Playlistable

Privacy Policy

Last updated: 1 October 2026

Playlistable ("we", "us", or "our") is an independent product from Brackyt. This Privacy Policy explains what personal data we collect, why we use it, who receives it, how long we keep it, and the controls you have.

It covers playlistable.io, app.playlistable.io, our iOS and Android apps, and the MCP server at mcp.playlistable.io (including when you connect Playlistable from ChatGPT or another MCP client). Together these are the "Service".

We do not sell your personal data. We collect only what we need to run the Service. Questions: contact@playlistable.io.

1. Categories of personal data we collect

Depending on how you use the Service, we may collect:

  • Account and identity: email address (when your music provider shares it), display name, Playlistable user ID, streaming-provider user ID, signup client (web, iOS, Android, or MCP), and first-touch attribution (for example campaign source or OpenAI Ads click IDs).
  • Streaming-service data: OAuth tokens for Spotify or Apple Music (access and refresh tokens, or an Apple Music user token and storefront) so we can create and update playlists in your library. We read the provider profile needed to sign you in. We do not store your Spotify or Apple Music password.
  • Playlist and generation data: the prompt you type, playlist title and description, track lists we generate or you pick, refinement instructions, generation status, model metadata, and whether a playlist is a teaser or public. If a playlist is published on playlistable.io, the title, prompt, and tracks can appear on that public page.
  • Billing: subscription status, plan, trial and period dates, and processor customer or subscription IDs. Stripe and the app stores handle card and store-account numbers. We do not store full payment-card numbers.
  • MCP and ChatGPT: OAuth client metadata, short-lived authorization codes, session records, and hashed MCP API keys so an agent can call tools on your behalf. Tool calls include the prompt or search you send through that client.
  • Device, logs, and support: IP address, user agent, last platform and app version, last-seen time, Firebase Cloud Messaging push tokens, in-app support tickets, and emails you send us. Application logs may include request paths, error traces, and identifiers needed to debug a failure.
  • Analytics and ads measurement: page views, referrer, device and browser, approximate country from IP, and conversion events (for example signup or checkout). See Cookies and analytics below.

We do not ask for payment-card PAN data, government identifiers, passwords for your music accounts, or health data.

2. Purposes of use

  • Create your account, keep you signed in, and connect Spotify or Apple Music.
  • Generate playlists from your prompt, save them to your music library, and show them in Playlistable.
  • Let ChatGPT and other MCP clients act on your connected account after you authorize them.
  • Process subscriptions, trials, invoices, and failed-payment notices.
  • Send transactional email (welcome, playlist-ready, billing, support) and, if you have not opted out, occasional product email.
  • Measure traffic and conversions so we can understand which channels work, fix bugs, and keep the Service reliable.
  • Prevent abuse, enforce rate limits, and meet legal or tax obligations.

Where GDPR applies, we rely on performing the contract (providing the Service you asked for), legitimate interests (security, product analytics, measuring ads that brought you here), legal obligation (invoices), and consent where required (optional marketing email; you can withdraw it at any time).

3. Who receives your data

We share personal data only with the processors and platforms needed to run the Service. They may use it only to provide that service to us, except where you have a direct relationship with them (Spotify, Apple, Stripe customer portal, ChatGPT).

  • Google / Firebase: authentication, Firestore (accounts and playlist metadata), Cloud Functions, hosting for the web app and API, Firebase Analytics and Crashlytics on mobile, and FCM push notifications.
  • OVH: hosting for the public marketing site (playlistable.io) and our private metrics pane.
  • Stripe: web subscriptions, invoices, and payment status.
  • RevenueCat / Apple / Google Play: in-app subscriptions on iOS and Android.
  • Spotify and Apple Music: sign-in and writing playlists into your library. Their own privacy policies apply to data they hold.
  • LLM providers (xAI, and OpenAI or Anthropic when those models are used): your prompt and the generation context needed to return a track list. Production generation currently uses xAI Grok. We do not send your music-account password. Providers may process that prompt under their own terms as our processors.
  • OpenAI (ChatGPT) and other MCP clients: if you connect Playlistable in ChatGPT or another agent, that client sends tool inputs to us and receives tool results (for example playlist titles and tracks). That client's privacy policy covers what it keeps.
  • Brevo: transactional and product email.
  • DataFast: first-party website and app analytics (page views, referrer, device, approximate location).
  • Microsoft Clarity: session analytics on the marketing site and web app (pages, clicks, and session recordings).
  • Google Ads and OpenAI Ads: conversion measurement when you arrive from those ads (for example hashed email and click IDs). We are not an ad network and we do not run third-party ad servers on the Service.
  • Sentry: error monitoring on the web app (stack traces and a user id when you are signed in).

