Innerhaus

Privacy Policy

Effective date: 15 June 2026  ·  Last updated: 15 June 2026

1. Who we are

Innerhaus ("Innerhaus," "we," "us," or "our") is the verified-attendance home base for live-music communities. This Privacy Policy explains how we collect, use, share, and protect personal information when you use the Innerhaus mobile application and any related services, websites, and features (together, the "Services").

Innerhaus is currently operated by its founders, Kieran Cousins and Danielle Gnibus, who act as the joint controllers of the personal information described in this Policy. On incorporation, the controller will become Innerhaus, a Delaware corporation, and this Policy will be updated accordingly.

If you have any questions about this Policy or your personal information, contact us at kieran@getfrequenz.app.

This Policy applies to the Innerhaus application(s) and Services, not only to any Innerhaus website.

2. Scope and your agreement

This Policy applies to everyone who uses the Services, including fans, superfan moderators, inner-circle members, artists, and artist managers. By using the Services, you acknowledge that you have read and understood this Policy. Where we rely on your consent to process personal information, we will ask for it separately and you may withdraw it at any time.

This Policy does not apply to third-party platforms you connect to Innerhaus (such as Instagram, Discord, or a ticketing platform), or to platforms we link out to (such as Spotify or Apple Music). Those services are governed by their own privacy policies.

3. Age requirements

The Services are intended for users aged 16 and over. We do not knowingly collect personal information from anyone under 16. If you believe a person under 16 has provided us with personal information, contact kieran@getfrequenz.app and we will delete it.

Many live-music venues impose their own minimum-age requirements (commonly 18+ or 21+, depending on jurisdiction and the event). Those requirements are set and enforced by venues and promoters, not by Innerhaus, and are separate from the 16+ minimum for using the Services.

4. Information we collect

We collect the following categories of personal information.

4.1 Account and identity information

When you create an account, we collect your email address, display name, and (optionally) profile photo or avatar, together with the identifier from your chosen sign-in method (Apple Sign-In, Google, email magic-link, or passkey). We use a third-party authentication provider to manage sign-in.

4.2 Ticket-verification and attendance information

To grant verified status, posting rights, and access to features such as Film Mode, we verify that you purchased a ticket to a specific event. Depending on how you verify, this may include:

  • order and confirmation details retrieved from, or provided by, a ticketing platform you authorize (for example DICE, Shotgun, Laylo, Eventbrite, or Tixr), which may include the event, ticket type, and purchase information; and
  • the contents of ticket-confirmation emails you forward to us, which we parse to confirm your purchase.

This information establishes which events you attended and your status within a community, and it informs aggregate community metrics. Forwarded emails are processed only to confirm ticket purchases and are retained no longer than necessary for that purpose and for dispute resolution.

4.3 Film Mode photographs and other content you create

If you use Film Mode, we collect the photographs you capture during a show. These images are stored privately until they "develop," after which they may be revealed to you and, if you choose, shared or submitted for community or artist curation.

Photographs taken at a live event may depict other people who are present. You are responsible for respecting others' wishes when capturing images, and for not capturing people who have asked not to be photographed. We do not apply facial recognition or other biometric processing to Film Mode photographs, and we do not use them to identify individuals.

You can revoke a submitted photograph at any time. When you do, we remove it from curation and, if it was already published, from the relevant feeds, with cleanup completing within a short period.

4.4 Social and community activity

We collect the content and interactions you create within the Services, including posts, comments, reactions, meetup creation and RSVPs, follows, and (where offered) peer connection requests.

4.5 Connected-platform content

With your authorization, you can connect external accounts you control so that your own published content appears in your Innerhaus community. This may include:

  • Instagram — your connected Business or Creator account's own published Posts and Reels, accessed through Meta's official APIs under our Meta app, only after you grant permission;
  • Discord — activity from servers and channels you connect via our bot;
  • YouTube — videos published on a channel you connect;
  • TikTok — your published videos, where supported by TikTok's API;
  • Substack and similar newsletters — published posts ingested via public RSS; and
  • Spotify and Apple Music — public catalogue metadata used to generate outbound links and embeds (we do not ingest listening data).

