splinterparty

Spotify & your privacy

Linking Spotify is optional. You can upload and listen to MP3 and FLAC files without a Spotify account.

What linking allows

We request permission to connect the Spotify browser player, read your account profile and playback state, search tracks, and control playback on your Spotify account. Spotify's browser player requires the email and private profile scopes; this app does not store your email. Each listener streams directly from Spotify through their own Premium account. Spotify audio is never downloaded or relayed by this server.

What this server stores

Your display name, access token, refresh token, and login session are kept in server memory for up to 24 hours, or until you unlink or the server restarts. A necessary HttpOnly cookie identifies your session. The browser player receives your short-lived access token; refresh tokens stay on the server. Tokens and your profile are not shared with room members.

Tracks you add share their title, artist, artwork, Spotify link, and duration with everyone who has the room code. That public track metadata remains in the room after you unlink and expires with the room. The server does not attach your account identity to tracks. Search queries are sent to Spotify and are not retained by this app.

Disconnect or revoke access

Choose Unlink in the room's Spotify panel to stop the browser player and delete the server-side session, profile, and tokens. To revoke the app's authorization at Spotify as well, visit your Spotify account's Apps page and remove splinterparty.

Third parties and hosting

When linked, this app loads Spotify's player and sends playback requests to Spotify. Spotify artwork is loaded when Spotify tracks appear. These connections expose your IP address to Spotify and are covered by Spotify's privacy policy. Your server operator and reverse proxy may keep their own access logs. Contact the person hosting your splinterparty instance for questions about their hosting or logs.

Back to splinterparty