Privacy Policy

We store as little as the platform can work with: an identifier from our login provider, your applications, hashes of your keys, and counters. This page says exactly what that means, including the parts that are inconvenient for us.

Last updated

1.Who is responsible

Spicy Lyrics is the controller for the personal data described here. Write to [email protected] about anything on this page. We have not appointed a data protection officer, as we are not required to.

We are based in Slovakia. Our servers are in the United States — see section 5.

2.What this covers

The developer platform at developers.spicylyrics.org, including the documentation and the signed-out playground, and the API at api.spicylyrics.org.

It does not cover the Spicetify extension, the Discord bot or the web client. It also does not cover what a developer does with data after their application receives it from the API — they answer for that themselves.

3.What we process, and why

Our own database normally identifies you only by your Clerk user ID. Your username, name and profile picture live with Clerk, our login provider, and we read them live when the dashboard needs them. When an administrator changes platform data, we also copy that administrator's email address into the audit log so the action remains attributable.

WhatWhyLegal basis
A user identifier from Clerk, and the date your account was first seen hereTo link your applications and keys to youContract, Art 6(1)(b)
Your email, username, name and avatar, held by Clerk and read live; an administrator's email is also stored with each audit entry they createTo sign you in, and to show who acted in the admin panelContract, Art 6(1)(b)
If you sign in with or link GitHub or Discord: that account’s ID, username, name, avatar and email, held by ClerkTo sign you in with that account, if you choose toContract, Art 6(1)(b)
Whether a Discord account is linked, and when you last answered our prompt to link one, held by ClerkTo ask you to link Discord, and to stop asking once you say noLegitimate interests, Art 6(1)(f)
Application name, description and project URL, origin allowlists, rate-limit settingsTo run the applications you createContract, Art 6(1)(b)
API key hashes (SHA-256), the first and last few characters, and when a key was last usedTo verify keys without ever storing one. We cannot recover a key and cannot show it to you twiceContract, Art 6(1)(b)
Request counters per application and hour, split by key type and response sourceTo show you your usage and to spot abuse. There is no record of individual requests, no IP address and no request path in this dataLegitimate interests, Art 6(1)(f)
Suspension state, the reason we give you, and an internal noteTo enforce the Terms and to answer an appealLegitimate interests, Art 6(1)(f)
Requests for information we send you about an application: what we asked, your answer, when each was sent, who sent the request, and an internal noteTo hear your side before deciding whether an application breaches the Terms, and to explain that decision laterLegitimate interests, Art 6(1)(f)
An audit log of administrative actions: who acted, their email, what changed, and a before-and-after snapshot of the rowTo be able to show why an account was suspended or a limit changed, and by whomLegitimate interests, Art 6(1)(f)
A SHA-256 hash of the IP address of signed-out visitors who use the playground demoTo rate-limit the demo so it is not drained by one networkLegitimate interests, Art 6(1)(f)
App templates you submit: the name, descriptions, links, category, the keys and origins you ask for, why you say it needs to be a template, the icon and banner you upload, and which account submitted itTo review the template and publish it in the catalogContract, Art 6(1)(b)
Review decisions about a template: who decided, when, what, the reasons we give you, what we changed, and an internal noteTo give you a statement of reasons, answer a challenge to it, and keep our decisions consistentLegal obligation, Art 6(1)(c), under Art 17 of the Digital Services Act; legitimate interests, Art 6(1)(f), for the internal note
Records of the images you upload: size, dimensions, time and accountTo limit uploads to 20 an hour per account, to check that a submission only uses your own uploads, and to delete images nothing uses any moreLegitimate interests, Art 6(1)(f)
Which app template an application was added fromTo apply the template’s settings to it, and to show us every copy of a template togetherContract, Art 6(1)(b)

Where we rely on legitimate interests, the interest is running a free service without it being abused, and you can object under section 9. For the Discord prompt, it is keeping the community around the API reachable; choosing “Don’t ask again” in the prompt is the objection, and it takes effect at once.

GitHub and Discord sign-in. Both are optional. You can use email instead, and linking Discord is never required for anything on the platform. When you use one of them, GitHub or Discord learns that you signed in here, and passes Clerk only what is listed above: we do not ask for your repositories, your servers or your messages. You can unlink either one under Manage account in the dashboard, and revoke our access in that service’s own settings. GitHub and Discord are separate controllers for their own side of this, under their own privacy policies; they are not providers of ours.