We access connected-platform content only for accounts that have authorized the connection, and only the content needed to populate the relevant community surface. We do not access your followers, your private messages, or content belonging to people who have not connected their accounts. If you disconnect a platform, we stop ingesting from it and remove cached content as described in Section 9.

4.6 Event and tour information

To populate show schedules, we ingest publicly available event and tour data from aggregators and ticketing sources, including Songkick, Bandsintown, Ticketmaster, and publicly published structured data on event pages (for example Resident Advisor). This information concerns artists, venues, and events rather than identifiable fans.

4.7 Device and technical information

We collect information generated through your use of the Services, including device and push-notification tokens, IP address, user-agent string, timestamps, and app-usage and diagnostic data. Where you opt in to ingestion of gated sources on an artist's behalf, we also record the consent event (timestamp, IP address, user agent, and the specific sources consented to) to maintain an auditable consent record.

4.8 Moderation and status information

We maintain your status within each community (for example verified, inner-circle, or moderator) and records of moderation actions taken by or affecting you.

5. How we use your information and our legal bases

We use personal information for the purposes below. Where the EU/UK GDPR applies, the legal basis for each purpose is identified.

PurposeExamplesGDPR legal basis
Provide and operate the ServicesCreate your account, verify tickets, render your feed, run Film Mode, surface connected contentPerformance of a contract
Verify attendance and assign statusConfirm purchases, grant verified/inner-circle status, gate posting and Film ModePerformance of a contract
Process Film Mode photographsDevelop, reveal, share, and (with your choice) submit photos for curationConsent
Connect external platformsIngest your own published content from accounts you connectConsent
Send notificationsRoll-ready alerts, meetup reminders, tour announcements, service messagesConsent (push) / legitimate interests (service messages)
Maintain safety, security, and integrityPrevent fraud and abuse, enforce community rules, debug, audit consentLegitimate interests
Improve the ServicesUnderstand usage, measure community health, develop featuresLegitimate interests
Comply with lawRespond to lawful requests, meet legal obligationsLegal obligation

Where we rely on legitimate interests, we balance those interests against your rights and only proceed where they are not overridden. You may object to processing based on legitimate interests as described in Section 11.

We do not sell your personal information, and we do not use Film Mode photographs, ticket data, or connected-platform content for advertising or to build advertising profiles.

6. Platform Data from Meta (Instagram)

This section describes how we handle information obtained through Meta's APIs, in addition to the rest of this Policy.

When you connect an Instagram Business or Creator account, we access only the published Posts and Reels of the account you connect, through Meta's official APIs and under our own Meta app, and only after you grant permission. We use this information solely to display your published content within your Innerhaus community and, where you enable it, to syndicate posts you create in Innerhaus back out with attribution.

We do not sell Platform Data, we do not transfer it to data brokers, and we do not use it for any purpose other than providing the Services you connected it for. We retain Platform Data only as long as needed to provide the Services, and we delete it when you disconnect Instagram, when you delete your account, or when you request deletion under Section 12. Our use of information received from Meta's APIs follows Meta's Platform Terms and Developer Policies.

7. How we share information

We share personal information only as described here.

