Privacy Notice
Effective date: September 12, 2026. Privacy Notice version: 2026-09-12.
Operator
Music Digging is operated by an individual. The operator's legal name and postal address are not published to protect personal safety and privacy. For a valid request requiring those details, contact us; after verifying the request, our target is to respond within 10 business days.
Service scope
This no-charge public beta is intended primarily for people in Japan and the United States. We do not geoblock the service. Availability remains subject to these terms, service limits, and applicable law.
Information we collect
We collect your email address; hashed email sign-in code and verification records; email and IP-address rate-limit state; authentication-session IP address and User-Agent; account and session records; session questions, messages, reactions, selected songs, notes, candidate history, and derived preferences; and, only if you connect Last.fm, your Last.fm username, listening history, and playcounts. Cloudflare Web Analytics collects aggregate site-traffic and performance measurements; we do not send it question, song, or account identifiers. Cloudflare Worker logs may contain service-operation information.
Purposes of use
We use this information to authenticate you; provide music-discovery sessions; avoid repeat candidates; remember keepers and observations; measure aggregate site visits, referrers, and performance; operate deletion, retention, security, and usage limits; and investigate failures or misuse.
Service providers and external transmission
Cloudflare provides the Worker runtime, global edge delivery, Durable Object storage for active session state, email/IP rate-limit storage, and Web Analytics for aggregate site visits, referrers, and performance measurement. Neon stores application, account, and authentication records in US East (Ohio). Resend receives the email address and code needed to send a sign-in email. OpenRouter receives the question, original user messages (including reactions and notes), anchors, derived constraints, prior candidates, and Last.fm and web-search results to generate responses; every call requests Zero Data Retention routing. Serper receives web-search queries. MusicBrainz receives only candidate artist and track names plus the application User-Agent, and returns recording title, artist credit, and MBID for existence verification. Last.fm is used only when its integration is enabled and connected; it receives artist and track names and the linked username, and returns listening history and playcounts. Apple iTunes Search receives candidate artist and track names with country=JP and lang=ja_jp; its response is memory-cached for up to one hour.
International processing
Information may be processed outside your country. Cloudflare's edge and Durable Object locations are not restricted to one jurisdiction. Neon processes and stores its database in US East (Ohio); Resend processes email principally in the United States; OpenRouter routes through the United States and uses variable Zero Data Retention-qualified endpoints; Last.fm may process data in the United Kingdom and globally. Serper's exact processing location and Apple's processing location are not published. Provider processing and retention are governed by their policies; we do not make promises about unverified provider settings or practices.
Cookies and local storage
We use a necessary first-party, HttpOnly session cookie for sign-in. Its default lifetime is seven days. We store your language preference (music-digging-locale) in localStorage. For signed-in users, your dismissed Privacy Notice version is stored in your account on our server; for visitors who are not signed in, we may store it (music-digging-privacy-notice-version) in localStorage.
Retention and deletion
Sign-in codes expire after five minutes; verification records become eligible for deletion after 24 hours; and email/IP rate-limit state expires in about 10 minutes. Raw session events and reaction text become eligible after 30 days. Completed session state, and unfinished session state after 24 hours of inactivity, become eligible for scheduled deletion; deletion uses batches and retries and is not immediate. Account-associated application data is deleted through the account-deletion flow. Cloudflare Worker logs are retained for up to seven days. Cloudflare Web Analytics makes its site-measurement data available for up to six months. Provider backups, logs, and other provider-side retention follow their own policies and are not controlled by us.
Security
We use account-scoped access controls, encrypted transport, hashed sign-in codes, secret-access restrictions, rate limits, and scheduled deletion. No security measure can guarantee that an incident will never occur.
Your requests and rights
You may ask about access, correction, deletion, or other handling available under applicable law through the contact route. Send a request from your registered email address when possible. We may ask for information needed to verify the request and protect another person's data.
No sale or targeted advertising
We do not sell personal information, use it for targeted advertising, or use advertising cookies. We use Cloudflare Web Analytics only for site measurement.
Age requirement
The service is for people aged 18 or older. Do not use it if you are under 18.
Changes
We may change this notice when necessary. We will publish a new effective date and version before the change applies.