Privacy Policy

spotAI Music · Last updated: September 12, 2026 · Version 1.0

One-line summary Listening to music on spotAI Music requires no account and no personal data. If you choose to sign in to save favorites, we store only what that feature needs — and you can ask us to delete it at any time.

1. Who we are

spotAI Music (hereinafter, "the App") is developed and operated by Ingeniería.dev, led by Chris Flores (hereinafter, "we", "the Developer"). The App is the mobile listening client for the spotIA platform, available on the web at spotia.ingenieria.dev, where all music is generated with artificial intelligence.

2. What data we collect

2.1 If you do not sign in (guest mode)

You can browse and play the entire catalog without an account. In guest mode the App does not ask for, and we do not receive, your name, email address, phone number, or any other personally identifiable information. Playback counts are recorded anonymously, with no identifier that links them to you or to a device (see section 2.3).

2.2 If you choose to sign in

An account exists for one reason only: to save your favorites and your ratings across devices. Signing in is always optional. When you sign in with Sign in with Apple or Google Sign-In, our server receives and stores:

DataWhy we store itSource
Provider account identifier (the sub claim from Apple or Google) To recognize you as the same user on your next sign-in. It is the only mandatory field. Apple or Google
Email address, only if the provider sends it Account recovery and support. With Sign in with Apple you may choose Hide My Email, in which case we only ever receive Apple's private relay address and never your real one. Apple or Google
Display name To show who is signed in inside the App. Apple or Google
Country To understand which regions the catalog reaches, in aggregate. Derived at sign-in

We never receive your Apple ID or Google password. Authentication happens entirely on Apple's and Google's side; we only receive the resulting token.

2.3 Activity linked to your account

Once you are signed in, the following actions are stored on our server so they survive reinstalling the App or switching devices:

Plays are recorded anonymously when there is no session — if you are not signed in, the play is counted for the track but is not associated with any user. We do not build listening profiles, we do not infer interests for advertising, and we do not use this information for automated decisions about you.

2.4 What we never collect

3. What is stored on your device

The App keeps very little on the device itself:

DataPurposeLocation
Session token Keep you signed in so you do not have to authenticate every time. Only exists if you signed in. Device (iOS Keychain)
App preferences (for example, whether onboarding was completed) Avoid repeating the introduction on every launch Device (UserDefaults)
Temporary audio and image buffers Smooth playback and scrolling Device (system cache, cleared by iOS)

The session token is stored in the iOS Keychain, the system's encrypted credential store. Signing out or deleting the App removes it from the device.

4. External services used

The App communicates with the following services and no others:

If you never sign in, neither Apple's nor Google's authentication services are contacted at all.

5. System permissions

spotAI Music does not request any sensitive iOS system permission. The App does not ask for access to:

The App does declare the background audio capability, which is what lets music keep playing when you lock the screen or switch apps. This is a playback capability, not a permission: iOS does not show a consent dialog for it and it grants no access to your personal data.

6. Marketing and advertising

The App displays no ads. We do not collect data for remarketing, profiling, segmentation, behavioral analysis, or any promotional purpose. We do not participate in ad networks, and we do not sell information to third parties. We do not send marketing email.

7. Minors

The App is not directed at children. We do not knowingly collect personal information from minors. If you believe a minor has created an account, please write to [email protected] and we will delete it.

8. User rights (GDPR, CCPA, LGPD, LFPDPPP)

You have the following rights over the data associated with your account:

8.1 How to delete your account

To request deletion of your account

Email [email protected] from the address linked to your account, with the subject "spotAI Music Account Deletion". If you signed in with Apple using Hide My Email, write from that relay address so we can match the request to your account.

We delete the account and all data associated with it — provider identifier, email, display name, country, favorites, and ratings — within 30 days, and confirm by email when it is done. Anonymous play counters are not linked to you and therefore cannot be attributed to, or removed for, an individual user.

Deleting the App from your iPhone removes the session token from the device, but does not by itself delete the server-side account — send the request above for that.

For any question about your rights, please email [email protected].

9. Security

All communication between the App and our server happens exclusively over HTTPS/TLS 1.2+. The session token is stored in the iOS Keychain and protected by device-level encryption (Apple's Data Protection API). We never store Apple or Google passwords, because we never receive them.

10. Data retention

Account data is retained for as long as the account exists. When you request deletion under section 8.1, it is removed within 30 days. If you never create an account, there is nothing associated with you to retain.

11. International transfers

Our server is hosted outside Mexico. If you use the App from the European Economic Area, the United Kingdom, or Brazil, the limited account data described in section 2.2 is processed on that server. We apply the same protections described in section 9 regardless of where you are.

12. Changes to this policy

We may update this Privacy Policy to reflect changes to the App or to applicable law. The current version will always be published at this URL, along with the date of the last update. Material changes will also be announced inside the App.

13. Governing law

This Policy is governed by the laws of the United Mexican States, in particular the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP). Any dispute will be submitted to the competent courts of Mexico City.

14. Contact

Privacy Officer: Chris Flores
Email: [email protected]
Postal address: Av. Javier Barros Sierra 495, Santa Fe Lomas de Santa Fe Zedec Santa Fé, Álvaro Obregón 01219, Mexico City, CDMX, Mexico