Privacy Policy
Last updated: July 31, 2026
Cosign (“we”, “us”) lets you upload your Spotify listening history to see how early you discovered artists who later blew up, and to compare with others. This policy explains what we collect, why, and your choices. We’ve kept it plain.
1. Data you give us
- Spotify listening history (your upload). When you upload your Spotify Extended Streaming History, we read artist names, track names and identifiers, the first time you played each, and how often and how long you played them. We store the derived per-artist first-play dates, play counts and scores; and, for songs you first played recently, the track name and identifier, artist name, first-play time and play count (up to 500 songs per upload) — these song rows power the “songs taking off” feed.
- The export file itself. After a successful score we keep a private copy of your export so we can rebuild your score as our scoring improves, without asking you to re-request it from Spotify. It is stored in a private bucket, is never made public or shared, and is deleted when you delete your account (see Retention).
- Monthly listening aggregates. For each artist, per calendar month, we store how many plays you had, how many plays including tracks you skipped before 30 seconds, and the total time you spent listening — plus which months your uploads cover. This is what lets us show how your listening to an artist grew or faded over time.
- Sign-in account. When you sign in with Google we receive your display name, email, and profile image. We hold no provider access tokens — sign-in is identity-only.
- last.fm username (optional, Pro). If you connect a last.fm username we read your public scrobbles to verify your open cosigns. Username only — no last.fm login, no tokens; disconnect any time in Settings.
- Your profile. A display handle you choose, the scores, rankings, calls, and picks we derive from your data, the people you follow, and — where a song we showed you in a discovery reel later appears in your upload — a record linking that recommendation to your play (the song and when you played it). We use that record to measure whether our recommendations work, including for sponsored placements; only aggregate counts are shared with any sponsor.
- Optional profile details you add. Social handles (Instagram, X, TikTok) and a self-declared school — both shown on your public profile, both removable in Settings.
- School email (optional). If you claim the “verified student” tick you give us a school-domain email address so we can send a one-time 6-digit code. We never store that address — only the fact that the check passed.
- Artist profile (artist plan). If you claim your artist page on the paid artist plan, the profile you submit — bio, links, location, and label status — appears on your public artist page, and your business contact is shown to customers of our label product so they can reach you. That is what it exists for. Edit or remove any of it in your dashboard at any time.
- How you found Cosign. Your one-tap answer to “how did you hear about us?”, plus the referring site, landing page and any campaign tags recorded on your first visit. We use it for acquisition analytics only.
2. Data we collect automatically
- A small set of essential first-party cookies for sign-in: a session cookie that keeps you signed in, plus the CSRF and callback-URL cookies our auth library sets, and two short-lived cookies (15 minutes) used only during the Google sign-in redirect. We also keep a few small values in your browser’s local storage: your analytics choice, and referral/first-visit details (which link or site brought you here), which are attached to your account if you go on to sign up. We use no advertising cookies.
- Privacy-friendly analytics. We use Vercel Web Analytics to count page views and a few basic in-app events — an upload completing, opening the export guide, and viewing or clicking an invite link (an invite event includes the public profile id of the person who invited you, so we can measure referrals). It is cookieless: it sets no cookies, does not collect your name, email or listening data, builds no profile of you, and doesn’t track you across sites. It runs by default because it cannot identify you. We use no advertising or cross-site trackers of our own.
- Embedded Spotify player. Some pages embed Spotify’s own player (an iframe from open.spotify.com) so you can preview a track. When that player loads, Spotify may set its own cookies and receives your IP address and the track you are viewing, under Spotify’s privacy policy. We neither control nor receive that data.
- Optional second analytics provider (opt-in). If we ever enable Plausible — also cookieless — it runs only after you allow it via the consent banner, and you can change your choice anytime via “Analytics preferences” in the footer. It is not enabled today, so that banner does not appear.
- Server logs and rate-limiting. Basic server logs (request times, errors) for security and reliability, plus your IP address, which we store as a rate-limiting key in our database to stop abuse (upload flooding, scripted requests). Counts of distinct IPs are also used internally as a rough visitor metric. We do not link these keys to your account or to your listening data.
- Referral and campaign data. When you first arrive we record which site referred you (host and path, query string stripped), the page you landed on, and any utm_* tags in the link. It is stored without your IP or account id and is used only to see which channels bring people to Cosign.
- In-product usage events. When you browse the song reel we record which tracks were shown to you, whether you started a preview and roughly how many seconds you played, and taps on “open”/“embed” links. These are stored in our own database, linked to your account when you’re signed in, and are used to measure the feed and to report anonymized play counts to artists or sponsors whose tracks were featured.
3. How we use your data
To compute and show your Cosign score, early calls, medals, and picks; to run the public leaderboard and following; to verify your cosigns against your uploads (and, if connected, your public last.fm scrobbles); and to keep the service secure. We never sell your personal data. We use listening data in aggregated, de-identified form to power Cosign’s own features — artist trend statistics and internal models that surface emerging artists. We do not use your data to train generative-AI or third-party models.
Two different rules cover reporting to people outside Cosign, and it matters which one applies:
- Your non-public listening data — your raw history and the monthly listening aggregates above. External research and industry reporting draw on this only as anonymized aggregate statistics: never record-level, never identified, and never attributed to you. A figure is published only when enough different people sit behind it that no individual can be inferred — both across the whole dataset and within each individual number — and it is withheld entirely otherwise. Statistics of that kind describe a crowd, not a person. You are included by default; setting your profile to private, or turning off Anonymized industry stats in Settings, removes you from these figures entirely going forward.