  • Within communities. Content you post, your reactions and RSVPs, and your community status are visible to other members of the relevant community according to its access tier. Visitors who are not verified may be able to read certain content but cannot post or react.
  • Service providers (processors). We share information with vendors who process it on our behalf and under contract, including: our database, authentication, storage, and serverless infrastructure provider (Supabase); our inbound-email processing provider (SendGrid); platform providers you connect (Meta/Instagram, Discord, Google/YouTube, TikTok, Substack); catalogue and link providers (Spotify, Apple); event-data sources (Songkick, Bandsintown, Ticketmaster); push-notification delivery (Expo); geocoding (Mapbox); link-preview rendering; and, where used, managed data-fetching infrastructure for permitted sources. These providers may process information only for us and may not use it for their own purposes.
  • Legal and safety. We may disclose information where required by law, to respond to lawful requests, or to protect the rights, safety, and security of users, the public, or Innerhaus.
  • Business transfers. If Innerhaus is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

We do not "sell" personal information as that term is defined under U.S. state privacy laws, and we do not "share" it for cross-context behavioral advertising.

8. International data transfers

We are based in the United States, and we process information in the United States and in the locations where our service providers operate. If you are in the European Economic Area, the United Kingdom, or another region with data-transfer restrictions, we transfer your information to the United States and other countries in reliance on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, where required. You may contact us for more information about these safeguards.

9. Data retention

We keep personal information only as long as necessary for the purposes described in this Policy, after which we delete or anonymize it.

  • Account information is retained while your account is active and for a limited period afterward.
  • Ticket-verification records are retained to maintain your verified status and attendance history, and for dispute resolution.
  • Forwarded ticket emails are retained only as long as needed to confirm a purchase and resolve any dispute, then deleted.
  • Film Mode photographs are retained while your account is active; revoked submissions are removed from curation and feeds promptly after revocation.
  • Connected-platform content is cached only while the connection is active; when you disconnect a source or revoke consent, we stop ingesting and remove cached content (other than records we are required to keep), generally within 30 days.
  • Consent records for source ingestion are retained for the life of the consent and renewed periodically; lapsed consent disables the affected ingestion.

10. How we protect your information

We use technical and organizational measures to protect personal information, including encryption in transit, access controls, row-level security on our database, and private storage for sensitive content such as undeveloped Film Mode photographs. No system is perfectly secure, and we cannot guarantee absolute security, but we work to protect your information and to limit access to those who need it to operate the Services.

11. Your privacy rights

11.1 EEA and UK residents (GDPR)

Subject to applicable law, you have the right to: access the personal information we hold about you; request correction of inaccurate information; request erasure; restrict or object to certain processing; request portability of information you provided to us; and withdraw consent where processing is based on consent (without affecting prior processing). You also have the right to lodge a complaint with your local data-protection authority.

11.2 California residents (CCPA/CPRA)

Subject to applicable law, you have the right to: know the categories and specific pieces of personal information we have collected; know the categories of sources, the business purposes, and the categories of third parties with whom we share information; request deletion; request correction; and not be discriminated against for exercising your rights. Because we do not sell or share personal information for cross-context behavioral advertising, no opt-out of sale or sharing is required; if that ever changes, we will provide a clear opt-out. You may also direct us to limit the use of any sensitive personal information to what is necessary to provide the Services.

11.3 How to exercise your rights

To exercise any of these rights, email kieran@getfrequenz.app. We will verify your request and respond within the timeframes required by applicable law. You may use an authorized agent where the law permits.

12. How to delete your data

You can request deletion of your personal information at any time:

  • In-app: delete your account from the profile/settings screen, which removes your account and associated personal information, subject to records we are legally required to retain; or
  • By request: email kieran@getfrequenz.app with the subject line "Data Deletion Request".

When you delete your account or your data, we delete your personal information from our active systems and instruct our service providers to do the same, and we remove data obtained from connected platforms, including any Instagram Platform Data. Some information may persist in backups for a limited period before being overwritten, and we may retain limited records where required by law.

13. Third-party platforms and links

The Services let you connect to and link out to third-party platforms. We are not responsible for the privacy practices of those platforms. Review their privacy policies before connecting or sharing information with them.

14. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you within the Services. Your continued use of the Services after an update takes effect means you accept the revised Policy.

15. Contact us

Innerhaus

Email: kieran@getfrequenz.app