Playdate
Privacy Policy
Updated 17 September 2026
Playdate turns a music link from one streaming service into a link that opens in any of them. This policy explains what Playdate collects when you use the app, the website, the iOS share extension or the App Clip, why, and what you can do about it. There are no accounts, no passwords, no ads and nothing is sold.
The short version
- You do not create an account. The app gives your device an anonymous, random identifier so links you make can be tied to you and to nobody else.
- The links you make are stored on our servers so they keep working for the people you send them to. They contain public catalogue information about the music (title, artist, artwork, track list), not anything about you.
- Connecting Spotify or Apple Music is optional and only needed for playlists. Sign-in happens on Spotify’s or Apple’s own screens. Playdate never sees a password.
- We collect anonymous usage analytics and crash reports so we can see what breaks and what people use. They are not linked to your name, email or advertising identifier, and we do not use them for advertising or tracking across apps.
- We do not sell personal information and we do not show ads.
What we collect and why
Links you paste or share
When you give Playdate a Spotify, Apple Music or Deezer link, we send that link to our servers to look up the same music on the other services. We store the result — the original link, the matching links, and the public catalogue information for the music (title, artist, album, artwork, track list, and for playlists the playlist’s name, description and the display name of its owner) — under a random share token. That is the Playdate link you send to people. It is stored for as long as the link needs to keep working, and it is tagged with your anonymous identifier so we can tell which links you made.
A Playdate link is open to anyone who has it. Anyone you send it to, and anyone they pass it on to, can see the music it points to. Do not use Playdate to share a playlist whose contents you want to keep private.
Your anonymous identifier
The first time the app runs it asks Google Firebase for an anonymous sign-in. This creates a random user ID that is not tied to a name, email address, phone number or any account. We use it to associate the links you make with your device, to tell requests apart on our servers, and to group analytics and crash reports from the same install. Deleting the app or clearing the website’s site data discards it; a fresh install gets a new one.
Connected music services
Songs, albums and artists never need a connected account. Connecting one is only required to read a private playlist of yours or to add a playlist to your library. When you connect:
- Spotify: you sign in on Spotify’s own page and choose whether to allow Playdate to read your playlists and library and to create or change playlists. Spotify then gives the app an access token and a refresh token. They are kept on your device (in the iOS keychain, or in your browser’s storage on the web) and sent to our servers with a request only when a request needs them, for example to read one of your private playlists. When a token is sent to the server as part of connecting or refreshing, the server may keep a copy under your anonymous identifier so it can act on your behalf.
- Apple Music: on iOS, the app asks for permission to use the Apple Music account already on your phone. Apple gives the app a Music User Token. It is kept on your device and sent to our servers so playlists can be built in your Apple Music library; the server keeps a copy under your anonymous identifier.
- Deezer: nothing to connect. Deezer’s public catalogue is read without any account.
We use connected-service tokens only to do what you asked (read a playlist, build a playlist) and never to read your listening history, post on your behalf, or for anything else. We do not keep a copy of your library or your private playlists beyond the individual playlist you chose to convert. You can disconnect a service at any time in Settings: that removes the tokens from your device and tells our servers to delete their copy. Revoking Playdate’s access in your Spotify account settings or in iOS Settings makes any remaining token useless.
Playlists hosted on Playdate’s Spotify account
When a playlist is converted to Spotify, Playdate creates a copy of it on Playdate’s own Spotify account rather than in yours, and the Spotify link we give you opens that copy. The copy carries the playlist’s name, description and songs. It is not shown on Playdate’s public profile or in Spotify search, but anyone who has the link can open it and save it to their own library. Converting a playlist to Spotify means you are asking us to publish that copy.
Usage analytics
We use Google Firebase Analytics (Google Analytics for Firebase) in the app and on the website to understand how Playdate is used: app opens, links converted, links copied or shared, which service a link was opened in, whether a service was connected, and errors. Events may include the public catalogue details of the music involved (title, artist, album, share token) and your anonymous identifier. They do not include your name, email, contacts, precise location, or the advertising identifier (IDFA / GAID). We have not enabled advertising features, and we do not use this data to track you across other companies’ apps or websites. Firebase also records coarse device information: device model, operating system version, app version, language and country derived from your IP address.
Crash and performance reports
The iOS and Android apps use Firebase Crashlytics and Firebase Performance Monitoring. If the app crashes or hits an error, a report is sent containing the error, a stack trace, device model and OS version, app version, your anonymous identifier, and a short trail of what the app was doing (for example “resolve started”). Performance Monitoring records how long screens and network requests take. The website uses Vercel Speed Insights, which records page load timings without cookies.