- Your public profile — the handle, score and early calls that already appear on the leaderboard (see What is public). Because these are public, an individual early call can appear in artist-level reporting as described in Who we share with. If you don’t want that, set your profile to private in Settings and you are left out of it entirely.
4. What is public
Cosign is a public leaderboard. Your handle, score, medals/standings, early calls, recent picks, any social handles (Instagram / X / TikTok) you add in Settings, your school if you set one, and your follower and following lists are visible to anyone — not just the counts: anyone can open the full list of who follows you and who you follow. Social handles and school are optional; leave them blank and nothing is shown. If you set a school, it and any “verified student” tick also appear on that school’s public leaderboard at /schools/…, alongside your handle and score. Clear your school in Settings to remove yourself, or set your profile to private — private profiles are left off school boards entirely. Your email and raw listening history are never public. Don’t upload anything you wouldn’t want associated with your handle.
Email is used for sign-in; for a small number of service emails; and, only if you opt in (Settings → “Monthly recap email”), a once-a-month recap of your score, rank and streak. Service emails: if you sign in but never upload an export, we send you one reminder about five days later (plus one follow-up if you tell us your export still hasn’t arrived); and, if you ask for the verified-student tick, a one-off 6-digit code sent to the school address you supply. Every recap and reminder carries a one-click unsubscribe; unsubscribing stops them permanently, and opting out of the recap deletes the send token immediately.
5. Who we share with
We share data only with providers that help us run Cosign:
- Google — for sign-in (governed by Google’s own privacy policy).
- last.fm — public scrobble reads, only if you connect a username (governed by last.fm’s own privacy policy).
- Public artist data — artist-popularity figures (monthly listener counts and their history) come from public sources we collect ourselves, including public artist pages and the Internet Archive. This involves artist data, not your personal data.
- Our hosting/infrastructure provider — stores the app’s data.
- Stripe — payment processing for all paid plans (Cosign Pro, the artist plan, and label seats); receives your email address and handles your card details directly (we never see them).
- Resend — our email provider; receives your email address and the contents of any email we send you (the monthly recap, an export reminder, a school verification code), solely to deliver it.
- Artists and sponsors whose tracks we feature — receive aggregate counts of how a track performed in the song reel (impressions, previews, clicks, and plays we can attribute): never your identity, email, or listening history.
- Industry partners (labels, artists, researchers) — including paying customers of Cosign for Labels, who see these statistics in a dashboard — may receive artist-level statistics and individual early-call records: the artist called, the month it was called, and how early. This is built from your public profile — the same early calls anyone can already see on your page — never from your non-public listening data, which leaves Cosign only as anonymized aggregate statistics over at least 5 people (see How we use your data); you are included in those by default and excluded, going forward, the moment you set your profile to private or turn off Anonymized industry stats in Settings. Records appear under a pseudonymous scout code, which is not a guarantee of anonymity: handles are public, so someone with the leaderboard could match a code back to you. A scout is shown by handle only if they opted into the public scout directory. Private profiles are excluded from these reports entirely. We never share your email or your full raw listening history.
We may disclose data if required by law.
6. Legal bases (EEA/UK)
We process your data based on your consent (you choose to upload, to opt into the recap email, and to connect last.fm); performance of our contract with you (running and billing a Cosign Pro or artist subscription, via Stripe); and our legitimate interest in operating and securing the service — which includes producing genuinely anonymized aggregate statistics (minimum 5 people behind every figure; they describe a crowd and identify no one). Your listening is included in those aggregates by default; an explicit objection is honored everywhere — turn off Anonymized industry stats in Settings or set your profile to private, and you are excluded going forward. You can likewise withdraw a specific consent at any time in Settings — turn off the Monthly recap email, disconnect last.fm, or remove your school and social handles — or withdraw everything by deleting your account. Withdrawal and objection apply going forward: anonymized aggregates and dated research snapshots already produced are not retrospectively rebuilt.
7. Retention
We keep your data until you delete your account — including the export file you upload, stored privately so we can rebuild your score as our scoring improves without asking you to re-request it from Spotify. Deleting your account (on your profile, under Account → Delete account) removes your submission, derived listening data, stored export files, picks, and follow relationships from our store.
8. Your rights
- Access your data — it’s shown on your profile.
- Correct your handle — Account → edit username.
- Delete your account and data at any time — Account → Delete account.
- Withdraw consent — sign out and delete your account.
Depending on where you live (e.g., the EEA/UK under GDPR, or California under CCPA/CPRA) you may have further rights, including requesting a copy of your data or lodging a complaint with your data-protection authority. We do not sell personal information. To exercise any right, email privacy@cosigned.fm.
9. Children
Cosign isn’t for anyone under 13 (or under 16 where required by local law). We don’t knowingly collect data from children.
10. Security
We take reasonable measures to protect your data, but no method of storage or transmission is perfectly secure. Cosign is an early-stage product — please don’t treat it as a vault.
11. International transfers
We may process and store data in the United States and other countries whose data-protection laws may differ from yours.
12. Changes
We may update this policy; we’ll change the date above and, for material changes, do our best to notify you.
13. Contact
Questions or requests: privacy@cosigned.fm.
Cosign is not affiliated with, endorsed by, or sponsored by Spotify AB. See also our Terms of Service.