Sound Atlas ("we", "the app") is a personal music discovery application operated by Hooman Takhtechian. This policy explains what we collect, why, how long we keep it, and how you remove it. It applies to the Sound Atlas web application and the Sound Atlas Android application.
The short version: your ratings and playlists are private to your account, we do not sell your data, we do not use it for advertising, and you can delete all of it at any time.
What we collect
| Data | Why we hold it |
|---|---|
| Your email address, display name, and the account identifier your sign-in provider gives us | To identify your account, keep your data separate from other users, and contact you about the service |
| Song ratings and notes you enter | They are the core of the product: recommendations and playlists are built from them |
| Your taste profile, derived from those ratings | To rank and select songs for you |
| Playlists you create or save, and their song order | So you can return to them and send them to a streaming service |
| Streaming service authorisation tokens, encrypted | So the app can create and update playlists in your own account when you ask it to |
| App usage records such as onboarding progress and listening sessions | To restore where you were and to fix problems |
| A security audit record of significant actions on your account | To detect and investigate misuse |
We never receive or store your streaming service password. Authorisation happens on that service's own sign-in page.
How we use it
- To generate your recommendations, playlists and taste profile.
- To create or update playlists in your streaming account, only when you ask.
- To operate, secure and debug the service.
- To contact you about the service if something needs your attention.
We do not use your data for advertising, we do not sell or rent it, and we do not use it to train advertising or general-purpose machine learning models.
Google user data and YouTube API Services
Sound Atlas uses YouTube API Services. By using the parts of Sound Atlas that connect to YouTube, you agree to be bound by the YouTube Terms of Service. Google's own handling of your information is described in the Google Privacy Policy.
What we request and why
When you link YouTube Music, we request permission to manage your YouTube account
(https://www.googleapis.com/auth/youtube) together with your basic identity.
We use it for one purpose: to create a playlist in your account, and to update a playlist
Sound Atlas created earlier, using the songs and order you selected in the app.
We do not upload videos, post comments, change your subscriptions, alter playlists Sound Atlas did not create, or read your watch history.
Limited Use
Sound Atlas's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data is used only to provide the features described above, is not transferred to others except as required to provide those features or by law, is not used for advertising, and is not read by humans except with your explicit permission, for security purposes, or where required by law.
Withdrawing access
You can disconnect a streaming service inside Sound Atlas at any time, which deletes the stored authorisation. You can also revoke it directly at Google account permissions. Playlists already created in your YouTube account belong to you and remain there; delete them in YouTube if you no longer want them.
Who we share it with
We share your data with no one, other than:
- the streaming service you have linked, and only the song identifiers and playlist details needed to carry out an action you requested;
- infrastructure providers who host the service on our behalf and process data only under our instructions;
- authorities, where we are legally required to do so.
Where it is stored and how it is protected
Data is held in a PostgreSQL database with per-user access rules enforced by the database itself, so one account cannot read another's data. Streaming authorisation tokens are encrypted before storage. Access to production systems is limited to the operator.
No system is perfectly secure. If a breach affects your data, we will tell you and the relevant authority as required by law.
How long we keep it
We keep your account data while your account exists. If you delete your account, your ratings, taste profile, playlists and stored authorisations are deleted. Security audit records may be retained for up to 12 months, and backups are cycled out within 30 days.
Your rights
You can request a copy of your data, correct it, or have it deleted. The app includes an export feature for your own records, and disconnecting a streaming service removes its stored authorisation immediately. For anything else, email hello@soundatlas.app and we will respond within 30 days.
Depending on where you live, you may also have the right to object to processing, to restrict it, or to complain to your local data protection authority.
Children
Sound Atlas is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.
Changes
If we change this policy we will update the date above, and we will tell you in the app before any material change takes effect.
Contact
Hooman Takhtechian
hello@soundatlas.app