Privacy
Last updated 2 July 2026
songdrop is a small independent music-sharing app. This page describes what data we collect, why, the legal basis, and your rights. Written to be plain and short.
Who we are
songdrop is operated as an independent project. For any privacy question or request, write to drop@songdrop.me.
What we collect and why
Each row describes a category of data, why we process it, and the GDPR legal basis (Art. 6).
- Your email address — only to send you the magic sign-in link. We never sell it, never use it for marketing. Legal basis: performance of a contract (Art. 6(1)(b)) — we cannot sign you in without it.
- An auto-generated display name (e.g. GentlePrelude13), shown to other users when you Swap or Drop. Editable from your profile. Legal basis: performance of a contract.
- Songs and reactions you submit — URL, title, artist, platform, and vibe. Visible to other users depending on context: your Swap partner sees your pick, Drop participants see everyone's picks after the reveal, and
/statsshows the aggregate community catalog. Legal basis: performance of a contract. - A session cookie — keeps you signed in for 30 days. HTTP-only, same-site lax, no cross-site tracking. Legal basis: strictly necessary for the service (ePrivacy exemption).
- Small state cookies —
seen_songsandreacted_songsremember what you've already viewed on Discover. Legal basis: strictly necessary for the discover feature. - Your IP address and user-agent — logged briefly to detect bot abuse and diagnose incidents. Not connected to your account for profiling. Legal basis: legitimate interest (Art. 6(1)(f)) in securing the service. Retained for 90 days in security logs, then deleted.
Providing an email address is required to use signed-in features (Swap, Drop, reactions, submissions). If you don't, you can still browse the public catalog on /stats, but you can't sign in.
Third parties we share data with
We use a few external services because we'd rather focus on the music experience than reinvent infrastructure. Each is a data processor acting on our instructions.
- Resend (United States) — delivers the magic sign-in emails. Sees only your email address and the message body.
- Render (United States) — hosts the application. Sees whatever data reaches the server.
- Cloudflare — sits in front of our servers for security and performance. Sees request metadata (IP, headers).
- Spotify — if you export a Drop to a playlist, you authorise Spotify directly. Tokens live in your browser to make the calls you asked for; they are not stored on our servers.
- YouTube Data API, Odesli, and platform oEmbed endpoints — fetch song metadata (title, artist, artwork) when you paste a link. These see only the URL you paste.
We do not use Google Analytics or any third-party analytics that set cookies.
Cookies
We only set cookies that are strictly necessary for the service. No advertising, no analytics, no cross-site tracking.
session— required for signed-in features. HTTP-only, same-site lax, 30 days.seen_songs,reacted_songs— remember your reading state on Discover. 30 days.
Retention
- Account data (email, display name, songs, reactions) — retained while your account exists. Deleted on request within 30 days.
- Sessions — expire and are deleted 30 days after issue.
- Magic links — expire and are deleted 15 minutes after issue.
- Security logs (IP, user-agent, request path) — 90 days, then automatically purged.
- Inactive accounts — if you don't sign in for 24 months, we email you and delete the account 30 days later unless you sign back in.
Your rights (GDPR)
If you are in the EU/EEA, or in another region with equivalent legislation, you have the right to:
- ask what data we hold about you (right of access, Art. 15);
- correct inaccurate data (Art. 16);
- delete your data (Art. 17);
- restrict processing while a request is being handled (Art. 18);
- take a copy of your data in a portable format (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- file a complaint with your national data protection authority (in France, the CNIL).
To exercise any of these, email drop@songdrop.me. We reply within 30 days and don't charge a fee for reasonable requests.
Automated decision-making
We do not use your data for automated decision-making or profiling that produces legal or significant effects on you.
International data transfers
Our hosting (Render) and email delivery (Resend) are provided from the United States. Both providers are certified under the EU-US Data Privacy Framework, which the European Commission recognises as providing an adequate level of protection for personal data transferred from the EU/EEA.
Children
songdrop is not intended for users under 13 (or under the digital age of consent in your country, which in France is 15). We don't knowingly collect data from children. If you believe a child has provided us data, contact drop@songdrop.me and we will delete it.
Data breach notification
If a data breach occurs that is likely to result in a risk to your rights, we notify the CNIL within 72 hours and inform affected users when required by GDPR Art. 34.
Changes
If we change anything meaningful, we update the date at the top and note the change on the homepage. Continuing to use songdrop after a change means you accept the updated policy.