wavfeed

Privacy

Last updated 8 October 2026

wavfeed reads your own Bandcamp feed and gives it back to you in a form you can actually read. This page says what that involves. What gets gathered, where it goes, how long it stays and how to stop it. It covers this site, the phone app for iPhone and Android and the web app that used to run at app.wavfeed.com.

wavfeed is one person, Ellie Nieuwdorp, and it is invite only. Anything you want to ask or have deleted goes to ellie@nieuwdorp.me and I read it myself, there is nobody else. The phone app needs no wavfeed server at all. The web app has closed and on 30 September 2026 everything its server held about web app accounts was deleted. That server, a Hetzner Cloud machine in Helsinki, now serves this site and counts its visits and nothing else.

The phone app

The app does all its work on your phone. You sign into Bandcamp on Bandcamp's own page inside the app and the phone keeps that sign in the way a browser would. The app asks Bandcamp for your feed from the phone, keeps what comes back in a database on the phone and builds everything you see from that. None of it goes to wavfeed. There is no wavfeed account and no wavfeed server holding your feed.

It never reads your Bandcamp sign in. The sign in lives in the phone's own cookie store for the app and the phone attaches it to the app's requests to Bandcamp. The app never reads it out, never keeps a copy and never sends it anywhere.

What it writes to your Bandcamp account. One thing. When you press the heart it asks Bandcamp to add that release or track to your own wishlist or take it off again. Nothing else is ever written.

How to remove it all. "Remove everything gathered" in Settings deletes everything the app gathered on the phone. It leaves your Bandcamp sign in, which goes when you sign out of Bandcamp in Settings. Deleting the app removes both.

Updates to the app. When it opens the app asks Expo, the company whose tools it is built with, whether a newer version of its code is ready and downloads it if so. That request carries the phone's operating system, which app it is and a random token that tells Expo whether this copy of the app has asked before. Nothing about you or your Bandcamp account, though Expo's servers see the phone's IP address like any server does. Expo handles it on wavfeed's behalf as a processor and it happens whether or not you say yes to the counts below.

Newer builds. When it opens the app also reads a small file on dl.wavfeed.com that names the newest build in TestFlight, in Google Play and on wavfeed.com, so it can tell you when one is waiting that it cannot fetch by itself. If you installed the APK from wavfeed.com, the app downloads the next APK from there when you press install. Neither request carries anything about you or your Bandcamp account. Cloudflare, who serve that address for wavfeed, see the phone's IP address like any server does, and wavfeed keeps no log of it. Both happen whether or not you say yes to the counts below.

Counts of what gets used, only if you say yes

A few people are testing wavfeed and I want to know which parts get used and what breaks on phones that are not mine. So the app can send counts, but only if you say so.

Nothing is sent until you say yes. Once, after you first sign in, the app asks whether it may send counts of what gets used and a short report when something breaks. The answer starts at no. Until you press "Yes, happy to help" nothing is sent, nothing is kept on the phone for later and the fact that you said no is not sent either. Looking around without signing in never asks and never sends.

What it sends if you say yes:

What it never sends:

What they are for. Seeing whether sign in and the first catch-up work on other people's phones, what breaks and where, which parts of the app get used and whether testers come back. Not advertising, not a profile of you, nothing else.

Where they go. To a small service wavfeed runs for itself on Cloudflare. Cloudflare stores them in the EU and handles them in transit at its nearest location, under a data processing agreement. So if you are outside the EU a batch of counts passes through the memory of a Cloudflare data centre near you on its way and is stored only in the EU. The agreement covers that journey with the EU's standard contractual clauses. Cloudflare acts only on wavfeed's instructions and does not use the counts for anything of its own. I am the only one who reads them, on a private page behind a sign in.

How long they are kept:

Your yes and taking it back. The counts rest on your consent (article 6(1)(a) of the GDPR). You can take it back at any moment with the switch in Settings, "Help improve wavfeed". Turning it off stops sending at once, deletes anything still waiting on the phone and drops the random id. Turning it on again makes a new id and the app keeps no link between the old one and the new one. Taking your yes back does not undo what was already sent. For that, ask me to delete it.

