Skip to content

VireMusic · Legal

Privacy Policy

Last revised: July 5, 2026draft — not legal advice

01What Data We Collect

When you sign up via Yandex (OAuth), we receive:

  • your email address;
  • your display name;
  • your avatar URL (we store the link; the image itself is not copied).

When you sign up by email (password or magic link), we receive only your email address.

If you upload your own avatar, the image is stored in our file storage (S3).

When you presave an announced release without signing in, we receive only the email address you provide for the release notification.

As you use the Service, we record:

  • track likes (track_id + user_id);
  • playlist likes (playlist_id + user_id);
  • artist follows (artist_id + user_id);
  • the playlists you create and their contents;
  • release presaves: user_id for registered users, or email for guests;
  • play events: track_id, an anonymous session_id, date/time, duration, and playback source. A user_id is attached only for registered users;
  • favorite moments on a track (timestamp + anonymous session_id; user_id only for registered users);
  • the “listening now” presence signal — an anonymous session_id kept in in-memory storage (Redis), never retained longer than 45 seconds of inactivity;
  • mood tags and genres assigned to a track (by the track's owning artist only).

02How We Use the Data

  • Authenticating and identifying you within the Service.
  • Building your personal follows feed.
  • A taste profile for the track-recommendation algorithm (“Wave”) — aggregated from your listening and like history (track mood tags and genres) to generate personal recommendations.
  • Notifying you about a release you've presaved, and automatically adding the release to your likes on release day.
  • Analytics for artists: play counts, unique listeners, day-by-day trends.
  • Ensuring security and preventing abuse (including rate-limiting requests by IP address).

03Sharing Data with Third Parties

We do not sell or share personal data with third parties for advertising or commercial purposes.

Data may be shared only:

  • with infrastructure providers (hosting, file storage, email delivery) — to the extent necessary to operate the Service;
  • at the request of authorized government bodies, in cases established by law.

04Cookies, Browser Storage, and Analytics

We use essential cookies — an Auth.js session token for user authentication.

To collect site traffic statistics, the platform uses Yandex.Metrica (JSC “Yandex”, Russia). Metrica collects:

  • data on pages viewed, referral sources, and time spent on the site;
  • click maps and scroll maps (clickmap);
  • session recordings — Webvisor (mouse movement, clicks, scrolling). Webvisor does not capture input into form fields (passwords, emails).

This data is processed by Yandex in accordance with Yandex's privacy policy. We do not share personal data (email, name) with Yandex — only browser session behavioral data.

localStorage is used to store player state (playback queue, volume, track position) and interface preferences (for example, whether you've dismissed a banner). This data stays in your browser and is never sent to our server.

05Data Storage and Deletion

Data is stored on servers in Russia (Timeweb Cloud VPS). Files — cover art, audio files, avatars — are stored in S3-compatible storage on the same infrastructure.

To delete your account and the personal data associated with it, use the feedback form. We will process your request within 14 days.

After account deletion, anonymized play events (without a user_id) may be retained in aggregated statistics.

06Security

We apply standard technical safeguards: HTTPS, an httpOnly session cookie, and files stored in a private S3 bucket accessible only via signed URLs.

07Changes to This Policy

We will notify users of material changes to this Privacy Policy by email or via an in-Service notification.

08Contact

For questions about the processing of personal data: feedback form