Last updated October 10, 2026 · English
Privacy Policy
This policy explains how PlaylistAI handles information when you use our website, iOS app, and music playlist plugin. The information involved depends on which features you use and which music services you connect.
Who we are and how to contact us
PlaylistAI is operated by Sound Bytes, LLC. We provide tools for discovering music and creating playlists. For questions about this policy, access to your information, or a deletion request, contact brett@playlistai.app. Sound Bytes, LLC handles these requests. Please identify the PlaylistAI product and connected account involved, but do not send passwords or access tokens.
Information we receive
Account information: when you sign in or connect a service, we may receive an account identifier, email address, and profile information made available by that sign-in provider. We also receive authorization credentials that allow the features you approve to work. We do not ask you to give PlaylistAI your Spotify or Apple password.
Playlist information: we process your prompts, song and artist requests, playlist titles, descriptions, music-service identifiers and links, and playlist content needed to carry out your request. The iOS app and older integrations can retain created-playlist records including the prompt, title, provider playlist ID and URL, creation time, and associated account. If you keep the preselected onboarding-email choice on the connection page, the Spotify plugin stores your account ID and available email address when registering you for onboarding after playlist creation. If you clear that choice, it skips this account registration and email collection. It does not save new playlist-history records to our database; it processes the song and playlist details needed to complete your request. The Spotify library browser retrieves playlist and track information, including artwork, from Spotify.
App and purchase information: the iOS app and subscription-management features may process playlist history, credits, subscription status, customer or transaction identifiers, and linked-service details. Payment providers handle payment details; these features are separate from the free Spotify plugin.
Support and technical information: we receive messages you send us and collect service activity, error information, request identifiers, and usage events. Our hosting and analytics providers process technical information about requests and devices. We use this information to operate the service, understand usage, and investigate failures.
How we use information
We use information to authenticate you, maintain the music connections you authorize, search for songs, create and edit playlists at your request, display your library, save connection preferences and, in the app and older integrations, playlist history, provide support, manage app entitlements, prevent abuse, and maintain the reliability of PlaylistAI.
We use service activity for product analytics and improvement. The Spotify plugin keeps operational request and error telemetry and sends account-linked usage events to Mixpanel when you complete a connection, create a playlist, or create a new onboarding account. These events use your Spotify account identifier with a Spotify-specific prefix to link activity from the same account. Connection events include reconnecting; they do not necessarily indicate a new PlaylistAI account. Playlist-creation events include song counts, playlist visibility, and whether adding songs was confirmed. We also send the service, environment, and a deduplication identifier. We do not send your email address, prompts, song titles, playlist title, or playlist ID in these plugin analytics events. Connection and playlist-creation analytics are separate from the onboarding-email choice and occur even if you clear that checkbox. An onboarding-account event occurs only when a new account record is created.
When the onboarding-email choice is enabled, after the plugin creates a Spotify playlist, including one saved with only some requested songs, it retrieves your Spotify account ID and available email address for account registration. The connection page includes a separate onboarding-email checkbox that is selected by default. You can clear it before continuing to avoid enrollment. If that selection is kept, a newly registered account or an existing account whose email is added for the first time is enrolled in our onboarding workflow unless it is already marked unsubscribed. Connecting Spotify alone does not start this workflow, and existing accounts with an email address are not enrolled again. This sends a playlist prompt guide and, about three days later, information about the PlaylistAI iOS app. The choice is saved for the connection and reused if you choose to remember the connection approval. Older connections without an email choice do not enroll you. App accounts and older integrations may also receive onboarding messages. You can use an unsubscribe option in those messages or contact us to request that they stop.
Do not include sensitive personal information in a playlist prompt or support message unless it is necessary for your request. Playlist names, descriptions, and song choices can reveal information about you, particularly when you make a playlist public.
Spotify plugin connections
The Spotify plugin requests permission to modify public and private playlists. It also requests access to your email address if you keep the preselected onboarding-email checkbox; clearing it omits that email permission and skips new account registration for onboarding. Connection analytics, library browsing, and ownership checks also use your Spotify account identifier. Account-linked analytics are separate from email enrollment. With the email choice enabled, the plugin stores your Spotify account ID and available email address after playlist creation for account registration and onboarding email. It does not save new playlist-history records. If your existing connection does not include email permission, you may need to reconnect to grant it. Connecting Spotify does not give PlaylistAI your Spotify password.
Our plugin connection service stores Spotify access and refresh tokens and connection preferences in encrypted server-side storage. Connection records have a 30-day expiry that can be renewed when the connection is refreshed or settings are saved. Temporary sign-in transactions normally expire after 10 minutes. The plugin’s own access tokens expire after one hour and can be refreshed while the connection remains valid.
