This Privacy Policy explains how SamePlaylist accesses, collects, uses, stores, and shares information when you use sameplaylist.com and its Google and YouTube integrations. SamePlaylist is an independent service and is not affiliated with or endorsed by Google or YouTube.
1. Google and YouTube services we use
SamePlaylist uses Google OAuth and the YouTube API Services. When you choose to connect your account, Google shows you the permissions requested by SamePlaylist and you decide whether to grant them. SamePlaylist currently requests basic Google account information and read-only YouTube access using the youtube.readonly scope.
By using features powered by YouTube API Services, you are also subject to the YouTube Terms of Service. Google's handling of information is described in the Google Privacy Policy.
2. Information we access and collect
Google account information
- Your Google account identifier, email address, display name, and profile picture made available through Google OAuth.
- SamePlaylist does not receive or store your Google or YouTube password.
YouTube API data
- Your YouTube channel identifier and channel profile information when available.
- Playlist metadata and playlist items that you authorize SamePlaylist to read, including user-created playlists, Liked videos, and Uploads where available.
- Video metadata needed for SamePlaylist features, such as YouTube video IDs, titles, descriptions, thumbnails, and category information.
SamePlaylist account and usage data
- Your SamePlaylist nickname, locally stored avatar, playlists, imported videos, custom playlist names or thumbnails, recommendation source selections, generated recommendations, registration time, and related counters.
- Essential session and OAuth-state cookies used to keep you signed in and protect the authentication flow.
- Encrypted Google OAuth access and refresh tokens when Google provides them. Server-side session tokens are stored in hashed form.
3. How we use information
We use this information only to provide and secure SamePlaylist features, including signing you in, letting you preview and import authorized YouTube playlist data, displaying your SamePlaylist profile and playlists, playing YouTube videos, generating recommendations, maintaining your session, and preventing abuse.
SamePlaylist's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
4. What becomes public
SamePlaylist is designed around public profiles and shared music discovery. Your SamePlaylist nickname, avatar, imported playlist names and thumbnails, imported video metadata, playlist membership, and related public counters may be visible to other visitors. Your Google email address, Google account identifier, OAuth tokens, and session credentials are not displayed publicly.
5. Sharing of information
We do not sell Google user data. We do not use Google user data for advertising. Information may be transmitted to Google or YouTube as necessary to use their authentication and API services, and to infrastructure providers that are necessary to operate SamePlaylist. We may also disclose information when required by law or when reasonably necessary to protect users, SamePlaylist, or the public.
6. Cookies and local storage
SamePlaylist uses essential cookies for authentication, OAuth state validation, and session management. These cookies are required for account features. SamePlaylist does not need advertising cookies to provide the service.
7. Data security
We use reasonable technical measures intended to protect stored data. OAuth tokens are encrypted at rest by the application, session tokens are stored server-side in hashed form, and uploaded avatars are normalized and stored locally by SamePlaylist. No method of storage or transmission is completely secure, so absolute security cannot be guaranteed.
8. Retention, revocation, and deletion
We retain account information and imported SamePlaylist data for as long as needed to provide the service, comply with legal obligations, resolve disputes, and protect the service. Authorization tokens are retained only while needed for the features you authorized.
You can revoke SamePlaylist's access to your Google/YouTube data at any time from your Google Account's third-party connections or security settings. Revoking access stops future authorized API access, but it does not automatically delete information that was already imported into SamePlaylist.
To request deletion of your SamePlaylist account and stored personal data, contact the SamePlaylist developer using the developer/support contact information displayed on the Google OAuth consent screen. After verifying the request, we will delete or anonymize data that we are not required to retain by law.
9. Children
SamePlaylist is not directed to children who are below the minimum age required to independently consent to online services in their jurisdiction. Do not use SamePlaylist if you are not legally permitted to do so.
10. Changes to this policy
We may update this Privacy Policy when SamePlaylist features or data practices change. The effective date at the top of this page will be updated when material changes are published.
11. Contact
For privacy questions, access requests, or deletion requests, use the developer/support contact information published for SamePlaylist on the Google OAuth consent screen.