01 / ACCOUNT-FREE, NOT IDENTITY-FREE
Oasis Radio does not require a listener account. The receiver creates a random Listener Session identifier in local browser storage and a separate random tab identifier for the current page instance. These are pseudonymous identifiers: they are not a name, but they can distinguish a browser session and its tabs.
02 / RECEIVER AND STATION DATA
When the optional Convex backend is connected, the receiver may send the Station key, Listener Session and tab identifiers, presence state and heartbeat time, current Program Item and exact occurrence, and a Skip Vote.
Receiver Power and in-app volume determine whether a tab is eligible to report active presence. The app does not store the exact volume level in the backend, but behavior records can show that an audible window ended because Receiver Power was turned off or volume reached zero.
03 / ENGAGEMENT AND RELIABILITY DATA
The beta may record Song exposure, natural completion, exact-next continuation, early exit, audible listening-window start and end times, active duration, Program Item timing, interruption or departure reason, and event timestamps. Skip Votes remain separate from behavior events.
These records support shared playback, Active Listener and collective Skip eligibility, private aggregate listening metrics, reliability checks, abuse prevention, and operation of the strict-free beta.
04 / OWNER ACCESS
The protected Owner Control Room uses one HTTP-only Owner-session cookie named oasis_owner. It confirms access for up to 12 hours, uses SameSite=Strict, and is marked Secure outside local development. It is not a listener advertising or ranking cookie.
05 / PROVIDERS
Cloudflare serves the web application and static MP3 files. Convex is the optional provider for shared server time, Station state, presence, Skip Votes, and behavior records. Network providers may process ordinary request information such as IP address, request headers, and browser or device information under their own notices. Oasis Radio does not add those fields to its listener analytics tables.
The launch review is currently U.S.-focused. Provider processing may occur in the United States or other locations described in their notices. This draft does not promise a particular processing territory or resolve whether a worldwide launch is cleared.
06 / RETENTION
The Listener Session identifier remains in local storage until browser data is cleared. The tab identifier is not written to persistent browser storage and is replaced when that page instance ends or reloads. The Owner-session cookie expires after 12 hours.
When Convex analytics are enabled, raw behavior events, stale presence rows, and per-Session Skip Votes are scheduled for removal once they reach the 30-day server-time cutoff. Before eligible behavior and Skip rows are deleted, the service may merge supported totals into daily Station and Program Item aggregates that contain no Listener Session or tab identifiers. Those identity-free aggregates may be kept longer and currently have no automatic expiry.
Cloudflare and Convex may retain their own security, request, or service records under their policies and controls.
07 / WHAT THE MVP DOES NOT BUILD
The listener product does not ask for names, email addresses, listener accounts, precise location, contacts, payment details, or advertising profiles. It does not sell listener data, use cross-context behavioral advertising, or publish listener profiles, Likes, rankings, or leaderboards.
08 / LISTENER CONTROLS
Turning Receiver Power off or setting in-app volume to zero ends active-listener eligibility. Clearing the browser's site data removes the locally stored Listener Session identifier and creates a new one on a later visit. Because there is no account and the service does not know a listener's name, Oasis Radio may be unable to locate a particular pseudonymous record without the exact technical identifier.
09 / CHILDREN, CHANGES, AND CONTACT
The beta is not directed to children under 13, and Oasis Radio does not knowingly collect their personal information. This draft may change before release as the product and legal review develop.
For privacy or copyright questions, use the real public contact shown on the Copyright and Takedown Contact page. If that page shows a launch blocker, no public contact has been configured and the beta is not ready for publication.