1. Who We Are
Chameleone FM 94.9 is a radio station based in Bujumbura, Burundi. We operate the Chameleone FM mobile application for Android and iOS, and the website at chameleone.fm.
Data controller: Chameleone FM
Contact: privacy@chameleone.fm · chameleone.fm/contact
2. Scope
This Privacy Policy covers the Chameleone FM mobile application and the website at chameleone.fm. Data practices differ between the app and the website — see Sections 4 and 5 below. It does not cover third-party websites or services you may open through links (for example, social media or WhatsApp).
3. Summary
You can listen to Chameleone FM without creating an account. An account is optional and is required only for features such as live listener chat, a saved profile, and push notifications. We do not sell your personal data and we do not display third-party advertising.
When you use our services we may process:
- On-device preferences — playback settings and language (stored locally on your device)
- Account information — if you sign in with email, Google, or Apple (via our authentication providers)
- Chat messages and profile details — if you use listener chat or set a username/avatar
- Technical and usage data — to deliver streams, secure our services, and understand how features are used in aggregate
- Push notification tokens — if you allow notifications on the mobile app
4. Mobile App (com.chameleone.fm)
4.1 Listening without an account
You may stream live radio, browse the program schedule, read news, and change on-device preferences without signing in. In this mode we do not create a listener profile for you.
4.2 Information stored locally on your device
The app saves the following on your device using local storage. This data is not transmitted to our servers unless noted elsewhere in this policy:
- Playback settings (volume, mute, auto-play, background playback, mono mode)
- Equalizer preset selection
- Language preference (English or French)
You can remove this data by clearing the app's storage in your device settings or uninstalling the app.
4.3 Accounts and sign-in (optional)
If you choose to create an account or sign in, we use Supabase (our backend platform) together with Firebase Authentication to verify your identity. You may sign in using:
- Email and password
- Sign in with Google
- Sign in with Apple (iOS)
Depending on the method you choose, we may receive:
- Email address
- Display name or username you provide
- Profile photo (if supplied by Google or Apple, or if you upload one)
- A unique account identifier assigned by our authentication providers
We use this information to operate your account, display your profile in chat, and secure access to account-only features. We do not use social sign-in data for advertising.
4.4 Profile, chat, and community features
If you are signed in, we store the following on our servers (hosted by Supabase):
- Profile — display name, username, optional avatar image URL, account role (for example listener or staff), optional phone for staff, and account timestamps
- Chat messages — message text, your user ID, username/role shown at the time of posting, and timestamp. Chat requires a signed-in account. Messages are visible to other signed-in listeners in the app's chat feature and may be moderated by station staff.
- Avatar uploads — if you choose a profile photo, the image is stored in our secure storage bucket and linked to your profile
You can update your username and avatar in the app. You can delete your account from Settings, which removes your auth record, profile, and chat messages associated with your account, subject to any legal retention requirements.
4.5 Push notifications and preferences
If you allow notifications, we use Firebase Cloud Messaging (FCM) to deliver station updates and announcements. We store an FCM device token linked to your account so we can send notifications to your device. In Settings you can toggle push notifications, email updates, and feedback prompts. You can disable notifications at any time in your device settings.
4.6 App usage analytics and crash reporting
We use PostHog to understand how features are used in the mobile app and admin panel (for example screen views, stream play/pause, news opens, and chat interactions). PostHog may collect device and app-instance identifiers, session replay data where enabled, and event metadata as described in PostHog's Privacy Policy. We also use Google Firebase Crashlytics to collect crash reports and stability data so we can fix errors. Analytics and crash data are used to improve our services and are not sold to advertisers.
4.7 Streaming and content delivery
When you stream live radio or load schedule, presenter, and news content, the app connects to our backend and streaming infrastructure. This may process:
- Network connection data — IP address, device type, timestamps, and request metadata needed to deliver audio and content
- Stream URLs and program data — loaded from our Supabase database and delivered through our broadcast/streaming providers
- Device information — operating system and app version needed for playback and compatibility
Connection logs may be retained for a limited period for operations, troubleshooting, and security.
4.8 Information the app does not collect
- Precise or approximate GPS location
- Contacts, SMS, call logs, or calendar data
- Microphone recordings (the microphone permission string on iOS relates to audio playback session configuration; we do not record your voice)
- Payment or financial information
- Health or biometric data
- Advertising identifiers for targeted third-party ads
5. Website (chameleone.fm)
When you use our website, we may process the following:
- Streaming and page content — our site loads live audio, program schedules, presenter information, and news articles from our Supabase backend. Technical metadata (such as IP address, browser type, and timestamps) may be logged for delivery and security.
- Language preference — stored in your browser's
localStorageif you switch between English and French - Careers application drafts — if you start a job application, form progress may be saved locally in
localStorageon your device until you submit or clear it - News engagement metrics — when you interact with news content, we may increment aggregate article counters (such as views or opens) to understand overall interest. These metrics are tied to articles, not used to build advertising profiles.
