Privacy Policy

Effective July 21, 2026

This policy explains what personal information Track Star (“we”, “us”) collects, how we use it, and the choices you have. It applies to the Track Star iOS app, the trackstar.net website, and any related services.

Who we are

Track Star is a music-guessing game and media brand. The iOS app is distributed through the Apple App Store and TestFlight. The service is operated by the Track Star team; contact information is at the bottom of this page.

Information we collect

Account information (Sign in with Apple)

When you sign in with Apple, we receive: your Apple user identifier, your email address (or Apple's private-relay email if you chose to hide your email), and your first and last name if you chose to share them at first sign-in. We never receive your Apple ID password.

Gameplay data

We store the guesses you submit, the songs you correctly identify, your per-song time-to-guess, your daily and pack scores, streak counts, and badge progress. This data powers your Me tab, the leaderboards, and product analytics.

Music service connections (Spotify and Apple Music)

When you connect a music service via the “Add to playlist” affordance:

  • Spotify: we use Spotify's OAuth 2.0 PKCE flow. Your Spotify access and refresh tokens are stored only on your device in iOS Keychain — they are never transmitted to our servers. We call the Spotify Web API from your device to list your playlists, create a “My Track Star songs” playlist (or add to a playlist you pick), and add the tracks you heard in-game.
  • Apple Music: your Music User Token is transmitted to our servers once at connect time and stored encrypted at rest using symmetric encryption (Fernet AES-128-CBC + HMAC-SHA256). The encryption key is held separately from the database. Cleartext of your token exists only in server memory at the moment we call the Apple Music API on your behalf. You can revoke this at any time by tapping Disconnect in the app.

What we log about music adds

For each “Add to playlist” action, we record: your user id, the Track Star song id being added, the music service (Spotify or Apple Music), the target playlist id and name, whether the add succeeded, and any error reason. We use this to triage catalog problems (e.g. tracks that consistently fail to resolve on Spotify search) and to understand product usage. We do not read any of your other Spotify or Apple Music library data.

Device and push tokens

If you allow push notifications, we store your Apple Push Notification service (APNs) token so we can notify you when the daily drop publishes. You can disable push notifications at any time in iOS Settings → Notifications → Track Star.

Approximate location

We approximate your country from your device's IP address when you sign in and each time you open the app. We use this to understand which countries our players are in and where games are played. Your IP address is used only momentarily to look up the country and is never stored or logged — we keep only the resulting two-letter country code. We do not collect precise or GPS location.

Analytics and diagnostics

We use PostHog for product analytics (event names like “round_started”, “round_correct”, “pack_completed”) and Sentry for crash reporting. Analytics identifiers are tied to your Track Star user id. We do not share individual analytics with third parties.

How we use your information

  • Operate the game (serve rounds, track scores, compute leaderboards).
  • Personalize your Me tab, streaks, and archive.
  • Add songs to your Spotify or Apple Music library when you explicitly tap “Add to playlist”.
  • Send daily-drop push notifications if you have opted in.
  • Understand where our players are (aggregate, country-level geography).
  • Improve the product via aggregated analytics and crash diagnostics.
  • Prevent abuse and enforce our Terms of Service.

How we share your information

We do not sell your personal information. We share data with:

  • Music services (Spotify, Apple Music) — only the information required to complete an action you initiated (creating a playlist, adding a track).
  • Service providers — Railway (hosting), Apple (Sign in with Apple, APNs, App Store), Anthropic (LLM generation of hints/trivia — no personal data sent), PostHog (analytics), Sentry (crash reporting). Each processes data on our behalf and is bound by confidentiality obligations.
  • Law enforcement or legal process — if we are required by law to disclose information.

Data retention

We retain your account and gameplay data for the life of your account. If you delete your account, we delete or anonymize your personal data within 30 days, except where retention is required by law (e.g. tax records) or to resolve disputes.

Your rights

You can:

  • Access the personal data we hold about you by emailing us (contact below).
  • Correct your profile information via the Me tab.
  • Disconnect Spotify or Apple Music at any time from the app.
  • Delete your account by emailing us at privacy@trackstar.net. In accordance with App Store guidelines, in-app account deletion is available in the app settings.

Depending on your jurisdiction, you may have additional rights under laws such as the GDPR (EU/UK) or CCPA (California). We respond to verified requests within 30 days.

Children

Track Star is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, please contact us and we will delete it.

International transfers

Track Star is operated from the United States. If you access the service from outside the US, your data is transferred to and processed in the US, where privacy laws may differ from those in your country.

Changes to this policy

We may update this policy from time to time. We will post the revised policy at this URL and update the effective date at the top. Material changes will be surfaced in-app.

Contact

Questions or requests: privacy@trackstar.net.