Playlistr Privacy Policy
Effective date: July 23, 2026
1. Who we are
Playlistr is a cross-platform music-sync service at playlistr.co that connects your music accounts and keeps your playlists in sync across them. Playlistr is operated by Anatolii Lobanov, an individual doing business as Playlistr in the State of New Jersey, United States ("Playlistr", "we", "us", or "our").
This policy explains what information we collect, why, who we share it with, and the choices you have. It covers the Playlistr website and app (the "Service"). It does not cover Spotify, Google, YouTube, or any other platform you connect — those services handle your data under their own privacy policies.
2. What we collect
We collect only what we need to sign you in and sync your playlists. We do not ask for your date of birth, your address, or any payment details.
Your email address
You sign in either with a one-time code sent to your email, or with Google. Either way we store your email address, which is how we identify your account and send you sign-in codes. We never store a password for your Playlistr account — there isn't one.
Google sign-in information (if you use it)
If you sign in with Google, Google sends us a stable account identifier (your OpenID Connect sub), your email address, and basic profile information. We request the openid, email, and profile scopes. From what Google returns, Playlistr stores only your email address, that stable account identifier, and your first name — your first name is used solely as a label for your account. We do not store your Google profile picture, your full name, or your locale, and we do not receive or store your Google password. Signing in with Google stores no Google access tokens and gives Playlistr no access to your YouTube library — connecting YouTube is a separate step with its own consent screen.
Connected-account credentials and connection details
When you connect Spotify or YouTube, that platform sends us tokens that let Playlistr act on your behalf. For each connection we store:
- OAuth access and refresh tokens, so we can keep syncing without asking you to sign in again each time. These tokens are encrypted at rest (AES-256-GCM); we never store them in plain text.
- The token's expiry time and granted permissions (scopes).
- The account's name on that platform (your Spotify display name or YouTube channel title) and an identifier for the account, so the app can show you which connection is which. You can rename a connection; that label is only for display.
Your playlists and tracks
To synchronize your music, we access and store metadata about your playlists and their tracks from the platforms you connect. We store metadata only — Playlistr does not download or store audio or video files from Spotify or YouTube.
- For Spotify, this includes playlist identifiers, names, descriptions, and cover images; and track metadata such as title, artist, album, duration, and Spotify track identifiers.
- For YouTube, this includes your YouTube channel identifier and title; playlist identifiers, titles, descriptions, thumbnails, and item counts; and, for each video, its identifier, title, channel (uploader) name, duration, and thumbnail. So we can match and re-check videos accurately, we also store each video's description and tags as returned by the YouTube API, in a raw-metadata field.
Alongside this metadata we keep match records — which source track resolved to which item on the target platform, and a confidence score for that match — so we can match tracks across platforms and keep your target playlists up to date.
Your sync rules
We store the Sync Rules and Smart Rules you create — what should be mirrored from where to where, and your settings for each rule.
Sync history
We keep a record of each sync run: when it ran, what was matched, what was written to the target, and whether it succeeded or failed. This is what powers the status you see on each rule and lets us diagnose problems. Because these records reference the tracks and videos involved, they can contain YouTube-derived identifiers and metadata.
Basic technical logs
Like any web service, our hosting providers keep standard server logs (such as IP addresses, timestamps, and error diagnostics) needed to run and secure the Service. We use these to operate the app, keep it secure, and fix bugs.
3. How we use your information
We use the information above to:
- Sign you in and identify your account.
- Run your syncs — connect your accounts, read your playlists and tracks, match tracks across platforms, and create or update playlists on the target you choose.
- Show you the state of your syncs and help you review matches.
- Send you service email — sign-in codes and important notices about the Service or your account.
- Keep the Service secure and working — prevent abuse, investigate errors, and debug problems.
- Meet our legal obligations and enforce our Terms of Service.
