Privacy Policy
Last updated: 24 August 2026
Tunemail lets you send someone music so it opens in whatever streaming service they already use. It is built and run by one person, Daniel Fainberg (dafaspace). This page says plainly what data exists, where it goes, and how to remove it. There is no advertising, no analytics, and no sale of data of any kind.
What you can do without an account
Opening a shared playlist page, browsing public playlists, and playing 30-second previews require no account and create no records about you. Guest browsing inside the app stores nothing anywhere.
What is collected when you create an account
- Email address and password. Used only to sign you in. Passwords are stored hashed by Supabase; nobody can read them.
- Display name, and a username if you choose one. Shown on playlists you make public, in the form "shared by ...".
- Your playlists and tracks. Artist names, track titles, albums, durations, and links. Private playlists are visible only to you, enforced at the database level. Public ones are visible to anyone holding the link.
- Feedback you send. The message, your display name, and your email, so a reply can reach you inside the app. If you attach a screenshot it is stored in a private bucket that only you and the developer can read, never on a public address, and deleting the message deletes the picture with it.
- Link corrections you submit. If you suggest a direct link for a track, the suggestion is stored with your account id for review.
Services that touch data, and what each one sees
- Supabase (hosting of the database and sign-in) holds everything listed above. Servers currently in the ap-northeast-1 region.
- GitHub Pages serves the app itself and keeps ordinary web server logs, including IP addresses, under GitHub's own policy.
- Cloudflare Workers render shared link cards, relay feedback, and resolve track codes. Requests pass through; nothing personal is stored there.
- Apple (iTunes Search and Apple Music API) receives artist and track names, or track codes, to fetch artwork, previews and exact links. Never anything about you.
- Deezer receives track codes for the same purpose. Never anything about you.
- Spotify is contacted only if you connect it to import your playlists. You sign in on Spotify's own page; Tunemail receives a temporary read-only token and the contents of the playlists you pick, and never sees your Spotify password.
- Telegram delivers feedback messages to the developer personally: your display name and the message text.
Streaming links on playlist pages lead to the platforms themselves (Spotify, Apple Music, YouTube Music, Bandcamp and others). Once you tap one, that platform's own privacy policy applies.
The microphone, and identifying a song
In the App Store and Google Play versions only, Tunemail can listen to the music around you to work out what is playing. Nothing happens until you tap the listen button, and your phone will ask for permission the first time.
The recording never leaves your device. Identification uses Apple's ShazamKit, which turns the sound into a short mathematical signature on the phone itself and sends only that signature. The audio is not uploaded, not stored, and not sent to us. We never receive it and never receive the signature either.
What comes back is the name of the recording. If you then add it to a playlist, the artist and title are saved the same way a track you typed in would be. If you do not, nothing is kept.
The browser version does not have this feature and never asks for the microphone.
Deleting your data
Open your account (the avatar in the top bar) and choose Delete my account. This permanently removes your account, your profile, and every playlist and track you created. Shared links to your playlists stop working. This happens immediately and cannot be undone.
Anonymous data that never belonged to a person, such as cached album artwork for recordings, is not tied to any account and is not affected.
What is deliberately not here
- No analytics or tracking scripts of any kind.
- No advertising and no advertising identifiers.
- No selling, renting, or sharing of personal data with anyone.
- No cookies beyond the session that keeps you signed in.
Changes and contact
If this policy changes, the date above changes with it. Questions and requests: feedback@dafaspace.com.
Tunemail is developed by dafaspace. tunemail.app