Privacy Policy
Spicy Lyrics
Effective: 2026-09-23 Last updated: 2026-09-23
In short. Your Spicy Lyrics profile is public — anyone can open it without an account, and search engines can index it. We store the profile you customise, a record of the lyrics you have contributed, and how many times they have been viewed. Your IP address is used only to keep bots and abuse off the service, for minutes at a time. We run no analytics, no advertising, and no tracking, and we never sell your data. To see, correct, or delete your data, email [email protected].
Scope — this site only
This Privacy Policy applies only to the websites and web services at spicylyrics.org, including public profile pages and the profile embed used inside the Spotify desktop client.
Spicy Lyrics offers other products and services — the Spicetify extension, the Discord bot, and the lyrics API among them — and each has its own separate privacy policy and terms of service. This document does not cover them.
Spicy Lyrics runs on a shared database used across the whole Spicy Lyrics ecosystem. Data you see on this site is often written by another part of that ecosystem (mainly the Discord bot), and data you change here is visible to the rest of it. Section 4 sets out exactly where each piece of data comes from.
1. Who we are
The Spicy Lyrics web services are operated by Spicy Lyrics, from Slovakia (EU). For the processing described in this policy, Spicy Lyrics acts as the data controller under the General Data Protection Regulation (GDPR).
You can reach us:
- by email at [email protected] — our primary contact for anything in this policy
- on our Discord server at discord.gg/lyrc
Use whichever you prefer. Both reach a person; neither is an automated system.
We have not appointed a Data Protection Officer. We are not a public authority, our core activity is not large-scale monitoring of individuals, and we do not process special categories of data at scale — so Article 37 GDPR does not require one. Write to the address above instead.
2. What we process, why, and for how long
Each row below is a separate processing activity, with the legal basis under Article 6 GDPR that we rely on for it.
| What | Why | Legal basis | How long |
|---|---|---|---|
| Your Clerk account and its link to your Discord account, including your Discord user ID | To sign you in and to know which profile is yours | Art. 6(1)(b) — necessary to provide the service you asked for | Your account record lives with Clerk for as long as you keep it. Your Discord ID stays in our database as the key your profile hangs on, until you ask us to remove it |
| Your Discord username, display name, and avatar and banner image references | To render your public profile | Art. 6(1)(b) for your own profile; Art. 6(1)(f) for showing it to visitors, so contributions can be attributed to a person rather than an anonymous ID | Until you ask us to remove it |
| Which lyrics you made or uploaded, when, and how many times each has been viewed | To show your contributions and their view counts | Art. 6(1)(b) and Art. 6(1)(f) — our and the community's interest in crediting contributors | Until you ask us to remove it |
| The profile customisation you set yourself: colours, background effect and its settings, pronouns, and social links | To render your profile the way you chose | Art. 6(1)(b) | Indefinitely — this has no automatic expiry. It stays until you clear the fields yourself or ask us to remove it |
| Your IP address, for rate limiting | To stop any one client from flooding the service | Art. 6(1)(f) — keeping the service available to everyone | About 60 seconds. Your IP forms part of a short-lived counter key, which expires on its own |
| Your IP address, for the anti-bot check | To tie a solved captcha to the connection that solved it, so one solved challenge cannot unlock a whole fleet of machines | Art. 6(1)(f) — preventing automated abuse | 40 minutes for a pass record, 5 minutes for a single-use challenge handle. Both are deleted automatically |
| Your IP address and your interaction with the captcha, sent to hCaptcha | To verify you are a person | Art. 6(1)(f) — preventing automated abuse | Held by hCaptcha under their privacy policy, not by us |
| Your Clerk user ID, as a rate-limit key (used instead of your IP once you are signed in) | Same as rate limiting above | Art. 6(1)(f) | About 60 seconds |
| Diagnostic error messages, which can include your Discord user ID | To find out why something broke | Art. 6(1)(f) — keeping the service working | Written to our server's console output. We do not send them to any logging or monitoring service, and we do not index, search, or analyse them |
We also cache song metadata and album artwork from Spotify for about 7 days. That describes songs, not people, so it is not personal data — it is listed here only for completeness.
