Privacy Policy

Last updated: February 13, 2026

Welcome to Sonusly ("Sonusly," "we," "us," or "our"). Sonusly is an independent platform created by music enthusiasts for discovering, discussing, and sharing songs. This Privacy Policy explains how we collect, use, and protect your personal information when you use our website and services (collectively, the "Services").

This Privacy Policy is incorporated into and forms part of our Terms of Service.

Before using our Services, please review this Privacy Policy carefully. By using Sonusly, you agree to the practices described in this Privacy Policy. If you do not agree to this Privacy Policy, please do not use the Services.

For deletion requests, please contact us at contact@sonusly.com. See Section 4 for additional information regarding changes to accounts and deletion of personal information.

For California residents, please see Section 5 for additional disclosures under the California Consumer Privacy Act (CCPA).

1. Personal Information We Collect

We collect information that alone or in combination with other information in our possession could be used to identify you ("Personal Information").

personal information you provide

we may collect personal information when you create an account, use our features, or communicate with us:

account information

when you create a Sonusly account, we collect:

  • username (required, up to 15 characters)
  • email address (required, for authentication)
  • password (stored securely using bcrypt hashing via Supabase Auth)
  • about section (optional, up to 300 characters)
  • join date (automatically recorded)

content you create

we collect content you voluntarily create on Sonusly:

  • posts: song discussions you submit, including post titles and descriptions (up to 280 characters)
  • comments: comments you make on posts, including nested replies
  • votes: your upvotes on posts
  • saved posts: posts you bookmark
  • saved songs: songs you save to your collection

communication information

when you contact us, we may collect your name, email address, and the contents of any messages you send.

personal information we collect automatically

when you visit, use, and interact with Sonusly, we may receive certain information automatically ("technical information"):

log data

information your browser automatically sends, including:

  • internet protocol (IP) address
  • browser type and version
  • operating system
  • date and time of your request
  • pages visited and features used
  • referring website addresses

device information

  • device type (desktop, mobile, tablet)
  • screen resolution
  • browser settings

usage information

  • features you interact with
  • actions you take (voting, commenting, saving)
  • time spent on pages
  • navigation patterns

cookies

we use cookies to operate and administer Sonusly. a "cookie" is a small file stored on your device that helps us recognize you and remember your preferences.

types of cookies we use:

  • essential cookies: required for authentication and core functionality (e.g., keeping you logged in)
  • analytics cookies: help us understand how users interact with Sonusly to improve our services

for more information about cookies, visit All About Cookies.

your choices: most browsers allow you to control cookies through settings. you can check support pages for:

  • Google Chrome
  • Mozilla Firefox
  • Apple Safari
  • Microsoft Edge

please note that disabling cookies may limit your ability to use certain features.

do not track signals

our site currently does not respond to "do not track" (DNT) signals and operates as described in this privacy policy whether or not a DNT signal is received. if we respond to DNT signals in the future, we will update this privacy policy accordingly.

2. how we use personal information

we use personal information for the following purposes:

to provide and operate the services

  • create and maintain your account
  • authenticate you when you log in
  • enable you to post, comment, vote, save posts, and save songs
  • display music information from Spotify (song details, artist pages, album artwork)
  • display your posts, comments, and profile to other users
  • calculate and display your karma score

to improve the services

  • analyze how users interact with Sonusly
  • identify and fix bugs and technical issues
  • develop new features
  • understand user preferences and behavior patterns

to communicate with you

  • send essential account-related notifications
  • respond to your questions, feedback, and support requests
  • notify you of important service announcements

to ensure security and enforce policies

  • detect and prevent fraud, spam, abuse, and manipulation
  • enforce our terms of service and community guidelines
  • protect the rights and safety of Sonusly, our users, and the public
  • investigate potential violations

aggregated information

we may aggregate personal information and use the aggregated information to analyze the effectiveness of our services, improve features, and for other similar purposes. aggregated information does not identify you personally.

3. sharing and disclosure of personal information

public information

the following information is publicly visible to all Sonusly users:

  • your username
  • your "about" section (if provided)
  • your join date
  • your karma score
  • your posts and comments
  • your saved posts (visible on your profile)
  • your saved songs (visible on your profile)

important: your posts, comments, saved posts, saved songs, and profile information are intentionally public. this is core to how Sonusly works as a community platform.

information we do NOT share publicly

  • your email address
  • your IP address
  • your vote history (individual votes are private; only totals are shown)

service providers

we share personal information with third-party service providers who help us operate Sonusly:

providerpurposedata shared
Supabasedatabase hosting, authenticationaccount data, content, usage data
Spotifymusic data (song info, artist pages, album artwork)server-side API requests only (no user data shared)
Vercelwebsite hosting, deployment, analyticstechnical/log data, IP addresses, page views
Google Analyticsusage analytics and site performanceanonymized usage data, page views, device info

these providers process data pursuant to our instructions and are contractually obligated to protect your information.

Spotify

Sonusly uses the Spotify API server-side to fetch song information, artist details, album artwork, and discography data. we do not collect or store any user Spotify account data. no Spotify account is required to use Sonusly.

Spotify content displayed on Sonusly is subject to Spotify's privacy policy and terms of service.

legal requirements

we may disclose your personal information if required to do so by law or in the good faith belief that such action is necessary to:

  • comply with legal obligations or government requests
  • protect and defend our rights or property
  • prevent fraud or illegal activity
  • act in urgent circumstances to protect personal safety
  • protect against legal liability

business transfers

if Sonusly is involved in a merger, acquisition, or sale of assets, your personal information may be transferred as part of that transaction. we will notify you via email and/or prominent notice on our site of any change in ownership.

with your consent

we may disclose your personal information to third parties when you request it, direct us to do so, or provide consent.

