Privacy Policy
Last updated: September 18, 2026
This policy explains how xmplaylist collects, uses, shares, and retains information when you use our website, API, and connected AI assistant tools, including the xmplaylist app in ChatGPT. Contact [email protected] with questions or privacy requests.
Information we collect and why
- Account and access information. We receive account identifiers, email addresses, profile information you provide, sign-in and authorization information, and subscription or access status from Clerk. We use these to authenticate you, manage your account, provide paid features, and deliver requested emails. Clerk and its payment providers process subscription payments; payment-card details are not inputs to our assistant tools.
- Your searches and saved preferences. We process search terms, selected artists, tracks, stations, dates, and report options to find airplay and generate reports. We store saved artist rosters, search-alert filters and delivery preferences, and recent website/API searches with your account so you can use those features again. Browser storage also remembers settings such as search preferences.
- Exports and usage. We store your account identifier, daily API/MCP request counts, plan and allowance, and request timestamps to enforce the shared usage allowance. Export records include your filters, job identifier, request time, processing status, row count, file size, storage location, download URL, and processing duration. The export queue also receives your account email to deliver the result.
- Technical and diagnostic information. Our hosting, logging, and monitoring systems process IP addresses, browser or client details, request URLs and query strings, account identifiers, subscription information, response status, timing, and errors. Export diagnostics can include the recipient email and requested filters. We use this information to keep the service reliable, investigate failures, prevent abuse, and support users.
- Website activity and advertising information. Website analytics process page views, clicks, downloads, referring pages, search parameters, device and browser details, and identifiers. Signed-in activity may be associated with your account identifier and subscription tier. Advertising providers may collect cookie identifiers and browsing activity. These uses and your choices are described below.
- Communications. If you contact us or submit feedback, we receive the message, contact details you provide, and any attachments or screenshots you choose to include. We use these to respond, resolve problems, and improve the service. We also use your account email, name, recent account activity, and subscription status to send occasional product announcements, plan offers, and requests for feedback. You can opt out of this outreach as described below.
Connected AI assistants
Connecting ChatGPT or another assistant lets that provider send tool requests to xmplaylist on your behalf. Clerk handles sign-in and consent. The connection can receive your account identity, email, basic profile, and public account metadata under the permissions you authorize, and can maintain access between sessions. xmplaylist checks the authorization and your access eligibility for requests.
We receive the tool name and structured inputs selected by the assistant. These can include a search phrase; artist, track, station, or document names and identifiers; ISRC recording codes; record labels; genres; date ranges; matching and aggregation options; minimum play counts; ranking direction; and pagination or result limits. These inputs may reflect information you included in your conversation. Our tools do not request your full conversation history or provide general access to your chats, messages, contacts, or files.
- Search, discovery, and airplay reports use those inputs to return station and music metadata, recorded play times and counts, rankings, changes over time, artwork and music-service links where available, source-report links, and explanations of the results and their coverage. Responses may repeat the requested filters. SiriusXM airplay describes broadcasts, not your personal listening history.
- Saved-roster reports read the artists saved to your xmplaylist account and return their names, roster totals, airplay metrics, recent plays, newly detected songs and stations, and links to your account's roster reports. The roster tools do not add or remove artists.
- CSV exports use your requested filters to prepare a file and email a download link to the primary email address on your connected account. The assistant receives a status and confirmation that can include that email address. The latest-export tool can return the status, request time, row count, and download link for your account's most recent export, including one requested on the website or API. Anyone you share a working download link with may be able to access the file. The export tool does not accept an arbitrary recipient email address.
We use assistant inputs and account information to perform these requests, deliver results, enforce limits, and operate and troubleshoot the service. xmplaylist does not use assistant tool inputs or outputs to train AI models or target advertising. Our assistant responses do not contain ads. Opening an xmplaylist website link from a response is a website visit and is subject to the website analytics and advertising practices below.
Tool inputs and results are also available to the assistant provider. Its policies and your settings govern its retention, conversation history, memory, sharing, and any model improvement use. For ChatGPT, see the OpenAI Privacy Policy and your ChatGPT data controls. Disconnecting an assistant does not erase earlier conversations, exported files, or records already held by xmplaylist or the assistant provider.
Who receives information
We share information with providers that help us deliver the service, and with the assistant you choose to connect. The recipients and their purposes include:
- Clerk and its payment providers: account, profile, authentication, authorization, and subscription information for sign-in, access management, and billing.
