AVL Music Companion
Privacy
Last updated July 2, 2026
AVL Music Companion is a free, community-powered discovery board for Asheville shows. The short version: we collect the minimum needed to make discovery personal, we never write to your Spotify account, we never sell your data, and nothing you do privately is ever shown publicly.
What we collect
- Browsing without an account — an anonymous session cookie remembers your taste signals (what you tap, save, or skip) so the board can improve for you. It isn't tied to your name or email; when you sign in, that trail migrates to your account rather than being duplicated.
- Email address — if you sign in with an email magic link (via Resend; no passwords are stored, because there are none), or request a Spotify beta seat — seat requests store the email you give us and your optional note, used only to notify you when your seat is ready.
- Spotify profile and listening taste — only if you connect Spotify: your display name, the email on your Spotify account, and your top artists and tracks, under read-only scopes (
user-read-private,user-read-email,user-top-read). We never see your password. - Your activity here — saves, going/fire signals, follows, song recommendations, and discovery-tuning preferences, tied to your account (or the anonymous cookie above until you have one).
- Page analytics — privacy-friendly, cookieless Umami page counts. No cross-site tracking, no ad networks.
How it's used — and what we never do
One purpose: helping you find local shows worth showing up for. Taste signals rank the same public listings for you personally. We never write to your Spotify account — no playlist changes, no follows, nothing; our scopes physically don't allow it. We never sell or share personal data, run ads, or take payment for placement — “no money buys rank” is an invariant our tests assert. Your private activity (saves, going/fire signals, who you follow) is never shown publicly: community counts are anonymous crowd totals, and “your people” attribution is visible only to followers each person has explicitly opted into sharing with. Regular listeners never get a public profile.
Spotify, specifically
- Read-only. We never post, follow, modify playlists, or control playback on your Spotify account.
- Tokens stay server-side. Spotify access tokens live in our database and never appear in public pages or API responses — a claim our test suite enforces, not just a promise.
- Revocable both ways. Disconnect Spotify from your profile here — that deletes our copy of your tokens, and “remove imported data” also deletes the imported top artists/tracks. You can additionally revoke access at spotify.com/account/apps.
Where it lives
Hosting on Vercel, database on Neon (Postgres), sign-in and notification email via Resend, listening data from the Spotify Web API, page counts via Umami. Each processes data only to provide the service.
Control, retention & deletion
Taste tuning is directly editable (every dial is yours) and signing out ends the session. Account data is kept while your account exists. To delete your account and its data — or to ask anything about this page — email avlmc@agent828.com and we'll handle it promptly. Disconnecting Spotify (above) removes tokens immediately without deleting your account.
Changes
If our data practices change, this page changes in the same release, with the date above updated. Questions welcome — this product runs on trust with a small local community, and we intend to keep it.