Your privacy

Echo accesses a narrow set of Spotify data for one reason: to maintain your private listening archive.

At a glance

Purpose
Maintain one private playlist.
Browser storage
One encrypted essential cookie.
Sharing
Echo does not sell or share your data.
Deletion
Disconnect deletes your local data.

Data and purpose

Echo accesses your Spotify profile, recently played history, and private playlist data solely to create and update your private playlist archive.

Access and refresh credentials, the playlist association, archive preference, sync cursor, and archived track URIs, names, artists, and play timestamps are stored on this deployment until you disconnect.

Browser cookie

An encrypted essential cookie stores only a local user identifier, session generation, browser binding, and CSRF value. It expires within seven days.

Echo does not sell or share this data.

Disconnect and deletion

Disconnect immediately deletes the local account, playlist association, and all retained Spotify data. A non-reversible keyed safety fence blocks an already-started callback for 14 minutes 30 seconds, then becomes inactive within 15 minutes. Best-effort maintenance normally deletes that row on its next 30-second pass, but process or database downtime can delay physical deletion.

The remote playlist is retained in your Spotify account and is not deleted or edited by disconnect. Because Echo deletes the association, a later reconnect creates a new Echo playlist instead of reusing the retained one.

Questions

Questions or deletion concerns: hello@b-raffetseder.com.

Return to Echo