Legal · Privacy
Privacy policy
Effective 12 July 2026 · applies to the embeddable.music web application, its API and content-delivery services, the docs.embeddable.music documentation site, and the embeddable.music Discord integration.
The short version. embeddable.music runs no analytics, shows no ads, and never sells or shares data for marketing. If you just view or share a preview page, the only personal data we handle is what any web server sees: your IP address in short-lived server logs, plus two small preference cookies stored in your own browser. If you choose to sign in with Discord or Spotify, we additionally store your basic account profile (username, email, avatar) and the OAuth tokens needed to power the features you asked for — and nothing more.
1.Who is responsible
embeddable.music is a small, independently operated service. It is not affiliated with Spotify, Apple, Google/YouTube, Deezer, Tidal, SoundCloud, or Discord. For anything privacy-related — questions, access requests, deletion requests — contact the maintainer (see section 11).
2.What the service is
You paste a link to a song, album, or artist (or search for one), and embeddable.music produces a shareable preview page with artwork, a short audio preview, and buttons that open the music in the recipient's own preferred streaming service. The same previews can be posted into Discord servers through the embeddable.music Discord integration. Signing in is optional and only needed for extra features (a personal dashboard, Discord server management, and Spotify "now playing" display).
3.Using the service without an account
If you browse or share preview pages without signing in, we process:
| Data | Where it lives | Why |
|---|---|---|
| IP address, request path, method, status, timing | Server request logs (standard access logging on our hosting platform) | Operating, securing, and debugging the service |
Preference cookies (preferred_music_providers, auto_redirect_settings) | Your own browser, first-party cookies, 365-day expiry | Remembering which streaming service you prefer and your auto-open setting |
| Theme choice and a first-visit marker | Your browser's localStorage / sessionStorage | Remembering light/dark mode; showing the redirect countdown only on your first visit |
| Aggregate cache statistics (how often a cached image or audio preview was served, and when last) | Our content-cache database | Deciding which cached content to keep; these counters are per asset, not per person, and cannot be tied to you |
We do not:
- run analytics, tracking pixels, or session recording of any kind;
- set any advertising or cross-site identifiers;
- build profiles of anonymous visitors, or use IP addresses for anything beyond ordinary server logs and abuse response;
- read or record which page or app you shared a preview link from.
Fonts. The main web application loads its typefaces from Google Fonts, and the documentation site loads its typefaces from Scalar's font service (fonts.scalar.com). Your browser requests those files directly, which — like any web request — exposes your IP address and browser user agent to Google and Scalar respectively. Neither request carries any account information from us.
4.If you sign in (optional)
You can sign in with Discord or Spotify via OAuth. Sign-in happens on the provider's own pages; we never see or store your password. When you sign in, we store:
- Your basic profile from the provider — provider user ID, username, email address, and avatar URL.
- OAuth access and refresh tokens for the provider(s) you connected. These let us act on your behalf for the features below, and are presented only to the provider that issued them.
- A session cookie (
em_session) — an HTTP-only, secure cookie valid for 7 days that keeps you signed in.
What connected providers are used for:
- Spotify (scopes: recently played, currently playing, top items, email, private profile): to show you your own now-playing and recently-played tracks in the app. We display this data to you; we do not maintain a listening log of our own from it. Track metadata encountered this way is cached anonymously under a generated ID so preview pages load fast — the cache records the track, not that you played it.
- Discord (scopes: identify, guilds): to show you which Discord servers you can manage and to power the server dashboard.
If you use the Discord integration in a server, we additionally store what is needed to manage those embeds: the Discord server (guild) ID, channel and message IDs of embeds created, per-server settings and playback history, your Discord account ID linked to your embeddable.music account, and — where a server admin has configured one — the Discord webhook used to post embeds.
5.Server logs and diagnostics
- Access logs (which include IP addresses) go to our hosting platform's log stream and are kept only as long as the platform retains them; we do not ship logs to any third-party analytics or logging vendor.