App templates. What the catalog shows about a template is public: its name, descriptions, icon, banner, category and links. It does not show which account submitted it, so do not put personal details in those fields that you do not want public. We re-encode every image you upload, and that removes its metadata, including the location a photo was taken, if it has one. The developer who submitted a template sees how many people added it and how many requests those copies made in total, never who added it. We, as administrators, can see who added it, which we need to act on abuse.

4.The signed-out demo, and IP addresses

The playground in the documentation works without an account. To stop one network exhausting it, we hash the visitor IP address with SHA-256 and count requests against that hash. The same hash is carried in a short-lived sl_demo cookie.

Hashing here is data minimisation, not anonymisation. There are only about four billion IPv4 addresses, so anyone determined enough can reverse a SHA-256 of one. We treat the hash as personal data and so should you; we are not going to call it anonymous because it would sound better.

Signed-out demo requests are limited to a small list of tracks and a low request ceiling. We do not log the requests themselves.

A separate anti-bot challenge (hCaptcha, run by Intuition Machines, Inc.) can be switched on for the demo by an administrator. It is off by default, and while it is off no hCaptcha script loads and nothing is sent to them. When it is on, the hCaptcha script runs in your browser and collects interaction and device data under their own policy, and we send them the challenge token together with your IP address so they can score it.

5.Who else sees this data

We use a small number of providers. All of them are in the United States, which means your data is transferred outside the EEA.

ProviderWhat reaches them
Clerk (identity and login)Your account: email, username, name, avatar, the GitHub or Discord account you sign in with or link, session data. Also free-text search terms when an administrator looks a user up. Clerk sends all authentication email; we send none
Oracle Cloud Infrastructure (hosting)Everything in section 3 except template images. We rent one virtual machine in the United States and run both the application and its Postgres database on it ourselves. Oracle supplies the machine; the database is not a service of theirs, but the data sits on their hardware
Cloudflare (network)All traffic to the platform passes through Cloudflare, which terminates TLS and supplies the visitor IP address to us
Cloudflare R2 (file storage)The icons and banners uploaded for app templates, including those still in review. They are served from Cloudflare’s content delivery network, so anyone who has an image’s address can open it. The address contains a long random identifier, and until a template is approved we show it only to the account that uploaded it and to administrators. An image from a rejected or replaced submission stays at its address until we delete it (section 8), and the network may keep a copy for up to a day after that. We have not restricted where Cloudflare keeps the files, so they may be stored outside the EEA
Intuition Machines (hCaptcha)Only when the demo challenge is enabled: the challenge token and your IP address, plus what their script collects in your browser
Spicy Lyrics APIWhen you run a request from the playground, the request is forwarded to our own API together with your IP address, user-agent, language and referrer headers. Your session cookie is stripped and never leaves this site

The United States has an adequacy decision, the EU-US Data Privacy Framework, but it reaches only providers certified under it. Where a provider is certified, the transfer rests on that decision. Where it is not, the transfer rests on the European Commission Standard Contractual Clauses in that provider’s data processing agreement, under Art 46(2)(c).

Ask us at [email protected] which of the two covers a given provider and we will tell you and send you the clauses. Certification lapses and is renewed, and we would rather answer with today’s position than print a list here that quietly goes stale.

The Framework is under challenge. The General Court upheld it in September 2025 and an appeal is pending before the Court of Justice. If it is annulled or withdrawn, every transfer above falls back to the Standard Contractual Clauses, and this page will say so.

We also disclose data where the law requires it. We do not sell personal data and we run no advertising or analytics on this site at all.

6.Contributor details in API responses

When the API answers with a community sync, the response names the people who made it: a Discord user id, a username, an avatar URL and a link to their Spicy Lyrics profile, for the uploader and where applicable the maker. This is deliberate — the credit is the point — and it means every developer using the API receives those details.

A developer who receives them is a separate controller for what they then do. The Terms allow them to use those fields for attribution only. Contributors can withdraw a sync at any time; we stop distributing it, and cached copies expire within 30 days under the Terms.

If you are a contributor, your relationship is with the Spicy Lyrics service you uploaded through, and its own policy governs it. You can still reach us at [email protected].