- Hosting, database, and network providers, including Fly.io and Cloudflare: requests, stored account records, and technical information to run, secure, cache, and deliver the service. Cloudflare R2 stores generated export files.
- Amazon Web Services: SQS processes queued jobs containing account identifiers, recipient email, and export filters; SES processes recipient addresses and email contents, including export links, to send requested emails, alerts, account notices, and product outreach.
- Axiom and Sentry: request logs, errors, performance information, account identifiers, and relevant diagnostic context to investigate problems. Sentry also processes feedback and screenshots you submit. Email addresses and export filters may appear in diagnostic records.
- Google Analytics, Amplitude, and Cloudflare analytics: website usage and technical information to understand traffic and feature use. Google Analytics and Amplitude can associate website events with your account identifier and plan.
- Google and its advertising partners: website advertising and cookie information to serve and measure ads, including personalized ads where enabled.
- Your connected assistant provider: authorized account information and tool results, including your roster information and export delivery details when you use those features.
We may also disclose information when required by law or when necessary to address fraud, enforce our terms, or protect rights, property, or safety. We do not sell your account information or assistant tool inputs and outputs. Website advertising involves the separate cookie and browsing-data practices described below. Providers may process information in the United States and other countries where they operate.
How long we keep information
- Account, roster, and alert settings: we keep saved artists and alert settings while your account is active, unless you remove them or request deletion. We delete these preferences and associated database records after 12 months of account inactivity. Records for sign-in accounts deleted in Clerk are also removed during database cleanup. Inactivity is measured using Clerk account activity and recorded website/API/assistant activity. This cleanup does not close your Clerk account or remove support, billing, or other provider records. Disconnecting an assistant does not delete saved data.
- Recent website/API searches: we keep up to ten distinct recent searches per account, replacing older entries as new searches are saved. We delete entries 12 months after they were last searched. Assistant search tools do not add entries to this saved recent-search list.
- Export files: retained for 90 days. Signed download links expire after seven days, and the assistant stops returning stored download links once an export request is more than seven days old. Link expiry is not file deletion; public download URLs, when used, can remain accessible until the file is removed.
- Export queue messages: account identifiers, recipient email, and filters are removed from the processing queue after successful handling. Unprocessed messages normally expire from that queue after approximately 24 hours. Failed jobs can move to a separate failure queue and remain there for up to Amazon SQS's maximum of 14 days from transfer. Replaying a job starts a new queue period. These periods are separate from export files, history, and diagnostics.
- Export history: account-linked filters, job status, and file metadata are stored separately from the file. They do not automatically disappear when a link expires or a file is removed. We delete export records 12 months after the request.
- Usage and alert-delivery records: daily usage counters and delivery records are separate from your saved settings. We delete daily usage records after 12 months and completed or failed alert-delivery records after 90 days. Pending alert-delivery records are deleted after 12 months.
- Track-link reports and administrative history: account-linked reports of incorrect music links and records of administrative channel changes are deleted after 12 months.
- Diagnostics: Axiom logs are retained for up to 30 days. Sentry error events are retained for up to 90 days and logs for 30 days. Performance traces are generally retained for 30 days; sampled performance traces may be retained for up to 13 months under Sentry's plan settings.
- Google Analytics: ordinary event data is retained for two months; user data and key-event data for 14 months. New activity resets the user-data period, so an active user's data can remain longer. Expired data is removed during Google's monthly deletion cycle. Aggregated reports are not subject to these periods and can remain until we delete them or close the analytics property.
- Amplitude: automatic event expiry is not enabled. Account-linked website events and profiles can remain until we remove them in response to a deletion request or delete the analytics project. Signing out or disconnecting an assistant does not erase earlier analytics records.
- Cloudflare Web Analytics: unsampled website measurements are retained for seven days, then sampled for longer-term reporting. Reports are available to us for the previous six months; this reporting window does not establish when Cloudflare deletes all underlying records.
- Support and billing: support correspondence and billing records have no fixed automatic deletion period set by xmplaylist. We retain them until removed through a deletion request or service maintenance, subject to accounting, legal, and dispute-related obligations. Outreach opt-out preferences are kept with your account until you change the preference or delete the account, so future outreach can be suppressed. You can request access or deletion using the contact details below.
