Terms of Service

Use the API for your own app. Credit the people who made the syncs. Do not turn it into a source other people can call.

Last updated

1.Who we are, and what this covers

The Spicy Lyrics Developer Platform is operated by Spicy Lyrics (“we”, “us”). You can reach us at [email protected].

These Terms cover the developer platform at developers.spicylyrics.org and the API at api.spicylyrics.org — the account, the applications, the keys, the documentation, and every request you make with a key.

They do not cover the other Spicy Lyrics services. The Spicetify extension, the Discord bot and the web client each have their own terms, and nothing here changes them.

2.Eligibility

You must be at least 16 years old to hold an account. If you are using the API on behalf of an organisation, you confirm you are allowed to accept these Terms for it.

3.Your account and your keys

  • One account per person. Extra accounts to get around a limit are a breach of these Terms.
  • Secret keys (sl_sk_) belong on a server you control. Never ship one in a browser, an extension, or any client you hand to users. Use a publishable key (sl_pk_) for that.
  • You are responsible for every request made with your keys, including requests made by someone who got a key through you.
  • Do not share a key. If you publish source code that calls this API, each person who runs their own copy of it on a server needs their own key.
  • If your app runs on other people’s devices and each of them needs a key, submit it as an app template (section 12) rather than asking them to create applications of their own. The people who use your app do not need to be developers.
  • An origin allowlist is abuse deterrence, not authentication. It stops someone using your key on their own site; it does not stop someone using it from curl. Do not lean on it as a security boundary.
  • Some origins cannot be allowlisted, because they are shared by every user of a host application rather than by your application alone. The dashboard refuses those.
  • Tell us at [email protected] if a key leaks. You can revoke and rotate keys yourself at any time.
  • Every response is marked in a way that identifies the key that fetched it. The marks are not visible to your users. If sync data turns up somewhere it should not be, they let us tell which key it came through, including a key you have since revoked or rotated.

4.What you may build

Build your own thing with it: an app, a website, a player, a browser extension, a bot. Running your own server that calls the API and serves the result to your own users is expected and fine — that is what a secret key is for.

The line is who is at the far end, and what reaches them. Showing lyrics to the users of your application is use. Serving them to other developers, or to anyone who turns up with a request, is redistribution. So is handing your own users the data itself to take away. Section 5 covers both.

5.What you may not do

These are the restrictions we impose on use of the service.

  • Do not redistribute sync data as a public or third-party-accessible source. You may not re-expose what the API returns as your own API, a shared endpoint, a dataset, a dump, or any service other people can call — whether or not you charge for it, and whether or not you call it yours. This is not a preference of ours. It is a condition the people who upload community syncs attach to their work.
  • Do not build a downloader. You may not offer anything whose purpose is to give people lyrics or sync data to keep: a page, bot command, extension or tool where someone enters a track ID or link and gets back the raw response, or a file in LRC, SRT, TTML, JSON or any other format, converted or not. That is redistribution even when the only people using it are your own users. Data that leaves your application this way is out of reach of the 30-day cap in section 7, usually loses the attribution in section 6, and stays in circulation after a contributor withdraws it. Caching inside your application under section 7 stays allowed, including so a player works offline, and so does a user selecting lyrics on screen. The test is whether the data stays in your application and is shown there, or is handed out as something a person can save and pass on.
  • Do not bulk download, scrape or systematically extract a substantial part of the sync catalogue, and do not repeatedly extract insubstantial parts to the same effect.
  • Do not work around rate limits, key scopes, origin allowlists or a suspension, and do not use the signed-out demo as a substitute for a key.
  • Do not remove, obscure or alter attribution (section 6), and do not present community syncs as your own work.
  • Do not remove, alter or work around the marks described in section 3, including by combining responses fetched with different keys.
  • Do not use the Spicy Lyrics name, logo or branding in the name, domain, icon or store listing of your application, or in any way that suggests it is made, endorsed or supported by Spicy Lyrics. If your application is a fork or port of a Spicy Lyrics project, say plainly that it is unofficial. Saying that your application uses or is built on Spicy Lyrics is fine, and section 6 requires you to credit the source.
  • Do not use the service to break the law, to infringe the rights of others, or to attack the service or the people using it.