We may also disclose data if required by law, to protect the Service, or to a successor if Playlistable is transferred. We do not sell personal data and we do not share it with unrelated advertisers.

4. Data retention

These are the timelines we follow. When a period ends we delete or irreversibly anonymize the data, unless a longer legal hold applies (for example an ongoing dispute or a tax audit).

  • Account data (email, display name, provider IDs, billing flags, attribution, device metadata): kept while the account is active. After a verified deletion request, deleted or anonymized within 30 days.
  • Streaming OAuth tokens: kept only while the music account stays connected. Deleted as soon as you disconnect or we delete the account.
  • Playlist metadata we store (prompt, title, tracks, refinements, status): kept while the account is active, then deleted with the account within 30 days. Playlists already saved in Spotify or Apple Music stay in that library; you control them there. If a playlist was public on playlistable.io, we unpublish it and remove personal identifiers on deletion.
  • MCP / ChatGPT credentials: authorization codes expire after 10 minutes; pending login sessions after 1 hour; one-time display tickets after 5 minutes; completed session records after 24 hours. MCP API keys last until you revoke them or we delete the account.
  • Application and security logs (Firebase / Google Cloud): up to 90 days, unless we need a specific log longer to investigate abuse or a security incident.
  • Error reports (Sentry, Crashlytics): up to 90 days.
  • Billing records (Stripe, RevenueCat, invoices, tax-relevant subscription history): for as long as applicable accounting and tax law requires — typically 10 years.
  • Support tickets and email correspondence: up to 3 years after the last message, then deleted unless a longer legal obligation applies. We may keep a minimal record of a deletion request (email and date) for 12 months to show we handled it.
  • Analytics: DataFast events up to 3 years; Microsoft Clarity session recordings typically 30 days and aggregated Clarity data up to 13 months; Firebase Analytics typically 14 months.
  • Advertising measurement cookies / click IDs: Google Ads conversion cookies typically up to 90 days; OpenAI Ads identifiers as long as needed to attribute that conversion, then dropped from our systems with the account or within 13 months, whichever is sooner.
  • Push tokens: until the token is invalid or the account is deleted.

5. Cookies and analytics

The marketing site and web app use first-party cookies or similar identifiers for sign-in sessions and for analytics or ads measurement:

  • Session / auth cookies so you stay signed in on app.playlistable.io.
  • DataFast (first-party script) for traffic and conversion analytics.
  • Microsoft Clarity for session analytics, which may set cookies.
  • Google Ads (gtag) and the OpenAI Ads pixel for conversion measurement when you come from those campaigns.

You can block or delete cookies in your browser. Blocking analytics or ads cookies does not stop you from generating playlists after you sign in. Browser settings may sign you out of the web app.

6. Where data is processed

We operate from the EU. Processors above may store or process data in the United States or other countries. Where GDPR requires it, transfers rely on an adequacy decision or standard contractual clauses from those vendors.

7. Your controls

Email contact@playlistable.io to:

  • Access the personal data we hold about you.
  • Correct inaccurate account details.
  • Export a copy of your account and playlist metadata (we send a machine-readable file such as JSON).
  • Delete your Playlistable account and the personal data we store, subject to the billing and legal holds above.
  • Opt out of product / promo email (transactional mail about billing or security still goes out).

We aim to respond within 30 days. You can also:

  • Revoke Playlistable in your Spotify or Apple account settings (this stops new library writes; ask us if you also want the Playlistable account deleted).
  • Disconnect ChatGPT / MCP by revoking the connection in that client, or email us to revoke MCP API keys.
  • Cancel a web subscription in account settings or the Stripe customer portal; cancel an app subscription in Apple or Google Play settings.
  • Lodge a complaint with your local data-protection authority (in France, the CNIL).

8. Children

The Service is for people aged 13 or older (or the higher digital-consent age in your country). We do not knowingly collect personal data from children under 13. If you believe a child has created an account, email us and we will delete it.

9. Security

Account and playlist data live in Google Firebase. Streaming and MCP secrets are stored so we can act on your behalf; MCP API keys are stored as hashes. No internet transmission or storage is perfectly secure. If we become aware of a breach that affects you, we will notify you and regulators as the law requires.

10. Changes

We may update this Privacy Policy. The new version is effective when we post it on this page, with a new "Last updated" date. For a material change we will also try to email the address on the account when we have one.

11. Contact

Playlistable / Brackyt
Email: contact@playlistable.io
We do not publish a street address or phone number. A written email is how you reach us.

Using the Service means you have read this policy. Our Terms of Service cover the contract for using Playlistable.