Matching tracks across platforms
To find the same track on another platform, Playlistr sends the track's title and artist as a search query to that platform's search API. For example, to mirror a Spotify track onto YouTube, Playlistr sends the Spotify track's title and artist to YouTube's search API to find the matching video; the reverse applies when mirroring from YouTube to Spotify. We use each track's duration only locally, to help choose among the results — the duration is not sent — and we do not send album information. We perform these transfers only to carry out the synchronization you have configured.
4. What we do not do
- We do not sell or rent your personal information.
- We do not use advertising, ad networks, or cross-site tracking.
- We do not run third-party product-analytics or behavioral-tracking tools in the app.
- We do not use your playlists or listening data for anything other than running the Service you asked for.
5. Google API data and Limited Use
Playlistr's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. We use Google and YouTube user data only to provide or improve the user-facing account and synchronization features described in this policy.
Playlistr personnel do not routinely view Google or YouTube user data. A person may access specific user data only when you affirmatively request support and authorize access to the relevant data, when access is necessary to investigate a security, fraud, abuse, or technical problem, or when required by law.
6. The permissions you grant each platform
When you connect a platform, you approve a specific set of permissions on that platform's own consent screen. Playlistr asks only for what it needs to read your playlists and to create and update playlists you choose to sync to:
| Platform | Permissions Playlistr requests | What it allows |
|---|---|---|
| Spotify | playlist-read-private, playlist-read-collaborative, user-library-read, playlist-modify-private, playlist-modify-public | Read your playlists and saved library; create and update your playlists when Spotify is a sync target. |
| YouTube | https://www.googleapis.com/auth/youtube | Read and manage your YouTube playlists and playlist items — including creating target playlists, adding or reordering items, and removing playlist items when you expressly enable deletion synchronization. |
| Google (sign-in only) | openid, email, profile | Identify you at sign-in. This does not grant access to YouTube or any Google content. |
You can withdraw any of these permissions at any time — disconnect the account in Playlistr (see Section 8), and, if you like, also revoke Playlistr's access in the platform's own settings (for Google, at myaccount.google.com/permissions).
7. Who we share it with
We share personal information only in the limited ways below, and never to sell it.
Service providers
We run Playlistr on a small set of trusted providers that process data on our behalf, under their own security and privacy commitments:
| Provider | Role | What it handles |
|---|---|---|
| Vercel | Website hosting | Serves the Playlistr website. |
| Railway | Application/API hosting | Runs the Playlistr backend and API. |
| Neon | Database (PostgreSQL) | Stores your account data, encrypted credentials, playlist and track metadata, sync rules, and sync history. |
| Resend | Email delivery | Sends your sign-in codes to your inbox. |
The platforms you connect
When you run a sync, we exchange data with the platform you connected — Spotify or YouTube — to do what you asked (read your playlists, write to a target playlist). Each platform handles your data under its own terms. Because Playlistr uses YouTube API Services, your use of YouTube through Playlistr is also subject to the YouTube Terms of Service and the Google Privacy Policy.
Legal and safety
We may disclose information if we reasonably believe it is needed to comply with the law or a valid legal request, or to protect the rights, property, or safety of Playlistr, our users, or the public.
If the Service changes hands
If Playlistr is ever transferred to new owners (for example through an acquisition), your information may be transferred as part of that, and we will require the new owner to honor this policy.
8. Disconnecting accounts and deleting data
Keeping stored YouTube data current
While a YouTube connection remains active, Playlistr refreshes or deletes stored YouTube API Data no later than 30 calendar days after it was retrieved, and uses reasonable efforts to keep data displayed in the Service consistent with current data available through the YouTube API Services.
Disconnecting Spotify
You can disconnect Spotify from the Connections page at any time. When you do, we delete the stored Spotify access and refresh tokens and stop the sync rules that depend on that connection. We handle associated Spotify-derived data as described in this policy and as required by Spotify's applicable terms.
Disconnecting YouTube through Playlistr
You can disconnect YouTube from the Connections page at any time. When you do, Playlistr immediately stops the sync rules that depend on that connection, programmatically revokes the applicable Google authorization token, and deletes the stored access and refresh tokens.
We also delete YouTube Authorized Data associated with that authorization from our active systems as soon as reasonably possible and no later than seven calendar days after disconnection. This includes stored YouTube playlist, video, channel, matching, and sync-history data to the extent it contains or is derived from YouTube API Data.
Revoking access through Google
You may also revoke Playlistr's access directly with Google, on Google's third-party app-permissions page — reachable at myaccount.google.com/permissions or at security.google.com/settings/security/permissions. We periodically verify whether Google authorization remains valid. If we detect that access was revoked externally or that a token can no longer be refreshed, we stop the affected syncs, delete the credentials, and delete the related YouTube API Data from our active systems as soon as reasonably possible and no later than 30 calendar days after the revocation.
Deleting your Playlistr account
To request deletion of your Playlistr account and associated personal data, email support@playlistr.co from the email address associated with the account. We may take reasonable steps to verify the request. We delete YouTube API Data associated with the account from our active systems as soon as reasonably possible and no later than seven calendar days after a verified deletion request.
Deleting data from Playlistr or deleting your Playlistr account does not delete playlists, videos, or other content stored directly on YouTube, Spotify, or another connected platform. To delete content stored on those platforms, use the relevant platform or an authorized application that supports that action.
9. Your choices and rights
You can:
- Disconnect any connected platform at any time.
- Ask for a copy of the personal information we hold about you.
- Ask us to correct inaccurate account information.
- Ask us to delete your account and data.
Depending on where you live, you may have additional rights (for example under the GDPR or California law), such as the right to object to or restrict certain processing, or to complain to your local data-protection authority. We do not sell or share personal information as those terms are used under California law. To exercise any right, email support@playlistr.co; we may need to verify your identity first.
10. How we protect your information
- Encrypted credentials. Your OAuth tokens are encrypted at rest with AES-256-GCM. We never store them in plain text.
- No stored passwords. Playlistr has no password to store — you sign in with an email code or with Google — so there is no password of yours for us to lose.
- Encryption in transit. The website and API are served over HTTPS.
- Protected sessions. Your login session is an encrypted, signed cookie that JavaScript can't read (
HttpOnly), usesSameSite=Lax, is markedSecurein production, and expires after 30 days. - Limited access. We keep personal data on established hosting providers (Section 7) and limit who can reach it.
No system is perfectly secure, so we can't guarantee absolute security. If we ever learn of a breach affecting your personal information, we'll notify you and the authorities as the law requires.
11. Cookies and local storage
Playlistr keeps client-side storage to a minimum:
- A session cookie (
playlistr_session) that keeps you signed in. - Browser local storage that remembers small in-app display preferences, such as your playlist filters.
We do not use advertising or tracking cookies.
12. Children
Playlistr is not directed to children. You must be at least 18 years old to create an account or use the Service. We do not knowingly collect personal information from children. If you believe a child has provided personal information to Playlistr, email support@playlistr.co and we will take appropriate steps to delete it.
13. Where your data is processed
Playlistr is operated from the State of New Jersey, United States. Playlistr's providers (Vercel, Railway, Neon, and Resend) may process and store your information in the United States and other countries. If you use Playlistr from outside those countries, you understand your information will be processed there. Where the law requires a safeguard for such transfers, we rely on an appropriate mechanism such as the European Commission's Standard Contractual Clauses.
14. Changes to this policy
We may update this policy from time to time. When we make a material change, we will update the effective date above and provide an appropriate notice. If a change materially expands the types of Google or YouTube user data we access, or materially changes how we use, store, or share that data, we will obtain renewed consent before applying the new use to data you previously authorized.
15. Contact us
Questions about this policy or your data? Contact:
- Operator and data controller: Anatolii Lobanov, doing business as Playlistr
- Jurisdiction: New Jersey, United States
- Email: support@playlistr.co