Last changed 2026-10-04. The version before this date described the games only; this one covers the Resonance Lounge app as well.
1. Introduction
1.1 This policy explains what personal data narayana games UG (haftungsbeschränkt) ("we", "us", "our") processes when you use Resonance Lounge (the app for iOS, Android, the web and desktop, and this website, resonancelounge.app), and when you play our games Holodance and Beat the Rhythm, which use the same account service. We are the controller for all of it. For who we are, see Section 13.
1.2 Resonance Lounge is for adults. You must be at least 18 years old to use it, and we do not knowingly process the data of anybody younger. If you learn that somebody under 18 has an account, write to us and we will delete it.
1.3 The app contains no advertising, no advertising identifiers and no third-party analytics or tracking. This website uses our own Matomo installation (see Section 10) and nothing else that tracks you.
1.4 How to delete your account, or some of your data without the account, is on the Data Deletion page, together with exactly what we keep afterwards and for how long. You can also download your account data under your account management.
1.5 Where this policy says that a third party acts as a processor, it processes data only on our instructions and on our behalf, under a data processing agreement, and for no purpose of its own.
2. The data we process, and why
2.1 Account data: your email address, a password (stored only as a hash), whether the address is confirmed, your two-factor settings and recovery codes (hashed), your phone number if you add one (for codes and recovery only, never for signing up), the external logins you link (Apple, Google, Steam, Microsoft, Facebook, X, Spotify), your language, your country (your own answer), and when the account was created. Purpose: running your account, signing you in, keeping it secure, recovering it, and contacting you about it. Legal basis: performance of the contract with you (Art. 6(1)(b) GDPR); for security measures, our legitimate interest in protecting the service and its members (Art. 6(1)(f)).
2.2 Identity and profile data: the nickname, picture, bio, skills and interests of each identity you present, which you choose and which other members see. You may use any name; a legal name is never required. Pictures are reduced, re-encoded and stripped of metadata (EXIF, location) before storage. Purpose: showing you to the people you choose to show yourself to. Legal basis: contract.
2.3 Connections, circles and encounters: who you are connected with and as which identity, the circles and events you are a member of and your roles in them, invitations you create and redeem, the codes you scan, the record that you met somebody in real life, the introductions and resonance scores computed between you and others, and what you choose to share with whom. Purpose: the core of the service, connecting people. Legal basis: contract.
2.4 Location, in two forms, both only if you switch them on:
(a) Around you (presence): your latest position, coarsened to an area of roughly a few hundred metres, kept as one record per member that is overwritten each time and deleted when you switch presence off. We never keep a location history. Purpose: telling you when somebody you know is nearby.
(b) Meeting requests: exact coordinates, kept only while both sides of a request to meet have accepted, and deleted the moment the request ends, declines or expires.
Legal basis: your consent (Art. 6(1)(a)), given by switching the feature on and withdrawn by switching it off. Where the app uses Bluetooth or the local network to notice other members next to you, no location is computed or stored; the radio is used only while you switch it on.
2.5 Communications: the text, voice notes, pictures, videos and documents you send in chats; voice and video calls; and, where a conversation is recorded or transcribed, the recording and the transcript, the summary written from it and its translations. Whether a call is transcribed follows the choice of the person who starts it and is shown to everybody in it; recording is an explicit act, announced in the conversation. A conversation record belongs to everyone who took part and is deleted when every participant agrees. Chat, calls, recordings and transcription run on the infrastructure of Stream (getstream.io), acting as our processor; summaries and translations are produced by a language model run by Anthropic as our processor, from the transcript text only. Purpose: the service itself. Legal basis: contract; for recording, your consent and that of the other participants.
2.6 Device and usage data: an identifier the app generates on installation; your device's own per-device identifier (the identifier for vendor on iOS, the Android ID on Android), which we use only for fraud prevention and abuse review and never for advertising; what the device declares about itself (operating system and version, model, whether it is an emulator or rooted, app version, time zone, screen); push notification tokens; and, for every registration, launch, login and sign-out, the IP address, the country derived from it by our edge provider, and the user agent. We also record when the app was opened and for how long, which surface it ran on, and the moments of your onboarding. Purpose: keeping your account and the service secure, finding and investigating abuse, understanding how the app is used, and delivering notifications. Legal basis: legitimate interest (Art. 6(1)(f)) in security and in running the service; for notifications, contract. These facts are never combined into a fingerprint of your device.
2.7 Notifications: push notifications are delivered through Apple (APNs) and Google (FCM), and for messages and calls through Stream, which receive your push token and the notification's content. Where you have opted in, a change to an event you attend may reach you by SMS or WhatsApp through Twilio. Legal basis: contract; your choices in the app decide what is sent.
