Legal
Privacy Policy
Effective 25 September 2026
1. What we collect
From Spotify (only what you authorize): your email address, up to 500 liked songs, your top and followed artists, playlist names, and the genre profile Spotify derives from your listening. We request these through Spotify's standard OAuth flow; you can revoke access at any time from your Spotify account settings.
From you: your display name, age, bio, profile photo, city and the taste chips you choose to surface; your swipes, matches and messages; and your subscription tier.
Automatically: a session cookie containing your signed-in state (a JSON Web Token). We do not use third-party advertising or tracking cookies.
2. How we use it
- To compute compatibility scores and order your discovery feed.
- To display shared songs, artists and genres between you and a match.
- To calculate certification tiers and streaks for matched pairs.
- To operate subscriptions and unlock paid features.
- To keep the service running securely and diagnose failures.
We do not use your library for advertising, and we do not sell or rent personal data to anyone.
3. What other users see
Your name, age, photo, bio and selected taste chips are visible to candidates in discovery. Your full library is never shown to anyone — not even after a mutual match. Shared-song lists appear only on a match, and only for the tracks both of you liked. Your messages are visible to your match and to nobody else.
4. Storage and security
Data is stored in our own database. Authentication uses an encrypted, HTTP-only session cookie; Spotify access tokens are never exposed to your browser. Access to production data is limited to the small team operating the service, and communications are encrypted in transit with TLS.
5. Your choices and rights
- Revoke Spotify access at spotify.com/account/apps — discovery stops updating immediately.
- Re-sync your library anytime from your profile.
- Delete your account by writing to us — we remove your profile, swipes, matches and messages within 30 days. Messages already seen by a match may remain in their thread.
6. Spotify affiliation
SoundMatch uses the Spotify Web API. It is not affiliated with, endorsed by or sponsored by Spotify AB. Spotify is a trademark of its respective owners.
7. Changes and contact
If this policy changes materially, we will note the new effective date here. Questions or deletion requests: privacy@soundmatch.app.