plaiist
How it worksSign inStart free →

Privacy Policy

Effective date: 14 September 2026

1. Who we are

This policy explains what information plaiist collects when you use plaiist.com and the plaiist app, why, and what control you have over it.

2. What plaiist does, in one paragraph

plaiist is a chat assistant that builds and edits playlists in a music streaming account you connect — Tidal, Spotify, Apple Music, or YouTube Music. You describe what you want in plain language; plaiist searches the connected service's catalog and creates, renames, or edits playlists there. plaiist never plays or streams audio itself, and it never asks for your streaming service password — you connect through that service's own official sign-in.

3. Information we collect

Account information

When you sign up, we collect your email address and a password (handled by our authentication provider, Supabase — we never see your password in plain text). We keep a small profile record per account: how many free playlists you have left, which subscription state you're in, which connected service you're currently working in, and — if you signed up from someone's shared playlist link — which account invited you.

Payment information

If you subscribe, billing is handled entirely by Stripe. We never see or store your card number — we store only your Stripe customer ID, your subscription ID, and its status (active, cancelled, etc.), so the app can tell whether you have access.

Your connected streaming account

When you connect Tidal, Spotify, Apple Music, or YouTube Music, we store, on our servers only:

  • The access and refresh tokens (or, for Apple Music, the Music User Token) that let plaiist act on your behalf on that service.
  • Your account identity on that service (an internal user/channel ID and a display name — e.g. your YouTube channel name), so the app can show you which account is connected.
  • Your country or storefront, so catalog search returns results available to you.

These credentials are stored server-side and are never sent to your browser, never stored in your device's local storage, and are protected so that only plaiist's server — not even a signed-in user querying our database directly — can read them.

We never see or store your streaming service password. You authorize plaiist through that service's own official login screen.

Your chat messages and playlists

Every message you send plaiist, and every reply, is stored (so your conversation and playlist history carry over between visits). This includes the wording you use to describe a vibe or a playlist, and the track/playlist names plaiist finds or creates in response. We keep this until you clear your chat (Settings) or delete your account — there is currently no automatic expiry.

We also keep a small record of token usage per chat turn (how much the underlying AI model was used, and whether a playlist was created) for our own cost and reliability tracking. This record does not include the message content itself.

Public playlist shares

If you choose to share a playlist (a "Build free with plaiist" link), we create a public page containing a snapshot of that playlist — its title and the title/artist of each track — accessible to anyone with the link, no account required. This snapshot is separate from your live playlist: if you later edit or delete the original, or disconnect the service, the shared page still shows what you shared at the time. Deleting your plaiist account deletes these shared pages too.

Cookies and similar technology

plaiist uses only the session cookies set by our authentication provider (Supabase) to keep you signed in. We reviewed the code that ships to your browser and found no analytics, no advertising, and no tracking cookies or scripts of any kind — nothing from us profiles you or follows you across sites.

Information we do not collect

We don't collect device fingerprints, ad identifiers, or location data beyond the coarse "country/storefront" a streaming service reports. We don't buy or sell personal information, and we don't run ads.

4. YouTube API Services — required disclosures

plaiist's use of information received from Google APIs (via the YouTube Data API) adheres to the Google API Services User Data Policy, including the Limited Use requirements.

plaiist uses YouTube API Services. By connecting YouTube Music, you agree to be bound by the YouTube Terms of Service, and your use of Google's services is also governed by the Google Privacy Policy.

What we access: when you connect YouTube Music, plaiist requests permission to manage your YouTube account's playlists (the youtube scope). Specifically, plaiist can:

  • See your channel's basic identity (channel ID and name), so we can confirm which account is connected and prevent it from being connected to more than one plaiist account.
  • List, create, rename, and delete your YouTube playlists.
  • Search YouTube (scoped to YouTube's Music category) to find tracks.
  • List, add, and remove items in your playlists.

What we don't access: plaiist requests no access to your watch history, subscriptions, comments, likes, or any video content, and it never streams, downloads, or plays anything through your YouTube account.

Why: solely to carry out the playlist actions you ask for in chat — search, create, edit.

What we store: your YouTube OAuth access token and refresh token, your channel ID, and your channel display name, all server-side (see "Your connected streaming account" above). We do not store your watch or search history from YouTube itself.

What we share: the track and playlist titles plaiist finds or builds are passed to our AI provider (MiniMax) so it can describe, in chat, what it did — see "AI processing" below. Your YouTube tokens, channel ID, and any other YouTube account data are never sent to MiniMax or any other third party. If you create a public share link for a playlist built on YouTube Music, the shared page shows the track titles and artist names, not anything else about your YouTube account.