If you choose Remember this approval, a secure browser cookie and a server-side approval record remember the approved connection for 30 days. This does not bypass Spotify’s own sign-in or permission controls. Clear site cookies to remove the remembered browser approval.
Disconnect the integration in your ChatGPT settings and remove PlaylistAI’s access in your Spotify account settings to stop future authorized access. Disconnecting is different from requesting deletion of any PlaylistAI account records saved for onboarding, or account and playlist records saved by the app or older integrations. It does not automatically delete previously collected analytics, playlists already saved in Spotify, or copies of conversation content retained by ChatGPT.
Service providers and information sharing
We send the information needed for your requested action to the connected music service. Playlist and song results are returned to the host where you use the plugin, such as ChatGPT. The host and music provider handle information under their own policies and account settings. Artwork is loaded from Spotify’s image servers, which receive the image request.
We use service providers for hosting and databases (including Vercel and Upstash), authentication (Clerk and sign-in providers), usage analytics (Vercel Analytics and Mixpanel), email and workflows (Resend and Inngest), and app payments and entitlements (Stripe, Apple, and RevenueCat). The providers involved depend on the product and feature you use.
AI-powered features may send the prompt and supporting information you provide to an AI provider through our infrastructure, including Vercel AI Gateway. When you use PlaylistAI in ChatGPT, OpenAI processes your conversation under its own terms and privacy controls. The Spotify tools receive the arguments needed for the requested action, rather than requiring access to your entire conversation.
We do not sell or rent your personal information. We may disclose information where required by law, to respond to valid legal requests, or to protect the security and rights of users and the service.
Cookies and local preferences
The website uses cookies for authentication where required and to remember preferences such as language, a dismissed language suggestion, or an app-opening preference. The music connection flow uses temporary security cookies and the optional remembered-approval cookie described above. Browser settings let you clear or block cookies, although doing so may require you to sign in again or prevent some features from working.
We use Vercel Analytics on the website and usage analytics in other PlaylistAI services. These help us understand visits and product use. A music-service connection is not required merely to read these legal pages.
Retention and security
Temporary Spotify connection records expire as described above. Account records saved for current plugin onboarding, and account and playlist history saved by the app or older integrations, are separate: they are not automatically deleted when a plugin connection expires, is disconnected, or is uninstalled. When the onboarding-email choice is enabled, the Spotify plugin stores account ID and email records for registration and onboarding, but does not create new persistent playlist-history records. We do not currently apply a single fixed automatic deletion period to all account history, account-linked analytics, support messages, billing records, and operational logs. Contact us to request deletion and to ask which records remain associated with your account.
Different systems, including backups and provider records, can have different retention behavior. Information needed to resolve disputes, prevent abuse, or meet legal obligations may need to be retained. We do not promise that a disconnect or deletion request immediately removes every copy from every system.
We use technical controls such as encrypted plugin credential storage and restricted service access. No internet service or storage system can guarantee absolute security. Do not send credentials to our support address.
Your choices and privacy rights
You can choose whether to connect a music service, disconnect it, change playlist visibility, unsubscribe from onboarding emails, and contact us to request access, correction, or deletion of information. In the iOS app, account-deletion controls apply to the app account; tell us separately if you also use the plugin or website. Deleting an account does not itself cancel an App Store or other third-party subscription.
Depending on where you live, you may also have rights to receive a portable copy, restrict processing, object to processing, or withdraw consent where processing depends on consent. You may complain to your local data-protection authority. We may need information to verify that a request concerns your account. Contact brett@playlistai.app to exercise a right or ask about its application.
Some information is necessary to fulfill a request: without a valid music-service connection, for example, we cannot save a playlist to that account. Music providers and ChatGPT offer their own privacy controls for information they hold.
Children and eligibility
PlaylistAI is intended for people aged 13 or older, or the higher minimum age required by applicable local law or the connected platform. We do not knowingly collect personal information from children below that age. If you believe a child has provided information to PlaylistAI, contact brett@playlistai.app so Sound Bytes, LLC can investigate and handle a deletion request.
International use and policy changes
PlaylistAI uses infrastructure and providers that may process information outside your country. Privacy protections can differ between countries. Contact us if you need information about the providers and safeguards relevant to your data.
We may update this policy as the service or its data practices change. The date at the top identifies the latest version. Material changes will be communicated where required. This policy does not replace the policies of Spotify, Apple, OpenAI, or other services you choose to use.