🔒 Our Core Privacy Commitment
LyricWave is built with a zero-retention, client-first architecture. We do not track your personal identity, build advertising profiles, or sell any information.
🎙️ 1. Microphone Recognition (Audio)
- What is captured: A temporary, 10-second compressed audio recording initiated strictly after you tap "Listen".
- Where it goes: Sent to our serverless Cloudflare Pages endpoint (
/api/recognize) which generates an acoustic fingerprint for ACRCloud recognition. - Storage policy: Audio data is processed in-memory and never saved to disk or logged. Once recognized, the recording buffer is discarded.
- Hardware release: All microphone tracks are explicitly closed immediately upon recording completion so your browser/system microphone indicator turns off.
🔍 2. Manual Song Search
- What is sent: Your text query (e.g. song title or artist).
- Where it goes: Directly to LRCLIB (open-source lyrics community database) and Apple iTunes Search API to fetch artwork and durations.
- No authentication: No login or personal information is transmitted.
📻 3. Last.fm Scrobble Tracking
- What is sent: Your public Last.fm username only.
- No password: LyricWave never asks for, receives, or stores your Last.fm password.
- Where it goes: Directly queries the public Last.fm API (
user.getrecenttracks) to detect your active scrobble.
🟢 4. Spotify Live Tracking (OAuth PKCE)
- Authentication: Secure OAuth 2.0 with Proof Key for Code Exchange (PKCE).
- Tokens: Access and refresh tokens are stored strictly in your device's browser
localStorageand never sent to our servers. - Permissions: Read-only access to track identity (
user-read-currently-playing), playback time and play/pause state (user-read-playback-state), and profile avatar/display name (user-read-private).
💾 5. Local Storage on Your Device
LyricWave stores preferences locally on your browser for convenience:
- Visual theme, lyrics font scale, and word-by-word reveal mode.
- Last selected input source and per-source calibration offsets.
- LRCLIB cached lyric files (to prevent redundant network requests).
- Last.fm username and Spotify PKCE tokens (if authenticated).
Data Retention Guarantee: None of your music sessions or microphone recordings are stored on our servers. You have complete control over all data saved in your browser.
🛡️ Your Data & Privacy Controls
Take immediate action on any locally stored data or connected sessions: