HORHI

Privacy Policy

Last updated: 16 September 2026

Who we are

HORHI is an independent music project operated by a single person. The site is horhi.com. Contact for any privacy question is below.

Data from listeners

Listening to the stream requires no account and no personal data.

If you create an account, we store your email address, a display name of your choosing and a password hash. We never store passwords in readable form.

We keep what you do on the station: tracks you liked, listening history and shout-outs you sent. This exists to make your own page work and is not sold or shared.

The site uses Google Analytics and Yandex Metrica to count visits. They set their own cookies and are governed by their own policies.

News emails

If you tick the box when creating an account, or switch news on in your settings, we use your email address to tell you about new tracks and videos. We send these rarely and only about the project.

Every email contains a one-click unsubscribe link that works without signing in. You can also switch news off at any time in your settings. We never share or sell your email address.

Data from connected social accounts

The publishing tool connects to social platforms owned by the project. When a platform account is connected through its official API, we receive and store: the account identifier, an access token, a refresh token and their expiry dates.

From the TikTok API we additionally request basic profile information (nickname, username, avatar) and the creator's current posting settings — the privacy options available to the account and whether comments, duets or stitches are disabled. This information is displayed in the publishing form so that each post is configured correctly, as required by TikTok's guidelines. It is not stored beyond the page session.

Tokens are stored on our own server, in our own database, accessible only to the operator. They are used for one purpose: publishing the project's own videos to the project's own accounts. They are never sold, shared with third parties, or used for analytics or advertising.

How long we keep it

Social platform tokens are kept until the account is disconnected. Disconnecting revokes the token with the platform and deletes it from our database immediately.

You can also revoke access at any time from your own settings on the platform, which invalidates the token regardless of our storage.

Listener account data is kept until the account is deleted.

Deleting your data

To delete a connected social account and everything stored for it, open the publishing tool and press Disconnect next to that account. This revokes the access token with the platform and deletes it from our database immediately, along with the stored account identifier.

To delete a listener account and all data attached to it - likes, listening history and shout-outs - write to the address below from the email address of that account, or use the delete option in your account settings. We complete such requests within 30 days and confirm by email.

If you authorised our app from a social platform, you can also revoke that access from the platform's own settings at any time. The token stops working immediately, regardless of our storage.

Your rights

You may request access to your data, its correction or its deletion by writing to the address below. We answer every such request.

Security

The site is served over HTTPS. Credentials and tokens are held outside the web root or in the database with restricted access. Administrative pages are open only to the operator's account.

Changes

This policy may be updated. The date above always reflects the current version.

Contact

Questions about this document: [email protected]