Privacy Policy
MusiCal is a small concert calendar run by Tyler Barnes as an individual. This page describes what data MusiCal collects, why, and what you can do about it. Plain English; no fine print.
What we collect
If you just browse the calendar
- Page views and basic metadata (referrer, country, device type) via Cloudflare Web Analytics. No cookies, no individual identifiers, and Cloudflare doesn't share this data with third parties.
- Server error reports via Sentry — only when something breaks. Includes the request URL and a stack trace, but we have user IPs and emails explicitly turned off.
If you sign in with email
- Your email address. Used to send you the sign-in link and to identify your account on return visits. We don't sell, share, or send marketing — just the sign-in link itself, delivered through Resend.
- A session cookie on your browser that keeps you signed in for 30 days. It's HttpOnly and Secure, only readable by MusiCal's server.
If you also connect Spotify
- A Spotify access token and refresh token tied to your MusiCal account. These let MusiCal read your listening data from Spotify until you disconnect or delete your account.
- Your Spotify display name and a list of artists you've listened to (recent + top artists). This powers the "Only show my artists" filter. We never read or store your full listening history, playlists, friends, or anything else from Spotify beyond the artist names and ranks.
Who else sees your data
MusiCal uses a few third-party services as processors. Each only sees the narrow slice they need:
- Neon — hosts MusiCal's database.
- Railway — runs MusiCal's server.
- Resend — sends the sign-in email.
- Cloudflare — handles traffic to the site and provides anonymized analytics.
- Sentry — receives error reports (no personal data attached).
- Spotify — only if you choose to connect Spotify. Their privacy policy applies on their end.
No data is sold to anyone. No advertising trackers. No analytics tools beyond Cloudflare's privacy-friendly Web Analytics.
How long we keep things
- Calendar data (concert listings) — kept indefinitely; it's public information.
- Your account and Spotify data — kept until you delete your account.
- Sign-in links — automatically expire after 15 minutes and can only be used once.
- Sessions — expire after 30 days of inactivity.
- Error reports — retained by Sentry per their default (90 days).
Your controls
- Disconnect Spotify at any time from the Streaming filters card. Wipes your Spotify tokens and artist list.
- Sign out at any time to end the current session.
- Delete your account from the Streaming filters card. This permanently removes your email, sessions, Spotify tokens, and artist data. It can't be undone.
- Email us at [email protected] for any other request — access, correction, deletion outside the UI, or just a question.
Changes to this policy
If we materially change what we collect, we'll update this page and bump the date at the top. Continued use of MusiCal after a change means you accept the updated policy.
Contact
Questions or concerns: [email protected].