Privacy

Version . In force from .

AnyRequests is a Rhexen product. Rhexen is the data controller for personal data processed through this service, and processes it in accordance with UK GDPR.

If you are requesting a song

When you send a request we store:

We do not ask you for an account, an email address or a phone number, and we do not use advertising or analytics trackers.

Who can see your request

The musician sees everything you send, including any name you added, and that is what the name field is for. On the public request page only song titles and vote counts are shown. Names are never displayed publicly, and the permissions on our database stop the public page reading them at all.

How long we keep what you type

The name or message you type is deleted three hours after the gig ends. It is removed by a job that runs every ten minutes, so it goes without anyone having to remember, and three hours is measured from the end of the gig rather than the start.

What is kept afterwards is the song and the fact that somebody asked for it. The musician needs that to see which songs get requested, and it says nothing about who you are.

There are two exceptions, and they are the whole of the list:

The request itself is kept, with your details taken out of it. Once the three hours have passed, what is left is the song, the date and the fact that somebody asked for it. There is no date on which that is deleted, and there is no longer any job that removes old requests: the musician's history of what their audience asked for is theirs to keep.

Version 1.0 of this policy said requests were deleted after twelve months, and until 7 September 2026 a nightly job was set up to do exactly that. It never actually deleted anything, because this product is younger than that window, and it has been removed. Deleting the whole record would have taken the song and the count with it, which is the musician's history rather than your personal data. What is deleted now is the part that is about you, and it goes in three hours rather than twelve months.

If a musician reports a request

A musician can report a request as abusive or inappropriate. Only the musician can do this. There is no way for anybody in the audience to report anybody else, deliberately, because a request that anyone in the room could flag is a request anyone in the room could have removed.

They can do it during the gig and for three hours after it ends. After that there is nothing left to look at, because everything typed has already been deleted.

A reported request is kept for twelve months and then deleted the same way. We keep it so we can read it, decide whether something needs doing, and have a record if it does.

If you are a musician using AnyRequests

We store your email address and password (hashed, never in plain text) for signing in, plus whatever you put on your page: your name, page link, tagline, images, links and tip link. You can change or delete any of it from your dashboard whenever you like.

We also record, from the moment you sign up:

Venues

When you set up a gig you can name the venue. We store that name and the fact that you played there, and if the name includes a town we note the town. Other musicians never see the name you typed or where you have played.

Behind the scenes, we recognise when different musicians have named the same place, so that one venue is not counted as several spellings of it. This only happens when the name includes a town, so that two pubs with the same name in different towns stay apart.

Once a venue has had at least three gigs, what audiences asked for there, across every gig at that venue whoever played it, can be used to suggest songs when a musician makes a songbook for it by describing the gig. What is used is song titles and how often they were asked for, and nothing else: never a musician, a gig, a date or anybody's name. So what your audiences asked for can help another musician build a songbook for the same place.

When you make a songbook by describing a gig, what you describe, including the venue, is sent to Anthropic with your song list and those song titles and counts, and the venue name may be looked up on the web.

Tips and money

Stripe is the payment processor and the musician is the merchant of record. When you tip, the payment is made to the musician's own Stripe account. It does not pass through a Rhexen account and it never sits on our balance.

We never receive or hold bank details. Card numbers, wallet details and the musician's bank account are handled by Stripe and are never sent to us, never stored by us, and cannot be seen by the people who run AnyRequests. If you want to know what Stripe does with them, their privacy policy covers it.

We take a service fee on tips, which Stripe deducts at the moment of payment and pays to us. What we record about each tip is the amount, the fee, the Stripe reference, when it happened, which musician and which gig, and whether it was later refunded or disputed. We do not record who paid.

Financial records cannot be deleted on request. We are required to keep records of transactions for tax purposes, and we keep them for seven years. If you close your account we will remove your personal details, but the financial ledger stays, because we are not permitted to destroy it. This is the one part of your data that a deletion request does not reach.

