TuneScriptTuneScript

Privacy Policy

26 July 2026

This policy explains what TuneScript stores about you, why, who else sees it, and how you can get it back or delete it. It describes what the app actually does today — not what it might do one day.

Who is responsible

TuneScript is an independent project run by a private individual based in Israel. There is no company behind it. For any question about your data, write to offvitja@gmail.com — that address reaches the person who operates the service.

What we store

You sign in with Spotify — that is the only way to create an account. From Spotify we receive and store:

  • your email address;
  • your Spotify display name and profile picture URL, if you have them;
  • your Spotify account identifier;
  • access and refresh tokens, which let the app read your library on your behalf. We never show these tokens to anyone and never send them anywhere except to Spotify.

Spotify permissions we request: read your saved tracks, read your private playlists, read your collaborative playlists, read your email, and read your profile. Five permissions, all of them read-only. We cannot modify your library or your playlists, and we do not play music: the app has no player of its own and only offers a link that opens the track in Spotify. A Spotify Premium subscription is not required.

The app used to have a built-in player and asked for playback permissions as well. Those permissions are no longer requested. However, permissions are baked into the access tokens already issued, so if you signed in before that change, the token we hold still carries the old, wider set until you sign out and sign in again. We do not use those permissions, and signing in again replaces the token with the narrower one.

You give us directly:

  • your interface language and the language you want tracks translated into;
  • phrases and lines you save, together with your own notes and tags;
  • tracks you mark as favourites;
  • questions you type about a phrase, and the answers generated for them;
  • corrections you submit when the lyrics of a track look wrong.

The app records automatically:

  • which tracks you opened and when — this is your history screen;
  • sign-in sessions, including the IP address and browser identification of the device you signed in from. This is standard session security data and it is deleted when the session expires.

We do not use analytics services, advertising networks, or third-party trackers. There is no advertising in the app. Interface fonts are served from our own server, so your browser does not contact Google to load them.

Cookies and local storage

We use only what the app needs to work — no advertising or analytics cookies, so no consent banner is required:

  • a session cookie, which keeps you signed in;
  • a cookie holding your chosen interface language;
  • a few values in your browser's local storage: your theme choice, whether the pronunciation line is shown, and per-track view preferences. These never leave your device.

Data received from Spotify, and disconnecting it

Spotify's developer terms oblige us to let you sever the connection and to delete the personal data we received from Spotify within five days of that. We treat that as binding.

Everything in your account that came from Spotify: your email address, your display name, your profile picture, your Spotify account identifier, and the access and refresh tokens. Nothing else does. Your interface and translation languages, your saved lines and phrases, your notes and your history are things you created inside TuneScript, and Spotify has no part in them. We do not receive or store your country, your Spotify subscription status, or your payment details.

How to sever it. Spotify is currently the only way to sign in to TuneScript, so disconnecting it and keeping the account is not possible — you would have nothing to sign in with. Deleting your account does the severing completely and at once: the tokens, the email, the name and the picture all go, well inside the five days. You can also revoke this app's access from your Spotify account settings at any time, which stops our tokens from working; write to us afterwards if you also want the data we already hold removed. When a second sign-in method is added, disconnecting Spotify on its own will become available in Settings.

Why we are allowed to store it

Under the GDPR, we rely on the performance of a contract — you asked for an account and for the service, and we cannot provide either without your Spotify identity, your language settings, and the material you save. Session security data rests on our legitimate interest in keeping accounts from being hijacked. We do not process your data for marketing and we do not sell it. Israeli privacy law applies to us in parallel, and it grants you the same practical rights of access and correction described below.

Who else sees your data

The app talks to several outside services. Most of them receive only the name of a song and its performer — not you. The table below is exhaustive:

ServiceWhat it receivesWhy
Spotify (Spotify AB, Sweden)Your account tokens and our requests for your library and playlists. These requests are made by our server, not by your browser. The app loads no Spotify script and no third-party script of any kind into your browser.Sign-in and your music library
Google (Gemini API)Song title, performer, the song text, the target language, and the question you typed if you asked about a phrase. Not your name, email, or account identifier.Generating the translation and the analysis
Groq (speech recognition)An audio fragment of the track, when no written lyrics can be found anywhere. Nothing that identifies you.Machine transcription as a last resort
Genius, LRCLIB, song.guru, Shironet, YouTube, WikidataA search query built from the performer and the song title. Requests are made by our server, so these services see our server, not your device.Looking for the lyrics and checking cultural references
Railway (hosting and database)Everything the app stores, because the app and its database run there. Servers are in the United States.Running the service

We may add another AI provider later (an Anthropic Claude integration already exists in the code but is switched off). If it is enabled, it will receive exactly what Google receives today: the song and your question, never your identity. This page will be updated before that happens.

Because our hosting is in the United States, your data is transferred outside the EU and outside Israel. We have no separate transfer safeguards in place beyond the terms of our hosting provider — if that matters to you, please take it into account before creating an account.

What is shared with other users

Song texts, machine transcriptions and generated analyses are stored once and reused for everyone. That is what makes the service affordable to run. This shared library contains nothing personal: it is not linked to your name, your email, or your listening history, and other users cannot see what you opened, saved, or asked. If you submit a lyrics correction, your account identifier is attached to it while your account exists, so we can follow up — it is removed if you delete your account.

How long we keep it

  • Your account and everything attached to it: for as long as your account exists.
  • Sign-in sessions: until they expire, then they are removed.
  • After you delete your account: personal data is removed from the live database immediately. Database backups made by our hosting provider may still contain it for a while until they are rotated out.
  • The shared library of song texts and analyses is kept indefinitely — it is not personal data and does not identify you.

Your rights

You can exercise most of these yourself, without asking us:

  • Access and portability — Settings → Download my data gives you a single JSON file with everything the account holds.
  • Correction — your languages and saved material can be edited in the app; write to us for anything else.
  • Deletion — Settings → Delete account removes your account and your personal data.
  • Objection and restriction — write to us and we will respond.
  • Disconnecting Spotify — deleting your account removes the stored Spotify tokens. You can also revoke the app's access at any time in your Spotify account settings.

For anything that cannot be done in the app, write to offvitja@gmail.com. We aim to answer within 30 days. If you are in the EU or the UK and are unhappy with our answer, you may complain to your national data protection authority; in Israel, to the Privacy Protection Authority.

Deleting your account

Open Settings, scroll to the bottom and choose Delete account. You will be asked to confirm. Deletion is immediate and cannot be undone.

Deleted with the account: your profile and email, your Spotify connection and tokens, your sign-in sessions, your listening history, your favourites, your saved lines and phrases with your notes, your phrase questions and their answers, and your plan record.

Kept: song texts, transcriptions and analyses in the shared library, because they belong to everyone using the app and removing them would degrade the service for other people. Any lyrics correction you submitted stays as an anonymous suggestion, with your identifier stripped from it.

If you cannot sign in, write to offvitja@gmail.com from the email address of your account and ask for deletion.

Children

TuneScript is not intended for children under 13, and a Spotify account is required to use it. We do not knowingly collect data from children under 13. If you believe a child has created an account, write to us and we will delete it.

Security

Traffic is encrypted in transit. Access to the database is limited to the person operating the service. We are a small independent project and cannot promise the security posture of a large company; please do not store anything sensitive in your notes.

Changes to this policy

If what we collect or who receives it changes, this page changes with it and the date at the top is updated. For a significant change we will tell you in the app before it takes effect.