Privacy Policy

Last updated 13 August 2026

DemocraTune has no accounts, so there is no name, email or password to lose. What it keeps is a nickname you pick, the songs you queue and the votes you cast — and all of it is deleted with the room, within 48 hours.

Who this covers

This policy covers the copy of DemocraTune running at democratune.timkolesnichenko.me. It is operated by Tim Kolesnichenko, who is the data controller for this instance.

DemocraTune is open source, and anyone is free to run their own copy. If you are using someone else's instance, this policy does not apply to it — that operator decides what their server does, and you should ask them.

What is stored

When you join a room, the app creates an anonymous identity for your browser. It is a random identifier and nothing more: it is not linked to a name, an email address, a phone number or a social account, because you never give us any.

Attached to that identifier, while a room is alive:

  • The nickname you type. You choose it, and other people in the room see it. It does not have to be your real name.
  • The songs you queue — title, artist, length and the YouTube video — and which room they went into.
  • The votes you cast, and the rating they add up to inside that room.
  • A timestamp saying you are still here, refreshed while the room page is open. This is what makes the skip threshold a share of the people actually present.
  • The room's play history, including how each song was voted on.

The app also keeps a catalogue of the songs themselves — title, artist, length, and links to the same recording on other streaming services. That catalogue is about music, not about people, and it carries no connection to who played what.

What is not stored

No account, no password, no email address, no phone number. No advertising or cross-site tracking cookies. Nothing is sold, rented or shared for marketing, by anyone, ever.

How long it is kept

Rooms expire 48 hours after they are created, and an automated job clears out expired ones every hour. When a room goes, everything attached to it goes with it: its queue, its history, its votes and its presence records.

You do not have to wait for that. A room host can end a room at any time, which deletes the same data immediately.

Analytics

DemocraTune uses PostHog to count things like how many rooms get created and which pages people open. It runs in cookieless mode, which means it sets no cookies and builds no persistent profile of you across visits. The data is processed on PostHog's EU infrastructure.

Other services involved

Running the app means handing some data to the companies underneath it. Each has its own privacy policy:

  • Vercel hosts the site and keeps ordinary server logs, which include IP addresses and request details.
  • Convex stores the room data described above.
  • YouTube and Google provide the embedded player that actually plays the music, and the search results behind the song picker. Watching a video in the embed is a visit to YouTube, and Google treats it as one.
  • song.link is asked which other services carry a given recording, so the history can link out to them. It is told the video, never anything about you.
  • PostHog, as described above.

Connecting Spotify

Exporting a room's history to a Spotify playlist is entirely optional, and it happens in your browser rather than on our server.

Signing in sends you to Spotify, and Spotify sends back an access token that stays in your browser tab. It is never transmitted to DemocraTune, so there is nothing on our side to leak or misuse. The token asks for permission to create and add to playlists — nothing else — and it is discarded when you close the tab. No long-lived refresh token is stored, so the connection cannot outlive your visit and give anyone standing access to your account.

Children

DemocraTune is not aimed at children and does not knowingly collect anything from them. Since it asks for no personal details at all, there is very little to collect either way.

Your choices

Leaving a room stops the presence timestamp. Not connecting Spotify means no Spotify data is ever involved. Waiting 48 hours, or asking the host to end the room, removes the rest.

If you want something removed sooner, or want to know what is held about a room you were in, get in touch and we will sort it out. Because the app has no accounts, we may not be able to work out which anonymous identifier was yours without your help.

If you are unhappy with how your personal data is handled, you can also complain to the UK Information Commissioner's Office through its complaints service.

Changes

If this policy changes, the date at the top changes with it. The full history of every version is in the project's public git repository, so you can see exactly what moved and when.

Contact

Privacy questions and data-protection requests can go to democratune@gmail.com. General questions can also go to an issue on the GitHub repository if you would rather ask in public.

See also the Terms of Service.

Privacy Policy | DemocraTune