Your code and deleting what was sent. While sharing is on, Settings shows a six character code, the start of your random id. Email it to ellie@nieuwdorp.me and I delete everything stored under it and tell you when it is done. Just after you turn sharing off, Settings still shows the code that was dropped for as long as you stay on that screen, so you can still ask. The same code gets you a copy of what was sent. Without it I have no way to find your counts, because nothing in them says who you are. The daily totals stay since they name no id.

"Remove everything gathered". With sharing on, the app first sends one last count saying that everything was removed, then deletes everything it gathered on the phone, the random id included. Your Bandcamp sign in stays until you sign out. The app opens on its first screen again and asks again after the next sign in.

No tracking. Nothing the app sends is sold, used for advertising or joined with anything from other companies' apps or websites. The app does not track you across apps and sites, which is why it never asks for permission to.

Testing through TestFlight and Google Play

If you join through the public TestFlight link on wavfeed.com, I give Apple nothing about you, and Apple shows me the tester as anonymous: when the app was installed, how many sessions it had and whether it crashed, not your name or your email address. If I invite you by email instead, for TestFlight or for Google's Play internal testing, I give Apple or Google the email address you gave me, and their consoles show me whether you installed the app. If the app crashes outright Apple or Google may pass me a crash report, as their testing programmes and the sharing settings on your phone allow. Each hour the same small service on Cloudflare copies those reports from Apple and Google and stores them in the EU for 90 days, so I see a crash the hour it happens. It asks only for what crashed, in which build and on which system version, and never for your name, your email address or anything you typed with the report, and a copy is never joined with the counts. Anything you send through TestFlight's feedback or through "Send feedback" in Settings reaches me with the app's version, and with your code when sharing is on. Those lists and messages stay in Apple's and Google's consoles and in my mail and are never joined with the counts.

The web app and its server

The web app at app.wavfeed.com came first and it has closed. That address now sends you to this site. When it closed its server stopped asking Bandcamp for anything. On 30 September 2026 its database was deleted with every backup of it and no copy was kept anywhere. This is what it had held for web app accounts:

None of it exists any more, so there is nothing of yours left on the server to see, copy or delete.

The web app set one cookie, wavfeed_session, so it knew you were still you between visits. It was 32 random bytes and the database held only a hash of them. Nothing checks it any more and clearing your browser's data for app.wavfeed.com removes it. It was the only cookie the web app set. No third party cookie, no tracking cookie.

If you signed up by pasting your Bandcamp cookie

At first there was one way for wavfeed to read your feed. You pasted your Bandcamp identity cookie once and the server kept an encrypted copy. Friends did that, thank you friends. On 30 September 2026 every one of those copies was deleted with the database and its backups and no copy was kept.

What never happens

Your data is not sold, rented, shared or used to train anything. There is no ad network here, no data broker, no social pixel, no session recording and nothing that follows you across other apps or websites. The counting wavfeed does is its own. Umami on wavfeed's own server for this site, and in the phone app, after your yes, wavfeed's own counts, which Cloudflare stores in the EU. What Bandcamp says about you, your feed, your purchases and your wishlist, lives in two places. Bandcamp, which is your own account on their site, and your phone, where the app keeps it. What the web app gathered while it ran was deleted with its server's database. There is no third place. The counts say that something was pressed, never what.

Counting visits

wavfeed counts page views on this site with Umami, running on wavfeed's own server, so the numbers never leave the machine. It sets no cookie and nothing it records says who you are. It also counts three kinds of press. The Instagram link, the GitHub link and the link that asks to join the test. Any content blocker stops it and nothing on the page depends on it. The page views the web app counted the same way while it ran are kept there too. The phone app has no Umami in it. Its only counting is the one under "The phone app", and only after your yes.

Keeping and deleting

Your rights

Ellie Nieuwdorp decides what wavfeed does with your data, which makes her the controller in the GDPR's terms. You can ask to see what is kept about you, to have it corrected or deleted, to get a copy of it or to have its use stopped, and you can take back any yes you gave. Write to ellie@nieuwdorp.me. If you think wavfeed has got this wrong you can complain to the Autoriteit Persoonsgegevens, the Dutch data protection authority, or to the one where you live. Or preferably email me first, I will fix it faster than they will.

When this page changes

wavfeed is one person's project and it changes often. When what it does changes this page changes in the same commit. The date under the heading says when that last happened.