2.8 Subscriptions and payments: which plan you are on, through which store or payment provider, when it started and ends, and the provider's transaction references. Payment is taken by Apple (App Store), Google (Google Play) or Stripe (web and desktop); we never see card numbers or bank details, only a customer reference. The region your prices come from follows your country and, in a store, the store's own territory. Purpose: providing what you paid for, accounting, and the legal duty to keep financial records. Legal basis: contract; legal obligation (Art. 6(1)(c)).
2.9 Identity verification (optional, on paid plans): if you choose to verify an identity, a specialised provider acting as our processor (Didit, or Stripe Identity as a fallback) captures your government ID and a liveness check and matches the face against that identity's profile picture. We keep only what a law-enforcement handover would need: the legal name, a stage name where the document carries one, the document type, number and issuing country, the date of birth, the provider's references and the match result, all encrypted with access to every read logged. Document images and the liveness capture are not retained by us. Purpose: trust and safety between people who meet in real life. Legal basis: your consent; for the retained minimum, our legitimate interest in being able to identify a person who harms another member.
2.10 Date of birth, birth time and place: the date of birth if you give it (age assurance), and optionally the time and place of birth for the matching engines you switch on (astrology, Four Pillars, Jyotish, Human Design), with the readings computed from them. Legal basis: consent, withdrawn by clearing the fields.
2.11 Reports and moderation: reports you file about others and others file about you, with the reason, your words, and the identifiers of the conversations and encounters you shared in the week before; suspensions and circle bans with their reasons; appeals; and the device facts of 2.6 where an abuse case needs them. Purpose: keeping the service safe, which the stores we publish in also require of us. Legal basis: legitimate interest; where the law requires it, legal obligation.
2.12 Game data (Holodance, Beat the Rhythm): play sessions, scores and leaderboard entries under your nickname, beatmap ratings, and the movement data of replays; where you opt in, the fitness estimates (calories) the games compute. Purpose: the games. Legal basis: contract. This data is collected by the games, not by the Resonance Lounge app.
2.13 Crash and error reports: from the build that first ships it, the app sends a report to Sentry (EU region, acting as our processor) when it crashes or meets an error: the error and where in the code it happened, the app version, device model and operating system, and the steps just before. No IP address is stored, no name, no message content. Purpose: fixing defects. Legal basis: legitimate interest. The server's own logs are kept in Google Cloud.
2.14 Correspondence: what you write to us, and our answers. Legal basis: legitimate interest in answering you and in keeping a record.
2.15 We may process any of this data where necessary to establish, exercise or defend legal claims, to comply with a legal obligation, or to protect somebody's vital interests.
2.16 Please do not give us another person's personal data unless we ask you to.
3. Who else receives your data
3.1 Processors, each under a data processing agreement and each only for the purpose named: Google Cloud (Cloud Run, Cloud SQL, Secret Manager, logging; region europe-west1, Belgium) for the account service and database; MongoDB Atlas for the game database; Cloudflare in front of the website and for delivering downloads and images; Stream for chat, calls, recordings and transcripts; Stripe for web payments; Twilio for codes by SMS and WhatsApp; Apple and Google for push notifications; Anthropic for conversation summaries and translations; Didit and Stripe Identity for identity verification; Sentry for crash reports.
3.2 Independent controllers: the stores you install the app from and pay through (Apple App Store, Google Play) process your purchase under their own policies, and so do the providers you sign in with (Apple, Google, Steam, Microsoft, Facebook, X, Spotify) and, for the games, Steam, Viveport, Meta, Microsoft, Sony and Unity Technologies (see 3.3). We receive from a sign-in provider your identifier there, your name and, where the provider has verified it, your email address.
3.3 Our games use Unity Analytics, governed by the Privacy Policy of Unity Technologies; you can opt out in the games' settings. Game progression, achievements and leaderboards are also transmitted to the store you bought a game from: Steam, Viveport, Meta, Microsoft, PlayStation, Google Play, Apple. Fitness tracking through YUR.fit is opt-in and governed by their terms.
3.4 Other members see what you choose to show them: the identity you present, and in a conversation what you say in it. Content you publish (a circle's public programme, for example) can be seen by anyone it is published to.
3.5 Authorities: we disclose personal data where the law obliges us to, or where it is necessary to protect a person. A report of potentially criminal behaviour is reviewed by us first and handed on only when it stands up to that review.
