Privacy Policy & Terms of Use
Effective date: 19 September 2026
Privacy Policy
tunimal (“tunimal”, “we”, “us”) is a web application at tunimal.vercel.app that tells you which animal matches your music taste. To do that, it reads a small, read-only slice of the music library you keep in YouTube Music or Spotify and turns it into a result shown only to you.
This page is our complete privacy policy. It explains exactly which data we access, what we do with it, where it is kept and for how long, and which third parties are involved. The conditions for using the app are in the Terms of Use. Please read both before you connect an account.
1. Who is responsible
tunimal is operated by an individual developer and their team in Thailand as a personal, non-commercial project. We are the controller of the limited personal data described below.
Questions, requests to delete data, or anything else about this policy: MhuffyDev@mhuffy.net.
2. Information we access
We access only what is needed to work out your result. Nothing is read until you choose a music app and sign in to it yourself.
- YouTube Music (through Google sign-in). We request the single read-only scope “View your YouTube account” (youtube.readonly) and read: the videos on your Liked videos list (the most recent 200), the playlists you created (up to 5, the first 50 items of each), the channels you subscribe to (up to 100), and, for those videos, the details YouTube publishes about them: title, channel, duration, upload date, view count and topic category. We do not access your watch history (Google does not make it available), your email address, your contacts, comments, messages, or anything you did not like, playlist or subscribe to.
- Spotify (testers only). We read your top artists and tracks, recently played tracks, saved (liked) tracks and playlist names, through Spotify’s Web API with the read-only permissions you grant on Spotify’s consent screen.
- The name you type. A display name you enter for the result. It is stored only in your browser.
- Technical data. Our hosting provider (Vercel) records standard server logs for each request (IP address, time, requested address, browser type) for security and operation of the service. We do not combine these logs with your music data.
3. How we use it
We use the data above for one purpose: to compute your taste profile (your genre mix, the animal that matches it, and the figures shown on the result page) and display it to you, and to let you save or share the result image you create.
- We do not use your data for advertising, marketing, profiling for any other purpose, or research.
- We do not sell, rent, or trade your data, and we never send it to anyone for their own use.
- We do not write to your accounts: we never like, follow, save, create, delete or change anything in YouTube or Spotify on your behalf.
4. Where your data is kept, and for how long
- Your result and the music data it is based on are computed in your browser and stored only in your browser’s local storage on your device. We do not store your music data, your result, or your name on our servers.
- Sign-in tokens issued by Google or Spotify are stored in httpOnly cookies on your device and are used only to call the provider’s API on your behalf. Google access tokens last one hour; a refresh token lasts up to 30 days. Spotify tokens are handled the same way. Page scripts cannot read these cookies.
- YouTube data: in line with the YouTube API Services Developer Policies, data obtained through the YouTube API is refreshed or deleted within 30 days. A result older than 30 days is discarded and you are asked to connect again. Disconnecting deletes it immediately.
- Genre lookups: to refine genres we look up artist names (only the names, never your identity, account, or which songs you liked) in the public MusicBrainz database, and cache the answer (artist name → genre tags) on our server so we do not repeat the same lookup. That cache contains no personal data.
- When you revoke the app’s access at Google or Spotify, everything we hold that came from that provider is deleted within 7 days — in practice immediately, since it lives only on your device.
5. Third-party services
tunimal relies on the following services. Each has its own terms and privacy policy, linked at the end of this page.
- Google / YouTube API Services. The YouTube Music option uses YouTube API Services. By using it you also agree to be bound by the YouTube Terms of Service, and Google’s Privacy Policy describes how Google handles your data. You can revoke tunimal’s access at any time from your Google account’s security settings (myaccount.google.com/permissions).
- Spotify Web API. The Spotify option uses Spotify’s Web API under Spotify’s Developer Terms. While the app is in Spotify’s development mode only accounts on its tester list can connect. You can remove tunimal at spotify.com/account/apps.
- Spotify embedded player. For Spotify users, the result page can play a track of your most-played artist through Spotify’s embedded player, which loads content from Spotify and is subject to Spotify’s privacy policy.
- MusicBrainz. Artist names are sent to the MusicBrainz API to fetch genre tags, as described in section 4.
- Vercel. The app is hosted on Vercel, which processes the technical data described in section 2 on our behalf.
6. What we never do
We never write to your account. We never like, follow, save, create or delete anything. We never sell, share, or transfer your data to anyone, and we never send it anywhere other than the provider you signed in to and, as artist names only, MusicBrainz. Your taste profile is computed in your browser and stored only on your device.
7. Your choices and rights
- Disconnect. Open Settings and tap Disconnect: this deletes the result, your music data and the sign-in on this device.
- Revoke at the source. Google: myaccount.google.com/permissions. Spotify: spotify.com/account/apps. Revoking stops the app from reading anything further.
- Clear everything. Clearing your browser’s site data for tunimal.vercel.app removes every trace of the app from your device.
- Access, correction, deletion. Because your data is kept only on your device, you already hold the only copy. If you believe we hold anything about you, contact MhuffyDev@mhuffy.net and we will answer within 30 days.
- If you are in a jurisdiction that grants you additional rights (for example the EU/UK GDPR or Thailand’s PDPA), those rights apply and you may exercise them through the same contact.
8. Cookies
We use only strictly necessary cookies: the sign-in tokens described in section 4 and a short-lived value that protects the sign-in against forgery. We do not use analytics, advertising, or tracking cookies, and we do not load third-party trackers.
9. Security
The app is served over HTTPS. Sign-in tokens are kept in httpOnly cookies that page scripts cannot read, and we request the minimum permissions the result needs. No system is perfectly secure; if you believe your data has been affected, contact us.
10. Changes to this policy
We may update this page when the app or the law changes. The effective date at the top shows the current version. Using the app after a change means you accept the updated policy; if a change reduces your rights we will ask you to read and accept the page again.
Terms of Use
These terms govern your use of tunimal, the web application at tunimal.vercel.app that tells you which animal matches your music taste. How we handle your data is described in the Privacy Policy, which forms part of these terms.
1. Acceptance
By using tunimal you agree to these terms and to the privacy policy above. When you use the YouTube Music option you also agree to be bound by the YouTube Terms of Service; when you use the Spotify option, to Spotify’s terms. If you do not agree, do not connect an account.
2. The service
tunimal is free, for personal, non-commercial entertainment. The result is an estimate derived from the music you keep; it is not an assessment of you, and genre labels come from third-party data that may be incomplete or wrong. We may change, suspend, or discontinue the app, or any part of it, at any time without notice.
3. Your account
Connect only a music account you own or are authorised to use. You are responsible for keeping your Google and Spotify credentials to yourself; tunimal never sees your password.
4. Acceptable use
- Do not use automated tools, scrapers or scripts against the app or the provider APIs through it.
- Do not attempt to circumvent limits, security measures, or access another person’s data.
- Do not use the app in any way that violates the YouTube or Spotify terms, or any applicable law.
5. Content and intellectual property
The animal artwork, names, descriptions, and the app itself belong to the tunimal team. You may save and share the result images the app creates for you for personal, non-commercial purposes, with the tunimal name left intact. Music metadata (artist names, titles, artwork) belongs to its respective owners and is displayed under the providers’ terms.
6. Disclaimer and limitation of liability
The app is provided “as is” and “as available”, without warranties of any kind, express or implied, including fitness for a particular purpose and uninterrupted or error-free operation. To the fullest extent permitted by law, we are not liable for any indirect, incidental, special or consequential damages, or for any loss of data, arising from your use of, or inability to use, the app. Nothing in these terms limits liability that cannot be limited under applicable law.
7. Governing law
These terms are governed by the laws of Thailand. Where mandatory consumer-protection rules of your country apply, they are not affected.
8. Contact
MhuffyDev@mhuffy.net