Privacy
What notch.fm knows about you
This is a description of what the app actually does with your data, written from the code that does it. It is deliberately specific, including about the parts that are not flattering.
Last reviewed 2 September 2026
notch.fm and Spotify
notch.fm is an independent project. It is not affiliated with, endorsed by, sponsored by or connected to Spotify, and nothing on this site is a Spotify product or speaks for Spotify.
It is a rating and tagging layer over your own Spotify account. You sign in with Spotify’s own login, notch.fm never sees or asks for your Spotify password, and it works with the account you already have. Everything you play stays on Spotify: notch.fm has no player of its own. When you press play here it sends a command to the Spotify app or web player already signed in on one of your devices, and Spotify plays the audio, counts the stream and pays the rights holders exactly as it would if you had pressed play there. That also means playback control needs Spotify Premium, because Spotify requires it.
Spotify’s handling of your data is governed by Spotify’s privacy policy, not this one. This page only covers what notch.fm does.
What it reads from Spotify, and what each one is for
Connecting the app opens Spotify’s own permission screen. It asks for the permissions it uses and no others - and it does ask for write permissions, because saving a like and building a playlist are writes. Each row below is a permission, the Spotify data it covers, and the part of notch.fm that would stop working without it:
- Library and saved tracks
- Your Liked Songs, with their album and artist metadata. This is the raw material of the whole app: the library page, rating, tagging, sorting, the charts and the stats are all built on the songs you have saved.
- Top artists and tracks
- Two jobs. When you connect, they seed a starting score for songs you have never rated, so the library is not a wall of blanks on day one - and a seeded score is marked as seeded, is never counted as your opinion, and never feeds the community averages. After that they are re-read now and then, cached for a few minutes at a time, to put the songs you actually listen to at the front of the rating queue instead of whatever happens to be alphabetically first.
- Currently playing and playback state
- What is on right now, how far through it is, and which device is active. It is what the Now Playing screen follows, and it is how notch.fm records that you played something so the history and stats pages have anything in them.
- Playback control
- Play, pause, skip, seek and queue, issued only when you press the button on a notch.fm screen. The command goes to Spotify and Spotify does the playing; notch.fm decodes no audio.
- Playlists
- Reading your playlists, including private ones, so notch.fm can show them and use them as a source when you build one here. Creating and editing a playlist happens only when you ask for it, on the playlist you named, and never touches a playlist you did not choose. Like a save, a playlist write Spotify refuses is kept and pushed later rather than lost.
- Search
- Spotify catalogue search, run with your own account, so you can find a song, album or artist that is not in your library yet, open it, rate it or add it to a playlist. Your search text goes to Spotify to answer the search and is not kept as a search history.
- Saving to your library
- The like button writes a song to your Spotify Liked Songs. It happens when you press it, never on its own, and never in bulk behind your back. If Spotify refuses the write, notch.fm keeps it and pushes it when Spotify will accept it, so nothing you did is silently dropped - the screen says which state it is in rather than pretending it landed.
- Account basics
- Display name, email address, avatar, Spotify id, and whether the account is Premium. The last one exists so the app can say plainly that playback control needs Premium instead of failing at you with an unexplained error.
- Recently played
- Requested, and currently unused. No code in this app calls the recently-played endpoint: the history and stats pages are built from plays notch.fm observed itself through Now Playing. It is listed here because the permission screen will show it to you and a page that quietly omitted it would be lying by arrangement.
What notch.fm never does with Spotify data
- No audio is downloaded or stored. Not tracks, not previews, not clips. There is no audio player and no audio file anywhere in this app. Album art is shown from Spotify’s own image links rather than copied onto these servers.
- No model is trained on it. notch.fm trains nothing, on anybody’s data. Where a third-party model is used it is called through an API under commercial terms that state inputs and outputs are not used to train it, and the exact sends are itemised below.
- It is not mixed with other music services. Spotify is the only music service notch.fm connects to. Nothing here combines Spotify content or metadata with Apple Music, Tidal, Deezer, YouTube or anything else, and there is no code that could.
- Your Spotify tokens never reach the browser. They are encrypted before they are stored and are used only by the server, so no page in this app has ever held one. They are not shared with, sold to or sent to any third party, ever.
- Nothing is sold, and there is no advertising. No data broker, no ad network, no audience list, no profile of you sold on to anyone.
Turning it off
You can review or revoke notch.fm’s access at spotify.com/account/apps. It is your switch, not one this app can hold shut.
- Revoking takes effect immediately. notch.fm can no longer read your library, see what is playing, control playback or write anything to your account.
- The stored tokens stop working, because Spotify stops honouring them. Nothing here can quietly keep reading.
- Any save or playlist edit still waiting to reach Spotify stops waiting. It stays in your notch.fm library, and it lands on Spotify only if you reconnect.
- What you made in notch.fm - your ratings, tags, notes and local playlists - stays in your notch.fm account, so reconnecting picks up where you left off. If you want that gone as well, export it and then delete the account: both are below.
What it stores
- Your ratings
- The score you gave each song, with a revision history, so a chart can tell a considered change of mind from a mis-tap.
- Your tags
- The genre, mood, vibe, sound and custom tags you put on songs, and any tag names you coined.
