Skip to content

Side B · Legal

Privacy Policy

Last updated: 2026-08-03

The short version

Goat Music is a place to rate albums and follow people whose taste you trust. We collect what we need to run the service, we don't sell your data, and you can delete your account at any time. Clearly labelled contextual or affiliate placements may appear; optional analytics and ads measurement require consent.

Who we are

Goat Music ("we", "us") is a music product operated by Puya Ventures LLC. Production is hosted at www.goatmusic.me. If you have a privacy question, email privacy@goatmusic.me.

Information we collect

The categories below cover the information used to run your account, provide the features you choose or use, personalize Discover, and protect the service:

  • Account identity. When you sign in with an enabled provider such as Google, Apple, or SoundCloud, the provider sends us a stable identifier, your display name, your email address, and a profile picture URL. We never receive your password. Spotify sign-in is currently limited to previously connected or allowlisted accounts.
  • Music-service tokens. For connected music services, we may store an OAuth access token and refresh token so the app can perform the feature you request. Scopes vary by service and may include library or playback reads; Spotify export and playback features may also request playlist or playback write access. We use those permissions only for actions you initiate in Goat Music.
  • Content you create. Album boards, ratings, reviews, tier-list placements, your chosen username, and your privacy preferences (public vs. private profile). Track ID requests include any title or context text you type alongside the clip.
  • Search and import details. When you search Goat Music, we receive the words you submit and the type of music result you request. We send catalogue searches to our active search provider (Spotify in the current release) and cache a provider-, result-type-, and lowercased-query key in server memory. A cached result is eligible for reuse for 10 minutes. An expired key is not served, but it can remain in process memory until that query is requested again or the server instance ends. Our application logger removes query strings; hosting-platform and provider handling is governed by their configurations and terms. If you use the optional Discogs preview, we receive the Discogs username and personal access token you enter, hold them in request memory, and forward them to Discogs. We do not write either value to the Goat Music database, but Discogs and infrastructure providers may process request records under their own terms.
  • Discover activity. We record the type and identifier of a Discover item and actions such as viewing, tapping, adding, following, rating, or dismissing it. A dismissal can also include a short reason. Signed-in activity is associated with your account. Its session or dismissal identity field uses a one-way account-scoped identifier rather than the anonymous cookie. Eligible signed-out website activity is associated with the anonymous gm_did cookie. Requests without an account or valid device identifier do not create an interaction row, and we do not store a raw IP address as a Discover session identifier.
  • Website concert location. On signed-in website Discover pages, we may infer location from IP-based hosting headers and combine it with up to three artists derived from your highly rated albums to find nearby concerts. This website-only enrichment is not enabled for native Discover requests. Ordinary API requests, including native requests, can still supply an IP address to our hosting provider and operational security logs.
  • Operational logs. Standard server logs (IP address, user agent, request path, status code, latency) retained in active systems for diagnostics and abuse prevention for up to 30 days under our application logging policy. Hosting and other providers may separately process request metadata under their configurations and terms. Web errors may be forwarded to Sentry when that integration is configured. The web integration strips designated personally identifying fields before forwarding. Disaster-recovery backups may persist for up to 90 days.

How we use it

  • To authenticate you and keep your session alive.
  • To render your album board, your ratings, your reviews, and your public profile (if you've enabled one).
  • To personalize Discover from your ratings, interactions, and dismissals and, on the signed-in website only, to find potentially relevant concerts near an IP-inferred location.
  • To call the music services you connected (e.g. fetching what you're currently playing on Spotify).
  • To run the optional Track IDs automatic match: we send the public URL of your uploaded snippet to our recognition partner so they can return title and artist metadata (see Track ID audio snippets).
  • To keep the service running — debugging errors, monitoring performance, and stopping abuse.
  • To send account or service messages and, when you explicitly join a waitlist or enable a digest, the updates you requested. You can unsubscribe from optional messages.

We do not sell or rent your personal data. We do not build targeted advertising profiles from your ratings. Goat Music may show contextual, house, or affiliate placements and record impressions or clicks; optional third-party analytics and ads measurement run only after consent.