- Error and diagnostic records created when something breaks may include the IP address and browser user agent of the request that triggered the error, along with the error details, so we can reproduce and fix the problem.
- We use no third-party crash-reporting, error-tracking, or telemetry vendors. Internal performance traces, where enabled, stay within our own infrastructure.
6.Where your data goes (processors and third parties)
We share personal data only with the infrastructure providers that run the service, and only as needed to run it:
- Fly.io hosts the API, content cache, video renderer, and database (region: San Jose, California, USA). Fly's servers see standard request data to deliver the service — see Fly.io's privacy policy.
- Netlify hosts the web application and the documentation site — see Netlify's privacy policy.
- Cloud object storage (Cloudflare R2 / Amazon S3) may hold encrypted-in-transit database backups (see retention, section 8).
Music metadata, artwork, and audio previews are fetched from the streaming platforms and music databases we support — Spotify, Apple Music, YouTube / YouTube Music, Deezer, Tidal, SoundCloud, MusicBrainz, and Wikipedia/Wikidata. These lookups are made by our servers, not by your browser, so those providers do not see your IP address when you view a preview page. Your browser contacts a streaming provider only when you click through to open the music there (or have auto-open enabled), at which point that provider's own privacy policy governs; and it contacts Discord's CDN when the dashboard displays your Discord avatar or server icons.
We do not sell personal data, share it for advertising, or disclose it to anyone except the processors above or where the law requires.
The service is operated from the United States. If you use it from elsewhere, your data is processed in the US, which may have different data-protection laws than your jurisdiction. Connections to the service are encrypted with HTTPS (TLS); still, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7.Cookies summary
| Cookie | Type | Lifetime | Purpose |
|---|---|---|---|
preferred_music_providers | First-party, preference | 365 days | Your chosen streaming service(s) |
auto_redirect_settings | First-party, preference | 365 days | Whether/where preview pages auto-open |
em_session | First-party, essential (signed-in users only) | 7 days | Keeps you signed in; HTTP-only |
No third-party cookies are set. The documentation site sets no cookies; it uses localStorage only for reader-interface preferences such as color mode.
8.Retention and deletion
- Content caches (metadata, artwork, audio previews) expire on rolling TTLs — typically 24 hours for metadata and about 7 days for artwork and audio in the API cache — or are evicted when space is needed. This is licensed third-party content, not personal data.
- Sessions expire after 7 days; signing out ends the session immediately.
- Inactive Discord webhooks are deactivated on expiry and deleted after 90 days.
- Database backups are kept on a short rolling window (approximately 7 days).
- Account deletion: contact us (section 11) and we will delete your account and everything linked to it — profile, OAuth tokens, sessions, Discord account link, per-user usage and diagnostic records, and Discord embed records tied to your account. Revoking embeddable.music's access from your Spotify or Discord account settings invalidates our stored tokens on their side as well.
9.Legal bases and your rights
Where the GDPR, UK GDPR, or similar laws apply: we process anonymous-use data (server logs, caching) under legitimate interest in operating and securing the service; account and provider data under performance of the service you signed up for (consent given at the OAuth screen, withdrawable by disconnecting the provider or deleting your account). You have the right to access, correct, export, and delete the personal data we hold about you, and to object to processing — contact us (section 11). For data held by Spotify, Apple, Google, Deezer, Tidal, SoundCloud, or Discord themselves, exercise your rights with those services directly. You also have the right to lodge a complaint with your local data-protection authority. Under the CCPA: we do not sell or share personal information as those terms are defined there.
10.Children
embeddable.music is not directed at children, and we do not knowingly collect personal data from children under 13; if we learn that we have, we will delete it. Sign-in requires a Discord or Spotify account, each subject to that provider's own age requirements.
11.Contact
Email privacy@embeddable.music for any privacy question or request.
12.Changes to this policy
Changes take effect when published on this page, with the effective date updated above. Material changes — meaning changes in what the service actually does with data — will be called out in release notes or in-app.
> made with 💖 by cmdly