Draft - not yet in effect

Privacy statement

Last drafted 2026-09-26.

This is a draft, written ahead of Liner Notes’ beta so the app has an honest privacy statement from day one. It will be finalized - and this notice removed - once the legal entity behind Liner Notes is registered (see “Who runs this” below) and a lawyer has reviewed it.

Who runs this

Liner Notes (linernotes.me) is built and operated by Fredrik Andersen, Oslo, Norway. The legal entity is not yet registered - a sole proprietorship (enkeltpersonforetak) or a limited company (AS) - so this section will name that entity, its registration number and a contact address once it exists. Until then, contact privacy@linernotes.me for any privacy question, including exercising the rights below.

What we collect

  • Account: your email address, used only to sign you in (a magic link, no password) and for service email.
  • Your taste data: album ratings, “want to listen”/“not interested” states, journal entries and notes, and what you import.
  • Imports: a file you import (an M3U playlist, a CSV export, or your Spotify data export) is read in your browser, and the file itself never leaves it. Only a summary per album reaches us: the artist and album, your rating if the file has one, and - from a listening history such as a Spotify export - how many times you played the album and when you last played it. We never store your individual plays. If you import from ListenBrainz, the username you enter is sent to ListenBrainz to read your public listening stats; we keep the same per-album summary and nothing else - not the username, and not your individual listens.
  • Settings: your preferred streaming service, market and new-vs-classics mix.
  • Usage analytics: which features you use (e.g. viewing a recommendation, rating it, dismissing it) via PostHog, hosted in the EU. This is used to improve the product, never sold or shared for advertising.
  • Error reports: via Sentry, hosted in the EU, when something breaks, so it can be fixed. A summary of some error reports (the error message, the page it happened on with any link stripped of its query string, and technical details like browser and OS) is also copied into our internal work-tracking tool, Plane, so the error can be triaged and fixed. This summary never includes your name, email, IP address or account id.
  • Admin actions: decisions the site’s administrator makes on the internal admin dashboard are logged permanently: who, what, when, the browser and a one-way hash of the IP address. This concerns the administrator’s own account only; it records nothing about other users. Because the log is permanent, an account with logged admin decisions can’t be deleted from Settings.

We never buy, sell or share your personal data with third parties for their own marketing. There are no ads and no ad trackers in Liner Notes.

Where your data is stored and processed

Everything runs on infrastructure in the EU: the app on Vercel (Frankfurt), the database on Neon Postgres (Frankfurt), the background worker on Fly.io (Frankfurt), email via Resend, error tracking via Sentry (EU) and analytics via PostHog (EU). Data processing agreements with each of these vendors are part of what’s pending before this draft becomes final.

Where music data comes from

Album, artist and critic-score data comes from public and licensed sources - MusicBrainz, Wikidata, Wikipedia’s published rating tables, ListenBrainz, Discogs, the iTunes and Deezer APIs, and (where enabled) the Guardian, the New York Times, Last.fm and a small list of publication RSS feeds. This is data about albums, not about you.

Your rights

Under GDPR, you can:

  • Export everything the app has stored about you, as a JSON file, from your account settings.
  • Delete your account and everything tied to it, permanently, from the same page.
  • Ask questions or raise a concern at privacy@linernotes.me.

How long we keep it

Your data is kept for as long as your account exists. Deleting your account removes it immediately and permanently from the live database - this isn’t reversible.

For disaster recovery, we also keep automatic database backups made just before each schema update, so a failed update can be rolled back. These backups are deleted within about 7 days (checked daily, and capped at the 5 most recent regardless of age), so a copy of your data from before deletion can exist in one of these backups for up to that long. They exist purely for our own recovery purposes, are never restored to serve the live app, and aren’t used, read or shared for any other reason.

Cookies

Liner Notes uses one essential cookie to keep you signed in. There are no marketing or advertising cookies.

Children

Liner Notes is not directed at children and is not knowingly used by anyone under 16.

Changes to this statement

This is a living document while Liner Notes is in beta. Meaningful changes will be announced by email to registered users.