Privacy Policy
The short version
- Orpheus keeps what it needs to build your rotations: your email, your time zone, the music you upload or choose to have it read from Spotify, how often each track has been served, and an encrypted Spotify credential. Nothing else.
- If you send feedback, it keeps what you wrote, along with the screen you were on, your browser's description of itself and your window size — so a problem can be reproduced without a back-and-forth. That is all: never the contents of the page you were looking at.
- It never sees your Spotify password or your listening history. It can create and change playlists, and check that the playlists it made are still in your library — Spotify only allows that check with permission to read your private playlists. Orpheus uses that permission for nothing else unless you switch on reading playlists from Spotify: then it also reads the playlists you choose, and keeps their tracks the way it keeps an upload.
- No advertising, no analytics, no tracking cookies. Your information is never sold or shared for advertising.
- You can download everything or delete your account yourself, at any time, from your account page.
1. Who we are
Orpheus is a service that builds a rotating playlist in your Spotify account from music you upload, or from playlists you choose to have it read from Spotify. It is operated by ZeusARuse ("we", "us"). This policy explains what information we collect when you use Orpheus, why, how long we keep it, and the choices you have. It applies to the Orpheus website and service at https://orpheusproject.duckdns.org. Questions go to jeenz2069@gmail.com.
2. Information we collect
| What | Where it comes from | Why we need it |
|---|---|---|
| Account details — email address, password (stored only as a one-way hash), time zone, when you signed up and last signed in | You, when you register and use your account | To let you sign in, run your rotations at your local time, and contact you about your account |
| Music you upload — the contents of the Exportify file you choose to upload: each track's Spotify identifier, title, artists, album, release date, length, whether it is explicit, the artist's genres, when it was added to that playlist, and Spotify's audio measurements (tempo, energy and similar) | You, by uploading a file | To choose tracks for your rotations and to apply the filters you set |
| Playlists you choose to read from Spotify — only if you switch that on: each track's Spotify identifier, title, artists, album, release date, length, whether it is explicit, and when it was added to the playlist; the playlist's Spotify identifier, and the version marker Spotify gives it; when Orpheus last checked it | Spotify, when you add a playlist, and when one of your rotations checks it on the schedule you choose | To choose tracks for your rotations from the playlist as it is now, and to tell when it has changed without reading it all again |
| Rotation data — your settings, how many times each track has been served and when, the tracks each run chose, and each run's outcome | Created by Orpheus as it runs | This is how Orpheus avoids repeating what you heard recently — it is the service |
| Spotify connection — your Spotify app's client ID, your Spotify user ID and display name, the permissions you granted, when you approved, and a refresh token that lets Orpheus update your playlist while you are away | Spotify, when you approve Orpheus on Spotify's own page | To create and update your rotation playlists. The token is encrypted (AES-256) and never leaves Orpheus |
| Security records — sign-ins, password and email changes, account deletion, with a one-way keyed hash of the IP address involved (not the address itself) | Created by Orpheus when those events happen | To protect accounts and investigate misuse |
| Feedback you send — what you wrote, and, attached automatically at the moment you send it: the address of the page you were on, which screen and section that is, the description your browser gives of itself, your window size, and your device's clock reading. Plus any replies on the conversation that follows | You, when you use the Feedback button; the rest is what your browser already tells every website, collected at that moment and attached to what you wrote | So a problem can be understood and reproduced without having to ask you where you were and what you were using. It is shown to you in full before you send it, and you can choose not to send |
| Server logs — technical records of requests and errors | Created automatically by the servers | To keep the service running and fix faults |
We do not collect: your Spotify password (you only ever enter it on Spotify's site), your saved tracks, listening history or followers (Orpheus is not given permission to read them), the contents of your other playlists (Orpheus reads a playlist's tracks only if you switch on reading from Spotify and add that playlist; otherwise it uses the permission only to ask whether its own playlists are still in your library, and keeps nothing but that yes-or-no answer), payment information (Orpheus is free), your location beyond the time zone you choose, or any information from advertising networks or data brokers.
3. How we use it
Only to provide and protect the service:
- to build and update your rotation playlists on the schedules you set;
- to send you account email — address confirmation, password resets, a reminder before Spotify's six-month approval period ends, and notice if your rotations stop working. We do not send marketing email;
- to keep accounts secure, prevent abuse, and fix problems;
- to comply with the law.
We do not sell your information, share it for advertising, build advertising profiles, or use it or any Spotify data to train machine-learning or AI models.
4. Spotify
Orpheus uses Spotify's Web API, under Spotify's Developer Terms, through a Spotify app that you register yourself. When you connect, Spotify asks you to approve Orpheus managing your playlists and reading your private playlists. The second is used only to check that the playlists Orpheus made are still in your library: removing a playlist in Spotify does not delete it, so without that check Orpheus would go on updating a playlist you had removed. Information Orpheus receives from Spotify is used only to operate your rotations. Your use of Spotify itself is governed by Spotify's own terms and privacy policy.
If you switch on reading playlists from Spotify — it is off unless you do — Orpheus also uses that permission to read the tracks of the playlists you add as sources, and to check them for changes on the schedule you choose, when one of your rotations runs. It reads no other playlist, and keeps the same details about each track that an upload gives it. Switching it off stops the reading; what was last read stays, like an upload, until you delete it.