We may retain limited records longer when required by law or necessary for an active dispute, security investigation, or fraud prevention. Backup copies may remain until replaced or expired through the relevant provider's backup cycle. If an exception prevents us from fulfilling a deletion request in full, we will explain it in our response. Copies already downloaded, emailed, or stored by an assistant provider are subject to the recipient's own controls and retention.
Your choices and privacy requests
- Account and saved data: use your xmplaylist profile to manage account details and API keys. Remove saved artists from your roster, and manage or delete search alerts. Alert emails include unsubscribe controls. Unsubscribing from alerts does not stop account or export emails you request.
- Product outreach: reply to an outreach email or email [email protected] to ask us to stop product announcements, plan offers, and feedback requests. We process these requests manually and record the preference on your account. This is separate from search-alert subscriptions and does not stop sign-in, billing, or requested export emails.
- Assistant access: disconnect xmplaylist in the assistant's connection settings to stop using that connection. Contact us if you need help revoking access or deleting xmplaylist-held data. Manage previous conversations and files separately through the assistant provider.
- Access, correction, and deletion: email [email protected] from your account email and describe your request. You may request a copy or correction of your personal information, deletion of your account and associated records, or restriction of or objection to a use of your information. We may verify account ownership before acting. A request can cover roster data, search history, export files and job records, usage records, associated diagnostics, and identifiable website analytics, subject to the retention exceptions above. Deleting your sign-in account or disconnecting an assistant alone does not necessarily remove records stored in other systems; contact us for an associated-data deletion request. We respond in accordance with applicable law.
- Cookies and advertising: use browser controls to block or clear cookies and local storage. Some settings and sign-in features may stop working. Review Google's Ads Settings to control personalized advertising and its Analytics opt-out tool for supported browsers. Clearing browser data does not delete server-side account records.
Website cookies, analytics, and advertising
We and our providers use cookies, local storage, and similar technologies for sign-in, preferences, traffic measurement, security, and advertising. Google and its partners may use advertising cookies based on visits to xmplaylist and other websites. Analytics can include the page URL and its search parameters, referral information, device or browser details, and interactions with site features. See the Google Privacy Policy and Amplitude Privacy Notice for their practices. These browser technologies run on website visits; the MCP tools do not load website advertising or analytics scripts inside your assistant conversation.
YouTube API Services
xmplaylist uses YouTube API Services to locate public YouTube videos associated with tracks in the xmplaylist catalog. We use the results to provide outbound links that open the selected video on YouTube. xmplaylist does not embed, download, modify, or rehost YouTube video or audio content.
To create these links, xmplaylist may access public, non-authorized YouTube API data such as a video ID, URL, title, and channel information. We may store the resulting public YouTube URL with the corresponding xmplaylist track record. We use this information only to match tracks to relevant public videos and display the outbound link. We do not sell YouTube API data.
xmplaylist does not ask users to sign in with Google or authorize access to a YouTube account. We do not access or store YouTube login credentials, private YouTube data, viewing history, subscriptions, playlists, uploads, or other data associated with a user's YouTube account.
YouTube links and related public API data are retained only while needed to provide and maintain the track-linking feature. We remove or refresh this data when it is no longer needed, becomes inaccurate, must be removed under applicable policy, or our access to the YouTube API Services ends.
Use of YouTube is subject to the YouTube Terms of Service. Google's handling of information is described in the Google Privacy Policy. xmplaylist does not request Google account authorization, but users can review access granted to other applications from their Google security settings.
To ask what information xmplaylist has associated with you or request deletion of your personal data, email [email protected]. Deleting data held by xmplaylist does not delete data held by YouTube; requests concerning data on YouTube must be made through YouTube.
Security
We use access controls, authenticated account requests, and encrypted connections to protect information. No storage or transmission method is completely secure. Keep your credentials and export download links private, and contact us if you suspect unauthorized access.
Children
xmplaylist is not designed for or marketed to children under 13. If you believe a child under 13 has provided personal information, contact us so we can investigate and remove it.
Other services and policy changes
Links to music services, assistant providers, and other third-party sites are governed by those services' policies. This policy covers information handled by xmplaylist. Our Terms of Service also apply to use of xmplaylist.
We will update this page and its last-updated date when our practices change. Contact [email protected] with questions or to exercise your privacy choices.