Privacy policy
Last updated 22 September 2026
This policy explains what Spot if AI (https://spot-if-ai.xyz) processes when you use it. The service is operated by Sergey Amirov, Prague (contact: amirov@larixon.com). We designed it to work with as little personal data as possible.
1. Using the site without signing in
You can check any artist without an account. We then process your IP address to protect the service from abuse (a per-address request limit, held in memory and not written to disk) and standard web-server logs, which are kept for up to 14 days. Nothing about you is stored beyond that.
2. Connecting Spotify
To analyse your playlists you can sign in with Spotify. We request read-only access to your playlists, your recently played tracks and your top tracks (Spotify scopes playlist-read-private, playlist-read-collaborative, user-read-recently-played, user-top-read). We do not ask for e-mail, profile or any write permission.
- Your Spotify access token, refresh token, Spotify user id and display name are stored only in an encrypted cookie in your browser (AES-256-GCM, httpOnly). We keep no account database. Signing out deletes the cookie; it expires after 30 days otherwise.
- The list of your playlists is cached on our server for 15 minutes, keyed by your Spotify user id, to reduce calls to Spotify.
- When you run an analysis, the playlist’s name, its tracks and the artist results are stored on our server for 7 days so the result page and its share link keep working. The result is only reachable by its random link. Your listening history (“recently played”, “top tracks”) is treated the same way.
Spotify’s own terms and privacy policy apply to your Spotify account. You can revoke our access at any time at spotify.com/account/apps.
3. Data about artists
Spot if AI processes public information about music acts (release history, encyclopedia entries, press coverage, registry listings) to produce an estimate. Artist analyses are cached for up to 30 days. Artists are typically not private individuals in this context; if you are an artist and believe a page about you is inaccurate or should not exist, contact us and we will review and, where appropriate, correct or remove it.
4. Third-party services we call
| Service | What is sent | Purpose |
|---|---|---|
| Spotify Web API | Your access token; artist / playlist identifiers | Read playlists and artist catalogues |
| MusicBrainz, Wikipedia | Artist name | Documented history |
| SlopTracker | Artist name | AI-artist registry lookup |
| Serper (Google results) | Artist name in a search query | Press and web presence |
| TypeSafe (Jev model) | Structured signals about the artist — never your identity or playlist | Probabilistic interpretation |
| PostHog (only if enabled) | Anonymous usage events with a random id stored in your browser | Product analytics |
No personal data about you is sent to any of these except your Spotify token to Spotify itself.
5. Cookies
One functional cookie (sia_spotify) holds your encrypted Spotify session; a short-lived one (sia_pkce) is used during sign-in. No advertising or tracking cookies. If analytics is enabled, a random identifier is kept in your browser’s local storage; clearing site data removes it.
6. Your rights
If you are in the EU/EEA or UK, you have the rights of access, rectification, erasure, restriction and objection under the GDPR. Because we keep no accounts, most requests are satisfied by signing out (which deletes your session) or by sending us the link of a result page you want removed. For anything else, write to us at amirov@larixon.com. You may also complain to your local data-protection authority.
7. Changes
We will update this page when the service changes what it processes. The date at the top tells you when.