Groovara Legal
Groovara Privacy Policy
Effective Date: July 16, 2026
GROOVARA LLC ("Groovara," "we," "us," or "our") respects your privacy and is committed to being transparent about how information is collected, used, stored, and shared.
This Privacy Policy applies to the Groovara website, beta platform, Tracklists, Mixlists, Studio, music-platform integrations, playlist import and export tools, and related services.
Information We Collect
Account and Authentication Information
When you create or use a Groovara account, we may process:
- Email address and user account identifier
- Account creation and login timestamps
- Session and authentication metadata
- Beta access, invite, or redemption status
- Security, rate-limit, and abuse-prevention records
Authentication is provided through Supabase Auth. Groovara does not store your plain-text password in its application database. If you use Google sign-in, Groovara and Supabase may receive your email address, display name, profile image, and Google provider identifier.
User Content and Listening Activity
Groovara stores content and activity needed to provide the service, including:
- Tracklists, Studio drafts, and imported playlists
- Mixlists, titles, descriptions, messages, and finishing notes
- Song order, song notes, reveal settings, and visibility settings
- Reveal progress, clicked-song state, and listening progress
- Sent, received, archived, and recently opened Mixlist records
- Platform preferences, theme settings, and feature settings
- Feedback messages and the page from which feedback was submitted
Mixlists shared through a public or access-by-link URL may be viewed by anyone who obtains that link. Do not place sensitive personal information in a Mixlist, message, description, or song note that you are not comfortable sharing with its recipients.
Connected Music Accounts and Authorization Data
When you connect Spotify or YouTube, Groovara may store or process OAuth access tokens, refresh tokens, granted scopes, provider account or channel identifiers, connection status, and token expiration information. These credentials are used only to provide the connected features you request, such as importing a playlist or creating a playlist in your connected account.
Groovara never asks for or stores your Spotify, Google, YouTube, or Apple account password. Authentication occurs on the provider's own authorization page.
Music Catalog, Import, Export, and Matching Data
When you search, import, convert, listen to, or export music, Groovara may process:
- Song, artist, album, channel, and playlist names
- Provider URLs, track IDs, video IDs, playlist IDs, and artwork
- International Standard Recording Codes (ISRCs), when available
- Public search results and platform source information
- Import and export results, counts, errors, and created playlist URLs
- Cached conversion, availability, and validation timestamps
Groovara may create reusable track-matching records using an ISRC or a normalized title-and-artist identity. These records connect a song identity to a provider track or YouTube video and may be reused to improve matching for other users. They are intended to describe music catalog relationships, not an individual's listening history.
Technical and Usage Information
Groovara and its service providers may process browser type, device type, operating system, page or route viewed, referrer, approximate region, event timestamp, feature interactions, diagnostic information, and pseudonymous analytics identifiers. Server logs may also temporarily process IP addresses and request metadata for security, reliability, and abuse prevention.
YouTube API Services
Groovara uses YouTube API Services to search for public videos, display YouTube content, validate cached video data, import public playlists, match songs, and—after a user explicitly chooses to do so—create a playlist in the user's connected YouTube account.
Use of YouTube-powered features is also subject to the YouTube Terms of Service. Google's privacy practices are described in the Google Privacy Policy.
Groovara does not use YouTube authorization data for unrelated advertising, profiling, or surveillance, and does not permit unauthorized third parties to access a user's connected YouTube account data.
Cookies, Local Storage, and Similar Technologies
Groovara uses cookies, browser storage, and similar technologies for the categories described below.
Strictly Necessary
Supabase authentication cookies and related security storage are used to keep you signed in, refresh sessions, protect accounts, and provide authenticated features. Disabling these technologies may prevent login or other core features from working.
Preferences and Functionality
Local storage or similar browser storage may remember your light or dark theme, preferred listening platform, reveal progress for anonymous sessions, dismissed notices, and other interface preferences.
Analytics and Product Improvement
Groovara uses Vercel Web Analytics for aggregated traffic and performance information. Vercel Web Analytics is designed not to use third-party cookies for visitor identification.
Groovara also uses PostHog for product analytics. Depending on Groovara's configuration and your browser, PostHog may use a first-party cookie, local storage, or another pseudonymous identifier to recognize a browser and associate related product events. Groovara does not intentionally send passwords, OAuth tokens, the text of song notes, or the text of Mixlist messages to analytics providers.
