A little more privacy.
Here is how the Fiji Client website and Windows client handle your information.
Your account and email
We store your email address, display name, account creation time, and records needed to manage sign-in sessions. Resend delivers verification codes to your email. Codes are short-lived; we store a keyed hash of each code, not the code itself. Website session cookies are essential to sign-in and download access. Signing out removes the active website session.
Your payment
Stripe processes checkout and payment information on its own hosted page. Fiji stores purchase references, payment status, and the associated account; it does not receive your full card number. Refunds or disputes may revoke access. Stripe’s own privacy notice also applies to information it processes.
Your one-PC license
The Windows client sends a hashed device identifier and a public cryptographic key identifier to enforce the permanent one-PC license. Its private device key remains on the PC. This binding, purchase records, and security records are personal data when linked to your account. Device binding is not anonymous and is not a guarantee against all forms of tampering.
Your music and preferences
Fiji reads playback metadata from the selected Windows player or its optional browser extension. With Discord presence enabled, track information, artwork, timing, and available lyrics are sent to Discord. Artwork and lyric lookups may send track and artist information to their providers. The account API is not designed to collect a listening-history database. Custom backgrounds and client settings are kept in your Windows user profile.
Browser playback
The optional Chrome, Edge, and Firefox extension runs only on supported music domains and passes track metadata, the current music-page address, and playback position to Fiji through local native messaging. It does not request cookie access, record audio, or read unrelated tabs. The local app and the services it contacts still receive the information described above.
Hosting and security
Vercel hosts the website and private downloads. The configured PostgreSQL provider stores account and license records. Infrastructure providers may process connection information, including IP addresses and request logs. The site uses short-lived download links, secure sign-in cookies, rate limiting, and signed client requests. These measures reduce risk but do not eliminate it.
The site loads its fonts from Google Fonts, which receives the browser’s request and connection information. This site does not currently include advertising trackers or a separate analytics package.
Retention and your choices
Account and device-binding records are retained while needed to provide account access and enforce the license. Purchase and payment-event records are retained as needed to establish ownership, prevent duplicate or fraudulent activation, handle payment disputes, and meet applicable legal or accounting obligations. Retention depends on those purposes and obligations rather than a single period for every record.
Expired verification challenges, website sessions, request nonces, download approvals, and rate-limit records are eligible for scheduled cleanup after one day; expired client sessions after two days, once dependent security records have been cleared. Cleanup runs in batches, so removal is not immediate at expiry.
You can disable Discord presence, remove the extension, sign out, or uninstall the app. Uninstalling does not delete your server account or reset a license. Email [email protected] to request access, correction, or deletion of personal data. We may need to verify account ownership. Available rights and required retention depend on applicable law. Account deletion can end access and does not create a new license.
Questions or requests
Fiji Client. Contact [email protected].
Visit help & setup →