7.Cookies and local storage

NameWhat it doesHow long
Clerk session cookiesKeep you signed in. Set on the documentation pages too, because the same middleware runs thereSession, per Clerk
sl_demoLets the signed-out playground work. Contains the hashed IP from section 4. HttpOnly, SameSite=Lax1 hour
hCaptcha, only while the demo challenge is onTheir script stores and reads its own data on your device to run and score the challenge. While the challenge is off, no script loads and nothing is stored. See section 4Per their policy
theme (local storage)Remembers light or dark, when you pick oneUntil you clear it
Documentation UI state (local storage)Remembers a dismissed banner and which code tab you choseUntil you clear it

There is no cookie banner, because there is nothing here to consent to. Section 109(8) of the Slovak Electronic Communications Act (No. 452/2021 Coll.) requires consent before anything is stored on or read from your device, unless it is strictly necessary to provide a service you explicitly asked for. The session, demo and challenge entries are strictly necessary in that sense. The two local-storage entries hold display choices you made yourself, which the EDPB treats as covered by the same exemption, and nothing is written until you make one. The rule applies to local storage exactly as it does to cookies, which is why both are listed above.

We run no analytics, no advertising and no tracking cookies. If that ever changes, this page changes first and a consent request comes with it.

8.How long we keep it

  • Hourly usage counters: 35 days, then rolled up into daily totals, which are kept for 13 months.
  • Demo IP hashes: roughly twice the demo rate-limit window, which is about 20 minutes at current settings.
  • Account, applications and keys: for as long as you have an account. Deleting an application marks it deleted and keeps the row, so that a key that was once live cannot be silently re-issued and so usage history stays coherent. Requests for information about an application, and your answers, are kept with it.
  • Audit log: five years from the entry. It exists to explain an administrative decision after the fact — why an account was suspended, and by whom — which it cannot do if it is pruned eagerly. Five years is the outside edge of the periods within which such a decision could still be disputed.
  • App templates: the text of every submission, and the decision on it, for as long as the template exists, so a decision can still be explained. Images are kept while a live template or a submission still in review uses them. Images from a rejected, withdrawn or replaced submission are deleted 90 days after the decision, and images uploaded but never submitted after about a day. The upload record goes with the image.

One honest caveat about every period above: the cleanups are driven by activity rather than a timer. Usage and demo data are swept when traffic arrives; expired audit entries are swept when the next audit entry is written; template images are swept at most once a day, when someone uploads an image. On a quiet installation, data can outlive its window until the relevant activity triggers the cleanup. Treat those periods as what we aim at, not a guarantee.

9.Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it to you in a portable form. Where we rely on legitimate interests, you can object and we will stop unless we have compelling grounds not to.

Email [email protected]. We answer within one month. There is no charge.

You can also complain to the Slovak supervisory authority: Úrad na ochranu osobných údajov Slovenskej republiky, Galvaniho 7/B, 821 04 Bratislava, dataprotection.gov.sk. You can complain to the authority in your own country instead.

10.Deleting your account

Two things worth knowing before you try:

  • Deleting your account with Clerk does not reach us. Our records are not linked back to Clerk, so nothing here is removed automatically. Email us as well.
  • We erase by hand, within the one-month deadline. We will remove your account record, your applications and your keys. Audit entries covering administrative decisions may be kept or redacted rather than deleted, where we still need them to establish or defend a legal claim.
  • An app template you submitted is not deleted if people have added it, because that would refuse all of their keys. We unlink it from your account instead, so nothing connects it to you, and retire it if you ask. Its images and text stay published under the licence in section 12 of the Terms until it is retired.

Aggregated usage counters are not linked to you once the application is gone, and age out on the schedule in section 8.

11.Automated decisions

Rate limiting is automatic, and a refusal is not a decision with legal or similarly significant effects on you. Suspensions, account restrictions and every decision on an app template are made by a person, not by a model or a rule. We do no profiling.

12.Children

The platform is not for anyone under 16. If you believe a child has created an account, tell us and we will remove it.

13.Changes to this policy

If we change what we collect or why, we update this page and change the date at the top. The new version takes effect immediately when we publish it here. There is no notice period, and the version on this page under that date is the one in force. For a significant change we will say so on the platform rather than leave you to notice, but that announcement is not a condition of the change taking effect.

A change applies to processing from publication onwards, not retroactively to what we already did. Two things are outside that: where we rely on your consent, a new purpose needs a new consent before we act on it, and a change does not shorten the notice or the rights that data protection law gives you in its own terms.

14.Contact

[email protected]. The Terms of Service cover what you may do with the API.