Third-party services

Goat Music depends on a small set of third parties. The entries below describe what we send or allow them to process when the relevant feature or configuration is active. Their own terms can also govern their handling.

  • OAuth providers (currently Google, Apple, and SoundCloud for public sign-in; limited Spotify access for existing or allowlisted accounts): handle sign-in and grant the scopes shown during authorization. Your relationship with each provider is governed by their respective privacy policies.
  • Last.fm integration (optional): if you enter a public Last.fm username, we use Last.fm's public, read-only endpoints to import that profile's top albums into Goat Music. This does not verify that you own the Last.fm profile or link its account. Matched albums are kept separate from verified personal listening history and are not shown as your listens. We fetch this public data only during an import you explicitly trigger; we do not receive or store Last.fm credentials and do not continuously read the profile after the import completes. Removing the imported profile deletes its Last.fm-sourced albums from your Goat Music account. Your use of Last.fm is also governed by Last.fm's privacy policy.
  • Catalogue search (Spotify in the current release): receives the search terms and music-result types you submit so it can return albums, artists, and songs.
  • Discogs import (optional): receives the username and personal access token you submit for a collection preview. Goat Music does not write either value to its database; after you confirm an import, we store the selected matched album identifiers, resulting board activity, and an import-job result with counts and limited error details.
  • Ticket discovery (signed-in website only): configured Ticketmaster and SeatGeek searches can receive an artist query plus IP-derived latitude and longitude. Dice receives the artist query; Goat Music applies the location filter to Dice results itself. The native app tells our server not to perform this concert enrichment, so native Discover does not trigger these provider requests.
  • Social cross-post connectors (Bluesky, Mastodon, and Threads; not all connectors are currently available): when you opt in, we store the credential needed to publish the posts you request. Disconnecting immediately deletes Goat Music's credential. If the provider does not allow Goat Music to revoke the remaining authorization with the credential it issued, we show you the provider-side settings step.
  • Hosting (Vercel and a managed Postgres provider): run the application and store the database that holds your account and ratings.
  • File storage (Vercel Blob) stores profile photos you upload and short audio files you attach to Track ID requests. Files are served from a public URL so other listeners can play the clip in the browser.
  • Error monitoring (Sentry): the web deployment can send errors when its integration is configured. Errors can include a stack trace and request metadata; the web integration strips personally identifying fields before forwarding. The mobile Sentry library is packaged in the current candidate but has no mobile DSN and returns before SDK initialization, so that candidate runtime does not activate Sentry. Packaged library declarations still have to be reconciled in the store privacy reports.
  • Consent-gated product measurement Vercel Analytics and Vercel Speed Insights load only after you accept optional measurement. Before a Vercel Analytics event is sent, its URL field is replaced with a fixed page category; query strings, fragments, usernames, and record IDs are not sent in that field. Custom event properties pass through event-specific, fixed-value allowlists; other call-site properties are not forwarded.
  • Separately switched third-party tracking Ahrefs Web Analytics, the Google AW/GA4 tags, and configured programmatic ad-network scripts (EthicalAds, Newor Media, or AdSense) are disabled by default. They load only when we explicitly enable a deployment switch and you have also accepted optional measurement. If enabled, these browser tags receive the current page URL and referrer; they may also receive browser, device, approximate location, traffic-source, and conversion information. Ahrefs is cookie-free but stores page and referrer URLs. We have not established a bounded storage or reporting lifetime for its Web Analytics history. Google tags may use browser identifiers. From June 1, 2026, Google Ads says hourly, daily, and weekly reporting data is available for 37 months; monthly, quarterly, and annual reporting data is available for 11 years. GA4 event retention is controlled separately in the Google Analytics property. A configured ad network can also read page information available to its browser script and handles it under that network's policy.
  • First-party anonymous funnel counts A cookieless beacon records only an allowlisted event name, a fixed coarse page category, and a server timestamp. It does not include an account identifier or raw path. Because the beacon is anonymous, these are directional aggregate counts rather than proof of unique people, and we do not use them for billing, security, or account-level decisions.

