Privacy Policy
Last updated: September 24, 2026
At Symphony, we take your privacy seriously. This policy describes how we collect, use, and protect your personal information.
1. Information We Collect
1.1 Account Information
- Username - Required for identification
- Email Address - Required for account verification and notifications
- Password - Securely hashed using bcrypt
- Profile Image - Optional, uploaded by you
- Bio - Optional, provided by you
1.2 Activity Data
- Reviews and ratings you submit
- Playlists you create
- Songs you listen to (when connected to Spotify)
- Login timestamps
1.3 Third-Party Data
- Spotify ID - When you connect your Spotify account
- Spotify Access Tokens - For API integration (stored securely)
- Listening History - From Spotify (with your permission)
2. How We Use Your Data
- ✓ To provide and improve our services
- ✓ To personalize your music experience
- ✓ To display your reviews and activity to other users
- ✓ To send important account notifications
- ✓ To analyze usage patterns and improve the platform
3. Data Security
- ✓ End-to-end encryption for all data transmission
- ✓ bcrypt password hashing (salt factor 10)
- ✓ Secure token-based authentication for third-party services
- ✓ Regular security audits and updates
- ⚠ No plain-text passwords are ever stored
- ⚠ Access tokens are stored securely and can be revoked
4. Data Sharing
We do NOT sell your personal data to third parties. We only share data:
- With Spotify when you connect your account (via OAuth)
- With third-party services you explicitly authorize
- When required by law or legal process
- To protect the rights and safety of Symphony and its users
5. Your Rights
- Access - View all data we have about you
- Rectification - Update or correct your information
- Deletion - Delete your account and all associated data
- Withdraw Consent - Disconnect third-party services
- Export Data - Request a copy of your data
6. Data Retention
- We retain your data as long as your account is active.
- When you delete your account, all associated data is permanently removed.
- Anonymized statistics may be kept for analytical purposes.
- Access tokens are revoked immediately upon disconnection.
7. Children's Privacy
- Symphony is not intended for children under 13 years old.
- We do not knowingly collect data from children under 13.
- If you believe we have collected data from a child, please contact us.
8. Cookies
- We use session cookies to keep you logged in.
- We use remember me tokens if you opt-in.
- Third-party cookies may be used by integrated services.
- You can disable cookies in your browser settings.
9. Third-Party Services
- Spotify - For music integration and listening history
- We only store what is necessary for the platform to function.
- Please review each service's privacy policy for more information.
10. International Data Transfers
- Your data is stored on servers located in the United States.
- By using Symphony, you consent to this data transfer.
- We comply with GDPR and CCPA regulations.
11. Changes to This Policy
- We may update this policy periodically.
- Significant changes will be communicated via email.
- Continued use constitutes acceptance of the updated policy.
12. Data Breach Protocol
- We have security protocols in place to detect and respond to breaches.
- If a breach occurs, we will notify affected users within 72 hours.
- All passwords are hashed, minimizing risk in case of a breach.
- We conduct regular security audits and penetration testing.
© 2026 Symphony. All rights reserved.