Privacy Policy
Effective date: April 1, 2026 · Last updated: April 24, 2026
Short version (the spirit of this policy): Music I Want collects the minimum information needed to operate the site and serve relevant ads. We do not sell personal data. We do not track you across the web outside of the analytics and ad cookies named below. You can request a copy or deletion of your data at any time via the contact page. The detailed terms below specify exactly what we collect, why, who else processes it, and what your rights are under GDPR, CCPA, and COPPA.
1. Scope of this policy
This Privacy Policy describes how Music I Want (“we,” “us,” “our”) collects, uses, discloses, and protects information when you visit musiciwant.com or use the services available there (collectively, the “Service”). It applies to all visitors regardless of location. Where applicable law gives you broader rights than those described here, the broader rights apply.
Music I Want is operated by an individual proprietor located in the United States, doing business as “The Hive.” You can reach us via the contact page for any privacy-related question.
2. Information we collect
2.1 Information you provide directly
- Email address, if you subscribe to our newsletter, save a playlist, or submit a fan story or Voice essay.
- Display name (first name or alias) when you submit a fan story, a song description, or a Voice essay.
- Free-text content you submit: fan stories, song descriptions, Voice essay bodies, ratings feedback, contact-form messages.
- Optional location (city, country) you may provide alongside a fan story.
- Demographic information you may volunteer (e.g., a child's age when submitting a Parent Note about a kids song). We do not request sensitive categories such as race, religion, sexual orientation, health, or political views; if you volunteer such information in free-text content, we treat it as ordinary user-submitted content.
2.2 Information collected automatically
- IP address (used to apply rate limits, prevent abuse, and infer approximate region for content recommendations).
- User-agent string (browser, operating system, device class).
- Referrer URL (the page that linked to ours).
- Pages viewed and timestamps, stored in standard web-server access logs.
- Approximate geographic region derived from IP address.
- Interactions with site features such as image upvotes, song-image votes, and prompt submissions. These records include the song or content identifier, the action taken, the timestamp, and your IP address.
2.3 Information from third parties
- Google AdSense may share aggregated information about ad impressions and interactions on our pages.
- Affiliate networks (eBay Partner Network) may share aggregated reporting on click-throughs and conversions originating from our pages.
- We do not purchase data from data brokers and we do not enrich your record with information obtained from outside the Service.
3. How we collect information
- Through your direct interactions with forms (newsletter signup, fan story, Voice essay, contact form, prompt submission, vote button).
- Through your browser when you load a page (HTTP request data, cookies, localStorage values you have authorized).
- Through third-party services we embed, such as YouTube and Spotify embed players, which set their own cookies when you interact with the embedded content.
4. Legal bases and purposes for processing
For visitors in the European Economic Area, the United Kingdom, and similar jurisdictions, we rely on the following legal bases under GDPR Article 6:
- Consent — for non-essential cookies, advertising personalization, and email marketing. You provide consent through the cookie banner on first visit and through the explicit subscription checkbox when you supply an email.
- Legitimate interests — for site security, abuse prevention, rate limiting, aggregated analytics, and content moderation. We balance our interests against your privacy rights and use the minimum data necessary.
- Contractual necessity — for delivering the specific Service you request, including emailing you a playlist restore link or sending the confirmation of a Voice essay submission.
- Legal obligation — where we must retain or disclose information to comply with law (for example, responding to a valid legal process).
We use the information described in section 2 for the following purposes:
- To operate, maintain, and improve the Service.
- To moderate user-submitted content for spam, abuse, copyright infringement, and harmful material.
- To send transactional emails you have requested (subscription confirmation, playlist restore, content approval notice).
- To serve advertising via Google AdSense (subject to your consent in jurisdictions that require it).
- To compute aggregated, non-identifying statistics (page-view counts by region, average session length, popular search terms).
- To respond to your inquiries, requests for data access, deletion, correction, or other rights requests.
- To detect, prevent, and address security incidents, fraud, and policy violations.
5. Third-party processors and recipients
We share information only with the third parties below, and only as required to operate the Service. We have data processing agreements in place where required by law.
- DigitalOcean, Inc. — hosting and infrastructure (United States).
- Cloudflare, Inc. — DNS and edge networking (global).
- Resend, Inc. — transactional email delivery (United States).
- Google LLC — advertising via AdSense, see section 7 for full disclosure.
- OpenAI, L.L.C. — for the “Analyze a Song” feature when you submit a song not in our library; we send the song title and artist name. We do not send your IP, email, or other identifying information to OpenAI as part of these calls.
- Anthropic, PBC — for autonomous editorial content generation (artist guides, guide expansions). Anthropic processes only the song-catalog data we send (title, artist, sensory ratings); no user-submitted personal information is sent.
- Replicate, Inc. — for AI image generation (Flux Schnell model). We send only the song's metadata as a prompt; no personal data.
- MetaBrainz Foundation (MusicBrainz, Cover Art Archive) — for album art lookup; we send only the song or album identifier, no user information.
- YouTube (Google LLC) and Spotify AB — for embedded players. These embeds set their own cookies and load resources from their domains when you interact with them. Their privacy policies govern this data.
- eBay Inc. (Partner Network) — for affiliate links on guide pages. Affiliate links append a campaign identifier; eBay handles any data collected after the click.
- Stripe, Inc. — we have integrated Stripe for future paid features but currently process no payments. If you make a payment in the future, no card data touches our servers; Stripe handles it directly.
We do not sell or rent personal information to third parties for monetary or other valuable consideration. The transfers above are operational, contracted, and limited to the data necessary to perform the named function.
6. Cookies and tracking technologies
6.1 First-party storage
We use browser localStorage (not server-set cookies) for the following first-party purposes:
- Storing your sensory-profile answers so the Library remembers your filter preferences.
- Remembering recently viewed songs for the homepage carousel.
- Storing your cookie-consent choice (the
miw_cookie_consentkey). - Holding pending form data (e.g., a Voice essay you started writing).
You can clear localStorage at any time via your browser's developer tools or site-data settings.
6.2 Third-party cookies
Third-party cookies are set by:
- Google AdSense — for ad serving and personalization. See section 7.
- YouTube and Spotify embeds — only when you click into an embedded player. Until you interact, the embeds are loaded with reduced cookie scope where supported.
6.3 Consent management
On your first visit, our cookie banner offers a clear binary choice: “Accept all” or “Essential only.” We use Google's Consent Mode v2 to communicate your choice to AdSense and any future analytics providers. The default state, before you make a choice, denies all advertising and analytics storage and personalization.
7. Google AdSense and advertising
Music I Want serves advertising through Google AdSense (“AdSense”). The following disclosures are required by Google's program policies and applicable law.
- Google, as a third-party vendor, uses cookies to serve ads on this site.
- Google's use of advertising cookies enables it and its partners to serve ads to our users based on their visits to our Service and other sites on the Internet.
- Users may opt out of personalized advertising by visiting Google Ads Settings or, for non-Google vendors, aboutads.info (NAI/AdChoices).
- Where applicable, Music I Want and Google use first-party cookies (such as the Google Analytics cookie) and third-party cookies (such as the DoubleClick cookie) together to inform, optimize, and serve ads.
- For users in the European Economic Area, the United Kingdom, and Switzerland, ads are served only with valid consent collected via the cookie banner; in default-deny mode the AdSense script loads but does not personalize.
We do not control which specific ads are served. Ads are selected by Google's automated systems based on the page context and (where consented) the visitor's interest profile.
8. Data retention
We retain personal information only as long as needed for the purpose for which it was collected.
- Email subscribers — retained until you unsubscribe via the link in any email or request deletion via the contact page.
- Fan stories, Voice essays, and song descriptions — retained while published on the site. If you request deletion, we remove the content within 14 days. The originating IP address attached to a submission is retained for 90 days for abuse investigation, then deleted.
- Image votes and prompt upvotes — the vote itself is retained as part of the public record; the IP address attached to it is retained for 90 days for abuse investigation, then deleted.
- Web-server access logs — retained for 30 days, then deleted.
- Aggregated analytics — retained indefinitely once de-identified.
9. Your rights
9.1 GDPR and UK GDPR (visitors in the EU/EEA, UK, Switzerland)
You have the right to:
- Access the personal information we hold about you.
- Rectify inaccurate or incomplete information.
- Erase personal information (“right to be forgotten”) when one of the GDPR conditions applies.
- Restrict processing while we evaluate a request.
- Object to processing based on legitimate interests, including direct marketing.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your local supervisory authority if you believe we are not handling your data correctly.
9.2 California (CCPA / CPRA)
California residents have the right to:
- Know what categories of personal information we collect, the sources from which it was collected, the business purposes for collection, and the categories of third parties with whom it is shared (all of which are disclosed in this policy).