When we can see your account

The people who run AnyRequests can open your account to help you. If you contact us with a problem, somebody may need to see what you see in order to fix it. We would rather say so plainly than have you find out.

Consent and marketing emails

When you sign up we record two answers separately: that you confirmed you are 18 or over, and whether you want marketing emails. Neither box is ticked for you. Each answer is stored with the date, the time and the version of this policy and the terms that were in force.

You can turn marketing emails off at any time from Settings in your dashboard, in one tap, without contacting anybody. Turning it off is recorded in the same way as turning it on, so there is always a record of what you chose and when.

Some emails are sent whatever you choose, because they are needed to run your account: confirming your address, resetting your password, and notices about your account itself. These are not marketing and cannot be turned off while the account is open.

We never share your address with anyone else. Not with third parties, not with other musicians, not with venues.

Notifications

If you turn on notifications, your browser gives us a subscription that lets us send a message to that browser. We store it so we can tell you when a request arrives during a gig. It is tied to that browser on that device, and turning notifications off in the app or in your browser settings ends it.

If you ask us to read a setlist

You can add songs by uploading a file. Most of those files never leave your phone or computer: spreadsheets, Word documents, CSV files, text files and PDFs that contain real text are all read on your own device by the app itself. Nothing is uploaded and nothing is sent to anyone.

Two kinds of file cannot be read that way, because there is no text in them to read: a photograph of a setlist, and a PDF that turns out to be a scan rather than a typed document. Those are sent to Anthropic, whose model reads the writing and sends back the text. The app tells you which of the two routes your file took at the moment you choose it.

A list you paste or type in is read by AI too. It is sent to Anthropic, whose model splits it into titles and artists so that it can cope with whatever shape your list is in. The box you paste into says so.

It is used to read the list of songs and for nothing else. It is not used to train anyone's model, it is not used for advertising, and it is not shared with anyone beyond that.

A photograph may show more than song titles. A picture of a page can catch handwriting, a venue name, other people's names, or whatever else happens to be on the paper or behind it. We only ask the model for the list of songs, but the whole picture is what gets sent, so it is worth a look before you upload it. If you would rather not send a photograph at all, a screenshot, a typed list or the Add a song button all work without one.

The same is true of a scanned PDF, and it is easier to forget. A scan is a picture of a page wearing a document's file name, so it carries whatever was on that page just as a photograph does, and the whole of every page is sent. If you are not sure whether a PDF is typed or scanned, the app tells you which route it took as soon as you choose it.

How long we keep a setlist photograph

We do not keep it at all. The photograph is held in memory only for as long as the request takes, and it is never written to our database or our file storage. What is saved afterwards is the list of songs you confirm, in your own repertoire, exactly as if you had typed them.

Anthropic's current policy is to delete it within 30 days. That applies to everything sent to their API, unless something is flagged by their safety systems, in which case they may keep it for longer.

This processing takes place outside the UK. The copy held for those 30 days is stored in the United States. There is no option to keep it in the UK or the EU on this route. If that matters to you, do not upload a photograph or a scan, and do not paste your list in: a spreadsheet, a Word document, a CSV or text file, or a PDF that contains real text is read on your own device and nothing is sent anywhere.

Getting something removed

Ask the musician whose page you used. They can hide or delete any request from their dashboard immediately. If you would rather contact us, or you want your musician account and all its data deleted, email privacy@anyrequests.app and we will deal with it.

The one thing we cannot remove is the financial record of a tip, for the reason given under Tips and money.

Where your data lives

AnyRequests is operated by Rhexen and runs on Supabase (database and file storage) and Vercel (hosting). Payments are processed by Stripe. Email is sent by Resend. When you ask us to read a photograph of a setlist, a PDF that turns out to be a scan, or a list you paste in, it is sent to Anthropic, whose model reads the writing in it. When you make a songbook by describing a gig, what you describe and your song list are sent to Anthropic too, as explained under Venues.

Rhexen's full registered entity details will be published here before public launch.