This Privacy Policy is developed in accordance with the requirements of Federal Law No. 152-FZ of 27.07.2006 (Russia) and Regulation (EU) 2016/679 (GDPR) and describes the data processing procedures for PlaylistMaker users.
IE Beshkarev Vladislav Viktorovich
Email: info@playlistmaker.ru
GDPR Representative: info@playlistmaker.ru
PlaylistMaker works with pseudonymized technical identifiers. We do not collect names, addresses, phone numbers or other classic personal data. Telegram ID is a platform technical identifier that does not allow identifying a natural person without access to Telegram.
| Data | Purpose | Required |
|---|---|---|
| Telegram ID, username, name | Bot user identification | Yes |
| OAuth tokens (AES-256 encrypted) | Access to music services | Yes |
| Playlist history | Statistics, usage limits | Yes |
| Credit balance | Paid and free operations accounting | Yes |
| Payment receipt only (tax requirement) | No | |
| Interface language | Bot localization | No |
Legal basis: user consent (Art. 9 152-FZ; Art. 6(1)(a) GDPR), contract performance (Art. 6(1)(b) GDPR), legitimate interest (Art. 6(1)(f) GDPR).
Data is stored on secure servers in Finland (EU, Hetzner Helsinki). Finland is an EU member state and provides a level of data protection compliant with GDPR requirements.
Primary servers are located in Finland (EU). Database backups are stored on servers in the Russian Federation for service reliability. All data is processed in accordance with GDPR.
All OAuth tokens are encrypted before storage using AES-256.
We do not sell or transfer data to third parties for commercial purposes. Transfers occur only to the extent necessary for service delivery:
| Recipient | Purpose | Country |
|---|---|---|
| Apple Inc. (Apple Music API) | Creating playlists in Apple Music | USA |
| Google LLC (YouTube Data API) | Creating playlists in YouTube Music | USA |
| Spotify AB (Spotify Web API) | Creating playlists in Spotify (Beta) | Sweden/USA |
| Yandex LLC (Yandex Music) | Creating playlists in Yandex Music | Russia |
| AudD API | Music track recognition | USA |
| DeepSeek AI | Playlist generation (user text prompt only) | China |
| YooKassa | Payment processing | Russia |
| Telegram Messenger | Bot platform | UAE |
PlaylistMaker uses DeepSeek AI for playlist generation. The architecture is built on the principle of complete data isolation in accordance with GDPR requirements.
This architecture complies with Google API Services User Data Policy (Limited Use), Apple Music API Terms and Spotify Developer Policy.
PlaylistMaker uses Google API exclusively for creating playlists in YouTube Music. We request access to the youtube.force-ssl scope.
Access tokens are stored encrypted (AES-256). We do not read the contents of the user's YouTube account.
PlaylistMaker's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
PlaylistMaker uses Apple Music API exclusively for creating playlists. Authorization via MusicKit — Apple's official mechanism. We do not access payment data or Apple ID passwords. Music User Token is stored encrypted and used only for playlist creation on user request.
PlaylistMaker uses Spotify Web API in closed beta testing mode exclusively for creating playlists. Authorization via OAuth 2.0. We do not access payment data or passwords. Token is stored encrypted. Beta participation — by request to info@playlistmaker.ru.
PlaylistMaker uses the unofficial Yandex Music API. The user independently obtains an OAuth token via Yandex authorization service. We do not access the account password. Token is stored encrypted. The user can revoke the token at any time in Yandex ID settings.
Users from EU/EEA have the following rights under Art. 15–22 GDPR:
Finnish supervisory authority: Office of the Data Protection Ombudsman (tietosuoja.fi)
To exercise your rights: info@playlistmaker.ru. Response time — 30 days.
Revoke access: Google · Apple ID Settings · Spotify · Yandex ID
The playlistmaker.ru website does not use cookies to track users. The Telegram bot operates without cookies.
When using third-party APIs (Apple Music, Google, AudD, DeepSeek) some data may be transferred outside the EU based on standard contractual clauses (SCCs) or other GDPR mechanisms (Chapter V). Transfers to DeepSeek (China) are limited to user text prompts and do not include data from Google/Apple/Spotify APIs.
The current version is always available at playlistmaker.ru/en/privacy. Users will be notified of significant changes via the bot.