Privacy & your data

Your stuff is yours.

What tonal keeps, what it doesn't, and how to take it with you or erase it.

Last updated July 20, 2026

The short version

01

What we store

tonal keeps a short list of things—and this is the whole list:

Your account
Your email and password—the password is stored only as a scrambled hash, so we can't read it. Your username. Optionally, a profile photo and a link. The link can be any web address you choose—we don't verify or restrict where it points—and it's displayed on your profile, so it's exactly as public as your library is.
What you shelve
The films, books, albums, songs, games, podcasts, and places you add—their titles, the cover art we look up for them, and which shelf they're on. Ratings, notes, and dates if you add them, and which service an item came from if it was imported.
How you arrange it
Sort order, shelves you show or hide, your theme, and whether your library is public or private.
Who you follow
So your feed knows whose shelves to show you.
02

What we don't store

When you import your history—a Spotify export, a Goodreads library, YouTube watch history—that file can hold tens of thousands of plays and views going back years. None of it is stored. It's read on your device, tallied into your top artists and most-watched, and discarded. Only the curated result—the things that land on a shelf—is saved.

Visits are counted in aggregate on the server—pages, referrers, countries—with no tracking scripts and no cookies. There's no profile of you behind the numbers.

The practical upshot: even if our database were stolen, there would be no behavioral history in it to steal. Your shelves are all there is.
03

What we do with it

One thing: show your library—to you, and to whoever you choose to share it with. Public means anyone with the link can see it; private means your shelves are visible only to you, though people can still follow you.

Beyond that, tonal learns from the anonymized shape of what people shelve—which albums and films are widely loved, what tends to be kept together. These are aggregate patterns, never a profile of you: nothing in them points back to you, even after you delete your data. They power tonal's recommendations and tell us what to build next. We never sell your data, and we never use it to target ads at you.

04

Your controls

Everything here is self-serve—no emailing support, no waiting:

Edit anything
Add, change, or pull any item off your shelves whenever you like.
Disconnect a service
Disconnecting a source cuts the feed but keeps the items you already imported—they're yours now. Removing them is a separate, deliberate choice.
Export your data
From Settings, download your whole library—shelves, arrangement, and all—as a single file you can keep or take elsewhere.
Delete it
Clear a shelf, wipe your whole library, or delete your account entirely—each removes the data here and on our servers. Routine server backups age out on their own within a few weeks; nothing is kept beyond that.
05

Who else is involved

We lean on a few services to run tonal, and share only what each needs to do its job:

Hosting & database
Your library lives in a database run by Supabase, on servers in the United States. The site is served by Netlify. Like every website, these servers keep routine technical logs for a short time; we don't use them to track anyone.
Email
Sign-in and account emails are sent through Resend. They handle delivery; they don't get your library.
Catalogs
When you search for or add something, the title is looked up in public catalogs—TMDB for film and TV, Apple and OpenLibrary for books, IGDB for games, and the like—to find cover art and details. Some of these requests, along with cover images and fonts, load straight from their servers—so those services see a normal web request from your browser, the same as any site you visit. None of them see your tonal account.
Video
Trailers, and any videos a member adds to their Channel shelf, play directly from the site hosting them—YouTube, Vimeo, or wherever the link points. Playing or viewing one means your browser talks to that host the same way it would on any site with an embedded video, under that host's own privacy policy—tonal never passes it your account. Trailers use YouTube's privacy-enhanced player, we ask Vimeo's player not to track viewers, and the links themselves are stored as part of that member's library.
Services you connect
When you import—Letterboxd, Goodreads, Steam, a Spotify export—we read only what you ask us to import, and keep only the curated result, per section 02.
06

Changes & getting in touch

If we change what we keep or how we use it, we'll update this page, date it at the top, and tell you directly when it's meaningful.

Questions? Email hey@tonal.cc.