- Your library, cached
- Track, album and artist metadata copied from Spotify - names, artwork links, release dates, durations - so the app can search and sort without asking Spotify on every keystroke. Metadata only: no audio, and no artwork files.
- What you played here
- notch.fm counts plays it saw itself while Now Playing was watching. It does not import your Spotify listening history.
- The social parts
- Your profile, who you follow, comments you post, superlikes, playlists, XP, level and badges.
- Spotify tokens
- Encrypted with AES-256-GCM before they touch the database. They are never sent to the browser, so no page in this app has ever held one, and they are never shared with a third party.
- Your session
- A signed token in an httpOnly cookie, valid for 30 days. JavaScript on the page cannot read it. See the cookies page.
- Billing
- Your plan and the subscription identifiers attached to it. Card numbers are never sent to notch.fm and are never stored by it.
What leaves this app
There is no analytics, no advertising and no tracking of any kind - no third-party scripts run on these pages. These services see data, and they see different things:
- Spotify
- Obviously - it is your library, and every playback command, search and write goes to them. Their handling of it is governed by their privacy policy, not this one.
- Anthropic (smart search)
- When you type a sentence into the search box, that sentence is sent to Anthropic’s API to be translated into a filter. Only the words you typed go - not your library, not your ratings, not your name. The model returns a filter object; your own database does the searching, which is why a hallucinated song title can never reach your results.
- Anthropic (notchbot)
- Asking notchbot a question about your own library is a bigger send, and it should be stated as one: a summary goes with the question - your display name, how many songs you have saved and rated, your average score, how many tags and playlists you have, your level, and your top artists and most-used tags with their counts. Individual songs, your email and your tokens are not included. Nothing sent is used to train a model.
- Ticketmaster
- The Concerts tab looks up tour dates by artist NAME. Opening that tab enrols the artists you have rated highest, and from then on their names are looked up on a schedule. The artist name is all that goes: never your name, never your Spotify id, and nothing that says whose watchlist it came from. If you never open the tab, nothing of yours is enrolled.
- Stripe
- Only if you subscribe. Stripe takes the payment and notch.fm receives the plan status back. Your card details go to Stripe directly and are never sent to notch.fm.
What other people can see
- Your profile, and anything you publish - comments you post and playlists you choose to make public.
- Community averages, only if you opt in. Settings → Preferences has a “Contribute to community averages” switch. While it is on, the ratings you set yourself are added into the aggregate scores behind the charts. Only your own ratings ever count - never the ones the app seeded for you - and the aggregate is a running total with no link back to who contributed what. Turn it off and your contribution is subtracted again.
- Nothing about your Spotify account, unless you publish it. Your email, your Spotify id and what you are playing right now are not on your public profile. Settings → Privacy chooses how findable you are at all, down to a mode where nobody can open your profile but you.
What the paid plan buys
Premium buys notch.fm’s own features and nothing else: it is not a way to pay for Spotify content. It lifts the caps this app imposes - unlimited rated songs and tags, unlimited playlists, publishing them, posting comments, the badge and level track, more superlikes, and uncapped smart search - and that is the whole of it.
It does not unlock anything on Spotify’s side, does not include or replace a Spotify subscription, and gives you no access to Spotify content you did not already have. Music, playback and streams stay entirely with Spotify and your own account with them. Paying here changes nothing about what Spotify lets you do.
Getting it all back
Settings → Your data → Export everything (JSON) gives you one file containing every rating and its revision history, every tag you applied, every like and playlist held locally, and the track metadata needed to read them. It is not behind the paywall and never will be - the ratings are the irreplaceable part, and an export you have to pay for is a hostage.
Deleting it all - including what survives
Settings → Danger zone → Delete account. You type a confirmation phrase, and it is a hard delete inside a single transaction: your account, your encrypted Spotify tokens, your ratings and their revisions, your tags, your play history, your sync state, your profile and your subscription all go. There is no soft delete, no thirty-day grace period, and no undo. Export first.
Two things deliberately do not go, and you should know before you press it:
- Comments are tombstoned, not removed. A comment stops being attributed to you, but the text stays where it is. Deleting an account should not silently delete half of other people’s conversations. Delete the comments you care about before you delete the account.
- A tag name other people use stays. If you coined a tag and nobody else has ever used it, it is deleted with you. If other people have adopted it, the tag survives - with no link to you - because removing it would strip it off their songs too.
One more, for completeness: if you contributed to community averages, the totals your ratings fed keep those numbers. They are sums and counts with no identity attached, and there is no row left that says they were ever yours.
Deleting your notch.fm account does not touch your Spotify account or anything in it. Songs you liked and playlists you built through notch.fm were written to your Spotify library and stay there; they are yours, and this app removing them on the way out would be vandalism. Revoke access separately at spotify.com/account/apps.
Who runs this, and questions
notch.fm is built and run by one person, as an independent project. It is not a registered company, so there is no corporate entity behind it to name and none is claimed here.
Privacy questions go through the contact page, which takes a message and an address to reply to without needing an account. There is deliberately no email address published here: an unmonitored inbox would be a worse answer than a form somebody reads.
Contact lists what you can do yourself and what to include if something here does not match what you are seeing. The cookies page covers what is stored in your browser rather than on the server, and terms covers the deal itself.