Privacy Policy

Last updated: March 2026

What DeepCut is

DeepCut is a personal music analysis tool. It reads your listening history from connected streaming platforms and generates a narrative story about your life as told through your music. Nothing is sold. Nothing is shared. The service exists solely to give you insight into your own listening history.

Data we collect

Account information

When you register, we collect your email address and a hashed password. We do not collect your name, phone number, or any other identifying information unless you choose to provide a display name.

Music listening data

When you connect a streaming platform (Spotify, Tidal, Apple Music, etc.), we store:

  • Track plays — song title, artist, album, timestamp
  • Playlist names and their track listings
  • Liked or saved tracks and when you liked them
  • OAuth access and refresh tokens needed to fetch your data

If you upload a Spotify extended history export, we process that file and store the same fields listed above. Uploaded files are deleted from our servers after processing is complete.

Track metadata

We enrich your listening history with publicly available metadata from third-party services (Last.fm, Genius, MusicBrainz, Discogs, Deezer). This includes genre tags, lyrical themes, tempo, and similar attributes. This data is cached permanently so we do not re-fetch it on every analysis.

Analysis data

We store the results of analyses we run on your listening history — mood signals, life event inferences, segment summaries, and generated narrative text. This data belongs to you and is viewable from your account.

How we use your data

Your data is used exclusively to generate your personal listening narrative. Specifically:

  • To display your listening history and statistics in the app
  • To run analysis pipelines that infer mood, themes, and life signals from your music
  • To generate narrative text describing your listening journey

We do not use your data to train AI models, target you with advertising, or share it with any third party except as described below.

Third-party services

DeepCut integrates with several external services to function. When you connect a platform or when we enrich your track data, requests are made to these services:

  • Spotify — listening history, track metadata, playlist sync
  • Tidal — listening history, playlist sync, liked tracks
  • Last.fm — track tags, artist tags, play counts
  • Genius / LrcLib / Musixmatch — song lyrics
  • MusicBrainz / Discogs / Deezer — genre, style, and tempo data

Each service has its own privacy policy governing how they handle requests made to their APIs. We send only the minimum data required (track title, artist name) to perform lookups. We do not send your personal information, email address, or any account details to these services.

Narrative text is generated using the Claude API (Anthropic). Segment summaries and mood analysis use a locally-hosted language model and do not leave our infrastructure.

Data retention and deletion

Your data is retained for as long as your account is active. If you delete your account, all associated data — listening events, analysis results, connected platform tokens, and generated narratives — is permanently deleted. Cached track metadata (genre tags, lyrics, BPM) may be retained as it is not personally identifying and is shared across users.

To request account deletion, contact us at the address below.

Security

OAuth tokens are stored in our database and used server-side only. They are never sent to your browser. Passwords are stored as bcrypt hashes. All connections to this site use HTTPS.

Cookies and sessions

We use a single session cookie to keep you logged in. No tracking cookies. No advertising cookies. No third-party cookies are set by this site.

Contact

For questions about this policy or to request data deletion, contact the project maintainer:

Charles Collins
deepcut.tinyrobot.io