Version 1.0 · Effective 11 September 2026
01What we collect
When you create an account we collect your email address and the display name you choose. If you connect your Spotify account we additionally receive and store your Spotify user ID, Spotify display name, and the OAuth access and refresh tokens required to read your playlists on your behalf.
We also store the collections, songs, and game history you create while using the service.
- Email address
- Display name (username)
- Spotify user ID and display name (only when Spotify is connected)
- Spotify OAuth access and refresh tokens (only when Spotify is connected)
- Collections, songs, and game-session history you create in the app
02How we use it
We use your email and display name to identify and authenticate your account. The legal basis for this processing is the performance of our contract with you (providing the service). If you connect Spotify, we use your OAuth tokens to read your playlists on your behalf so you can import them as song collections; this is also necessary to provide the Spotify-import feature you requested.
We do not access your Spotify listening history, liked songs, or any data beyond what is needed to list and import playlists. We do not use your personal data for advertising, profiling, or automated decision-making, and we do not sell it to third parties.
05Retention
We retain your personal data for as long as your account is active. When your account is deleted, we permanently remove your email address, display name, Spotify tokens, collections, songs, and game sessions. Game session records that referenced a deleted collection are retained with the collection link removed and no longer contain directly identifying information. Song records in our shared music catalogue are not deleted on account removal because they are shared across users and contain no personally identifying information.
We do not currently operate an automated backup-retention schedule beyond what our hosting providers maintain as part of their standard service. If that changes we will update this section.
06Your rights
If you are in the European Economic Area, you have rights under the General Data Protection Regulation (GDPR): the right to access, rectify, erase, restrict processing of, and port your personal data, as well as the right to object to processing. You also have the right to lodge a complaint with your national supervisory authority (in Poland: Urząd Ochrony Danych Osobowych, uodo.gov.pl).
Account deletion is currently handled by request: email contact@pasniczy.com and we will process it within 30 days. You may use the same address to request a copy of your data or to correct inaccurate information.
- Right to access your personal data
- Right to correct inaccurate data
- Right to erasure — email contact@pasniczy.com to delete your account
- Right to data portability — we will provide an export on request
07Security
All connections to the service use HTTPS. Spotify OAuth tokens are stored server-side only and are never exposed to the browser. Passwords are managed and encrypted at rest by Supabase. We apply reasonable technical measures to protect your data, but no system is perfectly secure.
If you believe your account has been compromised, change your password immediately and contact us at contact@pasniczy.com.
08Contacting us
Humus is operated by Bartosz Paśnik. For questions about this policy, to exercise your rights, or for any other privacy matter, email contact@pasniczy.com. We aim to respond within 30 days.
Questions? contact@pasniczy.com