- Request a copy of the specific pieces of personal information we have collected.
- Request deletion of personal information.
- Opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. We have no “Do Not Sell or Share My Personal Information” link because there is nothing to opt out of.
- Limit the use of sensitive personal information — we do not collect or use sensitive personal information as defined by CPRA.
- Be free from discrimination for exercising any of these rights.
To exercise any of the rights above, send a request via the contact page with the words “Privacy Request” in the subject. We will verify your identity (typically by responding to a control-of-email-address challenge) and respond within 45 days as required by CCPA, or extend by an additional 45 days if needed and we will tell you why.
9.3 Other jurisdictions
Where applicable law in your jurisdiction (Quebec's Law 25, Brazil's LGPD, Australia's Privacy Act, Japan's APPI, and others) provides rights similar to those described above, those rights apply to you on the same basis. Send a request via the contact page identifying the law you are exercising rights under.
10. Children's privacy (COPPA)
Music I Want is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13 in compliance with the Children's Online Privacy Protection Act (COPPA).
The Kids section of the site is editorial content written for parents and caregivers about music for children. It contains no chat, no children-directed forms, no children-directed advertising, and no fields that solicit personal information from children. Email subscriptions, fan-story submissions, and Voice essays all require an adult (13 or older). When a parent submits a Parent Note about a kids song, the parent provides their own first name and the child's age (a number between 0 and 17, used only as content that other parents can read); the child is not identified.
If you believe a child under 13 has submitted personal information through our Service, please contact us via the contact page. We will delete the information within seven (7) days of verification and will not use it for any purpose, retain it, or disclose it to any third party.
Age-appropriateness ratings on our kids songs are subjective recommendations, not clinical guidance. Every child is different. If your child has sensory processing differences, start any song at low volume and watch their reaction before full play.
11. International data transfers
Music I Want is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States. Where European data protection law applies, we rely on:
- The EU-US Data Privacy Framework for transfers to subprocessors that participate in the framework (where applicable).
- Standard Contractual Clauses (SCCs) approved by the European Commission for transfers to subprocessors that do not.
- Your explicit consent for limited, occasional transfers that fall outside the above.
The United States may not provide the same level of data protection as your country of residence. By using the Service, you understand that your information may be transferred to the United States and processed there subject to this policy.
12. Security measures
We implement reasonable technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, and destruction. These include:
- HTTPS/TLS encryption in transit on all pages, including form submissions.
- HTTP Strict Transport Security with one-year max-age and includeSubDomains.
- Server access secured by SSH keys (no password authentication).
- Database stored on encrypted volumes with restricted file-system permissions.
- Limited administrative access to one individual proprietor.
- Rate limiting and abuse detection on form endpoints.
- Regular software updates for the operating system, web server, and application stack.
- Content moderation queue for all user-submitted text, with human review before publication.
No system is perfectly secure. We will notify affected users of any data breach involving personal information without undue delay and in any event within 72 hours of discovery, where feasible, in line with GDPR Article 33-34 and applicable US state breach-notification laws.
13. Do Not Track and Global Privacy Control
We honor the Global Privacy Control (GPC) signal as a valid opt-out request for the sale or sharing of personal information under CCPA. When your browser sends GPC, we treat the request as a do-not-share preference for this Service and any future analytics providers.
Older “Do Not Track” (DNT) header signals are inconsistently implemented across browsers; we do not currently treat DNT as an opt-out, but we apply equivalent restrictions through the cookie banner's Essential-only choice.
14. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices, the Service, or applicable law. The effective date and last-updated date at the top of this page indicate when the most recent version took effect. For material changes that affect how we use information already collected, we will:
- Update the dates at the top of this page.
- Post a banner notice on the homepage for at least 30 days.
- Where we hold your email and the change materially affects your rights, send a direct email notice.
Continued use of the Service after a change becomes effective constitutes acceptance of the revised policy.
15. Contact
For questions about this Privacy Policy, to exercise any of the rights described above, or to report a privacy concern:
- General contact: Contact page
- Subject line for privacy requests: “Privacy Request”
- Response time: We aim to acknowledge within 7 days and resolve within 30 days for general requests, or 45 days for formal CCPA/GDPR requests with a possible 45-day extension as permitted by law.
Related documents: Terms of Service · Disclaimer · About Music I Want · Methodology