Privacy & data

Privacy Policy

Tracknote is built for private music curation. This policy explains what information we handle across the Tracknote website and mobile applications, why we handle it, and the choices available to you.

Effective and last updated: September 1, 2026
No raw audioMicrophone audio and Shazam signature buffers stay on your device.
No ad trackingWe do not sell personal information or use it for cross-app advertising.
Private by defaultYour Collection, reviews, notes, playlists, precise location, and Scout history are account-scoped.

1. Who we are and scope

“Tracknote,” “we,” and “us” refer to the Tracknote music curation service operated by Ryan Kim. This policy applies to tracknote.me, the Tracknote mobile applications, and related account and support services.

Third-party music, identity, map, and payment-free beta services have their own privacy policies. Their handling of information outside Tracknote is governed by those policies.

2. Information we collect

CategoryExamplesHow it is collected
Account and identityEmail address; optional name and profile image; Google account identifier; account role; DJ stage name or managed venue where submitted.From you or Google Sign-In.
Authentication and securitySalted password digest, email-verification status, session tokens and expiry, failed sign-in counters, OAuth state, and security or abuse signals.Generated when you create, secure, or use an account. We do not store plaintext passwords.
Music curationCollection tracks, ratings, favorites, tiers, energy arcs, BPM, key, grid state, moods, reviews, private notes, cue notes, playlists, comments, search and playback choices, and set-planning prompts.From your use of Tracknote and connected music services.
Live Scout and venue activitySelected venue, Scout session times and room, recognized title and artist, Shazam identifier, confidence, delivery and trust state, and a client-generated event identifier.When you explicitly start Live Scout.
LocationPrecise latitude and longitude, horizontal accuracy, capture time, location source, and calculated distance from the selected venue.Only after you grant location permission and use location-dependent Scout or nearby-venue features.
Connected servicesPublic Spotify catalog metadata and outbound Spotify track links; Apple Music storefront/link status; YouTube channel identity and OAuth tokens; optional Instagram Professional username, name, account type, profile image, follower/following/media counts, recent media metadata, OAuth token, scope, and expiry.Spotify catalog metadata and outbound links are returned without a Spotify account connection. Other provider data is collected only when you choose to connect that provider. Provider credentials and refresh tokens stay server-side. Instagram connection is available only to eligible DJ and venue-operator accounts using a Business or Creator profile.
Technical and supportBrowser or app configuration, local preferences, language, permission state, request diagnostics, and information you include in support or role-verification communications.From your device, service requests, or messages to us.
Microphone boundary. ShazamKit analyzes nearby music on the device. Tracknote receives recognized metadata, not raw microphone audio or Shazam signature buffers. We do not upload or store raw audio.

3. How we use information

Where applicable, we rely on performance of our agreement with you, your permission or consent for device access and optional integrations, our legitimate interests in operating and securing the service, and compliance with law.

4. What stays private and what may be public

Private account data

Your email, precise location evidence, account/device evidence, Collection, ratings, reviews, private notes, cues, playlists, comments, and OAuth credentials are not included in the public venue feed.

Public-safe venue activity

After server validation and a safety delay, a venue timeline may show a recognized track title and artist, venue and room, an approximate detection window, aggregate confidence state, and scout count. It excludes the scout’s identity, email, event ID, exact location, device information, and private Collection data.

Shared playlists

If you intentionally create a share link, the read-only page may show track order, public music metadata, and a saved set prompt. It excludes email, ratings, reviews, private notes, cues, and other private account data. Revoking the link disables access.

5. Service providers and disclosures

We disclose only the information needed to operate features you use:

We may also disclose information when required by law, to protect users and the service, or as part of a reorganization where appropriate safeguards apply. We do not sell personal information and do not share it for cross-context behavioral advertising.

6. AI processing

AI may parse a playlist brief or propose music classifications. For playlist planning, Tracknote sends the prompt and selected planning controls. For classification, it may send public track metadata such as title, artist, album, BPM, key, genre, label, release, and duration.

We do not intentionally send account credentials, OAuth tokens, precise location, private reviews, cue notes, ratings, or playlists to the AI provider for these tasks. AI output is advisory: actual track IDs and order are grounded in your real Collection and deterministic validation.

7. Retention

We retain account and private workspace data while your account is active or as needed to provide the service. Authentication, security, and support records may be retained for a reasonable period to prevent abuse, resolve disputes, and meet legal obligations. OAuth states and verification links expire; session and provider tokens are retained only as needed for authentication or a connection.

When an account deletion request is completed, we delete or de-identify personal account data unless limited retention is required for security, fraud prevention, legal compliance, or backup integrity. Delayed public venue entries that no longer identify an individual may remain as aggregate or de-identified venue history.

8. Your choices and rights

For other privacy requests, or if you cannot access your account, email kim.lenish@gmail.com from the address connected to your Tracknote account. We may ask for reasonable verification before acting. Rights vary by jurisdiction.

9. Security and international processing

Tracknote uses authenticated server boundaries, account-scoped authorization, transport encryption, server-side provider secrets, salted password hashing, device-protected mobile session storage, and public-response sanitization. No internet service can guarantee absolute security.

Our providers may process information in countries other than yours. Where required, we use contractual and technical safeguards appropriate to the transfer.

10. Children

Tracknote is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided information, contact us so we can investigate and delete it where appropriate.

11. Changes to this policy

We may update this policy as the product or law changes. We will update the effective date and, when a change is material, provide notice in the service or through an appropriate channel.

12. Contact

Tracknote privacy contactOperator: Ryan KimEmail: kim.lenish@gmail.comSend a privacy request