6.Attribution

Displaying attribution is a condition of using this API, not a courtesy. What you display depends on the source field of each response, so it cannot be hardcoded.

  • Always name the provider that answered.
  • When source is spicy_lyrics, the response is a community sync. Credit and link the uploader, and the maker where one is given. Use the url on each contributor as the link target.
  • Where a response does not identify its source, say the source is unknown rather than attributing it to anyone.
  • Attribution goes wherever the lyrics are. If lyrics are on screen, the attribution for that response is on screen too — not on an about page, not in a tooltip nobody opens. It can be small and quiet. It cannot be absent.

The attribution documentation shows what this looks like per source, and is part of these Terms.

7.Caching and storage

You may cache and store responses for your own application. You do not need to hit the API for every view, and we would rather you did not.

Anything you store must be refetched or discarded within 30 days. That cap is the whole mechanism by which a withdrawal takes effect. Contributors can pull a sync at any time, and we do not send removal notices. A stale copy you keep past 30 days is one we have no way to retract, which is why the cap is hard rather than a suggestion.

Building a persistent mirror or archive of the catalogue is not caching, and section 5 prohibits it.

8.Rights in what the API returns

One response can carry several different things, owned by several different people. They are not all the same.

  • The lyrics themselves. We claim no rights in the words of any song. They belong to their rights holders, and nothing in these Terms grants you any licence to them.
  • Community syncs. The timing and formatting data in a community sync is the work of the contributor who made it, and stays theirs. They license it to us with the right to sublicense it to you through this API. On that basis we grant you a limited, revocable, non-exclusive, non-transferable licence to use community sync data in your application, conditional on sections 5, 6 and 7. Break one of those and the licence ends.
  • The catalogue as a whole. Where a database right subsists in the collection of syncs made available through this API, we reserve it. We will not overstate it: that right protects investment in collecting, verifying and presenting a database rather than investment in creating its contents, and the syncs are made by contributors. The restrictions in section 5 bind you as a matter of contract, which does not depend on it.
  • Content from third-party sources. Responses may include lyrics text, songwriter credits, translations and romanizations that come from third parties. We grant you no rights in that content, make no representation about your use of it, and may stop returning it at any time.

9.Availability, limits and changes

The service is free, and carries no uptime commitment, no service level and no support commitment. It can be slow, wrong, or down.

Rate limits and the number of applications per account are set by us and can change at any time, including for your account specifically. The limits in force for your applications are shown in the dashboard.

We announce breaking changes to the API in the documentation before they take effect, where we reasonably can. That is how we work rather than a notice period you can hold us to.

10.Suspension and termination

You can stop at any time: pause an application, revoke its keys, or delete it from the dashboard.

We can revoke a key, disable client access, suspend an application, or suspend an account, if we reasonably believe these Terms have been breached, if the traffic is harming the service, or if we are required to.

If we have specific reasons to think an application may be breaching these Terms, we can ask you about it before deciding anything. The request appears at the top of your dashboard and on the application, and says what concerns us and what we want to know: what the application does, how it uses the data, or for access to it. You have 14 days to answer there. Until then the application keeps working, but you cannot delete it while the request is open.

Your answer stops the clock, and a person reads it. If it settles the concern, we close the request. If it does not, we may suspend the application under this section, and an answer that does not hold up counts among the facts we rely on. If no answer arrives within 14 days, the application is suspended when that period ends. The person who sends the request decides that when they send it, and the notice says the suspension took effect at the deadline. You can still answer after that, on the application, and a person decides whether your answer lifts the suspension. We can withdraw a request sent by mistake, and lift a suspension at any time.

If your account is suspended while a request is open, its clock stops, because you cannot answer then, and the time it had left is restored when the account is lifted.

While an application is suspended, you cannot change anything on it: not its keys, its settings or its allowed origins, and you cannot pause, resume or delete it. While your account is suspended, the same is true of everything on it, and you cannot create or add an application or submit a template, whatever your application limit is. The one exception is on an application suspended because a request went unanswered: you can still answer that request late, as described above, as long as your account is not suspended too.

