Privacy Policy
Last updated: July 2026
PairWave ("we", "the service") keeps playlists you link across music providers (Spotify, YouTube, TIDAL, SoundCloud) in sync. (Deezer was previously supported; that support and all associated data have since been removed.) This policy explains what data we hold and why. Operator: Federico Alunni, contact gmemo033@gmail.com.
What we store
- OAuth tokens for the providers you connect, encrypted at rest (AES-256-GCM). We use them only to read and modify the playlists you choose to link. If you connect Spotify with your own registered app ("bring your own client id"), that app's client id and secret are stored the same encrypted way.
- Account identifiers returned by each provider (your user/channel id and display name) so we can tell your connections apart.
- Your profile — a name and email seeded from the first provider you sign in with, then editable in the app. Used only to identify your account; we don't send you marketing.
- Playlist and track metadata for the playlists you link, so we can compute what to add and avoid duplicates.
- A session cookie to keep you signed in.
What we do not do
- We never sell or share your data with third parties.
- We never remove tracks from your playlists — the sync is append-only.
- We do not use your data for advertising or profiling.
Google / YouTube
PairWave's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke access at any time at myaccount.google.com/permissions.
Retention and deletion
Disconnect a provider or delete your account to remove the stored tokens and linked-playlist data. To request deletion, email gmemo033@gmail.com; we delete within 30 days.