Track ID audio snippets

Track IDs lets you upload a short audio clip so the community (and an optional automatic recognizer) can help identify the song. By posting a clip you understand that:

  • The file is stored on our infrastructure (Vercel Blob) and is reachable at a public URL so others can listen.
  • When automatic recognition is turned on for the deployment, we send that same public URL to AudD so they can analyze the audio and return metadata (title, artist, identifiers). We do not send your password or unrelated listening history to AudD — only the clip you chose to upload for that request.
  • You should upload only brief excerpts you are allowed to share, for identification purposes — not full commercial recordings.

Cookies

We use the following cookies to operate the service:

  • Session & auth cookies (strictly necessary): NextAuth session token, CSRF token, and short-lived OAuth state cookies during sign-in. These are required for authentication and cannot be disabled without breaking the service.
  • gm_did (functional): a pseudonymous device identifier set on your first visit unless you decline optional cookies (180-day lifetime). It supports signed-out Discover personalisation, pending quick-rating handoff, and first-party source attribution. Depending on the flow, related records may later be associated with your account after you sign in. The cookie itself contains no name or email.
  • gm_ref (functional): set when you arrive via a referral link (30-day lifetime). Records which referral code brought you to the site so we can credit the referrer at sign-up. Only set when a ?ref= parameter is present in the URL.
  • gm_consent (preference): remembers whether you accepted or declined optional measurement for up to one year. You can change this choice at any time through "Privacy choices" in the site footer.

Vercel's optional measurement tools load only after you accept them in the cookie banner. Ahrefs, Google, and configured programmatic ad-network scripts additionally require an explicit deployment switch that defaults off. Contextual or affiliate placements can still appear without consent, but they are not selected from a behavioural advertising profile. You may decline optional measurement on your first visit or change your choice later with "Privacy choices" in the site footer. If Google tracking is later enabled, it may use browser identifiers as described above; Ahrefs Web Analytics is cookie-free.

Mobile apps (iOS & Android)

Native apps are not currently available in public app stores. If you are using an authorised iOS or Android beta build, a few additional data flows apply on top of everything described above:

  • Push notification token. When you allow notifications, the app receives an Expo push token (a long opaque string issued by Expo using the device's Apple Push Notification service or Firebase Cloud Messaging credential). We store that token together with the platform name (ios or android), your device's human-readable name (e.g. "Puya's iPhone"), and the installed app version so we can send you push notifications you opted into — friend-rating alerts, replies, and weekly recaps. Your OS settings can stop notification display. Signing out attempts to unregister the stored address and always clears local account credentials. Requesting account deletion disables the address immediately; final deletion removes its database row. A future public push launch must establish Expo's end-user token deletion or bounded-retention behavior.
  • Native sign-in. On iOS the app uses Sign in with Apple and a native Google Sign-In sheet (which returns a one-time ID token). The ID token is sent to our server, verified against Apple/Google's public keys, and exchanged for a normal Goat Music session. We never see your Apple/Google password and we don't receive a long-lived OAuth token from the sign-in flow itself — only your verified email, name, and stable provider user id.
  • Local secure storage. The app may keep a short-lived session token in your device's secure storage (iOS Keychain / Android Keystore via expo-secure-store) so you don't have to sign in every time you open it.
  • Native Discover boundary. The native app explicitly requests a feed without concert enrichment. For that request our server does not read edge-geolocation headers, query ticket providers, or return concert tiles. The website behavior described above remains separate.
  • Update checks. On launch, the app contacts Expo's update service to ask for an update compatible with its platform, release channel, runtime, app version, and build. Expo receives that request plus ordinary network metadata such as IP address. Expo's exact identifiers, role, and retention are governed by the production account settings and agreement; this policy does not claim a separate bounded Expo retention period.
  • Mobile SDK status. We do not activate a mobile ad network or attribution SDK, read your Advertising Identifier (IDFA on iOS, AAID on Android), or request tracking permission. Google Sign-In is active with openid, email, and profile scopes and without offline access. Its packaged privacy manifest declares additional potential phone, coarse-location, device, and usage categories that are broader than Goat Music's requested scopes or confirmed persistence; we reconcile the exact store-generated report before submission. The current candidate also packages the Sentry and RevenueCat native libraries. Sentry has no mobile DSN and returns before initialization. RevenueCat has no configured platform key, Goat Pro is disabled, and purchase setup returns before initialization. Their packaged privacy manifests describe potential diagnostics and purchase history, but the candidate runtime does not activate those flows. We reconcile those dependency declarations with the exact store-generated reports before submission.
  • In-app account deletion. Per App Store Review Guideline 5.1.1(v), the app provides an in-app path to start account deletion. Your profile and activity are hidden immediately, with a 7-day recovery window before the permanent deletion process begins. Deletion is ordinarily completed within 30 days; provider or storage outages can delay completion while the hidden account remains inaccessible and retries continue. You can reach it from Settings → Delete Account inside the app, or directly at /account/delete.

