Music Timeline

Privacy Policy

This policy explains how Music Timeline handles guest playlist imports, account-backed sign-in, Spotify connection, generated profiles, and native app data.

Updated 2026-05-27

Music Timeline turns music context into a private profile, timeline, people directory, and concert/media recommendations. You can use the product as a guest by importing a playlist. Account sign-in and Spotify OAuth are optional paths when configured.

This repo-owned policy candidate must still be reviewed by the account owner before App Store submission and must be deployed before it can be used as the public App Store Connect privacy policy URL.
Data

Information the app may process

Guest playlist import

Spotify playlist URLs or IDs, anonymous guest IDs, imported artist/composer counts, generated music profile text, and playlist sync timestamps.

Account sign-in

If Google sign-in is enabled and used, the app may receive account identity fields needed to keep imported music state attached to that account.

Spotify connect

If Spotify OAuth is enabled and connected, the app may use Spotify authorization data to read listening or playlist context requested by the user.

Native apps

The iOS and macOS apps use a local anonymous ID and the configured music.tl API to load profiles, events, recommendations, and guest import state.

Operations

Hosting, storage, and provider systems can create ordinary server logs, error traces, request metadata, and diagnostic records needed to run the service.

Use

How information is used

The app uses imported music context to build recommendations, profile summaries, artist/composer lists, playlist readbacks, source filters, and event matches. Public profile data is only intended to be shared when the user chooses to publish a profile.

The app may send playlist or listening requests to Spotify, account requests to Google, and application requests to hosting or storage providers needed to operate music.tl. External music, video, venue, and profile links open the destination provider directly.

Controls

User controls

Guest users can remove browser cookies or local app data to reset the anonymous guest state. Account-backed users should use the connected provider controls to revoke Google or Spotify access when those providers are enabled.

Profile publishing controls live in settings. If a profile is unpublished, it should no longer be treated as a public music profile by the app.

Privacy Policy | Music Timeline