Privacy & Security

LyricWave Transparent Data Architecture

← Back to App

🔒 Our Core Privacy Commitment

LyricWave is built with a zero-retention, client-first architecture. We do not track your personal identity, build advertising profiles, or sell any information.

🎙️ 1. Microphone Recognition (Audio)

  • What is captured: A temporary, 10-second compressed audio recording initiated strictly after you tap "Listen".
  • Where it goes: Sent to our serverless Cloudflare Pages endpoint (/api/recognize) which generates an acoustic fingerprint for ACRCloud recognition.
  • Storage policy: Audio data is processed in-memory and never saved to disk or logged. Once recognized, the recording buffer is discarded.
  • Hardware release: All microphone tracks are explicitly closed immediately upon recording completion so your browser/system microphone indicator turns off.

🔍 2. Manual Song Search

  • What is sent: Your text query (e.g. song title or artist).
  • Where it goes: Directly to LRCLIB (open-source lyrics community database) and Apple iTunes Search API to fetch artwork and durations.
  • No authentication: No login or personal information is transmitted.

📻 3. Last.fm Scrobble Tracking

  • What is sent: Your public Last.fm username only.
  • No password: LyricWave never asks for, receives, or stores your Last.fm password.
  • Where it goes: Directly queries the public Last.fm API (user.getrecenttracks) to detect your active scrobble.

🟢 4. Spotify Live Tracking (OAuth PKCE)

  • Authentication: Secure OAuth 2.0 with Proof Key for Code Exchange (PKCE).
  • Tokens: Access and refresh tokens are stored strictly in your device's browser localStorage and never sent to our servers.
  • Permissions: Read-only access to track identity (user-read-currently-playing), playback time and play/pause state (user-read-playback-state), and profile avatar/display name (user-read-private).

💾 5. Local Storage on Your Device

LyricWave stores preferences locally on your browser for convenience:

  • Visual theme, lyrics font scale, and word-by-word reveal mode.
  • Last selected input source and per-source calibration offsets.
  • LRCLIB cached lyric files (to prevent redundant network requests).
  • Last.fm username and Spotify PKCE tokens (if authenticated).
Data Retention Guarantee: None of your music sessions or microphone recordings are stored on our servers. You have complete control over all data saved in your browser.

🛡️ Your Data & Privacy Controls

Take immediate action on any locally stored data or connected sessions: