A little more privacy.
Here is how the Fiji Client website and Windows client handle your information.
Your account and email
We store your email address, display name, account creation time, and records needed to manage sign-in sessions. Resend delivers verification codes to your email. Codes are short-lived; we store a keyed hash of each code, not the code itself. Website session cookies are essential to sign-in and download access. Signing out removes the active website session.
Your light or dark website theme is saved in a preference cookie for up to one year, shared across Fiji’s website subdomains. Browser local storage notifies other open tabs when you change it. This setting stays on your browser, does not change public profile designs, and is not used for tracking.
Your payment
Stripe processes checkout and payment information on its own hosted page. Fiji stores purchase references, payment status, and the associated account; it does not receive your full card number. Refunds or disputes may revoke access. Stripe’s own privacy notice also applies to information it processes.
Your one-PC license
The Windows client sends a hashed device identifier and a public cryptographic key identifier to enforce the permanent one-PC license. Its private device key remains on the PC. This binding, purchase records, and security records are personal data when linked to your account. Device binding is not anonymous and is not a guarantee against all forms of tampering.
Your music and preferences
Fiji reads playback metadata from the selected Windows player or its optional browser extension. With Discord presence enabled, track information, artwork, timing, and available lyrics are sent to Discord. For native players, Fiji may upload the small cover image already supplied by Windows to Fiji's private image storage so Discord can display it; the image is stored by content hash without a user, song, or listening-history record and is served through an unguessable-looking public cache URL. Artwork and lyric lookups may send track and artist information to their providers. The account API is not designed to collect a listening-history database. Custom backgrounds and client settings are kept in your Windows user profile.
Optional public profiles
If you connect Discord, Fiji stores your Discord ID, username, display name, avatar, banner, available avatar decoration, accent color, and displayed guild tag. Discord sign-in is used to verify the automatic profile URL; Fiji does not ask for your Discord password, personal user token, or email permission, and stores encrypted Discord OAuth access and refresh tokens on the server to update your identity automatically. Tokens are never sent to profile viewers. You can revoke Fiji’s access in Discord’s Authorized Apps settings; revoked connections are removed when detected.
Your profile stays private until you publish it. Anyone with its URL can then see those details, and their browser requests the profile images from Discord. Live Fiji activity is a separate opt-in: a supporting signed-in client sends its current music or idle activity to Fiji for display on your profile. Only the latest snapshot is kept, not a listening history. Snapshots stop being shown after 45 seconds without an update; expired stored snapshots and linking requests are removed by scheduled cleanup. You can hide the profile or stop activity sharing from Your account → Your profile. Public viewers can independently copy or save information while it is visible.
For custom badges, Fiji stores your chosen name, a resized static PNG made from your upload, its visibility setting, and the credit used to create it. The original upload and its embedded metadata are not retained by this feature. Visible badges appear on published profiles; hidden badges remain available to their owner. We also store your badge-glow preference and purchase references needed to track unused credits and refunds.
Profile backgrounds
Premium profile backgrounds are stored with your account. Images and animations are resized and re-encoded; accepted video files and a still preview are stored to play on your profile. Backgrounds are visible to visitors only while the profile is public and eligible. Replacing or removing a background deletes its previous stored version. Videos play muted and loop. Visitors who request reduced motion see the still preview instead.
Browser playback
The optional Chrome, Edge, and Firefox extension runs only on supported music domains and passes track metadata, the current music-page address, and playback position to Fiji through local native messaging. It does not request cookie access, record audio, or read unrelated tabs. The local app and the services it contacts still receive the information described above.
Job applications
The careers form collects the information you enter and the PDF résumé you attach. Resend sends that application to careers@fijiclient.com. Fiji Client uses it only to evaluate and respond to your application, restricts access to people involved in hiring, and retains it only as long as reasonably needed for that process and applicable obligations. Do not include sensitive identification, financial, health, or unrelated personal information. You may contact careers@fijiclient.com to withdraw an application or privacy@fijiclient.com with a privacy request.
Staff mail
The private Fiji Team portal stores staff mailbox addresses, recovery email addresses, password-verifier data, short-lived sign-in challenges, and message metadata. Message bodies and attachment references are encrypted before they are stored in the Fiji database. Resend receives, sends, and temporarily serves message attachments. Staff should not use these mailboxes for secrets, payment-card details, health information, or other regulated data.
Hosting and security
Vercel hosts the website and private downloads. The configured PostgreSQL provider stores account and license records. Infrastructure providers may process connection information, including IP addresses and request logs. The site uses short-lived download links, secure sign-in cookies, rate limiting, signed client requests, and Cloudflare Turnstile abuse checks. These measures reduce risk but do not eliminate it.
Fiji stores security-event categories, a one-way keyed representation of the request source, and a coarse browser/device label for up to 30 days. These records help identify repeated sign-in, download, payment, and release-publishing abuse. Security notices exclude codes, tokens, customer email addresses, applicant information, and raw IP addresses.
The site serves its fonts directly from Fiji’s own website. It does not currently include advertising trackers or a separate analytics package.
Retention and your choices
Account and device-binding records are retained while needed to provide account access and enforce the license. Purchase and payment-event records are retained as needed to establish ownership, prevent duplicate or fraudulent activation, handle payment disputes, and meet applicable legal or accounting obligations. Retention depends on those purposes and obligations rather than a single period for every record.
Expired verification challenges, website sessions, request nonces, download approvals, and rate-limit records are eligible for scheduled cleanup after one day; expired client sessions after two days, once dependent security records have been cleared. Security events and alert records are removed after 30 days. Cleanup runs in batches, so removal is not immediate at expiry.
You can disable Discord presence, remove the extension, sign out, sign out everywhere, or uninstall the app. Uninstalling does not delete your server account or reset a license. Email privacy@fijiclient.com to request access, correction, or deletion of personal data. We may need to verify account ownership. Available rights and required retention depend on applicable law. Account deletion can end access and does not create a new license.
Questions or requests
Fiji Client. Contact privacy@fijiclient.com.
Visit help & setup →