Privacy Policy
Last updated: September 09, 2026
This Privacy Policy explains how Songify handles personal data on songify.rocks, including account login, widgets, analytics, and support features. It is written to be transparent and aligned with the EU GDPR.
1) Who is responsible for data processing?
Data controller: Jan Blömacher (private individual, not a registered company)
Waldstraße 3, 56412 Nomborn, Germany
Email for privacy requests: info@songify.rocks
2) Scope
This policy covers data processing on the Songify website and related web endpoints (for example login, account, widgets, FAQ, and helper tools), plus app-linked backend records transmitted by the Songify desktop app to Songify-managed services.
3) What data we collect
3.1 Data from Twitch login
When you log in with Twitch, we receive account data from Twitch, including Twitch user ID, login, display name, account type/broadcaster type, profile images, and account creation date. Twitch may also provide your email address when permitted; Songify stores it as a one-way hash (HMAC-SHA256 with a secret pepper), not plain text.
3.2 Account and feature data
- Account profile data needed to run your Songify account
- Public stats preference (whether your stats page is publicly visible)
- Premium trial usage flag (whether a one-time trial has been used)
- API/widget token lookup hashes (not plaintext tokens)
3.3 Ko-fi and premium data
If Ko-fi webhook events are received, we store supporter/payment metadata needed for entitlement handling (for example timestamp, message ID, transaction ID, subscription flags, tier, and amount). Email fields are stored as hashes. For debug/audit purposes, a payload copy is stored with the verification token redacted and email hashed.
3.4 Security and operational data
- IP address for security/rate limiting and anti-abuse controls
- IP address and user agent for FAQ voting anti-duplication/fraud controls
- FAQ search terms and result count (for improving help search)
- Server-side error logs and operational events
3.5 Songify desktop app data sent to backend services
- Authentication/session linkage: Twitch user ID, Songify token verification data, and app UUID for secure API access.
- Now-playing and queue data: track metadata (artist/title/track id/cover/player type), requester display names, and queue state used for hosted widgets/stats/recaps.
- Cloud settings sync: settings snapshots linked to your Twitch user ID for Premium cloud backup/restore.
- App telemetry: minimal service telemetry (UUID, timestamp, Twitch user ID/display name, app version, player type). In current app versions this telemetry is sent by default and cannot be switched off in-app.
3.6 Data you actively submit to tools
- Spotify Token Helper: client credentials are kept only in memory for the flow and removed after use or expiry (~15 minutes); they are not stored in the database.
- Log Analyzer: uploaded log content is analyzed in-memory and not persisted by the feature itself.
4) Cookies and similar technologies
Songify uses a Consent Management Platform (Cookiebot). Non-essential analytics is consent-gated. Cookies may include:
| Name | Provider | Purpose | Typical Lifetime | Legal Basis |
|---|---|---|---|---|
connect.sid (session cookie name may vary) |
Songify | Login session/authentication | Up to 24 hours | Art. 6(1)(b) GDPR (service contract) |
darkmode/darkMode |
Songify | Store UI theme preference | ~30 days | Art. 6(1)(f) GDPR (usability interest) |
site_visitor_id |
Songify | Unique visitor counting in internal stats | ~1 year | Art. 6(1)(a) GDPR (consent, statistics category) |
CookieConsent and related CMP cookies |
Cookiebot | Store consent choices | Defined by CMP | Art. 6(1)(c)/(f) GDPR (compliance + proof of consent) |
Google Analytics cookies (for example _ga) |
Website usage analytics (IP anonymization enabled) | Defined by Google | Art. 6(1)(a) GDPR (consent, statistics category) |
5) Why we process data (purposes)
- Provide authentication, account access, and website functionality
- Provide widgets, premium logic, and account-level settings
- Provide desktop-app connected services such as queue sync, recaps/statistics, and cloud settings sync
- Protect systems against abuse and unauthorized access
- Measure and improve website usage (only where consent applies)
- Handle support and legal obligations
6) Legal bases under GDPR (Art. 6)
- Art. 6(1)(b) Contract/performance of service (account login and core features)
- Art. 6(1)(a) Consent (analytics/statistics cookies and related processing)
- Art. 6(1)(f) Legitimate interests (security, abuse prevention, service stability, UX preferences, and minimal desktop telemetry used to operate/debug services)
- Art. 6(1)(c) Legal obligations where applicable
7) Recipients and processors
Personal data is shared only where needed to run the service:
- Twitch (OAuth authentication and account information)
- Google Analytics / Google Tag Manager (statistics, only after consent)
- Cookiebot (consent management)
- Ko-fi (webhook event origin for supporter/premium processing)
- YOURLS (self-hosted) short-link service running on the same server/infrastructure as Songify; this feature does not introduce an additional external processor by itself.
