Privacy Policy
Last updated: 15 July 2026
The English version of this document is authoritative. Interface labels may be translated for convenience.
Privacy at a glance
NowPlaying uses personal data to provide accounts, connected-platform widgets, partner features, security and support. We do not sell personal data and do not use advertising trackers. We use Google Analytics to understand which pages and features are used, and it only runs after you accept optional cookies.
1. Controller and scope
now-playing.top is the controller for personal data processed through this website and its APIs. This policy covers the public website, accounts, widgets, connected-platform features, partner applications, public profiles, announcements and operator-controlled Discord integrations.
Privacy contact: info@now-playing.top.
2. Data we process
| Category | Examples | Why |
|---|---|---|
| Account identity | Provider ID, display name, username, email address, avatar and linked providers. | Create and secure your account, sign you in and send transactional notices. |
| OAuth and platform credentials | Granted scopes, encrypted access or refresh tokens, Last.fm session key, ListenBrainz username and optional token. | Read the connected data you request and keep widgets working until you disconnect. |
| Music and broadcast data | Track title, artist, album, artwork, playback state, source link, YouTube live-broadcast title/status and public stream status. | Render now-playing widgets, history widgets and partner live status. |
| Content and applications | Widget styles, uploaded images, public profile links, partner/collaboration applications, appeal text and announcements created by administrators. | Provide publishing, partner, moderation and support features. |
| Security and operations | Session ID, IP address, user agent, login/provider events, audit logs, request counters, failed-job details and security-key metadata. | Prevent abuse, troubleshoot failures, protect accounts and operate the service. |
| Optional public data | Public handle, selected social links, listening history, partner profile, follower counts and live status. | Shown only when you enable a public feature or join the partner program. |
3. Google API Services and YouTube data
NowPlaying allows users to voluntarily connect their own Google and YouTube accounts. This section explains what Google user data NowPlaying accesses, how that data is used, how it is protected, when it may be disclosed, and how it can be deleted.
Google Sign-In. If you choose Google as a sign-in method, we receive your Google account identifier, name, email address and profile picture (OpenID / profile / email) solely to create, link and authenticate your NowPlaying account and to send service-related email. Google sign-in access and refresh tokens are not retained after the sign-in callback.
Google user data we access
When a user connects their YouTube account, NowPlaying requests read-only access through the following OAuth scope:
https://www.googleapis.com/auth/youtube.readonly
Depending on the features used, NowPlaying may access:
- The authenticated user’s YouTube channel ID
- Channel name, handle and profile image
- Public channel statistics, including subscriber, view and video counts
- Active livestream status
- Public metadata associated with an active livestream, such as its title, thumbnail and broadcast URL
- OAuth access and refresh tokens required to maintain the connection
NowPlaying only accesses information belonging to the Google account that the user has explicitly connected. NowPlaying does not use this access to upload, edit or delete videos, livestreams, comments or other YouTube content, and never receives or stores the user’s Google password.
How we use Google user data
Google and YouTube data is used only to provide user-facing NowPlaying features, including:
- Connecting and identifying the user’s own YouTube channel
- Displaying the connected channel on the user’s NowPlaying account
- Displaying channel identity and public statistics on the user’s own public profile
- Using channel information in a creator or partner application submitted by the user
- Detecting whether the user’s own YouTube channel is currently live
- Displaying the user’s livestream status on their public profile and streaming widget
- Maintaining the authorized YouTube connection
Google user data is not used for advertising, profiling, credit decisions or purposes unrelated to these NowPlaying features.
Public display and data sharing
When enabled by the user, selected public YouTube information may be displayed to visitors of the user’s public NowPlaying profile or viewers of the user’s streaming widget. This may include the channel name, handle, profile image, public channel statistics, and public livestream status and broadcast information. OAuth tokens and other authentication credentials are never displayed publicly.
NowPlaying does not sell, rent or provide Google user data to advertisers, data brokers or information resellers. Google user data may only be processed or disclosed:
- To infrastructure and hosting providers that are necessary to operate NowPlaying
- When the user explicitly chooses to make public channel information visible through a profile or widget
- When required to investigate security incidents, fraud or abuse
- When required by applicable law or a valid legal request
Service providers may only process data as required to provide their services and may not use it for their own advertising or unrelated purposes.
Data protection and security
NowPlaying uses reasonable technical and organizational security measures to protect Google user data, including:
- HTTPS/TLS encryption for data transmitted between the user’s browser, NowPlaying and Google
- Application-level encryption for stored OAuth access and refresh tokens
- Restricted access to production systems and databases
- Access controls limiting sensitive data access to authorized systems and personnel
- Protection of application encryption keys and OAuth client credentials
- Logging practices designed to avoid recording OAuth tokens or other sensitive credentials
- Regular software and security updates
Although no online system can guarantee absolute security, NowPlaying takes reasonable measures to prevent unauthorized access, disclosure, alteration or destruction of user data.
Data retention
Google OAuth tokens and connected-channel records are retained only for as long as the user’s YouTube account remains connected to NowPlaying or for as long as they are required to provide the requested features. Public channel and livestream information may be refreshed or temporarily cached only as necessary to provide the profile and widget functionality.
