LEGAL
Privacy
Controller
Jochen BartlauZogelmannstr. 22
78462 Konstanz
Germany
Email: hi@musicdiscovery.net
Overview
Music Discovery does not use cookies, visitor analytics, tracking, or advertising, and has no user accounts or login. Nothing on this site identifies you, recognises you on a later visit, or follows you between pages. The sections below list every place personal data is processed while using the site. The one thing we do count is described under Usage counters, and it records no personal data at all.
Server access logs
Like most web servers, our hosting infrastructure automatically records technical data for each request — IP address, timestamp, requested page, and browser/user-agent string — to keep the service secure and stable. This happens on the basis of our legitimate interest (Art. 6(1)(f) GDPR) and the logs are kept only briefly before being rotated out.
Search and recommendations
The artist or song title you search for is sent to our server, which forwards it to the MusicBrainz and ListenBrainz APIs (both run by the MetaBrainz Foundation) to look up metadata and generate recommendations. Results are cached on our server to speed up repeat searches — from a few days for search results up to three months for stable identifiers such as the MusicBrainz ID of a recording. The cache stores only the music data itself and is not linked to you personally. See MetaBrainz's own privacy policy and GDPR statement.
Where ListenBrainz has no data for a song, or too little of it to build a playlist, our server additionally queries the Last.fm API (operated by Last.fm Ltd., United Kingdom) for similar tracks and similar artists. Only the artist and song name are sent, together with our own application key. These requests are made by our server, so Last.fm does not receive your IP address or any browser information, and no Last.fm content is loaded into your browser. Last.fm's responses are cached on our server on the same basis as the MetaBrainz data. See Last.fm's privacy policy. Transfers to the United Kingdom are covered by the European Commission's adequacy decision of 28 June 2021.
To find out whether an artist has a Wikipedia article, our server asks Wikidata (operated by the Wikimedia Foundation) for the item matching that artist's MusicBrainz ID. Only that identifier is sent, by our server, so Wikidata receives no IP address or browser information from you. A URL found this way is cached on our server like any other stable identifier; a "no article" result is not cached at all. Where an artist has no article, the Last.fm API described above is additionally asked for that artist's own Last.fm page, again using only their MusicBrainz ID.
"Share" creates a link that identifies the songs in that playlist, not you. Its short form stores the song list in the same cache described above, under a code derived only from the songs themselves — never from your IP address or any other visitor detail — so it ages out on the same schedule as everything else in that cache, up to three months.
Describing what you want in your own words
Beside the artist and song fields there is an optional field you can describe music in, in your own words — "late nineties trip-hop, mostly instrumental". Nothing in this section applies unless you type something there and submit it. The artist and song search described above never uses it.
When you do submit a description, our server sends the text exactly as you typed it to the Mistral AI API (operated by Mistral AI SAS, France) to be turned into search parameters: a handful of style names, and optionally a decade, a discovery range, a country, or the name of an artist you mentioned. The model answers in its own words; our server then matches those words against MusicBrainz's published genre list and keeps only the ones that match a real genre, so nothing it invents reaches a search. Only your text is sent, together with our own application key and a fixed instruction. The request is made by our server, so Mistral does not receive your IP address or any browser information, and nothing is loaded into your browser from them. Because Mistral AI is established in the European Union, this is not a transfer to a third country and needs no adequacy decision or contractual safeguard. We have opted out of Mistral using this site's API requests to train its models. See Mistral's terms and privacy documentation for what they do with data sent to their API.
What comes back is only ever a small set of tags and values, which our server then uses to search MusicBrainz for artists, exactly as described above. The result of that interpretation is cached on our server for a week so that the same description does not have to be sent twice. Your text itself is not stored. It is used to compute the key the cached result is filed under — a one-way SHA-256 hash — and that key is what is written to disk, so the cache cannot be read back to recover anything anybody typed.
Because this field is free text, please treat it as public: type a description of music, and do not type anything personal into it. To limit both cost and misuse, this field is capped at 200 characters and rate-limited per address and for the site as a whole; the counters behind that are the truncated hashes described under "Abuse prevention" below.
This feature is optional for us as well as for you. If it is switched off in our configuration, the field is not shown, its endpoint answers as though it does not exist, and nothing is ever sent to Mistral.
Usage counters
To see which parts of the site are actually used and whether the music databases we depend on are answering, our server keeps a set of plain counters: how many searches were made, how many playlists were built, how many times a particular button was pressed, how many requests each external music service answered or refused, and how long they took.
These are counters and nothing else. A counter is a single number that goes up by one; there is no record of an individual visit behind it. Specifically, we do not store your IP address or any hash of it, any identifier for you or your browser, your user-agent string, anything you typed into the search fields, which songs or artists you looked at, any session or visit identifier, or any timestamp more precise than the hour of the day. Two people pressing the same button are indistinguishable afterwards, and so are one person pressing it twice.
Because of that, these figures cannot tell us how many people visited, cannot be linked to you, cannot be linked to each other, and cannot be turned back into a record of anyone's activity. This is not visitor analytics and it is not a profile: it is the equivalent of a tally on the wall. No third party receives any of it, and nothing is sent from your browser for this purpose.
