Home

Privacy and data policy

Rosso brings your music history together. We only process what the product needs and leave control with you. Below: what we collect, why, and how you delete it.

Categories of data we process

DataPurposeRetention
Account info (email, display name)Sign-in, session management, and contacting you.Until the account is deleted.
Platform connection tokensSpotify library access.Until the connection is removed or the account is deleted (encrypted).
Listening events (play_events)Recap, stats, and musical identity (Taste).Until the account is deleted.
Spotify export ZIP filesImporting past listening data.May be deleted after processing; at latest when the account is deleted.

Data we don’t collect

We don’t store IP addresses. The ip_addr field in a Spotify export is not processed; it is not written to any table, log, or error record. The identity file (identity.json) is processed only during import and then deleted.

Your rights

Under GDPR you can access, correct, and delete your data. You can permanently delete your account and everything tied to it from Settings → Account. Deletion cannot be undone: listening events, playlists, platform connections, and files you uploaded are all removed.

Contact

Download a copy of your data from Settings › Download my data. To delete your account, use the account section on Settings.