4. your rights and choices

access and update your information

you can access and update your account information at any time through your profile settings:

  • change your username
  • update your "about" section

account deletion

you can request deletion of your account by contacting us at contact@sonusly.com.

upon deletion:

  • we will delete your personal information (email, about section)
  • your posts and comments will remain visible but will be anonymized (attributed to "[deleted]")
  • your votes will be removed
  • your saved posts and saved songs will be deleted

why we retain anonymized content: deleting your posts and comments would break discussion threads and remove context for other users' replies. this is standard practice for community platforms.

data export

you can request a copy of your personal information by contacting us at contact@sonusly.com. we will provide your data in a commonly used, machine-readable format within 30 days.

email communications

you can opt out of non-essential emails by contacting us. you cannot opt out of essential service-related communications (e.g., security alerts, terms of service updates) while maintaining an active account.

5. california privacy rights (CCPA)

if you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA).

your rights

you have the right to:

  • know what personal information we collect, use, and disclose
  • delete your personal information, subject to certain exceptions
  • correct inaccurate personal information
  • non-discrimination for exercising your privacy rights

categories of personal information collected

categoryexamplescollected
identifiersusername, email, IP addressyes
internet activitybrowsing history, interactions with Sonuslyyes
geolocationapproximate location from IP addressyes
audio/visualalbum artwork displayed (from Spotify)yes (third-party)
inferenceskarma score based on activityyes

sale or sharing of personal information

we do not sell your personal information. we do not share your personal information for cross-context behavioral advertising.

how to exercise your rights

to submit a request to know, delete, or correct your personal information:

  • email us at contact@sonusly.com

we will verify your identity by confirming your email address and/or account credentials. we will respond to verified requests within 45 days.

authorized agents

you may designate an authorized agent to submit requests on your behalf. the agent must provide written authorization, and we may require you to verify your identity directly.

6. data retention

we retain your personal information for as long as your account is active or as needed to provide you the services.

data typeretention period
account informationuntil account deletion
posts & commentsindefinitely (anonymized upon account deletion)
votesuntil account deletion
saved posts & songsuntil you remove them or delete account
log dataup to 90 days (varies by service provider)

after account deletion, we may retain certain information as required by law or for legitimate business purposes (e.g., preventing fraud, resolving disputes).

7. data security

we implement commercially reasonable technical, administrative, and organizational measures to protect your personal information:

  • encryption: data encrypted in transit (HTTPS/TLS)
  • password security: passwords hashed using bcrypt via Supabase Auth
  • access control: row level security (RLS) policies on all database tables
  • API security: Spotify API credentials kept server-side only
  • infrastructure: hosted on Supabase with enterprise-grade security

however, no internet transmission is ever fully secure or error-free. you are responsible for maintaining the confidentiality of your password and account. please notify us immediately at contact@sonusly.com (subject: security issue) if you believe your account has been compromised.

8. children's privacy

Sonusly is not directed to children under the age of 13. we do not knowingly collect personal information from children under 13. if you believe a child under 13 has provided us with personal information, please contact us at contact@sonusly.com (subject: privacy request), and we will delete that information.

9. international users and GDPR

data transfer

Sonusly is operated from and stores data in the United States via Supabase's infrastructure. by using our services, you understand and acknowledge that your personal information will be transferred to and processed in the United States, which may have different data protection laws than your country of residence.

European users (GDPR)

if you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):

legal basis for processing: we process your personal information based on:

  • contract: to provide the services you requested (account creation, features)
  • legitimate interests: to improve our services, ensure security, and prevent fraud

your GDPR rights:

  • right of access: request a copy of your personal information
  • right to rectification: request correction of inaccurate data
  • right to erasure: request deletion of your personal information ("right to be forgotten")
  • right to restriction: request we limit processing of your data
  • right to data portability: receive your data in a machine-readable format
  • right to object: object to processing based on legitimate interests
  • right to withdraw consent: withdraw consent at any time for consent-based processing

how to exercise your rights: contact us at contact@sonusly.com with the subject line "GDPR request". we will respond within 30 days.

supervisory authority: if you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.

10. third-party links and services

Sonusly contains links to third-party websites and integrates with third-party services (primarily Spotify). we do not control these third parties and are not responsible for their privacy practices. we encourage you to review the privacy policies of any third-party services you access through Sonusly.

  • Spotify privacy policy
  • Supabase privacy policy
  • Vercel privacy policy
  • Google privacy policy

11. changes to this privacy policy

we may update this privacy policy from time to time. when we make material changes:

  • we will post the updated version on this page
  • we will update the "last updated" date
  • for significant changes, we may notify you by email or prominent notice on Sonusly

your continued use of the services after changes become effective constitutes acceptance of the revised privacy policy.

12. contact us

if you have questions about this privacy policy or our privacy practices, please contact us:

email: contact@sonusly.com

when contacting us, please use one of the following subjects to help us route your request:

  • subject: privacy request - for privacy-related questions or data requests
  • subject: security issue - for security concerns or vulnerabilities
  • subject: DMCA notice - for copyright/DMCA matters
  • subject: legal - for legal inquiries
  • subject: general - for all other inquiries

Sonusly is an independent platform created by music enthusiasts. we are not affiliated with, endorsed by, or connected to Spotify AB, any record labels, music publishers, or artists. "Spotify" is a trademark of Spotify AB.