Privacy Policy
Last updated: September 9, 2026
setlist.id is operated by Skylight Studio LLC, which is the data controller for the information described here. Questions, or any request below, go to play@setlist.id. We answer them ourselves; there is no ticket queue to get lost in.
Skylight Studio LLC25 SE 2nd Ave Ste 550 #3123
Miami, FL 33131
United States
What We Collect, and Why
- Your account: email address and a hashed password. Needed to give you an account at all, so we process it to perform our contract with you.
- If you sign in with Google or Microsoft:we receive your email address, your name and profile picture, and the account identifier that provider uses for you. We store the email address and the identifier, so that signing in again reaches the same account; we do not store the name or the picture, and we ask for nothing else — no access to your contacts, files or mail. You can disconnect a provider at any time from your account page, and if it is the only way into your account we will ask you to set a password first. Needed to sign you in, so we process it to perform our contract with you.
- Your use of the service: the links you submit, whether each one could be priced and what it was quoted, the tracklists we identify, your set allowance and usage, and any share links you create. Same basis: it is the service.
- Billing: your plan, trial status, renewal date and the history of sets bought, spent and refunded. Card details are handled by Stripe and never reach us. Same basis.
- API tokens,if you create one to reach setlist.id from another tool. We store a hash of the token, never the token itself — which is why we can only show it to you once, and why a lost token has to be replaced rather than recovered.
- Anything you write to us: feedback submitted through the site, and email you send us. The feedback form asks for your name and email so we can reply.
- Analytics: how the site is used, described below. We rely on our legitimate interest in understanding and improving the product.
Your Mixes and the Audio
When you submit a link, our server fetches the audio from wherever it is hosted — so that platform sees a request from us, not from you, and whatever it logs about that request is governed by its own privacy policy. The audio is written to temporary storage on our server, fingerprinted, and then deleted. Nothing keeps it: it is removed as soon as the mix finishes, and a cleanup job sweeps anything older than an hour regardless of how the run ended.
The fingerprints — short numeric summaries of the audio, from which the audio cannot be reconstructed — are sent to ACRCloud to identify tracks. What we keep afterwards is the link you submitted, the title and length of the mix, and the tracklist we found.
A tracklist is private to your account until you create a share link for it. A share link is then public to anyone holding the URL: we do not list it anywhere or put it in our sitemap, but we also do not block search engines from it, so treat posting one publicly as publishing it. You can revoke a share link at any time, and deleting your account revokes every one you made.
Analytics and Session Recording
We use PostHog. What it does depends on where you are.
In the EU, EEA, UK and Switzerland: PostHog runs in cookieless mode. It stores nothing whatsoever on your device, and your activity is never linked to your account, even when you are signed in. Session recording is off, and our servers send no analytics about your purchases or your mixes. Because nothing is stored on your device without you asking for it - see Embedded Players below for the one thing that is, and when - there is no cookie banner to show you.
Everywhere else: PostHog sets cookies, and once you sign in your activity is linked to your account. It collects pages viewed, clicks, your browser and device, an approximate location from your IP address, referrer, performance data and errors, and records a replay of your session. What you type into form fields, passwords included, is masked; other content on screen is not.
We do not use any of this for advertising, and we do not sell your data.
Embedded Players
Where you can play a mix on setlist.id, it plays in the hosting platform's own embedded player - YouTube, SoundCloud, Mixcloud and the others we support. The audio is streamed to you by that platform, never by us. That means the platform sees your IP address and can tell that a player was loaded on a setlist.id page, under its own privacy policy rather than this one.
For the YouTube player we use YouTube API Services. Information collected through it is handled under the Google Privacy Policy, and using setlist.id also means agreeing to the YouTube Terms of Service. You can review and revoke setlist.id's access to your data through the Google security settings page. We load that player from youtube-nocookie.com, YouTube's privacy-enhanced host, so it stores nothing on your device unless and until you actually start playback.
Cookies
- One to keep you signed in. Required for the service to work.
- One, kept a year, recording only that an account exists on this browser so returning visitors land in the app rather than the marketing site. It does not identify you and is cleared when you delete your account.
- PostHog's analytics cookies, which as above are not set at all in the EU, EEA, UK or Switzerland.
- Cookies set by an embedded player once you press play on a mix. These are the platform's own, not ours, and we cannot read them. Nothing is stored by the YouTube player before you press play.
Who Processes Your Data
- ACRCloud: audio fingerprints derived from your mixes are sent to ACRCloud's automatic content recognition API to identify tracks, and may be processed under their own privacy policy. See acrcloud.com.
- Stripe: payments and card details.
- Google and Microsoft, but only if you choose to sign in with them. Data travels the other way here: they tell us the email address and account identifier described above, under their own privacy policies. We send them nothing about how you use setlist.id.
- PostHog: analytics and session recording.
- Postmark: your email address, to send sign-in, verification and password-reset email.
- Vercel (site hosting), Hetzner (our servers and database) and Cloudflare (DNS and SSL).
- Whichever platform hosts the mix you submit— SoundCloud, YouTube, Mixcloud and the like. They are not our processors and we have no agreement with them; our server simply requests the audio, the same way any listener's browser would. The same platforms see your browser directly when you play a mix in their embedded player, including Googlefor YouTube playback — see Embedded Players above.
Where Your Data Goes
Our servers and our analytics are in the United States, so using setlist.id from elsewhere means your data is transferred there. For visitors in the EU, EEA and UK, those transfers are covered by the standard contractual clauses in our providers' data processing agreements.
How Long We Keep It
- Downloaded audio: minutes, and never more than an hour.
- Your account, mixes, tracklists and submitted links: while your account exists, and in the reduced form described below after you delete it.
- Billing records: seven years after the transaction, because tax and accounting law requires us to keep them.
- Session recordings: 30 days.
- Analytics events: up to 7 years.
What Happens When You Delete Your Account
Deleting your account cancels any subscription and immediately makes the account unusable: every session is ended, every share link you made stops working, any API tokens are destroyed, and any Google, Microsoft, Spotify or Tidal connection is unlinked. Your email address, your password and your Stripe customer record are erased. No one can sign in as you afterwards, including us.
What we keep is the activity itself, detached from your identity: the mixes and tracklists, the links you submitted and what they were quoted, and the record of sets bought, spent and refunded. These rows stay attached to a random identifier that is no longer connected to any email address or name. We keep them because they are our billing and accounting trail, and because how the service actually gets used is what we improve it from.
We would rather be exact than flattering about this: that is pseudonymisation, not anonymisation. A link you submitted is text you chose, and a link to your own upload can name you. So if you want the retained records gone too, say so when you delete or email us afterwards and we will erase them, apart from the billing entries the law requires us to keep. We would rather do that than let you believe deletion had already done it.
Analytics already collected is separate and is not purged automatically. Email us and we will delete it.
Security
Passwords are stored only as bcrypt hashes and API tokens only as SHA-256 hashes, so neither can be read back out of our database — not by an attacker, and not by us. Third-party connection tokens are encrypted at rest. Traffic runs over HTTPS throughout. If we ever suffer a breach that puts your data at risk, we will tell you and the relevant regulator, without waiting to be asked.
Your Rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider. Where we rely on your consent you can withdraw it at any time. Email play@setlist.id and we will action it, normally within a few days and always within a month. We will not charge you for it, and we will not ask why.
If you are in the EU, EEA or UK and you think we have got something wrong, you can also complain to your national data protection authority.
Changes
We may update this policy. Changes are posted here with a new date. If a change means we start doing something materially different with data we already hold, we will email you rather than rely on you noticing the date.