Privacy policy

Last updated 12 September 2026. What Nightdrive.fm stores about you, why, who else processes it, and what you can ask for.

Who is responsible

The controller for the processing described here is:

Martin Karwacki
Siebensterngasse 4-6/8
A-1070 Wien
Austria
legal@nightdrive.fm

The site is run privately and non-commercially. There is no data protection officer: the processing here does not meet any of the thresholds in Article 37 that require one. Enquiries go to the address above and reach the controller.

What is stored, and why

Your email address. Held so you can log in: there is no password on this site. You either click a link sent to that address, or sign in with Google or Apple — either way the address identifies the account, and it is not shown to other users. Legal basis: Article 6(1)(b), performance of the contract you enter by opening an account.

Signing in with Google or Apple. If you choose one of those instead of the emailed link, that company supplies your email address, whether they have verified it, and the identifier they use for your account. That is all: the sign-in requests nothing beyond the basic profile, and your name and picture there are not read, stored or shown — the picture beside your username is either one you uploaded here or one drawn from the username itself. Nothing about your activity here is sent back to them, and this site has no further access to your account with them. Pressing the button hands your browser to them, and what happens there is governed by Google’s or Apple’s own privacy policy. Legal basis: Article 6(1)(b) — each is one of the ways of opening and reaching your account, and you choose which.

Hidden email addresses. Apple can withhold your real address and supply a forwarding address ending in privaterelay.appleid.com instead. That is the address stored and used for email. Two consequences follow. It differs from your real address, so signing in later by emailed link, or with Google, opens a separate account rather than returning you to this one. And if you stop the forwarding in your Apple settings, mail from this site — including its log-in links — can no longer reach you.

Your profile. Your username, and the picture and the line about yourself if you add them. All three are public. Article 6(1)(b).

What you do here. The playlists you add, the ratings and likes you give, the comments and replies you write, and who you follow. All of it is public and attributed to your username: ratings determine the order of the Hot and Top lists, and your profile lists what you have added, rated, liked and written. Article 6(1)(b).

Context tags. Tags you add to a playlist are stored against your account, one record per tag per playlist, with the date. What the site displays is the aggregate: a playlist page shows each tag and the number of people who applied it, not who applied it. Your own tags are listed on your profile, under your username, and in the data download described below. Article 6(1)(b).

Tags you follow. Following a tag stores one record per tag against your account, with the date, and fills your feed with the playlists people give that tag. A tag’s page shows how many accounts follow it and never which ones. You can unfollow at any time on the same page, and the list is in the data download. Article 6(1)(b).

Your notification setting. Whether you want an email when somebody you follow adds a playlist. Article 6(1)(b). It can be switched off in settings or from the link at the foot of any such email.

Technical records. The hosting provider keeps short-lived server logs, which include the IP address a request came from, and the same address is counted briefly to enforce rate limits on the public endpoints. This serves the availability and security of the site and is not used to build a profile of anybody. Legal basis: Article 6(1)(f), the legitimate interest in a site that stays available and resists abuse.

None of it is used for advertising, profiling, or automated decision-making producing legal effects. There is no analytics, no tracking pixel, and no third-party script measuring what you read.

Cookies

Three, and all three are strictly necessary, so no consent is requested for them. One holds your login session. One records the page you were on when you requested a login link, so that signing in returns you there, and is cleared as soon as it has done so.

The third records your answer about Spotify’s player, so you are not asked again on this device. It is set only if you agree, it lasts six months, and it is deleted the moment you withdraw — under the player itself, or in settings.

None of them is used to track you across sites, and there are no others.

Who else processes it

The site runs on services that process data on the operator’s behalf. Each acts only on instructions, under a data processing agreement:

  • Supabase — the database, the login system, and the storage holding profile pictures. Everything described above is held here.
  • Vercel — hosting. Serves every page and keeps the server logs described above.
  • Upstash — a cache in front of the database, and the rate limiter. Holds already-public content and, briefly, the IP addresses being counted.
  • Resend — sends the login email and the notification emails, and therefore processes your address.
  • Cloudflare — a check on the log-in form, and only there, that the request comes from a person rather than a script. It sees the connection making that one request. It measures nothing about what you read and appears on no other page. Article 6(1)(f), the legitimate interest in preventing the log-in form being used to send mail to people who did not request it.

Supabase, Vercel and Upstash process it in Ireland, inside the European Union. Your profile, your activity, the database, the cache and the pages themselves remain in the EU.

Resend is the exception. Email is sent from the United States, and what Resend holds — your address, the content of the messages sent to you and their delivery logs — is stored there. Selecting a European sending region does not change this; Resend state that no setting moves stored data to the EU. Those transfers are covered by the European Commission’s Standard Contractual Clauses, which form part of the agreement with them, and by their certification under the EU–U.S. Data Privacy Framework.

Google and Apple are not processors. A processor acts on this site’s instructions; neither of them does. If you sign in with one, that company determines for itself what it records about the sign-in, as its own controller and under its own policy, and this site receives the address it confirms. Both are transfers to the United States, covered by their certifications under the EU–U.S. Data Privacy Framework. This occurs only if you use one of those buttons; the emailed link involves neither.

No data is sold, and none is passed to anybody else except where the law requires it.

Spotify

The player does not load until you ask it to. A playlist page shows a placeholder in place of Spotify’s player, and nothing is requested from Spotify until you press it. The player is loaded by your browser directly from them: it discloses your IP address to Spotify and allows them to set their own cookies, as visiting their site would, and if you are signed in to Spotify they can recognise you. That processing is Spotify’s, under their privacy policy, not the operator’s.

Your answer is stored on the device it was given on and is not attached to your account, so agreeing on one device does not agree for another. It can be withdrawn at any time, on the player itself or in settings.

Cover artwork is the exception. Playlist covers are served from Spotify’s image servers, so a page showing them discloses your IP address to Spotify whether or not you load a player. This is not gated for two reasons: an image sets no cookies and reads nothing from your device, and Spotify’s rules require their artwork to be served from them, so it cannot be copied here to avoid the request. It rests on legitimate interest, Article 6(1)(f).

Playlist names, artwork and owner names shown here come from Spotify’s public API. Nightdrive.fm sends them nothing about you: it does not connect to your Spotify account and does not require one.

What other people can see

Your username, picture, bio, the playlists you added, your ratings and likes, your comments, and the lists of who you follow and who follows you are visible to anyone, signed in or not, and to search engines. Your email address and the technical records are not.

Context tags are shown as counts. A playlist page displays each tag and how many people applied it, and never who applied it. Your profile does list the tags you have used, and each of those pages shows the playlists you gave that tag — so a tag is public as something you have said, and never as an answer to “who tagged this playlist”.

Which tags you follow is not shown anywhere, and no profile lists them except your own to you. A tag’s page gives the number of accounts following it and no names, and a row of related tags drawn from what its followers have in common — which is a count of people, never a list of them, and is withheld entirely until enough accounts follow a tag for the figure to describe a group rather than a person.

Deleting a comment leaves the replies under it in place but removes the text and the attribution.

How long it is kept

Your account is kept while it exists. Delete it in settings and your email address, your picture, your bio, your username, every follow in either direction and every tag you follow are removed at once.

What you contributed remains — comments, ratings, likes, context tags and the playlists you added — under a generated username that no longer identifies you. Deleting it outright would remove parts of threads other people are reading and playlists other people have rated. Because your own words can still identify you, this is pseudonymisation rather than erasure: for erasure, write to the address above.

The cache and the rate-limit counters expire on their own, within an hour at the outside. Server logs are kept by the hosting provider for their own retention period. Emails already sent cannot be recalled.

Your rights

Under the GDPR you can ask for:

  • access — a copy of what is held about you (Article 15), which you can download yourself in settings. The file includes your context tags, which are not otherwise listed anywhere;
  • rectification — correction of anything inaccurate (Article 16). Your picture and bio you can edit yourself on your profile;
  • erasure — deletion of your account, which you can carry out yourself in settings (Article 17). See “How long it is kept” for what remains afterwards, and write to the address below for that to be removed as well;
  • restriction and objection — processing restricted, or objected to where it rests on legitimate interest (Articles 18 and 21);
  • portability — the data you provided, in a machine-readable file (Article 20). The download in settings is a JSON file and answers this as well.

Access, portability and erasure can be exercised directly in settings, without a request. For anything else, write to legal@nightdrive.fm from the address the account uses; requests are answered within one month. There is no charge in either case.

If you consider the processing here unlawful, you can lodge a complaint with a supervisory authority. In Austria that is the Datenschutzbehörde, Barichgasse 40-42, 1030 Wien.

Is any of this required

No. The site can be read in full without an account and without providing anything. An email address is required only to open one, because it is how you sign in.

Changes

If what the site does with data changes, this page is amended and the date at the top moves. Nothing here applies retroactively to data already deleted.

Details of who runs the site are on the imprint.

Privacy policy - Nightdrive.fm