When a user disconnects their YouTube account or deletes their NowPlaying account:
- Stored Google OAuth tokens are deleted from active systems
- The connection between NowPlaying and the Google account is removed
- Stored YouTube channel information associated with the connection is deleted
- NowPlaying stops requesting new information from the Google and YouTube APIs
Residual copies may remain in encrypted system backups for a maximum of 30 days, after which they are automatically overwritten or permanently deleted.
User controls and deletion
Users can stop NowPlaying from accessing their Google and YouTube data at any time by:
- Disconnecting YouTube from their NowPlaying account settings
- Deleting their NowPlaying account
- Using the NowPlaying data-deletion page
- Revoking NowPlaying’s access through their Google Account permissions
- Contacting us at info@now-playing.top
Deletion requests are processed as soon as reasonably possible and no later than 30 days after a valid request is received, unless a longer retention period is required by law.
Google API Services User Data Policy
NowPlaying’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve visible, user-facing features requested by the user.
4. TikTok Login Kit and API data
TikTok connection is optional and starts only when you choose TikTok. The application may request the approved scopes user.info.basic, user.info.profile and user.info.stats. Depending on what TikTok grants, we may receive your Open ID, Union ID, display name, username, avatar, bio, profile link, verification status, follower/following counts, likes and video count.
We use this information for TikTok sign-in, account linking, displaying the connected account, evaluating a partner application and operating your public partner profile. Access and refresh tokens are encrypted at rest and are deleted when you unlink TikTok or delete your account. We do not publish videos or take actions on your TikTok account.
For approved partner profiles, the scheduler checks publicly available TikTok profile/live pages to determine live/offline state, stream title and viewer count. This public-status check is separate from Login Kit and does not attempt to access private TikTok data.
5. Other connected services
- Twitch: identity, email, channel information, follower count and live status for login and partner features.
- Discord: identity and email for login; an operator-controlled bot/API may synchronize linked-account roles, partner status and bans.
- Spotify: read-only currently-playing and playback-state data using
user-read-currently-playinganduser-read-playback-state. - Last.fm: account name and recent/now-playing scrobbles.
- ListenBrainz: username, optional token and playing-now data. Cover art may be requested from the Cover Art Archive.
Each provider also processes data under its own terms and privacy policy. You can disconnect a provider from your account at any time.
6. Purposes and legal bases
- Contract/service request: accounts, widgets, connected platforms, public profiles and support you ask us to provide.
- Consent: optional OAuth permissions, public listening history, public links and optional preference storage. You can withdraw consent without affecting earlier lawful processing.
- Legitimate interests: service security, abuse prevention, debugging, aggregate usage counters, moderation and reliable operation.
- Legal obligation: responding to valid legal requests and keeping minimal records needed to demonstrate deletion or security actions.
7. Recipients and infrastructure
Data is shared only where needed to provide the service:
- the platform providers you connect, when making their API requests;
- hosting, MySQL/database, cache/Redis, object storage or CDN providers configured by the operator, including S3-compatible storage or Modora CDN where enabled;
- the configured SMTP/mail provider for transactional email;
- operator-controlled Discord webhooks and bot APIs for moderation, partner, status and member-sync workflows;
- Google Analytics (Google LLC) for aggregate site-usage measurement, loaded only after you accept optional cookies;
- external media or font hosts selected by a user or administrator when their URL is embedded in a public post or widget style.
We do not sell personal data or disclose it to advertising networks or data brokers. Providers may process data outside your country under their own safeguards and applicable transfer mechanisms.
8. Retention
| Data | Typical retention |
|---|---|
| Account, connections and content | Until you remove the item, disconnect the provider or complete account deletion. |
| OAuth/platform credentials | Until disconnect or account deletion; short-lived API access tokens may be cached for about 55 minutes. |
| Listening history | Until you clear it, disable/delete the public profile or delete the account. |
| Sessions | Normally 120 minutes of inactivity; persistent sign-in ends on logout, revocation or cookie removal. |
| Administrative audit logs | Normally 365 days, then automatically pruned. |
| Failed background jobs | Normally 7 days; the operator may configure a period up to 365 days. |
| Deletion record | A minimal status/timestamp record and anonymized audit event may be retained to demonstrate completion. |
9. Security
Connections use HTTPS. OAuth and platform secrets are encrypted at rest, sensitive model fields are hidden from normal output, and access is role-controlled. Optional TOTP and WebAuthn/FIDO2 protect accounts. No online service is risk-free, so keep widget URLs private and revoke anything you believe has been exposed.
10. Your choices and rights
You can review or change profile details, unlink providers, revoke widget tokens, clear listening history, disable public features, end sessions and request account deletion. Depending on applicable law, you may also request access, correction, portability, restriction or objection, and complain to your local data-protection authority.
Use the public Data deletion instructions or contact info@now-playing.top.
11. Children and changes
The service is not directed to children who cannot legally consent to the connected services in their country. We may update this policy when features, providers or legal requirements change. Material changes are identified by the updated date and, where required, an in-product notice.