Privacy and data policy
Rosso brings your music history together. We only process what the product needs and leave control with you. Below: what we collect, why, and how you delete it.
Categories of data we process
| Data | Purpose | Retention |
|---|---|---|
| Account info (email, display name) | Sign-in, session management, and contacting you. | Until the account is deleted. |
| Platform connection tokens | Spotify library access. | Until the connection is removed or the account is deleted (encrypted). |
| Listening events (play_events) | Recap, stats, and musical identity (Taste). | Until the account is deleted. |
| Spotify export ZIP files | Importing past listening data. | May be deleted after processing; at latest when the account is deleted. |
Data we don’t collect
We don’t store IP addresses. The ip_addr field in a Spotify export is not processed; it is not written to any table, log, or error record. The identity file (identity.json) is processed only during import and then deleted.
Your rights
Under GDPR you can access, correct, and delete your data. You can permanently delete your account and everything tied to it from Settings → Account. Deletion cannot be undone: listening events, playlists, platform connections, and files you uploaded are all removed.
Contact
Download a copy of your data from Settings › Download my data. To delete your account, use the account section on Settings.