A mark (section 3) traced to one of your keys is evidence a person weighs, not an automatic finding. A publishable key is used from your users’ browsers, so anyone using your application can pull data through it: a mark from one shows the data passed through your application, and we take that into account before deciding you are responsible for where it went. A mark from a secret key points at your own server, or at a leak of that key, which section 3 asks you to report.

When we suspend an application or an account, we tell you in the dashboard. The notice appears on each application it affects, and on your list of applications when it is your account, and it stays there for as long as the suspension is in force. We do not send it by email, so if your keys start being refused, the dashboard is where to look. Copy or save the notice if you want to keep it.

The notice tells you all of it: what we did and how far it reaches, that it lasts until we lift it, the clause of these Terms or the provision of law we relied on and why we think it covers what you did, the facts we went on, and whether someone else reported you. Suspensions are decided by a person, never by an automated assessment of what you did. The only one that takes effect without a person acting on the day is the one that follows an unanswered request, and its notice says so.

A key we disable, or client access we turn off, shows as such in the dashboard and in the API’s error for that key, without a notice of its own. We do that for a leaked key, or as a setting that is not about anything you did. When the reason is something you did, we suspend the application as well, so you get the notice above.

The same applies to an app template (section 12). We can suspend it, which refuses the keys of every application made from it, or retire it, which takes it out of the catalog. The notice is on the template’s page in the dashboard of the account that submitted it. People who added the app see on its page that it was suspended, and that this is not about anything they did.

If you think we have it wrong, write to [email protected] and a person will look at it again. You do not have to come to us first, or at all: you can go to a court, or to Rada pre mediálne služby, the Slovak Digital Services Coordinator.

In addition to, and without prejudice to, the grounds above, we may at our sole discretion terminate your account, or your access to the service or any part of it, without cause and without stating a reason. We give that notice in the dashboard, and termination on this basis takes effect 30 days after the notice first appears there. The notice identifies itself as given under this paragraph, and it is not a finding that you have breached these Terms.

Where serious grounds make it necessary, we may also suspend or block your access with immediate effect, whether or not those grounds amount to a breach of these Terms by you. Serious grounds include a genuine risk to the security, integrity or lawful operation of the service, to other users, or to us. A suspension on this basis is notified to you as described above.

When your access ends, so does the licence in section 8. The 30-day cap in section 7 still applies to anything you already stored, and then you stop serving it.

11.Reporting illegal content, and takedowns

[email protected] is our single point of contact for this — for users of the service and for authorities alike. Write to us in English or Slovak.

  • Rights holders, and anyone else. Tell us what the content is, where it is (the track id is enough, or for an app in the catalog, the address of its page), why you believe it is unlawful, how to reach you, and confirm that what you are telling us is accurate and complete as far as you know. We will look at it and act where the claim holds up.
  • Contributors. You can withdraw a sync you uploaded or made, at any time, with no deadline. We stop distributing it through the API. Copies developers have already cached expire under the 30-day cap in section 7.

What happens after you report something: we confirm we have it, without undue delay. Then we decide, and we write back telling you what we decided and why. That reply also says how to take it further if you disagree — a court, or Rada pre mediálne služby, the Slovak Digital Services Coordinator. A person makes these decisions; nothing here is decided by automated means.

12.App templates and the catalog

An app template registers an app you ship to other people, so that each of them can add it to their own account instead of creating an application for it. The catalog lists the templates we have approved.

If you add an app from the catalog. You get your own application, with the keys the template issues. Those keys are yours, and section 3 applies to them. The template sets the application’s rate limit, key types, allowed origins and scopes. When the template changes, your application changes with it, without notice. It does not count toward your application limit, you can hold one application per template, and it cannot be turned into an ordinary application. The app itself is made by another developer, not by us. We review its listing, not its code.

