Legal

Privacy Policy

Last updated: August 21, 2026

The short version: ListenTogether processes room data, account and subscription information, and minimized product analytics to provide and improve the service. Google and YouTube features are optional. We do not sell personal data or share it with advertisers.
1. Who we are

ListenTogether is operated by a French individual entrepreneur (referred to as "ListenTogether", "we", "us", or "our"). We are the controller of the personal data described in this policy, except where a provider acts as an independent controller for its own service. You can reach us using the contact details in section 11.

2. What data we process

The table below describes the data ListenTogether handles, the relevant product surfaces, its purpose and legal basis, where it is stored or sent, and how long it is retained.

Data Domain Purpose Stored where Retention
Required
Anonymous nickname
e.g. "BoldFox"
Extension, Mobile app Identify you in a room without requiring an account. Necessary to perform the service you request. Local app/extension storage + active room state Until cleared locally; active room copy deleted when the room ends
Room code Website, Extension, Mobile app Join and route messages to the right room. Necessary to perform the service you request. Backend active room state; local storage when needed for reconnect/join flow Deleted when the room ends; local copy until cleared by app/browser storage
Playback events
play, pause, seek, track change
Extension, Mobile app Keep participants synchronized in real time. Necessary to perform the service you request. Transient WebSocket relay / active room state Not persisted beyond the active room
Queue entries
track title, artist, YouTube Music URL
Extension, Mobile app Show and synchronize the shared queue. Necessary to perform the service you request. Backend active room state Deleted when the room ends
Session, security, and network metadata
session identifiers, timestamps, IP address and request/device context where applicable
Website, Extension, Mobile app, Backend Authenticate sessions, deliver requests, prevent abuse, and diagnose reliability issues. Necessary to perform the service and for our legitimate interests in security and reliability. Local session storage, backend and infrastructure security logs, relevant service providers Session data until sign-out or expiry; security logs for a limited operational period, or longer when needed to investigate an incident or meet a legal obligation
Accounts and billing
Google Play and RevenueCat subscription data
billing UUID, product and billing period, entitlement status, renewal or end date, and provider environment
Android app, Backend Process Google Play subscriptions, validate them through RevenueCat, and synchronize the account-level Plus entitlement across clients. Necessary for the performance of a contract and our legitimate interest in preventing inconsistent or fraudulent access. Google Play; RevenueCat; ListenTogether backend. RevenueCat receives an opaque billing UUID rather than an email address, and ListenTogether does not send raw webhook payloads or order IDs to product analytics. For the account and subscription lifecycle and then as required for accounting, fraud prevention, or disputes; provider-side records follow RevenueCat's and Google Play's policies
Account and profile data
email from Google, nickname, authentication identifiers, account settings
Website, Extension, Mobile app Create and secure your account, provide signed-in features, synchronize your profile and settings, and send required service messages. Necessary for the performance of a contract. Backend database; local app or extension session/cache where applicable Until account deletion, then removed or anonymized subject to limited backups and records we must retain by law
Subscription and billing records
plan, status, billing period and provider references
Website, Backend Activate and manage Plus, handle renewals, support, refunds, disputes, and required records. Necessary for the performance of a contract and compliance with legal obligations. Backend database; Lemon Squeezy For the account and subscription lifecycle, then for any period required by accounting, tax, fraud-prevention, or dispute laws
Lemon Squeezy transaction data
checkout contact, payment, tax, receipt, refund and chargeback information
Checkout and customer portal Process purchases and meet payment, tax, accounting, refund, and fraud-prevention requirements. Necessary for the performance of a contract and compliance with legal obligations. Lemon Squeezy as merchant of record; ListenTogether receives limited order and subscription records, not full card details Under Lemon Squeezy's retention notice and for any period required by applicable payment, accounting, tax, fraud-prevention, or dispute laws
Product and business analytics
Website analytics
page URL, referrer, campaign parameters, approximate location, device/browser context and analytics identifiers
Website Measure use and reliability of the public website. Google Analytics is currently loaded on public website pages; analytics storage is subject to applicable consent requirements. Google Analytics; analytics cookies or similar browser storage may be used Google Analytics' configured retention period and until browser storage is cleared or expires
Extension and Android product analytics
aggregate usage snapshots, short-lived session/runtime ID, app and technical context
Extension, Mobile app Understand feature use and reliability using minimized aggregate signals. Our legitimate interests in improving and maintaining the service; client analytics can be disabled in Settings. Short rolling local usage ledger where implemented; PostHog Local ledger for its limited rolling window and PostHog for the configured retention period
Pricing-page views
fresh random event identifier and locale
Website, Backend Measure interest in ListenTogether plans without an analytics browser cookie. Our legitimate interests in minimized product and business measurement. Sent server-side to PostHog PostHog's configured retention period
Checkout and subscription-lifecycle analytics
pseudonymous billing ID, status, period and provider timestamps
Backend Measure checkout and subscription operation using bounded billing properties. Our legitimate interests in operating and improving the paid service. PostHog; no email, name, checkout URL, card details, or provider customer ID is included in these events PostHog's configured retention period
Optional
Preferences
theme, language, remote mode, notifications
Extension, Mobile app Remember settings such as theme, language, remote mode, notifications, analytics choice, and similar UI preferences. Necessary to provide your chosen configuration. Local app/extension storage; account-backed sync where enabled Until changed, deleted, app/browser storage is cleared, or account is deleted
YouTube read access Mobile app Retrieve liked songs and playlists after you grant the requested permission. Necessary to provide the optional feature you request; Google authorization is based on your consent. Google access token stored locally on device; fetched YouTube data may be cached briefly by backend Token expires/refreshes; backend cache expires automatically
YouTube write access Mobile app Like a song or save one into a playlist after you grant the requested permission. Necessary to provide the optional feature you request; Google authorization is based on your consent. Google access token stored locally on device; write request sent through backend when the feature is available Token expires/refreshes; action persists in your YouTube account until changed there

Optional Google and YouTube permissions are requested only when you choose to use the related feature. You can use ListenTogether rooms without connecting a Google or YouTube account. YouTube write access is requested only when a visible write feature is available and you choose to use it.

3. What we do not collect

We do not collect your Google or YouTube password, receive or store your full payment-card details, use hardware fingerprints, collect precise location data, or collect content from browser pages other than YouTube Music tabs where the extension is active. Product analytics allowlists exclude room codes, track metadata, search queries, nicknames, email addresses, account IDs, and Google or YouTube identifiers. We do not collect your broader YouTube Music listening history beyond room, playlist, liked-song, or write features you explicitly use.


4. Product analytics

We use two analytics providers. The public website currently loads Google Analytics on its pages to measure visits. Google Analytics may process page URLs, referrers, campaign parameters, approximate location, device or browser context, network metadata, and analytics identifiers or cookies. Separately, we use PostHog for three limited product and business analytics flows based on our legitimate interests in understanding and improving ListenTogether, measuring the paid service, and keeping it reliable. Extension and Android product analytics use short-lived runtime or session identifiers, technical context, and daily or weekly aggregate usage snapshots. Chrome and Android client analytics are enabled by default. Edge client analytics remain disabled until you enable them in Settings. Firefox client analytics require Firefox's optional technical and interaction data permission. You can disable client analytics at any time in Settings; disabling them stops future client analytics and clears the locally retained usage ledger where that feature is implemented. Pricing-page views are also recorded server-side in PostHog with a fresh random identifier for each event and the visitor's locale; this separate server-side flow does not place or read an analytics cookie. Checkout and subscription-lifecycle analytics use a pseudonymous billing identifier derived from an internal user ID and limited billing properties. We do not send PostHog the user's email, name, checkout URL, full card details, or payment-provider customer identifier in these billing events. You may object to PostHog processing based on our legitimate interests by using the client Settings control where available or by contacting us.

5. Third-party services

We use service providers where needed to operate ListenTogether. Google Analytics processes public-website analytics, and PostHog processes product and business analytics on our behalf. Lemon Squeezy acts as merchant of record and payment provider for Plus: it handles checkout, payment details, taxes, receipts, refunds, and related transaction records under its own notices and terms. Hosting, database, email, security, Google Sign-In, Google APIs, and YouTube services process data only when relevant to the feature you use. A provider may process data outside your country; where required, we rely on appropriate safeguards such as an adequacy decision or approved contractual protections. Provider data is retained for the configured retention period or for the period stated in that provider's notice, subject to our instructions and applicable legal requirements.

Android subscriptions are processed by Google Play. RevenueCat receives an opaque billing UUID plus product, entitlement, status, billing-period, environment, renewal, and cancellation metadata to validate purchases and synchronize the account-level Plus entitlement. We use this information to grant access and provide provider-specific management; we do not send RevenueCat your ListenTogether email as its App User ID. Google Play and RevenueCat retain provider-side records under their own policies. You may exercise the rights in section 8 or contact us about ListenTogether's copy.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

ListenTogether uses YouTube API Services. When you use features powered by those services, Google may process information as described in the Google Privacy Policy.

Any other temporarily retained YouTube API Data is automatically deleted no later than 30 calendar days after it was retrieved or last refreshed.

6. Data sharing

We do not sell, rent, or trade personal data, and we do not share it with advertisers. Within a room, nicknames, playback events, and queue entries are relayed to participants as needed for the shared experience. Account, email, subscription, and private YouTube data are not shared with room participants unless a feature necessarily makes an action visible, such as adding a track to the shared queue. We disclose data to the providers described above, to professional advisers under confidentiality where necessary, or to authorities when legally required. We will notify you of a legal request where permitted and appropriate.

7. Data security

ListenTogether clients and the backend communicate over encrypted connections (TLS/HTTPS and WSS). We apply access controls and data minimization, keep account and subscription records in the backend database, and keep Google or YouTube access tokens used by the Android app locally on the device. No internet service is completely secure, but we review safeguards in proportion to the data and risks involved.

8. Your rights

Depending on where you live and subject to applicable exceptions, you may ask us to access, correct, delete, restrict, or receive a portable copy of your personal data. You may also object to processing based on our legitimate interests, withdraw consent for future processing where consent is the basis, and complain to your local data-protection authority. You can clear local preferences through browser or device settings, sign out to clear local session data, disable client analytics in Settings, and delete your ListenTogether account using available account controls. Contact us to exercise a right; we may need to verify your identity before responding.

9. Children

ListenTogether is not directed at children under 13, and we do not knowingly collect personal data from them. If local law requires a higher age or parental authorization for an online service, that requirement applies. If you believe a child has provided personal data, contact us so we can take appropriate steps.

10. Changes to this policy

We may update this policy when ListenTogether, its providers, or applicable requirements change. The date at the top identifies the latest revision. We will provide additional notice through the service or by email when a change materially affects how we use personal data and applicable law requires notice.

11. Contact

Questions, privacy requests, or objections can be sent through: