office, or the Data Protection Board of India. We would appreciate the chance to answer first.

We have not appointed a representative in the EU under Article 27 GDPR: the processing described here is occasional, involves no special categories of data and no profiling, and is unlikely to result in a risk to anyone's rights, which is the exemption that article provides.

If we have got something wrong

If you believe anything Melo does breaches a privacy or data-protection law where you live, tell us at support@sudhi.in. We will look into it promptly and fix it. See the Terms of Service for the same promise about station listings and content.

Changes

Material changes will be reflected here with a new date. Because this document is served from our API, you will see the current version without updating the app.

Contact

support@sudhi.in