Skip to content
Fonotech — back to the top
PT

Privacy

What stays on the device, what leaves, and how to erase it.

Version of September 4, 2026.

Summary

  • Your export is read in your browser and kept on your device. It is never uploaded to any server.
  • If you agree, artist and album names go out to three outside services to fetch genre and cover art.
  • If you ask for it, a totalled copy of your library is kept in your Google account; if you don't, nothing is uploaded.
  • If you connect your Last.fm, your username — already public — leaves this device and your history comes back.
  • The “Erase my data” button clears everything on this device, at once.

What is processed on the device

The Spotify file is opened and totalled inside the browser, in a Web Worker. The result — totals per year, per month, per artist — is stored in the device's IndexedDB. The original file is not kept.

The shelf — the records you pull in the room — is a list of names kept in this browser's localStorage. It does not leave the device either, and the erase button takes it along.

What leaves the device

Only if you accept the genre and cover notice: artist names, album names and the Spotify track identifier. Nothing else. No plays, no dates, no network addresses.

  • MusicBrainz — receives the artist name and returns genre tags.
  • Deezer — receives the artist name and returns the broad genre.
  • Spotify (oEmbed) — receives the track identifier and returns the album cover.

The lookups pass through a route on this site hosted by Vercel, which only relays the question and the answer. The route stores nothing; the hosting keeps access logs under Vercel's own policy.

Last.fm (optional)

You can connect your Last.fm instead of uploading the export. There is no sign-in, no password and no authorisation: a Last.fm username is public, and it is the only thing that leaves this device.

  • What leaves — your Last.fm username, and the artist and track names whose length is looked up. Nothing else.
  • How it leaves — through a route on this site, which only relays the question and the answer and stores nothing. The Last.fm key stays on the server; the hosting keeps access logs under Vercel's own policy.
  • What comes back — your scrobble history: what played, when, from which album, with the cover art.
  • Where it sits — totalled on your device, in IndexedDB, just like the export. None of it is uploaded anywhere.
  • The hours are estimates — a scrobble does not say how long the track played; the page uses the track length. The export carries the exact time.
  • How to erase it — the “Erase” button in the Last.fm block removes only that library; “Erase my data” below takes it along with everything else.

Legal basis: consent (LGPD art. 7, I; GDPR art. 6(1)(a)). Connecting is a choice, and erasing undoes it.

The library in the cloud (optional)

You can sign in with Google and ask for a TOTALLED copy of your library to be kept — the same totals the page shows. The original file is not uploaded, and no individual play is uploaded. Without signing in, the button does not even appear.

  • What goes up — the totalled library (totals per year, month, artist and genre), plus the name and email on your Google account.
  • What does not — the Spotify file, the plays one by one, and the full lists of artists, tracks and albums.
  • Where it sits — on Supabase, on servers outside Brazil.
  • For how long — until you delete it. Keeping it again replaces the previous copy.
  • Who can read it — only you. The rule is enforced by the database: your row is readable only by your session. The person responsible for the site has technical access to the database, as any administrator does.
  • How to erase it — the “Delete my account” button, on the “Your library” page. It removes the copy and the account at once.

Legal basis: consent (LGPD art. 7, I; GDPR art. 6(1)(a)). Signing in is one choice and keeping a copy is another, and you can undo both.

The cards you share

The card image is drawn inside your browser and handed to whichever app you pick in the system sheet. It goes through no server, is not stored here and leaves no copy on the site.

Legal basis

Two bases, one for each thing. Reading your file on your device runs on consent (LGPD art. 7, I; GDPR art. 6(1)(a)): you choose to upload the file and you can erase it whenever you want. Fetching genre and covers also runs on consent, asked separately before the first lookup. Keeping the site up and defending it from abuse runs on legitimate interest (LGPD art. 7, IX; GDPR art. 6(1)(f)).

For how long

As long as you want. The data sits on your device and is erased when you press the button, clear the site data in your browser, or uninstall the app. If you kept a copy in the cloud, it stays there until you delete the account — there is no automatic expiry and no version history: keeping it again replaces the previous copy.

Your rights

The LGPD (art. 18) and the GDPR (arts. 15 to 22) give you access, rectification, portability and erasure. Here you exercise them yourself, because the data is with you:

  • Access — the whole page shows your own data.
  • Portability — the original file is yours; it came from Spotify and stays with you.
  • Rectification — process a new export and the result is replaced.
  • Erasure — the button below clears everything; if you kept a copy in the cloud, “Delete my account” removes the copy and the account.
  • Withdrawal of consent — you can withdraw it at any time: “Withdraw consent” for the genre and cover lookup, “Delete my account” for the cloud.
  • Objection — you can object to the processing, and here that means erasing what is stored and no longer using the page.
  • Complaint — you can complain to the ANPD in Brazil, or to your country's data protection authority in the European Union.

For anything the page cannot settle on its own, write to fonotechapp@gmail.com.

Cookies

Without signing in with Google there are no cookies at all — no analytics, no tracking. The site uses browser storage (IndexedDB and localStorage) only to keep your library and your theme and language preferences. After you sign in with Google, a single session cookie keeps you signed in; it is strictly necessary for that, does not track you, and goes away when you tap “Sign out” or “Delete my account”.

Who else is involved

  • Vercel — hosts the site and the two lookup routes. Its server access logs follow its own policy.
  • MusicBrainz — open music metadata database.
  • Deezer — public catalogue API.
  • Spotify — public oEmbed, for the album cover.
  • Google — only if you sign in with Google to keep the library in the cloud. It confirms who you are and passes on your name and email.
  • Supabase — only if you keep a copy in the cloud. It is where that copy and your account live.
  • Last.fm — only if you connect your Last.fm. It receives your username and returns your scrobble history.

International transfers

This site's servers are outside Brazil: hosting is Vercel, in the United States, and the optional cloud is Supabase, also outside Brazil. MusicBrainz, Deezer, Spotify and Last.fm answer from outside Brazil and outside the European Union. The LGPD (art. 33) and the GDPR (arts. 44 to 49) govern these transfers; here they rest on the same consent that authorises each processing.

Who is responsible

The data controller is the person responsible for this site, and fonotechapp@gmail.com is the channel for data protection matters. There is no separately appointed data protection officer: Brazil's ANPD Resolution 2/2022 waives the appointment for small processing agents, and the contact channel still applies (LGPD art. 41).

Minors

The site asks for no name, email or account. Brazil's LGPD (art. 14) gives data on children and teenagers special protection; the GDPR (art. 8) sets 16 as the age for consenting on your own, and each EU country may lower it to 13. Below the age that applies where you live, use it with whoever is responsible for you.

Changes

Changes take effect from the date of this version.

Erase my data

Clears the library, the genre and cover caches and this device's preferences.

How to request your historyUpload mine