How to revoke access: you can disconnect YouTube Music from plaiist at any time in Settings, or revoke plaiist's access directly from your Google Account at security.google.com/settings/security/permissions.

How stored YouTube data is deleted: disconnecting YouTube Music in Settings deletes your stored YouTube tokens and identity from our database immediately — nothing on YouTube itself is touched or deleted. Deleting your plaiist account (Settings → Delete account) deletes the same data immediately, as part of deleting your whole account.

The same connect / store / delete pattern, and the same "we never see your password" guarantee, applies to Tidal, Spotify, and Apple Music — YouTube's section above is more detailed only because Google requires it to be.

5. How we use your information

  • To run the core product: authenticate you, remember your connected service and preferences, and carry out the playlist actions you ask for.
  • To send your chat messages (and the track/playlist names involved) to our AI provider so it can generate a reply and decide which tools to call.
  • To bill you, if you subscribe, and to enforce your free-trial allowance.
  • To send account emails — confirming your email, password resets, and similar — through our email delivery provider.
  • To keep the service reliable and within API limits (for example, YouTube's shared daily search quota is tracked so we don't send requests Google would reject).
  • To investigate abuse or enforce our Terms of Service.

We do not use your data to train any AI model, and we do not sell it.

6. Who we share information with

We share information only with the service providers that make plaiist work, each acting for us and only for the purposes above:

WhoWhat they getWhy
Supabaseaccount email, profile data, chat history, connection tokensour database and authentication provider
Stripeyour email, and whatever payment details you give Stripe directlypayment processing — we never see your card
Brevoyour email address, for the specific transactional email being sentdelivers our account emails (confirmation, password reset)
MiniMaxyour chat messages, and track/playlist titles from your conversationpowers the AI assistant that reads your request and builds the playlist
Tidal / Spotify / Apple Music / YouTube (Google)search queries and playlist edits, sent using your own connected-account tokencarrying out the playlist actions you ask for, on the service you connected

We do not share your information with data brokers or advertisers, and we don't share it for anyone else's marketing.

7. AI processing

plaiist's chat is powered by MiniMax's language models. When you send a message, that message (plus recent conversation history) is sent to MiniMax's API to generate a reply and decide which playlist actions to take. Track and playlist titles that plaiist finds or creates while doing so are also part of that exchange, since the assistant needs them to describe what it did.

We do not send MiniMax your email address, password, payment details, or streaming-service tokens.

8. How long we keep information

  • Chat messages: until you clear your chat or delete your account.
  • Connected-service tokens and identity: until you disconnect that service or delete your account.
  • Account and billing records: until you delete your account (an active subscription is cancelled with Stripe first, so you're never charged after deletion).
  • Auth email log (a record that an email was sent, for support purposes): deleted when your account is deleted.
  • Public playlist share pages: until you delete your account (deleting the account removes them too).

9. Your choices and rights

  • Disconnect a streaming service any time in Settings — this deletes the stored tokens for that service immediately; it does not touch anything on the streaming service itself.
  • Clear your chat any time in Settings/chat — deletes your stored conversation.
  • Revoke YouTube access from Google's side, independent of plaiist, at security.google.com/settings/security/permissions.
  • Delete your account (Settings → Delete account, type "DELETE" to confirm). This cancels any active subscription first, then permanently deletes your connected-service tokens, chat history, usage records, email log, and profile, then your login itself — you're signed out everywhere immediately. This cannot be undone.
  • Depending on where you live, you may also have rights to access, correct, or export your data, or to object to certain processing.

10. Security

Streaming-service tokens and other sensitive data are stored server-side, walled off so that only plaiist's backend — never your browser, and never another signed-in user — can read them. No system is perfectly secure, and we can't guarantee absolute security.

11. Children's privacy

plaiist is not directed at children, and we don't knowingly collect information from them.

12. International data transfers

plaiist is hosted in the EU. Depending on where you are, using plaiist may involve transferring your information to other countries — including the United States (Stripe) and the countries where MiniMax processes data. Where required, we rely on appropriate safeguards for these transfers.

13. Changes to this policy

We'll update the effective date above when this policy changes, and for material changes we'll make a reasonable effort to let you know (e.g. by email or in-app notice).

plaiistDescribe the music you can't name · How it works · FAQ · Privacy