This policy explains what data DiggFinder collects, why we collect it, and what you can do about it. We aim for the smallest possible footprint — if we don't need it to make the app work, we don't store it.
What we collect
- Spotify profile data: your Spotify user ID, display name, followed artists, saved tracks, playlists, and top tracks — only what you grant via OAuth scopes.
- OAuth tokens: access and refresh tokens stored server-side so we can talk to Spotify on your behalf. Never exposed to the browser.
- App content: crates, comments, reactions, follows, and digest subscriptions you create.
- Email address: only if you opt into the weekly digest. Stored to send digests and honor unsubscribe requests.
- Cached metadata: BPM, key, genre, year, label, and sample lineage from third-party providers, cached against track URIs (not against you personally).
What we don't collect
- We don't sell your data to anyone.
- We don't use third-party advertising trackers.
- We don't read or store your Spotify password.
Cookies
We set a single first-party session cookie linking your browser to your Spotify session on our server. No third-party advertising cookies.
Third-party services
DiggFinder fetches data from Spotify, Discogs, Last.fm, GetSongBPM, MusicBrainz, and WhoSampled. When you click outbound links (e.g. to Spotify or Discogs) those providers' privacy policies apply.
Transactional emails (digest, notifications) include a one-click unsubscribe link. We honor unsubscribes immediately and maintain a suppression list so you don't receive further mail.
Data retention & deletion
Your data lives in our database for as long as your account is active. To delete everything, email hello@diggfinder.com from the address tied to your account and we'll wipe your session, crates, comments, follows, and email subscriptions within 7 days. You can also disconnect DiggFinder from your Spotify account at any time, which immediately revokes our access.
Security
Data is stored on Supabase with row-level security and HTTPS-only transport. OAuth tokens are stored server-side and never sent to the browser.
Children
DiggFinder is not directed at children under 13.
Changes
We'll announce material changes to this policy on the site. Continued use after changes means you accept the new policy.
Contact
Privacy questions: hello@diggfinder.com.