The fine print

Privacy Policy.

Last Revised: September 21, 2026

The short version

Moodwave keeps no database and stores nothing about you on its servers. Your Spotify connection lives as an encrypted cookie in your own browser and dies after 2 hours or the moment you log out. The only things we touch outside your session are your IP address (held in short-term memory to enforce fair-use limits) and track titles shared with AI helpers to sharpen mood tags.

Who we are

Moodwave is a free playlist tool built by Point Woebegone. Contact for anything privacy related: pointwoebegone@gmail.com.

Spotify data: what we access and why

When you enter with Spotify, Spotify asks you to approve specific permissions. Moodwave requests only these, each with a job to do:

user-library-read: read your saved tracks so builds can draw from your full collection. user-top-read: read your top tracks across time ranges to weight what you actually play. playlist-modify-public and playlist-modify-private: create playlists in your account when you press Push. user-read-private: your display name and profile image for the Desk header.

Authentication runs entirely through Spotify. We never see or touch your Spotify password. Your access and refresh tokens are sealed inside the encrypted session cookie described below and are sent only to Spotify.

Where your data lives (nowhere)

There is no Moodwave database. No listening history, no profiles, no saved builds on our side. Your session cookie (mw_session, encrypted with AES-256-GCM, httpOnly, 2 hour life) holds your Spotify tokens in your browser only. Pressing Leave destroys it immediately, server side and client side.

Enrichment lookups

To classify tracks, Moodwave looks up public metadata: Last.fm track tags, FreqBlog audio features, and open sources such as MusicBrainz. These calls carry track and artist names only, never your tokens, email, or identity. Each is governed by its own policy in addition to this one.

AI processing

For low-confidence tracks (up to 10 per build) and playlist naming, Moodwave may send track titles, artist names, and mood labels to free-tier AI providers in a fixed fallback chain: Groq, then OpenRouter, then Hugging Face. Account credentials, tokens, and email are never sent. Providers process the request to return your result under their own policies, linked below. A daily limit of 6 AI assists per user keeps the free tier alive for everyone.

IP addresses and rate limits

To keep the free service standing, we count requests per IP address: 30 playlist builds per hour and 150 per day, 6 AI assists per day, plus burst guards on login and push endpoints. Counts live in server memory on a rolling 24 hour window. They are never written to disk or a database, never sold, never shared. Our host Vercel also logs IPs at platform level to operate the service.

Your rights

Depending on where you live, including under the GDPR and the Nigeria Data Protection Act 2023, you may access, correct, or delete data about you, and withdraw consent at any time by disconnecting. Since we retain nothing server side, logging out and removing Moodwave from your Spotify apps page completes deletion instantly. Anything residual (for example a platform log we cannot reach) can be requested at pointwoebegone@gmail.com and will be handled within 30 days.

Children

Moodwave is not directed at children under 13, and we do not knowingly collect data from them. A Spotify account is required to build, and Spotify has its own age requirements.

Third party policies

Spotify: spotify.com/privacy. Google and YouTube (where applicable): policies.google.com/privacy. Last.fm, FreqBlog, Groq, OpenRouter, Hugging Face, and Vercel each publish their own policies, which apply alongside this one.

Changes

If this policy changes in a way that matters, the Last Revised date below moves and the Desk will say so. Continued use after changes means acceptance.

Questions: pointwoebegone@gmail.com · Back to the room