Privacy Policy
Last updated: September 16, 2026
This Privacy Policy explains what information HearItFresh collects, why, and how it's handled when you use the app, including its integration with your YouTube account.
HearItFresh uses YouTube API Services. By connecting your YouTube account or using the app's YouTube features, you agree to be bound by the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
1. Overview
HearItFresh is a music recommendation tool that generates playlists based on lyrical similarity to songs you select as seeds. Optionally, you can connect your YouTube account so the app can create and manage a playlist directly on your behalf.
We do not run any analytics or tracking on this app. We do not sell or share your data with third parties, and we do not use your data for advertising.
2. Information We Collect
Google account profile
When you sign in with Google, we receive and store your Google user ID, display name, and profile image URL. We use these only to identify your account inside the app and to show you who you're signed in as. We do not request access to your email address.
Song and playlist data
You provide seed songs/artists used to generate recommendations. For signed-in users we store the seeds you chose, the resulting recommended tracks, and details of the playlists we created for you (name, link, and status), so you can see your generation history and resume or retry a generation that was interrupted.
YouTube account access (optional)
If you choose to connect your YouTube account, the app requests the following Google OAuth scope:
https://www.googleapis.com/auth/youtube
We request this scope solely to:
- Read the videos in a YouTube playlist you paste into the app, so they can be used as seeds for your recommendations
- Create a new playlist on your connected YouTube account
- Add videos to that playlist
- Remove videos from that playlist
- Read back the playlist's contents and details so we can display them in the app
Although this scope technically grants broader access to your YouTube account, we do not use it for anything beyond the actions listed above. We do not upload videos, manage subscriptions, post comments, or change any channel settings on your behalf.
3. Where Your Information Is Kept
Sign-in tokens
The tokens that keep you signed in are not stored in our database. Your refresh token is encrypted by our server, using a secret key that never leaves the server, before it is returned to your browser. Your browser holds that encrypted refresh token, plus a short-lived access token, in its local storage on your own device. Signing out removes them.
YouTube connection (signed-in users)
When you connect YouTube while signed in, we store your YouTube OAuth access token and refresh token in our database, together with the token's expiry time and the scope you granted. Both tokens are encrypted before they are written. We keep them so your connection persists between visits, and delete them when you disconnect YouTube, when Google reports them as revoked or expired, or when your account is deleted.
YouTube connection (guest users)
When you connect YouTube as a guest, your YouTube tokens are not stored on our servers. They are held in your browser's session storage for the current tab only, with the refresh token encrypted, and are sent to our servers only for the duration of a request that needs them, such as reading or building a playlist. They are removed when you close the tab or disconnect YouTube.
Account and playlist data
For signed-in users, the profile, seed, and playlist data described in section 2 is stored in our managed database, which is encrypted at rest by the hosting provider.
Guest users
If you use the app without signing into an account, we do not create an account record for you.
Storage on your device
HearItFresh does not use cookies to track you. It uses your browser's local storage and session storage only to keep you signed in, remember whether you chose guest mode, hold a guest YouTube connection, and resume a playlist generation that was interrupted. Clearing the app's site data removes all of it.
4. How We Protect Your Data
We treat your Google OAuth credentials as sensitive data and apply the following protections:
- Encryption in transit. All traffic between your browser, our servers, and Google's APIs is served over HTTPS using TLS 1.2 or higher.
- Encryption of OAuth tokens. YouTube tokens stored in our database are encrypted with AES before they are written, and refresh tokens returned to your browser are encrypted before they leave our server. The encryption key is held only in our server-side configuration; it is never sent to your device and never committed to our source code.
- Encryption at rest. Our database is a managed instance with provider-managed encryption at rest, and our application secrets are held in our hosting provider's encrypted secret store.
- Data minimisation. We request a single YouTube scope, used only for the playlist actions listed in section 2. We store YouTube tokens only for signed-in users who choose to connect, and never store tokens for guests.
- Short credential lifetime. Google access tokens are short-lived (approximately one hour) and expire on their own. Once you revoke access, any token we hold stops working immediately, and the app discards a token that Google reports as revoked or invalid.
- Access control. Access to the production database, hosting environment, and secrets is restricted to authorised administrator accounts protected by two-factor authentication. No third party, contractor, or advertiser is granted access.
No system can be guaranteed completely secure. If we become aware of a breach affecting your personal data or your Google user data, we will revoke the affected credentials and post a notice in the app and on this page without undue delay.
5. Google User Data and Limited Use
HearItFresh's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not transfer Google user data to third parties except as necessary to provide or improve the playlist feature, to comply with applicable law, or as part of a merger or acquisition; we do not use Google user data for advertising; we do not allow humans to read your Google user data unless you give explicit consent, it is necessary for security purposes or to comply with applicable law, or the data has been aggregated and de-identified; and we do not use Google user data to develop, improve, or train generalised or non-personalised AI or machine learning models.
6. What We Don't Do
- We do not run analytics, ad tracking, or third-party tracking scripts of any kind
- We do not sell, rent, or share your personal data with third parties
- We do not allow third parties to serve content or advertisements in the app
- We do not use your YouTube data to train any models
- We do not access or store any YouTube account data beyond what's needed for playlist creation/management as described above
7. Revoking Access
You can remove HearItFresh's access at any time:
- Open Settings in the app and choose Disconnect YouTube. This revokes the app's YouTube access with Google and deletes any YouTube tokens we hold.
- Sign out, which clears the sign-in tokens held in your browser.
- Revoke access from the Google security settings page, which immediately invalidates every token issued to the app.
8. Data Retention and Deletion
Account, seed, and playlist history data is retained for as long as your account exists, so that your history remains available to you. YouTube tokens are retained only until you disconnect YouTube, Google reports them as revoked, or your account is deleted. To have your data removed, you can:
- Disconnect YouTube from Settings, which deletes your stored YouTube tokens, and/or
- Email us at dunsincodes@gmail.com to request deletion of your account and all associated data. We action these requests within 30 days.
9. Children's Privacy
This app is not directed at children under 13, and we do not knowingly collect data from children under 13.
10. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated "Last updated" date.
11. Contact
If you have questions about this policy or how your data is handled, contact us at: dunsincodes@gmail.com