Privacy policy
Last updated: 1 October 2026
Discow is a map of music venues and the nights they host. This policy describes what the site and the app collect, why, and what you can do about it.
It is written as close to the technical truth as possible. Where something never leaves your device, it says so; where something does, it says that too.
Who is responsible
Lucien Hubert EI, sole trader, 47 rue Vivienne, 75002 Paris, France.
SIRET 819 623 760 00033.
Contact: [email protected]
Your position — it never leaves the device
The app may ask for your position. It serves two purposes and only two: sorting tonight’s parties by distance, and bounding the search to a radius around you.
That position is sent to no server, ours or anyone else’s. The calculation happens entirely on your device, and it is not kept once the app closes.
You can decline: everything works, and the night is bounded by arrondissement instead. The choice can be changed at any time in your device settings.
Audience measurement — what leaves, and in what form
To know what is being looked at and what is not, we record, with no cookie and no advertising identifier: the path of the screen opened, the tag or curated selection activated, and the text typed into search, normalised.
On arrival our server attaches a visitor identifier computed as SHA-256 of the day’s salt, the project, the IP address and the user agent.
The salt is random, lives only in memory, and is thrown away each day. Once the day has passed, nobody — us included — can link that identifier back to an IP address. Two days do not link: the same device produces a different identifier tomorrow. Your IP address is never stored; it enters the calculation and disappears.
There is no advertising tracker, no third-party measurement tool, no device identifier. The app does not ask for Apple’s tracking permission, because it does not track in the sense Apple means.
What we do not collect
No address book, no photos, no microphone, no calendar, no advertising identifier, no browsing history outside the service.
Accounts
The mobile app offers no way to create an account or sign in. Nothing is asked of you there, not even an email address.
The website offers accounts. If you create one, we keep your email address and a hashed password; for a paid account, billing details are handled by Stripe, which has its own policy. None of this passes through the mobile app.
Feedback you send us
On the website, a form lets you tell us what you think. It sends what you write in it — the topic you chose and your message —, your email address if you give it, and the language and address of the page you are writing from.
This feedback reaches Sourcea, the tool we publish to receive and follow up on messages. Nothing leaves until you send the form, and it sets no cookie and no identifier in your browser.
Your email address is only used to reply to you: it is neither passed on nor used for marketing.
Third parties you contact by using us
The basemap comes from CARTO, built on OpenStreetMap data. Your device requests the tiles directly, so CARTO’s servers see your IP address, as any server you contact does. We pass them nothing about you.
Ticket links leave the service and open sites that are not ours — Resident Advisor, Shotgun, Dice, venues’ own sites. What happens there is governed by their policies. We sell no tickets and receive nothing from those sites.
How long
Audience-measurement events are kept for thirty days, then deleted. This is not an intention: a purge runs inside the service that receives them — once at start-up, then once a day — and erases everything past that window.
Thirty days, because that is the window of the only screen that ever reads this data. The French regulator tolerates thirteen months; we keep no more than we use.
The visitor identifier stops being linkable to anything after a day, by construction.
Feedback sent through the form is not purged automatically: we keep it to come back to, and delete it on request at [email protected].
On what legal basis
Audience measurement rests on our legitimate interest in understanding how the service is used.
The design was built to fall within the consent exemption the French regulator provides for audience measurement: a single purpose, no cross-referencing with other processing, no tracking across sites or apps, and an identifier that stops being linkable after twenty-four hours.
Geolocation rests on your consent, given at the system prompt and revocable at any moment in the settings.
Feedback sent through the form rests on your consent: you choose to send it, and what goes in it.
Your rights
You have the rights of access, rectification, erasure, objection and restriction set out by the GDPR. Write to [email protected].
One honest note about the measurement data: because the visitor identifier is irreversible and renewed daily, we have no way of finding the events that correspond to you. That is not a refusal, it is a consequence of how the thing is built — it was made unable to recognise you. Your account data is findable.
You may also contact the CNIL: www.cnil.fr
Children
The service is not aimed at children and does not knowingly collect data about them.
Changes
Any change will be published on this page, with its date. A change that widened what is collected will be announced in the app.