- Newsletter or story leads — if you submit your email or contact details through a lead form, we store that information so our team can follow up
- Contact form — submissions through chameleone.fm/contact (name, email, message) are emailed to our team to respond to your inquiry
- Careers applications — job applications submitted through our careers pages are emailed to our HR team. Application data you provide (such as name, email, phone, experience, and attachments described in the form) is used solely for recruitment
The public website does not require an account to listen or browse news. We do not use third-party advertising trackers on the website.
6. Admin and Staff Systems
Station staff access a separate password-protected admin panel to manage programs, news, roles, broadcasts, and moderation. Staff accounts are provisioned by administrators and are subject to the same authentication and security controls described in this policy. Staff activity may be logged for security and operational purposes. The admin panel uses PostHog for aggregate product analytics shared with authorized administrators.
7. App Permissions
The mobile app may request the following permissions:
- Internet & network state — to stream live radio, sync chat/news/schedule data, and authenticate accounts
- Wake lock & foreground service (media playback) — to continue audio playback when the app is in the background or the screen is off
- Notifications — to deliver optional push alerts if you opt in
- Photo library (iOS) — only when you choose to upload a profile avatar; we do not access your photos otherwise
We do not request access to your camera, microphone (for recording), contacts, precise location, or SMS.
8. Third-Party Services
We use trusted service providers to operate Chameleone FM. Depending on how you use our services, data may be processed by:
- Supabase — authentication, database, realtime chat, file storage, and API hosting (Supabase Privacy Policy)
- Google Firebase — authentication (Google sign-in), crash reporting, and push messaging (Firebase Privacy)
- PostHog — product analytics for the mobile app and admin panel (PostHog Privacy Policy)
- Apple — Sign in with Apple on iOS (Apple Privacy Policy)
- Google — Sign in with Google and Google Fonts on the website (Google Privacy Policy)
- Chameleone FM streaming infrastructure — live audio delivery
- Resend / email hosting — delivery of contact and careers form messages where configured
- Vercel — website hosting for chameleone.fm where applicable
These providers process data on our behalf under their own privacy terms and appropriate contractual safeguards. We do not share your personal information with data brokers or advertising networks for their independent marketing purposes.
9. How We Use Information
- Deliver live radio streaming and related content (schedule, news, presenters)
- Operate optional accounts, profiles, and listener chat
- Send push notifications you have opted into
- Maintain app and website security, prevent abuse, and troubleshoot errors
- Understand feature usage through analytics to improve our services
- Respond to contact, careers, and newsletter inquiries
- Moderate community chat and enforce our community standards
- Meet legal obligations and protect our rights
10. Legal Basis (EEA/UK Users)
If you are in the European Economic Area or United Kingdom, we process personal data based on:
- Contract — to provide the streaming and account features you request
- Legitimate interests — to secure, maintain, and improve our services, and to understand aggregate usage
- Consent — where you opt in to push notifications, choose social sign-in, upload an avatar, or voluntarily submit forms
You may withdraw consent at any time where processing is consent-based (for example, by disabling notifications or deleting your account).
11. Data Retention
- On-device preferences — until you clear app data or uninstall the app
- Account and profile data — until you delete your account or ask us to delete it
- Chat messages — retained while your account exists; deleted when your account is deleted, unless we must retain specific content for legal or safety reasons
- FCM tokens — until you delete your account, disable notifications, or the token is refreshed/replaced
- Analytics events — retained according to PostHog and Firebase Crashlytics configured retention settings
- Server and streaming logs — limited period for operations and security, then deleted or anonymized
- Contact, careers, and lead submissions — retained only as long as needed to handle your request and meet legal obligations
- Website localStorage — until you clear your browser storage
12. Data Security
We use industry-standard measures to protect data in transit (including HTTPS for streaming and API requests) and limit access to systems that process listener data. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
13. Your Rights and Choices
Depending on your location, you may have the right to:
- Access, correct, or delete personal information we hold about you
- Export a copy of your account data where technically available
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Lodge a complaint with a data protection authority
Account holders: you can update your profile in the app, disable push notifications in device settings, and delete your account from the app's Settings screen.
All users: on-device data can be removed by clearing app or browser storage. To exercise other rights, email privacy@chameleone.fm. We will respond within a reasonable time.
14. Children's Privacy
The Chameleone FM app and website are not directed at children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
Listener chat and account features are intended for users who meet the minimum age required to consent to online services in their jurisdiction.
15. International Data Transfers
Our services may be accessed globally. Data may be processed in Burundi and in countries where our hosting, authentication, analytics, and infrastructure providers operate (including the United States and the European Union). We take steps to ensure appropriate safeguards where required by law.
16. No Sale of Personal Data
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
17. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Continued use of the app after changes take effect constitutes acceptance of the updated policy. For material changes, we may also notify users through the app or our website.
18. Contact Us
Questions about this Privacy Policy or our data practices?
Email: privacy@chameleone.fm
General inquiries: hello@chameleone.fm
Website: chameleone.fm/contact
Address: Chameleone FM Studios, Ave Source du Nil, Rohero, Bujumbura, Burundi