Embedded Music Content
YouTube, Spotify, Apple Music, and other embedded players may receive device, network, and interaction information and may set or access their own cookies or similar technologies under their respective privacy policies.
Groovara does not currently use advertising cookies or sell information for cross-context behavioral advertising.
You can delete or block cookies and local storage through your browser settings. Blocking necessary storage may sign you out or prevent some features from working. Where consent is required by applicable law, Groovara may request consent before enabling non-essential analytics or similar technologies.
Analytics
Vercel Web Analytics may process aggregated page views, routes, referrers, country or region, browser, device type, operating system, and event timestamps for traffic and performance analysis.
PostHog may process product events such as opening the Studio, creating or publishing a Mixlist, changing a platform, revealing a song, copying a link, importing a playlist, or exporting a playlist. Event properties may include internal Tracklist or Mixlist identifiers, platform names, item counts, and feature states.
We use analytics to understand whether features work, diagnose failures, improve usability, measure beta adoption, and make product decisions. We do not sell analytics data.
How We Use Information
Groovara uses information to:
- Create, authenticate, and protect accounts
- Store and display Tracklists, Mixlists, notes, and progress
- Import, search, match, convert, play, share, and export music
- Create playlists in a connected account at the user's direction
- Remember settings and improve the user experience
- Maintain API compliance, cache freshness, and service reliability
- Prevent fraud, abuse, unauthorized access, and quota misuse
- Analyze product usage and diagnose technical problems
- Respond to support requests, feedback, and legal obligations
How We Share Information
Groovara does not sell personal information. We may disclose information to service providers that help operate Groovara, including Supabase, Vercel, PostHog, Google and YouTube, Spotify, Apple Music, and other infrastructure or integration providers.
We may also disclose information when reasonably necessary to comply with law or legal process; protect Groovara, users, or the public; investigate abuse or security incidents; or complete a business transaction such as a merger, financing, acquisition, or sale of assets, subject to appropriate safeguards.
Connected Account Controls and Revocation
You may disconnect a supported music account through Groovara's settings when that control is available. Groovara will stop using the disconnected authorization and will revoke or remove associated credentials and authorized data as required by the provider's rules.
You may also revoke Groovara's Google or YouTube access through Google's third-party access settings. Revoking Groovara does not delete playlists or other content already stored by YouTube; those items must be managed through YouTube.
For YouTube Authorized Data, Groovara deletes data as soon as reasonably possible and within the periods required by YouTube, including after direct revocation, account deletion, or detection that authorization can no longer be refreshed.
Data Retention and Deletion
Groovara retains account information and User Content while your account is active and for as long as reasonably necessary to provide the service, maintain security, resolve disputes, comply with law, and enforce agreements.
Connected-account credentials are retained only while needed to provide an active connection. Public catalog matching records may be retained independently of a user account when they do not identify an individual and remain useful for platform matching.
Stored YouTube API data is refreshed, updated, validated, or deleted at least every 30 calendar days where required. Unavailable YouTube content may be marked unavailable or removed.
You may request deletion of your account information, connected authorization data, or User Content by emailing hello@groovara.com. Some information may be retained when required for security, fraud prevention, legal compliance, or to establish or defend legal claims.
Your Choices and Privacy Rights
Depending on your location, you may have rights to request access, correction, deletion, portability, restriction, or objection regarding personal information. You may also withdraw consent where processing is based on consent.
To exercise a privacy right, contact hello@groovara.com. We may need to verify your identity before completing a request. You may also manage connected-provider permissions directly through the applicable provider.
Data Security
Groovara uses reasonable administrative, technical, and organizational safeguards intended to protect information, including authenticated access controls, encrypted network transport, database access policies, and restricted server-side credentials. No internet service can guarantee absolute security.
Children's Privacy
Groovara is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can review and delete it as appropriate.
International Processing
Groovara and its service providers may process information in the United States and other countries. Those countries may have data protection laws that differ from the laws where you live.
Changes to This Privacy Policy
We may update this Privacy Policy as Groovara changes. The revised policy will display a new Effective Date. When required, we may provide additional notice or request renewed consent before using information in a materially different way.
Contact Information
Questions, complaints, privacy requests, account inquiries, or deletion requests may be directed to:
GROOVARA LLC