The counters are stored as one small file per day and are deleted automatically after twelve months. Our legitimate interest in knowing which features work and whether the site is healthy is the basis for this (Art. 6(1)(f) GDPR). As the data contains no personal data, it is not itself subject to your data-subject rights below, though everything else on this page is.
Abuse prevention
Because every search spends a shared quota at the music databases we rely on, the number of requests from a single internet connection is capped over a short period. To count them we store a shortened, one-way hash of your IP address — not the address itself — together with a counter. The entry is deleted automatically once the period lapses, is never combined with your searches, and is used for nothing else. This rests on our legitimate interest in keeping the service available (Art. 6(1)(f) GDPR).
Cover art images
Album cover art is loaded directly from the Internet Archive (archive.org) by your browser, not through our server. This means archive.org receives your IP address for those image requests, under their own privacy policy.
Audio previews (Deezer)
Pressing a track's cover plays a 30-second preview provided by Deezer (operated by Deezer SA, France). Nothing in this section happens unless you press a cover: no preview is requested, and nothing is loaded from Deezer, while a playlist is built or shown.
When you do, your browser contacts Deezer directly, in two steps. First it asks the Deezer API (api.deezer.com) for that track, sending its artist name, title and, where known, its ISRC (the industry code for a recording); this lookup runs in a sealed frame within the page that has no access to the rest of this site, and sends no referrer. Then it loads the audio from Deezer's content delivery network (dzcdn.net). Because both requests come from your browser, Deezer receives your IP address and your browser's user-agent string, together with which track you asked to hear, under Deezer's own privacy policy. Our server takes no part in this and stores nothing about it; the preview address Deezer returns expires and is not kept. Once one preview ends, the next track's preview starts automatically, which repeats both steps for that track; pausing, or opening a track on a music provider, stops it. Because Deezer is established in the European Union, this is not a transfer to a third country.
Your preferences (local storage)
Your dark/light mode choice and preferred music provider are saved only in your browser's local storage. The stored provider decides which service a track's title links to, and which one a playlist is offered to when you save it. They are never transmitted to our server and are used purely to remember your settings — not for tracking — so no cookie-consent banner is shown (§ 25 TTDSG).
Local storage additionally holds short lists of artists and tracks, kept only so that discovery can avoid repeating itself and the "Surprise me" button can propose something near your taste rather than at random.
The artist lists record the artist whenever you pick a starting point from a search or switch to a new one from a track — at most thirty of those, on a rolling basis — and, separately, any artist you have marked "Not for me" after replacing one of their tracks, so that artist is not proposed to you as a surprise; at most twenty of those. Older entries drop off.
The track lists hold recordings you have told us to leave out. Those you marked "I already know it" are kept out of later playlists. Those you marked "Not for me" are avoided whenever another track can take their place — if the pool for a starting point is too thin to fill twenty rows without them, they can still appear, because a short playlist is the worse outcome. Each list holds at most two hundred entries, again on a rolling basis. Replacing a track without giving a reason records nothing at all, and neither does choosing "Not right for this discovery" — that one is held in the page's memory rather than in storage, for as long as you keep exploring from the same starting point, and is gone as soon as you choose a new one or reload.
All four lists contain names and MusicBrainz IDs only: no searches, no playlists, no timestamps, no identifier for you. They stay in your browser while you browse. The artist lists are sent to our server on one occasion only: when you press "Surprise me", so that the artist can be chosen. The track lists are never sent as such — the recordings on them are simply named among the tracks a playlist request already asks us to leave out. We use any of this for that single response and do not store it, log it, or link it to anything. Clearing your browser's data for this site erases all of it, and "Surprise me" then simply falls back to a fixed set of well-known artists.
Outbound links to reference sites
The "Who's this" link on a track opens, in a new tab, either that artist's Wikipedia article, their Last.fm page, or — where neither exists — a DuckDuckGo search for their name. Nothing is sent to any of them before you click. Once you do, your browser contacts that site directly, so it receives your IP address under its own privacy policy, and the search engine additionally receives the artist's name as the search term.
Outbound links to music providers
Clicking a track's title opens it on a provider of your choice (Amazon Music, Spotify, Apple Music, YouTube Music, or Deezer) in a new tab. Once there, that provider's own privacy policy applies — we have no influence over it.
Saving a playlist (Soundiiz)
Only if you click "Save to …" on a finished playlist do we send that playlist to Soundiiz, operated by BRICKOFT SAS (France), so that it can be transferred into your own library. Nothing is sent before that click, and no transfer happens in the background.
What is sent: the track titles and artist names of the playlist, the playlist name (which repeats the artist or song you searched for and the discovery range you chose), the destination you selected, and the address of our own logo image. It carries no account, no login, and no identifier for you. The request is made by our server, not by your browser, so Soundiiz does not receive your IP address and cannot connect the playlist to you through this step.
Soundiiz replies with a temporary review page, which opens in a new tab. From that point you are on their site as their own visitor, and their privacy policy applies — including anything you do there, such as connecting your streaming account. That is a relationship between you and Soundiiz; we neither see nor store any part of it. The review link expires after 24 hours.
Your rights
Under Articles 15–21 GDPR you may request access to, correction of, or deletion of your personal data, or object to or restrict its processing. Contact us at the email address above. You may also lodge a complaint with your local data protection supervisory authority — for us, this is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW).