Privacy Policy

Last updated: June 19, 2026

1. Information We Collect

We collect the following information when you use Random Playlist:

2. How We Use Your Data

3. Data Storage

Your data is stored on Supabase (PostgreSQL) with row-level security enabled. OAuth tokens are encrypted at rest. We do not store your streaming platform passwords — only the OAuth access/refresh tokens provided by each platform.

4. Platform Account Metadata

When you connect a streaming platform account, Random Playlist may store metadata returned by that platform, such as your platform user ID, display name, profile image, email address when provided, and authorization tokens. This information is used to identify connected accounts, prevent the same streaming account from being linked to multiple Random Playlist users, and allow account switching inside your dashboard.

Random Playlist does not sell your streaming platform data.

5. Third-Party Services

Random Playlist uses the following third-party services:

By using Random Playlist, you also agree to be bound by the Google Privacy Policy.

6. YouTube API Services — Specific Disclosures

When you connect your YouTube or YouTube Music account, Random Playlist accesses the following data through YouTube API Services:

We use this data solely to display your playlists, allow you to reorder them, transfer playlists when YouTube is selected as a destination, and save the new order or created playlist back to YouTube. We do not download, store, or redistribute any YouTube audio or video content.

Data retention: YouTube OAuth tokens and associated data are stored only while your YouTube account is connected. When you disconnect YouTube from Random Playlist, all tokens and YouTube-related data are permanently deleted from our servers within 30 days. Inactive accounts (no login for 30+ days) will have their YouTube tokens automatically purged.

Revoking access: You can revoke Random Playlist's access to your YouTube data at any time by:

7. Data Sharing

We do not sell, trade, or share your personal data with third parties except as necessary to provide the service (e.g., Stripe for payments, streaming platform APIs for playlist access).

8. Your Rights

You have the right to:

9. Data Deletion

When you disconnect a streaming platform or delete your account:

10. Session Tracking

We track active sessions to enforce the device limit policy. Session records include a device identifier (stored locally in your browser), your IP address, and last activity timestamp. Inactive sessions are automatically deleted after 30 minutes.

11. Cookies

We use essential cookies for authentication (Supabase auth session). We do not use analytics or advertising cookies.

12. Contact

For privacy-related requests, contact us at privacy@randomplaylist.com.

← Back to home