Playlistation LogoPlaylistation
Log in

Account

Security and privacy

Playlistation never sees your Spotify password. You sign in on Spotify's own site, Spotify shows you the permissions being asked for and hands Playlistation a token limited to those. The legal text is the privacy policy.

Signing in with Spotify

Spotify shows a consent screen listing what Playlistation will be able to do, on every sign-in. Accept, and Spotify sends you back to the app with a one-time code that the Playlistation API exchanges for an access token and a refresh token. Refuse, and nothing is created. Free and Premium Spotify accounts both work.

The permissions asked for

Six permissions, and why each one is needed:

  • user-library-read: read your Liked Songs. This is the whole product; every smart playlist is built from them.
  • playlist-modify-public and playlist-modify-private: create playlists and add or remove their tracks, whether the playlist is public or private.
  • playlist-read-private: see your private playlists, so Playlistation can read the playlists it created when they are private, and notice when you have deleted one on Spotify.
  • user-read-private: your profile details. Playlistation keeps only the country from it; your display name and avatar come with the profile without this permission.
  • user-read-email: your email address, used for Stripe invoices if you subscribe, and as the address you write from to exercise your rights.

Playlistation does not ask to change your Liked Songs, control playback, read your listening history or upload images.

What is stored

On your account: your Spotify id, display name, email, avatar URL, country when Spotify sends it, interface language, the number of tracks in your Liked Songs, when you were last active, your plan and a copy of the Stripe subscription record (a customer id, never card details), your library stats, the Spotify access and refresh tokens, and one session token per device you are signed in on.

Belonging to your account: your smart playlists with their filters and the last match result for each track, the playlists suggested to you, and any language reports you filed.

Shared with every user: the track cache. Every track Playlistation has seen is stored once, keyed by its Spotify id, with its title, artists, album, duration and cover, plus its genres and detected language. This is a copy of Spotify's catalog, not a record of who liked what, and it is not tied to your account.

Never stored: your Spotify password, your card number, or the audio itself.

Sessions

Signing in creates a random 40-character token, kept in your browser and on your account, that every request to the API carries. It has no expiry date: it stays valid until you use Logout in Settings, which revokes that device's token only, or until Spotify disconnects the app, which drops every session at once. The Spotify access token is short-lived and is renewed with the refresh token in the background.

Where it is hosted

The API and its database, where everything above is stored, run on a server rented from OVH in Roubaix, France; so does the website. The app's own files, the interface your browser loads, are served by Firebase Hosting, a Google service; no account data is stored there.

Third parties

  • Stripe handles payment. Checkout receives your email and your user id as a reference; Stripe collects your card and billing address, and Playlistation stores only the customer id and the subscription record it sends back. See Plans and billing.
  • Featurebase provides the feedback portal and the in-app chat. The in-app chat loads only after you accept cookies. When it does, Playlistation signs a token with your Playlistation id, email, display name, language and avatar so that your messages and posts land on your account. Anything you write in the chat or on the portal is processed by Featurebase. Refuse cookies and the widget is never loaded; the public portal still works anonymously.
  • PostHog (EU servers) receives usage statistics. In the browser it starts only after you accept cookies, records page views and product events, and never records your screen. The API also records product events on its side, tied to your user id with your Spotify id, display name, avatar, language, country, plan and library size, never your email. Those server events set no cookie and do not depend on the cookie answer.
  • Sentry receives error reports. When something breaks, the report carries your user id, email, display name and plan, and for an error in the app a replay of the session in which it happened. Text on screen is visible in that replay; anything you typed into a field is masked.

Nothing is sold to anyone, and there is no advertising tracker.

Revoking access from Spotify

You can cut Playlistation off from Spotify's side at any time on Spotify's Manage apps page. The next time the API tries to renew its token, Spotify refuses; Playlistation then signs you out everywhere and parks your playlists in Error, out of the update rotation. The playlists stay on Spotify and your account stays until you delete it. Signing in again reconnects everything.

Your rights

To access, correct or erase your data, write to dpo@playlistation.app from the email address of your Spotify account. Erasing does not need an email: Deleting your account does it from the app.

Previous
Settings