How we protect it

All traffic is served over HTTPS. Database access is restricted to the application via credentialed connection. Provider tokens are encrypted by the application before they are stored, in addition to the database provider's storage encryption. We follow industry-standard practices — but no system is invulnerable, and we can't guarantee absolute security.

How long we keep it

We keep your account data for as long as your account is active. If you delete your account (Settings → Delete Account), your profile and activity are hidden immediately. You can restore the account by signing in during a 7-day recovery window. After that grace period, permanent deletion begins and is ordinarily completed within 30 days. Your profile remains hidden while provider and storage cleanup retries. Disaster-recovery backups may retain encrypted copies for up to 90 days and are not restored without replaying completed deletion requests. We may retain limited records longer where required by law or for fraud prevention.

  • Goat's in-memory catalogue search cache stops reusing each provider-, type-, and query-based entry after 10 minutes. After that it is not served as a cache hit, but the stale key can remain in process memory until the same query is requested again or the server instance ends; there is no separate deletion timer. Search providers and hosting platforms can have separate handling under their configurations and terms.
  • Signed-in Discover interactions and dismissals follow the account-deletion process above. Signed-out web interactions and dismissals associated with gm_did are deleted by a daily cleanup once they are more than 180 days old, matching the cookie lifetime. We do not use raw IP addresses as Discover session identifiers.
  • Goat Music does not write a Discogs username or personal access token to its database during preview. Those values live in request memory while we forward the requested calls to Discogs. Discogs or infrastructure logs may have their own retention.
  • Expo receives a native update check on launch. Its retention depends on the production agreement and account settings; we do not state a separate duration here without that confirmation.

Your rights

Wherever you live, you can:

  • See the data we have on you — most of it is already visible inside your account.
  • Correct anything that's wrong via your profile and account pages.
  • Delete your account from Settings → Delete Account. The account is hidden immediately, can be restored for 7 days, and then enters permanent deletion, ordinarily completed within 30 days.
  • Disconnect any service or integration you previously connected. We revoke upstream access where the provider offers a supported method and the required credentials are available, and always discard the related local tokens immediately. When only you can finish revocation, we show the provider-side settings step.

If you are in the EU, UK, or California, you have additional rights under the GDPR / UK GDPR and CCPA respectively, including the right to request a portable copy of your data and the right to object to certain processing. To exercise any of these, email privacy@goatmusic.me from the address tied to your account and we'll respond within 30 days.

Children

Goat Music is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has signed up, email us and we will remove the account.

International transfers

Our hosting and database providers operate in the United States. By using Goat Music you consent to your data being processed in the United States, with appropriate contractual safeguards where required by your local law.

Payment processing and analytics

Goat Pro is not currently available for purchase. If it launches, the checkout will identify the configured payment processor or merchant of record and link its terms before you pay. We will not store or transmit payment-card numbers directly.

After you accept optional measurement, we use Vercel Analytics and Speed Insights to understand product usage and performance. Vercel Analytics event URL fields are replaced with a fixed page category rather than the raw event URL. Approved custom event dimensions are limited to event-specific fixed values. Ahrefs, Google, and programmatic ad-network scripts remain off unless a deployment is explicitly opted in as described in "Third-party services" above. We do not load a Plausible Analytics client tracker.

Changes

If we change this policy in any material way, we'll update the "Last updated" date at the top of the page and, for significant changes, surface a notice the next time you sign in.

Contact

Privacy questions, deletion requests, GDPR/CCPA requests: privacy@goatmusic.me.

Privacy Policy · Goat Music