Pairwave
Back to Pairwave

Privacy Policy

Last updated: September 2026

Pairwave ("we", "the service") keeps playlists you link across music providers (Spotify, YouTube, TIDAL, SoundCloud) in sync. (Deezer was previously supported; that support and all associated data have since been removed.) This policy explains what data we hold and why. Operator: Federico Alunni, contact pairwave.willowyrd@gmail.com.

What we store

What we do not do

Who we send data to

Finding the same song on another platform means asking that platform, so a small amount of track information does leave Pairwave. This is the complete list of who receives it and what they get. None of it is a sale, and none of these recipients get your Pairwave password, your email address, or the OAuth tokens belonging to a different provider.

How we protect your data

Security procedures are in place to protect the confidentiality of your data, and we use encryption to protect your information both in transit and at rest.

Google and YouTube

Pairwave uses YouTube API Services to list the playlists you choose to link, read what is in them, and add matched tracks to them. By connecting YouTube you also agree to the YouTube Terms of Service, and the data Google receives is handled under the Google Privacy Policy.

When you press Play for a linked YouTube playlist, Pairwave loads YouTube's official privacy-enhanced player from youtube-nocookie.com. Nothing is loaded before that gesture. YouTube receives the playlist id and ordinary browser request data such as your IP address, page origin and referrer, and applies its own controls, ads, availability rules and privacy policy. Privacy-enhanced mode reduces storage before interaction; it does not mean that no data is sent to YouTube.

Pairwave uses the connected YouTube API to check whether the current video may be embedded, is age-restricted or is designated Made for Kids. These short-lived functional checks are not written to the database; their server cache expires after five minutes. Pairwave does not store listening history, watch time or player analytics, and never substitutes another recording when a playlist item cannot play.

Pairwave's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request one scope, https://www.googleapis.com/auth/youtube, and use it only for the purpose above. Data received from Google APIs is never sold, never used for advertising or profiling, and never used to train generalised AI or machine-learning models.

You can revoke Pairwave's access to your Google account at any time from myaccount.google.com/permissions, also reachable at security.google.com/settings/security/permissions. Revoking stops every further read and write on YouTube; to also remove the tokens we already hold, disconnect YouTube inside Pairwave or delete your account.

Retention and deletion

While your account exists we keep the data above for as long as it is doing something: a provider's tokens until you disconnect it, a playlist's track metadata until you unlink the playlist or delete the account. We keep it because the next sync has to know what it already added — there is no separate archive and no backup of it we hold beyond the running database.

Disconnecting a provider deletes its stored tokens. Deleting your account from Settings is immediate and removes everything tied to you — connections and their tokens, playlists, sync groups, matches and logs — in a single cascading delete. What survives is the shared catalogue of tracks Pairwave has seen (title, artist and platform ids), which carries no link to you or to any account. If you would rather ask us, email pairwave.willowyrd@gmail.com and we delete within 30 days.