How we handle your data when you join the waitlist or use the MusicChat app — in plain terms.
We only collect what MusicChat needs to work. Your Spotify identity is the source of truth. We don't sell your data, run ads, or share with third parties for marketing. Ever. You can delete everything by emailing hello@musicchat.io.
Because MusicChat is still in Spotify's Development Mode, access is limited. Our waitlist lets you opt in and get a trial when a slot opens.
When you tap Continue with Spotify on the waitlist page, Spotify asks for your consent and redirects back to us with an authorisation code. We exchange that code briefly to read your Spotify profile, then discard the token — we don't keep long-lived Spotify access from the waitlist flow.
What we keep in our waitlist table:
| Field | What it is | Why |
|---|---|---|
| Spotify ID | Your stable Spotify user identifier | Prevent duplicate signups; verify identity on activation |
| The email on your Spotify account | Send your position, trial activation, opt-out link | |
| Display name | Your Spotify display name | Personalise emails |
| Country | Your Spotify account country | Aggregate geography stats only |
| Product tier | Free / Premium | Waitlist requires Premium |
| Signup IP hash | SHA-256 of your IP + a server salt | Rate-limit abuse; never the raw IP |
| Unsubscribe token | 64-char random token | Let you opt-out without logging in |
Every email we send includes a one-click unsubscribe link. Clicking it flips your status to unsubscribed; you'll never hear from us again unless you rejoin the waitlist.
When you sign in to the mobile app with Spotify, we receive and store:
When you use the app, we store:
Solely to operate the product:
We do not use your data for advertising, profiling, or targeted marketing.
MusicChat integrates with:
We do not sell, trade, or share your personal information with third parties for marketing purposes. The only sharing that happens is:
Your data is retained while your account is active. To delete your account and all associated data — profile, messages, playlists, waitlist entry — contact us at hello@musicchat.io. We respond within 7 days.
Waitlist signups can be removed instantly via the unsubscribe link in any of our emails.
We use industry-standard HTTPS/TLS for all data transmission. Spotify OAuth tokens are stored encrypted and never exposed to other users or on the client side. Database access is gated by row-level security policies enforced in Postgres.
No system is perfect — if you find a vulnerability, please email hello@musicchat.io and we'll fix it promptly.
MusicChat is not intended for children under 13. We do not knowingly collect information from children. If we learn that a child has provided us personal data, we delete it.
We may update this policy from time to time. Material changes will be announced in-app or by email. The "Last updated" date at the top always reflects the most recent revision.
Questions, concerns, or data-deletion requests:
Email: hello@musicchat.io
Website: musicchat.io