Submitting a template. Any account holder can submit one. We limit how many templates an account may have in review or live at once, and how many images it may upload in an hour. A person reviews every submission and every later change, and nothing about the decision is automated. The version already approved stays live until a change to it is approved. We refuse a submission or a change on one or more of these grounds:

  • The app does not need a key per person: it runs on its own server, or only a handful of people use it.
  • The app breaks the Terms, for example by redistributing sync data or working as a downloader.
  • The name, text or images use the Spicy Lyrics name or branding, or suggest the app is ours.
  • The description is misleading or incomplete, or the links do not lead to the app.
  • The submission includes text or images the submitter does not hold the rights to, or anything unlawful.
  • It duplicates a template that already exists for the same app.

When we approve a template, we decide its rate limit, which key types it issues, its origins and scopes, its category and whether it is listed. We may correct its text or remove an image before publishing it. If we do, we tell you what we changed and why.

What we tell you. When we refuse a submission, change what you sent, suspend a template or retire it, the notice is on the template’s page in your dashboard. It says what we decided, which ground or clause we relied on, the facts, and whether someone reported it. If you think we have it wrong, write to [email protected] and a person will look at it again. You can also go to a court, or to Rada pre mediálne služby, the Slovak Digital Services Coordinator.

The catalog. It is public. It shows each approved template’s name, descriptions, icon, banner, category and links. It does not show which account submitted it. Templates are grouped by category in an order we set, and are alphabetical within each category. Nobody pays for a place in it, and there are no featured positions. An unlisted template is left out of the catalog and can only be reached through its link.

The licence you give us. You keep every right in the text and images you submit. You grant us a non-exclusive, worldwide licence, free of charge, to reproduce them and make them available to the public in the catalog, on the template’s pages and in the dashboards of the people who added the app. It also lets us adapt them, but only by resizing, cropping and converting images to another format, and by the corrections described above. We may let the providers who host the service for us exercise it on our behalf. It lasts while the template is published and for 90 days after it is retired, or after the submission is rejected or replaced. You confirm that you hold the rights to grant it, that nothing you submit is unlawful, and that none of it uses the Spicy Lyrics name or branding in the ways section 5 prohibits.

Your app, and the people who add it. You remain responsible for your app. If the app itself breaks these Terms, for example by working as a downloader, we treat that as your breach and not as a breach by the people who added it. A mark (section 3) traced to one of their keys points at your app first. We may suspend the template, which refuses the keys of every application made from it until we lift the suspension, or retire it. You see how many people added your app and how many requests it makes in total, never who they are.

Retiring. You can retire a template you submitted at any time. It leaves the catalog, nobody can add it again, and applications already made from it keep working. A retired template cannot be changed. Submit a new one instead.

13.No warranty, and limits on liability

The service is provided as is and as available, without warranties of any kind, to the fullest extent the law allows. We do not warrant that responses are accurate, complete, uninterrupted, or cleared for any particular use of yours.

We are not liable for indirect or consequential loss, lost profits, lost data, or losses arising from your use of content returned by the API. Nothing here excludes or limits liability that cannot lawfully be excluded or limited, including for death or personal injury caused by negligence, for fraud, and any mandatory rights you have as a consumer.

14.Changes to these Terms

We can change these Terms, and a change takes effect immediately when we publish it on this page. There is no notice period and no waiting period. The version shown here, under the date at the top, is the version in force from that moment, and it governs your use of the service from then on.

For a significant change we will say so on the platform rather than leave you to notice, but that announcement is not a condition of the change taking effect. Continuing to use the service after publication means you accept the new version. If you do not accept it, stop using the service and close your account.

A change applies going forward. It does not retroactively alter what either of us already did under an earlier version. Where the mandatory consumer law that applies to you requires advance notice of a change, or gives you a right to end the contract because of one, that law prevails over this section to the extent of the conflict.

15.Governing law

These Terms are governed by the law of the Slovak Republic, and the Slovak courts have jurisdiction.

If you are a consumer resident in the EU, this does not deprive you of the protection of the mandatory rules of your own country, and you can still bring proceedings in the courts there.

16.Contact

[email protected] for anything in this document. See the Privacy Policy for what we do with personal data.