Privacy & your data
What tonal keeps, what it doesn't, and how to take it with you or erase it.
Last updated July 20, 2026
The short version
tonal keeps a short list of things—and this is the whole list:
When you import your history—a Spotify export, a Goodreads library, YouTube watch history—that file can hold tens of thousands of plays and views going back years. None of it is stored. It's read on your device, tallied into your top artists and most-watched, and discarded. Only the curated result—the things that land on a shelf—is saved.
Visits are counted in aggregate on the server—pages, referrers, countries—with no tracking scripts and no cookies. There's no profile of you behind the numbers.
One thing: show your library—to you, and to whoever you choose to share it with. Public means anyone with the link can see it; private means your shelves are visible only to you, though people can still follow you.
Beyond that, tonal learns from the anonymized shape of what people shelve—which albums and films are widely loved, what tends to be kept together. These are aggregate patterns, never a profile of you: nothing in them points back to you, even after you delete your data. They power tonal's recommendations and tell us what to build next. We never sell your data, and we never use it to target ads at you.
Everything here is self-serve—no emailing support, no waiting:
We lean on a few services to run tonal, and share only what each needs to do its job:
If we change what we keep or how we use it, we'll update this page, date it at the top, and tell you directly when it's meaningful.
Questions? Email hey@tonal.cc.