Privacy Policy

Last updated: August 27, 2026

This policy describes how Unified Music Data (“UMD”, “we”, “us”) handles information when you use our Developer Portal, API, free tools, and browser extension.

1. What we provide

  • Developer Portal — account registration, API keys, usage dashboard (unifiedmusicdata.org)
  • UMD API — programmatic access to unified music metadata (api.unifiedmusicdata.org)
  • Free tools — web utilities such as ISRC/UPC finders and link translation
  • UMD Browser Extension — overlay on supported streaming sites (Spotify, Apple Music, Deezer, YouTube Music, Tidal) that shows unified metadata for the page you are viewing

2. Information we collect

Developer Portal & API accounts

  • Account details you provide: name, email address, and password (stored hashed)
  • API keys you create and optional key labels
  • Usage metrics: request counts, endpoints called, timestamps, and error rates
  • Authentication logs related to portal login and OAuth sign-in

API requests

When you or your application calls the UMD API, we process the parameters you send (for example search terms, ISRCs, UPCs, or URLs) to return metadata. Request metadata (API key identifier, timestamp, endpoint, response status) is logged for billing, rate limiting, and abuse prevention.

Browser extension

The UMD Browser Extension collects and transmits data only when you click the extension icon on a supported streaming page:

  • API key — stored locally in your browser's sync storage after you enter it in extension settings; sent to our API in the Authorization header on each request you initiate
  • Current page URL — the URL of the active tab is sent to GET /api/v1/links/translate so we can resolve unified metadata for that track, album, or artist page

The extension does not collect your browsing history, scrape page text or media, read passwords, or run in the background without your click.

3. How we use information

  • Provide, operate, and improve the API, portal, tools, and extension
  • Authenticate requests and enforce rate limits and plan quotas
  • Display usage statistics in your dashboard
  • Detect abuse, fraud, and security incidents
  • Respond to support requests and legal obligations

4. What we do not do

  • We do not sell your personal data to third parties
  • We do not use your data for unrelated advertising or credit decisions
  • We do not transfer data except as described below to operate the service

5. Third parties & subprocessors

We use infrastructure and authentication providers to host the portal and API (for example cloud hosting, databases, and email delivery). These providers process data only on our instructions to run the service.

The extension communicates solely with UMD API servers. Metadata responses may include information originally sourced from third-party music platforms (DSPs), but those platforms are not given your API key or account details by us through the extension.

6. Data retention

Account and usage records are retained while your account is active and as needed for billing, legal compliance, and security. You may delete API keys at any time from the Developer Portal. Aggregated or anonymized analytics may be kept longer.

7. Your choices

  • Portal account — update profile details in Profile settings; revoke API keys in API Keys
  • Browser extension — remove your API key in extension settings or uninstall the extension to stop all data transmission
  • Account deletion — contact us to request deletion of your portal account and associated data

8. Security

API keys are secrets — treat them like passwords. We transmit API traffic over HTTPS. Passwords are stored using industry-standard hashing. You are responsible for keeping your API keys confidential.

9. Children

Our services are not directed at children under 13, and we do not knowingly collect personal information from children.

10. Changes

We may update this policy from time to time. The “Last updated” date at the top will change when we do. Continued use of our services after changes constitutes acceptance of the updated policy.

11. Contact

Questions about this policy or a data request? Open an issue or contact us through the Developer Portal using the email on your account, or write to privacy@unifiedmusicdata.org.