You can disconnect Spotify from the Spotify page at any time. Doing so immediately deletes the stored credential, every Spotify identifier we hold for you (your Spotify user ID, display name and the IDs of your rotation playlists), and the playlists read from Spotify — with any of their tracks you have not been served. What Orpheus served you stays in your play history. You can also revoke access on Spotify's side at spotify.com/account/apps. Spotify ends Orpheus's access automatically six months after you approve it; you can reconnect whenever you like.
Orpheus is not affiliated with or endorsed by Spotify. Spotify is a third-party beneficiary of this Privacy Policy and of our Terms of Service, and is entitled to enforce them directly.
5. Who we share it with
We share information only with:
- Service providers who run infrastructure for us, under contracts that limit them to doing so: our hosting provider (servers and storage in the United States) and our email delivery provider (which receives your address and the message in order to deliver it).
- Spotify, to the extent needed to update your playlist — for example, the list of tracks to put in it.
- Authorities, when the law requires it, or where necessary to protect the rights, safety or property of users or others.
- A successor, if Orpheus is transferred to a new operator — who must honour this policy for information collected under it, and you would be told first.
We do not sell personal information, and we do not "share" it for cross-context behavioural advertising as California law defines those terms.
6. Cookies
Orpheus uses only cookies that are strictly necessary for the site to work. There are no analytics, advertising or third-party cookies, and nothing that tracks you across other sites.
| Cookie | Purpose | Lasts |
|---|---|---|
.AspNetCore.Identity.Application | Keeps you signed in | Until you close the browser — or, if you tick "Remember me", until 14 days after your last visit |
.AspNetCore.Antiforgery.* | Protects forms from being submitted by other sites | Until you close the browser |
orpheus_spotify_auth | Carries the one-time verification code while you approve Orpheus on Spotify's page | 10 minutes, and only during connection |
Identity.StatusMessage | Shows a one-off confirmation such as "password changed" | Deleted as soon as it is shown |
You can block or delete cookies in your browser's settings. Because these cookies are necessary, blocking them will stop you signing in.
7. How long we keep it
- Your account, uploaded music, play counts and settings — until you delete them or your account. Play counts are deliberately kept when you replace an upload, so your rotations do not start over; deleting your account removes them.
- Playlists read from Spotify — until you delete them, disconnect Spotify (which deletes them at once), or delete your account. Each read replaces the tracks read before, so Orpheus holds the playlist as it last read it, with a count of what each read found — not a history of its contents.
- Run history (which tracks each run chose) — 180 days, then deleted automatically.
- Spotify API usage counts — 25 hours, then deleted automatically.
- Security records — one year. When you delete your account, your identity is removed from them and what remains (a date, an event type and a keyed hash) no longer relates to you.
- Feedback and its replies — until you delete your account, which removes them. You can also withdraw a report yourself while nobody has answered it yet. Once it has been replied to it stays, because it is then a conversation and not only your message.
- Server logs — overwritten automatically on a rolling basis as new logs are written (a fixed-size buffer; at normal activity, a matter of weeks).
- Backups — the database is backed up nightly and each backup kept for 14 days, so information you delete disappears from backups within 14 days.
8. Security
All traffic to Orpheus is encrypted with HTTPS. Passwords are stored only as salted one-way hashes. The Spotify credential is encrypted with AES-256 and bound to your account, so it cannot be used for anyone else's. Access to the servers is restricted to the operator. No system is perfectly secure; if a breach affecting your information occurs, we will notify you and the relevant authorities as the law requires.
9. Your rights and choices
Wherever you live, you can:
- See and download everything we hold about you — Download my data on your account page;
- Correct your email address or time zone on your account page;
- Delete your account and all its data yourself, immediately, from your account page;
- Disconnect Spotify at any time, which deletes the Spotify credential and identifiers;
- Ask us anything about your information at jeenz2069@gmail.com.
Residents of US states with privacy laws
If you live in a state with a comprehensive privacy law — including California, Colorado, Connecticut, Virginia, Utah, Texas and Oregon — you have the right to know what personal information we collect, use and disclose; to access, correct and delete it; to receive a portable copy; to opt out of its sale, of targeted advertising and of profiling (we do none of these); and not to be discriminated against for exercising these rights. We treat a Global Privacy Control signal as a valid opt-out, though there is nothing for it to switch off.
Most requests can be completed instantly from your account page. Otherwise, email jeenz2069@gmail.com from the address on your account so we can confirm it is you; an authorised agent may also make a request with your written permission. We respond within 45 days. If we decline a request, you may appeal by replying to our decision, and we will answer within 60 days; if you remain unsatisfied you may contact your state attorney general.
For California's disclosure requirements: in the past 12 months we collected identifiers (email address, Spotify user ID), internet activity information (security records, server logs), and other information you provided or had Orpheus read from Spotify (uploaded music data, playlists you chose, settings) — for the purposes in section 3, from the sources in section 2. We disclosed identifiers to our service providers for business purposes only. We have not sold or shared personal information, and we do not use or disclose sensitive personal information other than your account password and credential for authentication.
10. Children
Orpheus is not for children under 13, and we do not knowingly collect information from them. Registration requires confirming you are at least 13. If you believe a child under 13 has an account, contact us and we will delete it.
11. Where your information is kept
Orpheus is operated from the United States and your information is stored on servers there. If you use Orpheus from elsewhere, your information is transferred to and processed in the United States.
12. Changes to this policy
If we change this policy we will update the date at the top. For a change that materially affects how we use information we already hold, we will email you before it takes effect.
13. Contact
ZeusARuse — jeenz2069@gmail.com. See also the Terms of Service.