- Hosting/infrastructure providers required to operate Songify
Songify does not sell personal data.
8) International data transfers
Some providers may process data outside the EU/EEA (for example US-based services). Where required, transfers rely on GDPR-compliant safeguards such as EU Standard Contractual Clauses (SCCs) or equivalent legal mechanisms provided by the respective processor. The self-hosted YOURLS component runs on Songify-managed infrastructure and does not by itself create a separate third-country transfer.
9) Retention periods
- Account data: retained while account is needed for service operation. If you schedule website-account deletion, data enters a pending state and is permanently deleted by an automated daily purge job once the 30-day grace window has passed (unless cancelled before deadline), subject to legal retention obligations.
- Session data: short-lived (cookie max age currently up to 24 hours).
- Desktop app uploads and telemetry: retained while needed for app-connected features (queue/stats/recap/cloud operation, troubleshooting, anti-abuse). If you schedule app/cloud deletion, app-linked records enter a pending state and are permanently removed by the same daily purge job after the 30-day grace window (unless cancelled before deadline).
- Spotify helper temporary credentials: in-memory only, deleted after use or expiry (~15 minutes).
- FAQ vote/search logs, security logs, and visit counters: retained as long as needed for operations and abuse prevention; currently no fixed automatic deletion period for all log tables.
- Premium/Ko-fi related records: retained for entitlement history, troubleshooting, and legal/accounting needs.
10) Your GDPR rights
If GDPR applies to you, you have the right to request:
- Access to your personal data (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure of data (Art. 17), where legally possible
- Restriction of processing (Art. 18)
- Data portability (Art. 20), where applicable
- Objection to processing based on legitimate interests (Art. 21)
- Withdrawal of consent at any time (Art. 7(3)) for consent-based processing
To exercise rights, email info@songify.rocks.
Self-service deletion options in account settings:
- Schedule website deletion: creates a deletion request timestamp and a purge deadline (30 days). If not cancelled, website account/profile data is permanently deleted after the deadline during a daily purge run.
- Schedule app/cloud deletion: creates a deletion request timestamp and a purge deadline (30 days). If not cancelled, app-linked backend records (for example queue/history/telemetry/cloud-settings records linked to your Twitch account/UUID) are permanently deleted after the deadline during a daily purge run.
- Cancel deletion request: during the grace window, you can cancel a pending deletion request in account settings and keep the related data.
If you want full erasure, schedule both scopes (or contact us for a combined request), subject to legal retention obligations.
11) Right to lodge a complaint
You can lodge a complaint with your local data protection authority. If you are in Germany, this is typically the authority responsible for your federal state.
12) Children
Songify is not directed to children and is not intended for users under 16 in the EU without parental/guardian involvement.
13) Security measures
Songify applies technical and organizational safeguards such as hashed token storage, hashed email storage in core flows, session security settings, and rate limiting. No internet service can guarantee absolute security, but we continuously improve protections.
14) Changes to this policy
This policy may be updated when features, legal requirements, or processing activities change. Updates are published on this page with an updated revision date.