3.6 We do not sell personal data, and we do not give it to anybody for advertising.
4. International transfers
4.1 Our servers and databases are in the European Union (Belgium and Ireland). Several processors in Section 3 are or may be in the United States or process data there (Stream, Stripe, Twilio, Apple, Google, Anthropic, Cloudflare, MongoDB, Sentry). Transfers rest on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the recipient is certified, and otherwise on the Commission's standard contractual clauses, with additional safeguards where needed.
4.2 What you publish or send to other members can be read by them wherever they are.
5. Security
5.1 All data travels encrypted (TLS); nothing goes over plain connections. Passwords and recovery codes are stored as hashes; identity verification data is encrypted at rest with every read logged; secrets live in a managed secret store. The service runs in the European Union. We review access to member data and log it.
6. How long we keep data
6.1 We keep personal data no longer than its purpose needs. In particular:
(a) account, identity, connection, circle, settings and communications data: for as long as your account exists, and deleted with it (Section 7), except for what the Data Deletion page lists as kept;
(b) presence location: the latest position only, deleted when you switch presence off; meeting coordinates: deleted when the request ends;
(c) conversation records (recordings, transcripts, summaries): until every participant asks for their deletion, or until the account of the last participant is deleted;
(d) the install record and access log of 2.6: 365 days from each entry, then removed by a scheduled sweep;
(e) subscription and payment records: 10 years after the end of the year they belong to (German commercial and tax law);
(f) identity verification data: 5 years after the verification, then blanked, or immediately on account deletion; the log of who read it is kept;
(g) reports, suspensions and bans: up to 5 years after they were decided, keyed by an internal id once the accounts involved are deleted;
(h) crash reports: 90 days;
(i) database backups: the account database keeps seven daily backups and a seven-day point-in-time log (about one week); the game database follows MongoDB Atlas's backup schedule. A backup is restored only to recover from a failure, and deletions made since are then repeated.
6.2 An account that was registered and never given an email address and password is kept for abuse review; we are working out the period after which such accounts are removed and will state it here.
6.3 We may keep data beyond these periods where a legal obligation requires it or to protect somebody's vital interests.
7. Deleting your account
7.1 You can delete your account yourself, at any time, in the app (Identity tab, Your account) and on this website (Manage your account). The deletion runs at once across every surface. The Data Deletion page lists what goes, what stays and why, and how to delete some data without deleting the account. If you cannot sign in, write to [email protected]; we delete within 30 days.
8. Your rights
8.1 Under the GDPR you have the right of access (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20), to object to processing based on legitimate interest (Art. 21), and to withdraw a consent at any time without affecting the lawfulness of processing before the withdrawal (Art. 7(3)). Some rights have exceptions, for example where we must keep data to comply with a legal obligation.
8.2 You exercise most of them yourself: your account management lets you see, correct, download and delete your data; the app's settings let you withdraw each consent (location, birth data, notifications). For anything else, write to us (Section 13); we answer within a month.
8.3 You have the right to complain to a supervisory authority, in particular in the EU member state where you live or work or where the alleged infringement happened. The authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Ansbach, Germany.
8.4 We make no decisions about you based solely on automated processing that have legal or similarly significant effects. Resonance scores and introductions are suggestions you may ignore; moderation decisions are made by people.
9. Cookies and local storage
9.1 The app keeps your session, your settings and a copy of your chats on your device, in the device's secure storage where the platform offers it, so it works when you are offline. Nothing in the app is a tracking cookie.
9.2 This website uses cookies for signing you in and keeping you signed in, for protecting forms against forgery, and for remembering your cookie choice. These are strictly necessary. The analytics cookie of Section 10 is the only other one.
9.3 Most browsers let you refuse or delete cookies; see your browser's help. Blocking the necessary cookies stops you from signing in here.
10. Analytics on this website
10.1 This website (not the app) uses our own Matomo installation, hosted by us, to count visits and see which pages are read. It respects your browser's Do Not Track setting, and you can opt out below. The legal basis is our legitimate interest in knowing how the site is used. Google Analytics is not used on this website; some of our pages on other platforms (Steam, YouTube) are measured by those platforms under their own policies.
11. Amendments
11.1 We may update this policy by publishing a new version here, with the date of the change at the top. For a change that matters to you, we tell you in the app or by email.
12. Credit
12.1 Earlier versions of this document were based on a template from SEQ Legal (https://seqlegal.com).
13. Our details
13.1 Resonance Lounge, this website and our games are owned and operated by narayana games UG (haftungsbeschränkt).
13.2 We are registered at Amtsgericht München (Munich), Germany under registration number HR 195759, and our registered office and principal place of business is at Forellenstraße 17, 82266 Inning am Ammersee, Germany.
13.3 You can contact us by post at that address, by telephone on +49 (8143) 9928688, or by email at [email protected] for anything about your data and [email protected] for everything else.