Server logs
Our servers, like most, keep request logs: the time of a request, the endpoint, the response status and timing, and your IP address and browser or app user agent. We use your IP address to limit abusive request rates and to keep the service up. Our hosting and monitoring providers (listed below) keep these logs for a limited time on our behalf.
Preferences and history on your device
The list of links you have made, your “Always open in” choice and your appearance setting are stored on your device (and, on iOS, shared with the Playdate share extension and App Clip through an app group). They are not uploaded. “Clear the list” in Settings removes the list from the device; it does not delete the links themselves, which keep working for whoever has them.
The iOS share extension and App Clip
The share extension only reads the link you chose to share; it does not read anything else on the share sheet. The App Clip shows a link’s handoff screen without installing the app and remembers which service you chose. Both send the same analytics and crash reports as the app.
What we do not collect
- No name, email address, phone number or contacts.
- No passwords — sign-in happens on Spotify’s and Apple’s own screens.
- No precise location.
- No photos. iOS shows a photo-library notice because a component bundled with the app is capable of reading files; Playdate does not use it.
- No advertising identifier and no App Tracking Transparency request.
- No payment details. Playdate is free.
Who we share it with
We do not sell personal information and we do not share it for advertising. We share data only with the companies that provide the infrastructure the service runs on, each of which processes it on our behalf under its own terms and privacy policy:
- Spotify, Apple (Apple Music / MusicKit) and Deezer — to look up music and, when you ask, to read or build playlists. The link you paste and any token needed are sent to them. Their handling of that data is governed by their own privacy policies.
- Google Firebase (Google LLC) — anonymous authentication, the database that stores links, Analytics, Crashlytics and Performance Monitoring.
- DigitalOcean — hosts our API servers.
- Vercel — hosts the website and provides Speed Insights.
- New Relic and Raygun — server performance monitoring and error reporting, which may receive request logs and error details.
We will also disclose information if the law requires it, to protect the rights or safety of anyone, or as part of a sale or transfer of the service, in which case this policy continues to apply to it.
How long we keep it
- Links you make: kept so they keep working. Email us to have a link and its record deleted.
- Connected-service tokens: until you disconnect the service in Settings, which deletes them from your device and from our servers, or until they expire or you revoke Playdate’s access.
- Analytics: Firebase Analytics retains user-level event data for up to 14 months; aggregated reports may be kept longer.
- Crash reports: kept by Crashlytics for 90 days.
- Server logs: kept for a limited period by our hosting and monitoring providers, then deleted.
Your choices and rights
- Disconnect Spotify or Apple Music at any time in Settings; the tokens are deleted from your device and from our servers. You can also revoke Playdate in your Spotify account’s “Manage apps” page or under Apple Music in iOS Settings.
- Clear your list of links in Settings.
- Delete the app, or clear the website’s site data, to discard the anonymous identifier and everything stored on the device.
- Ask us to delete the links tied to your identifier, any stored tokens, or anything else we hold. Because we have no account to look you up by, include the Playdate links in question or the anonymous ID (we can tell you how to find it).
Depending on where you live, you may have the legal right to access, correct, delete or receive a copy of your personal data, to object to or restrict its processing, and to complain to a data protection authority. For people in the European Economic Area, the United Kingdom and Switzerland, our legal basis for processing is the performance of the service you asked for (creating and serving links, building playlists) and our legitimate interest in keeping the service secure and understanding how it is used. For California residents: we do not sell or share personal information as those terms are defined in the CCPA, and we do not discriminate against anyone for exercising their rights. To exercise any right, email support@playdate.vip. We will answer within 30 days.
Security
All traffic between the app, the website and our servers uses HTTPS. Service tokens are held in the iOS keychain or the platform’s secure storage on device. Access to the database is restricted so that a client can read only shared links and its own records. No method of storage or transmission is completely secure, so we cannot promise that data can never be accessed without authorisation; if we learn of a breach affecting you we will tell you as the law requires.
Children
Playdate is not directed at children under 13 (or the higher age your country sets for consenting to data processing, such as 16 in parts of the EU), and we do not knowingly collect personal information from them. If you believe a child has used Playdate, email us and we will delete what we hold.
International transfers
Our servers and providers are in the United States and may be elsewhere. If you use Playdate from outside the United States your data will be transferred there. Where the law requires it, our providers rely on standard contractual clauses or an equivalent mechanism for those transfers.
Changes to this policy
If we change what Playdate collects or how we use it we will update this page and the date at the top, and for a material change we will say so in the app before it takes effect. Continuing to use Playdate after a change means you accept the updated policy.
Contact
Questions, requests or complaints: support@playdate.vip. Website: https://playdate.vip.