About the legitimate interests we rely on. Where the table says Art. 6(1)(f), we have weighed our interest against your privacy. In every case the data is either technical and short-lived (IP addresses held for seconds or minutes, solely to block abuse) or it is information you chose to publish on a public profile. None of it is used to build a profile of you, to target you, or for any purpose beyond the one named. You can object to any of it — see Section 10.
About pronouns and social links. These are free-text fields you fill in yourself. Depending on what you write, they may reveal something sensitive about you, such as your gender identity. We treat that as information you have manifestly made public by choosing to publish it on a public profile page, which is the condition in Article 9(2)(e) GDPR. We do not infer anything from these fields, and you can clear them at any time. If you would rather not publish something, leave the field empty.
About your email address. We never read, display, or store it. When you are signed in, our server does fetch your full account record from Clerk in order to read your Discord ID out of it — the rest of that record, including your email address, is not used, not logged, and not saved anywhere by us.
3. What we do not do
- No analytics of any kind. No Google Analytics, no Plausible, no product analytics, nothing.
- No advertising, no ad networks, no ad identifiers.
- No behavioural tracking, no cross-site tracking, no fingerprinting.
- No selling, renting, or sharing your data with data brokers.
- No profiling in the sense of Article 4(4) GDPR — we do not evaluate or predict anything about you.
- No email marketing. We do not have your email address.
4. Where your data comes from
Some of what appears on your profile was never given to us by you directly. Article 14 GDPR requires us to say where it came from.
| Source | What comes from there |
|---|---|
| You, on this site | Your profile customisation: colours, background effect, pronouns, social links |
| Clerk and Discord, when you sign in | Your Clerk user ID and the Discord user ID linked to it |
| The Spicy Lyrics Discord bot and the shared ecosystem database | Your Discord username, display name, and avatar and banner image references; the record of which lyrics you made or uploaded and when; view counts; and any moderator or administrator role you hold |
| Spotify's metadata service | Song titles, artists, and album artwork — about songs, not about you |
The third row matters most: your public profile is largely assembled from data the Discord bot wrote, not from anything you typed on this website. If you want that data changed or removed, Section 10 tells you how — we handle it across the whole ecosystem, not just here.
5. Cookies and browser storage
| Name | Set by | Kind | What it does | How long |
|---|---|---|---|---|
capt_pstk |
Spicy Lyrics | Cookie — HttpOnly, SameSite=Lax, Secure over HTTPS |
Records that this browser passed a captcha, so you are not challenged again on every page | Valid for 40 minutes on our side. The browser copy is set to a much longer expiry, but it stops meaning anything after those 40 minutes — our server, not the cookie, decides when it expires |
capt_hnav |
Spicy Lyrics | Cookie — readable by the page, SameSite=Lax |
Tells the page to navigate by full page loads, so the security check can run on each one | Until you close your browser |
hp_deck |
Spicy Lyrics | Cookie — HttpOnly, SameSite=Lax, Secure over HTTPS |
Lists which of the homepage's demo clips you have already been shown, so a refresh gives you one you have not seen instead of repeating. It holds nothing but those clip names — no identifier, nothing about you — and is read for no other purpose | Until you close your browser |
| Clerk session cookies | Clerk | Cookie | Keeps you signed in and protects the session | Set by Clerk — see their privacy policy |
| hCaptcha cookies and storage | Intuition Machines (hCaptcha) | Cookie and browser storage, only on the captcha page | Runs the challenge and remembers its result | Set by hCaptcha — see their privacy policy |
Why there is no cookie banner. Almost everything in this table is strictly necessary to deliver a service you explicitly asked for — signing in, and the security check that keeps the site reachable. The one exception is hp_deck, which exists purely so the homepage does not show you the same clip twice; it stores a list of clip names and nothing else, it is never read for any other purpose, and clearing it costs you nothing but a repeated video. We set no analytics, advertising, or tracking cookies, so there is nothing to ask you to opt into.
6. Your profile is public
This is the most important thing to understand about this service.
- Profile pages are public. Anyone can open
spicylyrics.org/your-usernamewithout signing in. - Search engines can index them. We do not ask crawlers to stay away, so your profile can appear in search results.
- Your profile appears in link previews. When a profile link is shared on Discord, X, or anywhere that unfurls links, your Discord avatar is used as the preview image. On Discord, the preview is a card that also shows your display name, username and pronouns, how many songs you have made and uploaded with their view counts, and your most-viewed songs.
- Profiles can be embedded. A profile can be shown inside the Spotify desktop client through our embed view.
- A public profile shows: your username and display name, your avatar and banner, your pronouns, your social links, and the songs you have made or uploaded lyrics for, with their view counts.
Please do not put anything in the pronouns or social-link fields that you would not want public, indexed, and shared. If you want your profile taken down, see Section 10.
7. Who else your data reaches
We do not sell your personal data, and we never will. It reaches the following parties, and no others:
| Who | Why | Where |
|---|---|---|
| Clerk, Inc. | Runs authentication and sessions | United States. Certified under the EU–US Data Privacy Framework |
| Intuition Machines, Inc. (hCaptcha) | Runs the anti-bot challenge; receives your IP address and your interaction with the challenge | United States. Certified under the EU–US Data Privacy Framework |
| Cloudflare, Inc. | Proxies all traffic to the site, providing TLS, caching, and bot protection. All requests pass through it | Global network. Certified under the EU–US Data Privacy Framework |
| Our hosting provider | Runs the server the site is served from | United States (Phoenix, Arizona) |
| Discord | Your browser loads avatars and banners directly from Discord's CDN, so your IP address reaches Discord | See Discord's privacy policy |
| Spotify | Your browser loads album artwork directly from Spotify's CDN, so your IP address reaches Spotify | See Spotify's privacy policy |
| The wider Spicy Lyrics ecosystem | The Discord bot and the shared database read and write the same profile and contribution records | Covered by their own policies |
| Spicy Lyrics moderators and administrators | Can view and edit profile customisation for moderation purposes — see our Terms of Service | — |
| The public | Everything described in Section 6 | — |
We may also disclose data where we are legally required to, for example in response to a valid order from a competent authority.
8. International data transfers
We operate from Slovakia (EU). Our server is in the United States, and several of the providers above are US companies. Your data is therefore transferred to and processed in the United States.
For those transfers we rely on:
- the EU–US Data Privacy Framework, for providers certified under it — currently Clerk, Intuition Machines (hCaptcha), and Cloudflare; and
- the European Commission's Standard Contractual Clauses, together with supplementary technical measures such as encryption in transit, where a provider is not covered by the Framework.
The legal basis for transfers to the United States has been challenged before and may be again. If the Data Privacy Framework ceases to be a valid transfer mechanism, we will move the affected transfers onto Standard Contractual Clauses and update this policy.
9. How long we keep things
Section 2 gives the retention period for each activity. In summary:
- Rate-limit records — about 60 seconds.
- Anti-bot records containing an IP address — 40 minutes, or 5 minutes for a single-use challenge handle.
- Cached song metadata — about 7 days.
- Your profile customisation, contribution records, and view counts — kept indefinitely, with no automatic expiry, until you clear them yourself or ask us to remove them.
- Diagnostic error output — kept only as long as our server's console output is retained; not collected into any searchable store.
10. Your rights
If the GDPR applies to you, you have the right to:
- access the personal data we hold about you, and get a copy;
- rectify data that is wrong or incomplete;
- erase your data ("right to be forgotten");
- restrict how we process it;
- port it — receive it in a structured, machine-readable format;
- object to processing based on our legitimate interests (the Art. 6(1)(f) rows in Section 2).
