Privacy Policy
Last updated: June 16, 2026
Sortune ("we", "us", "our") operates the sortune.com website. This Privacy Policy explains what data we access via YouTube API Services, how we use it, how long we retain it, and your rights.
When you sign in with Google, we access (via YouTube API Services):
- Your Google account profile (name, email, avatar) — used for authentication
- Your YouTube Music library (playlists, liked videos, video metadata) — accessed via YouTube Data API v3 (part of YouTube API Services)
- AI-classified genre data for your tracks — stored in our database when you use the MCP integration
We store minimal data in our database:
- Your authentication session (managed by better-auth)
- MCP API tokens you generate for AI agent access (hashed)
- AI-classified genre metadata for your tracks (video ID, artist, title, genres)
We do NOT store your music files, listening history, watch history, or YouTube passwords.
Account data, OAuth tokens, MCP tokens, and AI-classified metadata are retained for as long as your account is active. When you delete your Sortune account (or contact us to request deletion), all associated data is permanently removed from our database within 30 days. Cached YouTube data is purged immediately upon revocation of access.
Sortune does NOT train any machine-learning or AI models on YouTube user data. AI classification of tracks (genre detection) is performed in real time by third-party AI agents you authorize via MCP, solely for the purpose of organizing your own playlists. Classified metadata is stored only against your account and is not aggregated, sold, or shared.
Sortune uses YouTube API Services (specifically YouTube Data API v3) to read and manage your playlists. Your use of Sortune is also subject to the YouTube Terms of Service, the Google Privacy Policy, and the Google API Services User Data Policy, which Sortune complies with, including the Limited Use requirements.
When you generate an MCP token, third-party AI agents you authorize can access your YouTube Music library through Sortune. You control which agents have access and can revoke tokens at any time from Settings. Sortune does not share YouTube data with any third party other than the AI agents you explicitly authorize.
We use essential session cookies for authentication. We do not use tracking cookies, analytics, or advertising cookies.
All data is transmitted over HTTPS. OAuth tokens are stored in a private PostgreSQL database (TLS in transit; database-level encryption depends on infrastructure provider). Access tokens are short-lived (typically 1 hour) and refreshed automatically. MCP tokens are stored as one-way hashes and can be revoked at any time.
You can:
- Revoke Sortune's access to your Google account at any time via the Google Account permissions page
- Delete your MCP tokens from the Settings page
- Request deletion of all your data by contacting us at sortune.app@gmail.com
For privacy questions or data deletion requests, contact us at sortune.app@gmail.com.