Cookies

One cookie, and a few remembered preferences

There is no banner on this site because there is nothing to ask you about. notch.fm sets exactly one cookie, it is the one that keeps you signed in, and the rest of this page is the complete list of everything else it puts in your browser.

Last reviewed 2 September 2026

The cookie

notch_session
A signed token that says which account this browser is signed in to. It is httpOnly, so no JavaScript on the page can read it - including any script that ever managed to get onto it - and SameSite=Lax, so it is not sent along with requests started by other sites. It lasts 30 days, and over HTTPS it is marked Secure.

It is strictly necessary in the real sense of the phrase: without it there is no way to know whose ratings to show you, so signing in is impossible. It carries no advertising identifier and is not shared with anyone.

It is not a Spotify token and it does not contain one. Your Spotify access and refresh tokens stay on the server, encrypted, and are never written to a cookie or to any browser storage. No page in this app has ever held one.

Kept in your browser, not on the server

These are not cookies - they are never sent with a request - but they are stored on your device, so they belong on this page:

notch.panelAlpha
How transparent you set the glass panels.
notch.visualizer
Whether the ambient background visualiser is on.
notch.hotkeys
Whether single-key shortcuts are enabled.
notch.now.tab
Which tab you last had open on Now Playing, so it is still there when you come back.
notch.now.last-track
The last song Now Playing showed you, so the screen has something on it while it waits for Spotify to answer rather than flashing empty. It is the same metadata already on the screen - title, artists, album and the artwork link - and no audio. Spotify’s answer replaces it the moment it arrives.
notch.rate.*
How you left the rating screen set up: the order, the album or playlist you were working through, and whether it plays the next song automatically. Keyed by your account id, so two people sharing a browser do not inherit each other’s view.
notch.trail
The breadcrumb trail of how you got to the page you are on. Stored for the tab only - closing it forgets.

The one that does leave

notch.logSession
A random id for this browser tab, sent to notch.fm’s own API on each request so that “it broke, I refreshed, it broke again” can be found in the server log as one story. It is stored for the tab only, so it is gone when you close it, and it is deliberately not in longer-term storage: an id that survived for months would be a durable way to recognise you, which is more than a bug report ever needed. It goes nowhere but this app’s own server.

What is not here

No analytics, no advertising, no tracking pixels, no third-party scripts. Nothing on these pages measures you, and nothing loads from a domain other than this one. That is why the list above is exhaustive rather than a representative sample.

There is no advertising cookie, no cross-site identifier and no fingerprinting attempt on any of these pages, in either configuration.

Signing in with Spotify

notch.fm is an independent app and is not affiliated with or endorsed by Spotify. Connecting your account sends you to Spotify’s own login on Spotify’s own domain, which sets Spotify’s own cookies as part of signing you in. That is between you and Spotify: their cookie policy covers it, and notch.fm can neither read those cookies nor set any of its own on a Spotify domain.

Album art on these pages loads from Spotify’s image servers, because that is where the artwork lives and copying it here is not something this app does. Links that offer to open something in Spotify take you there when you click them. Beyond those two, nothing on a notch.fm page is fetched from Spotify by your browser, and no Spotify script runs on it.

You can disconnect notch.fm from your Spotify account at any time at spotify.com/account/apps. The privacy page says exactly what stops when you do.

Clearing them

Log out
Clears the session cookie in this browser.
Sign out everywhere
Settings → Security. Invalidates every session token already issued for your account, not just this browser’s - the right move if you signed in on a device you no longer have.
Clear site data
Your browser’s own setting. Removes the cookie and everything listed above. Nothing you rated is stored in the browser, so nothing you rated is lost.
For what is stored on the server rather than in your browser - your ratings, your tags, your encrypted Spotify tokens - see the privacy page.