Exercising any of these is free, and we will not treat you differently for it.
How to exercise them. Email [email protected], or reach us on Discord. Tell us what you want and enough for us to find your data — your Discord username or user ID is usually enough. If we cannot tell that a request is really from you, we may ask for something that confirms it, such as a message from the linked Discord account.
We will respond within one month. If a request is unusually complex we may extend that by up to two further months, and we will tell you if that happens.
There is no self-serve delete button. Account and profile deletion is handled by hand — there is no button in the app for it today. Email us and we will do it. Because your profile data lives in a database shared across the whole Spicy Lyrics ecosystem, we handle erasure across that ecosystem and not only on this website.
You can also change or clear much of your data yourself at any time, without asking us: your colours, background effect, pronouns, and social links are all editable from your profile.
11. Complaints
If you think we have handled your data unlawfully, please tell us first — most things are quickest to fix directly. You also have the right to complain to a data protection supervisory authority at any time, without contacting us first.
Our lead supervisory authority is:
Úrad na ochranu osobných údajov Slovenskej republiky Hraničná 12, 820 07 Bratislava 27, Slovak Republic dataprotection.gov.sk
If you live elsewhere in the EEA, you can complain to your own national authority instead. The European Data Protection Board lists them all.
12. Automated checks on your connection
To keep bots and automated abuse off the service, some requests are screened automatically before the page loads. The screening looks at network-level signals our CDN provides about your connection — such as the type of network it comes from and whether it is a recognised bot — and at how many requests have recently come from it.
If a connection looks automated, the result is a captcha challenge: solve it, and you continue to the page you asked for. We do not publish the exact rules, because doing so would tell the abusers we are blocking exactly how to get around them.
This screening does not produce a decision that has legal effects on you or similarly significantly affects you, so Article 22 GDPR does not apply to it. It looks only at the connection, never at who you are or what you have done on the site, and it cannot delete anything or change your profile. If you believe you are being challenged or blocked in error, contact us and a person will look into it.
13. Children
You must be at least 13 years old to sign in and have a profile — or older, if the law where you live sets a higher minimum for using a service like this. You must also meet Discord's own age requirements, since signing in goes through Discord.
To be clear about why 13: Article 8 GDPR sets a higher age (16 in Slovakia) for services that rely on a child's consent. We do not rely on consent for any of the processing in Section 2 — it rests on providing the service you asked for and on our legitimate interest in keeping it running — so that threshold is not the operative one here. We have set 13 as our floor instead.
We do not knowingly process the data of anyone below that age. If you believe we hold data about a child who is too young to use the service, email [email protected] and we will remove it.
14. How we protect your data
- All traffic is served over HTTPS and passes through Cloudflare's proxy.
- The captcha pass cookie is
HttpOnly, so page scripts cannot read it. - We send hardening headers on every response, including a policy that stops the site from being framed by other websites.
- Requests are rate limited, so no single client can flood the service.
- We never store passwords or login credentials — authentication is handled entirely by Clerk.
- We collect as little as we can: no analytics, no tracking, and IP addresses held for minutes rather than months.
No system is perfectly secure, and we cannot guarantee absolute security. If we ever suffer a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the supervisory authority as Articles 33 and 34 GDPR require.
15. Changes to this policy
We may update this policy as the service or the law changes. The "Last updated" date at the top always reflects the current version.
If a change materially affects your rights or how we use your data, we will say so clearly on the site rather than quietly changing the date. Changes are not retroactive: we will not start using data we already hold for a materially different purpose without a lawful basis for doing so, and where that basis is your consent, we will ask for it.
16. Contact
For anything in this policy, including any request under Section 10:
- Email: [email protected]
- Discord: discord.gg/lyrc
A short description of what you need is enough to get started.