Privacy Policy
Last updated: September 2026
Pairwave ("we", "the service") keeps playlists you link across music providers (Spotify, YouTube, TIDAL, SoundCloud) in sync. (Deezer was previously supported; that support and all associated data have since been removed.) This policy explains what data we hold and why. Operator: Federico Alunni, contact pairwave.willowyrd@gmail.com.
What we store
- OAuth tokens for the providers you connect, encrypted at rest (AES-256-GCM). We use them only to read and modify the playlists you choose to link. If you connect Spotify with your own registered app ("bring your own client id"), that app's client id and secret are stored the same encrypted way.
- Account identifiers returned by each provider (your user/channel id and display name) so we can tell your connections apart.
- Your profile — a name and email seeded from the first provider you sign in with, then editable in the app. Used only to identify your account; we don't send you marketing.
- Playlist and track metadata for the playlists you link, so we can compute what to add and avoid duplicates.
- A session cookie to keep you signed in.
What we do not do
- We never sell your data, and we never pass it to data brokers, information resellers, advertisers, or anyone making credit or lending decisions.
- We do not use your data for advertising, personalised advertising, or profiling, and we do not build databases from it for any purpose other than running the sync you asked for.
- We do not use your data — including any data received from Google APIs — to develop, improve, or train generalised or non-personalised AI or machine-learning models, and we do not pass it to anyone else for that purpose.
- We never remove tracks from your playlists — the sync is append-only.
- We do not read anything you have not linked: connecting a provider does not give us a crawl of your library, only the playlists you pick.
Who we send data to
Finding the same song on another platform means asking that platform, so a small amount of track information does leave Pairwave. This is the complete list of who receives it and what they get. None of it is a sale, and none of these recipients get your Pairwave password, your email address, or the OAuth tokens belonging to a different provider.
- The providers you connect — Spotify, YouTube, TIDAL, SoundCloud, and your own server if you connect Subsonic/OpenSubsonic. To match a song we send the target platform's search API the track's title, artist, duration and ISRC where we have them, and nothing else. This includes tracks first read from your YouTube playlists, which is how a YouTube song ends up in your Spotify playlist. Each provider then handles that request under its own privacy policy.
- MusicBrainz — we look up ISRCs only against the public MusicBrainz database, to tell different releases of the same recording apart and retrieve that recording's public aggregate genres and community tags. The lookup carries the ISRC and nothing that identifies you or your account. Pairwave stores the public label names and aggregate counts as shared reference data; it receives no individual votes, uses no MusicBrainz account, and never writes tags back to MusicBrainz.
- Discogs — only if you link a Discogs wantlist or collection. We search Discogs by title and artist, and add or remove releases in the list you linked.
- Our hosting provider — the server and database that run Pairwave, operated on our behalf. Nobody else has access to them.
How we protect your data
Security procedures are in place to protect the confidentiality of your data, and we use encryption to protect your information both in transit and at rest.
- In transit — the site and its API are served over HTTPS/TLS only.
- At rest — the OAuth access and refresh tokens for every provider you connect, including Google/YouTube, are encrypted with AES-256-GCM before they are written to the database. The same applies to the client id and secret if you connect Spotify with your own registered app. The encryption key lives in the server environment, never reaches your browser, and tokens are never returned by our API.
- Passwords — stored only as a salted scrypt hash, never in plain text. Changing your password invalidates every session issued before the change.
- Access control — your playlists, links and connections are reachable only through your own authenticated session; every API endpoint checks it before returning anything.
- Data minimisation — we request a single Google scope, https://www.googleapis.com/auth/youtube, and use it solely to read the playlists you link and add matched tracks to them. We do not request access to any other Google data.
- Revocation — disconnecting a provider deletes the stored tokens for it, and you can revoke Pairwave's Google access at any time from your Google account.
Google and YouTube
Pairwave uses YouTube API Services to list the playlists you choose to link, read what is in them, and add matched tracks to them. By connecting YouTube you also agree to the YouTube Terms of Service, and the data Google receives is handled under the Google Privacy Policy.
When you press Play for a linked YouTube playlist, Pairwave loads YouTube's official privacy-enhanced player from youtube-nocookie.com. Nothing is loaded before that gesture. YouTube receives the playlist id and ordinary browser request data such as your IP address, page origin and referrer, and applies its own controls, ads, availability rules and privacy policy. Privacy-enhanced mode reduces storage before interaction; it does not mean that no data is sent to YouTube.
Pairwave uses the connected YouTube API to check whether the current video may be embedded, is age-restricted or is designated Made for Kids. These short-lived functional checks are not written to the database; their server cache expires after five minutes. Pairwave does not store listening history, watch time or player analytics, and never substitutes another recording when a playlist item cannot play.
Pairwave's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request one scope, https://www.googleapis.com/auth/youtube, and use it only for the purpose above. Data received from Google APIs is never sold, never used for advertising or profiling, and never used to train generalised AI or machine-learning models.
You can revoke Pairwave's access to your Google account at any time from myaccount.google.com/permissions, also reachable at security.google.com/settings/security/permissions. Revoking stops every further read and write on YouTube; to also remove the tokens we already hold, disconnect YouTube inside Pairwave or delete your account.
Retention and deletion
While your account exists we keep the data above for as long as it is doing something: a provider's tokens until you disconnect it, a playlist's track metadata until you unlink the playlist or delete the account. We keep it because the next sync has to know what it already added — there is no separate archive and no backup of it we hold beyond the running database.
Disconnecting a provider deletes its stored tokens. Deleting your account from Settings is immediate and removes everything tied to you — connections and their tokens, playlists, sync groups, matches and logs — in a single cascading delete. What survives is the shared catalogue of tracks Pairwave has seen (title, artist and platform ids), which carries no link to you or to any account. If you would rather ask us, email pairwave.willowyrd@gmail.com and we delete within 30 days.