The short version
Like Current Song runs entirely on your own device and talks only to the music service you connect it to. The project operates no server, collects no analytics, and the maintainer receives no data from your installation. Your access tokens never leave your device.
What the app accesses
When you connect an account, the app asks that service for one fixed set of permissions. The set is the same for everyone and is requested in full at sign-in, whether or not you later switch on the optional features — the in-app toggles control what the app does, not what it is allowed to do.
Spotify
The app requests, and the consent screen lists:
- What is playing right now
(
user-read-playback-state) — to know which song to save. - Your saved tracks, read and write
(
user-library-read,user-library-modify) — to add the song, and to check whether it is already there. - Your playlists, read and write
(
playlist-read-private,playlist-read-collaborative,playlist-modify-private,playlist-modify-public) and following artists (user-follow-modify, anduser-follow-readon desktop).
The playlist and follow permissions are used only by the optional extra actions — archive clean-up, best playlist and follow-artist. If you leave those switched off, the app never calls them, but the permission is still granted at sign-in, and you can see and revoke it at any time (see below).
YouTube Music
- The thumbs-up itself uses the media session that YouTube Music publishes on your phone. It needs no Google account and no sign-in.
- If you choose to sign in, the app requests exactly two scopes, and no others:
https://www.googleapis.com/auth/youtube— to look up the playing song through the YouTube Data API and rate it. The same scope also covers editing your own playlists and channel subscriptions, which happens only when you switch on the optional extra actions.openid— to obtain the account identifier that the like counter is keyed by, so a count follows you across your own devices. It gives the app no access to your name, email address or profile.
What is stored, and where
- Access and refresh tokens — on Android, in the operating system's
encrypted storage; on desktop, in files under
~/.like_spotify/. They stay on the device and are never transmitted anywhere except back to Spotify or Google. - Your own API credentials (the client ID and secret of the application you register) — stored the same way, on the device only.
- Your settings and the in-app log — on the device only. The log records what the app did (which song, which action, which error) so you can diagnose a failed like. You can clear it from the Logs screen.
- A local like counter — how many times you liked a given track or artist, kept on the device.
The optional shared counter
The app can keep the like counter across several of your own devices. The place it keeps it is a Google Sheet you own. There is no database and no server operated by this project, and nothing is shared with anyone: the numbers are rows in a spreadsheet in your own Google Drive, which you can open, edit, export or delete at any time.
It is off until a spreadsheet is configured. When you turn it on, the app asks you to sign in to Google a second time, separately from YouTube Music, and requests exactly one scope:
https://www.googleapis.com/auth/spreadsheets— to read and write the counter's own spreadsheet. This sign-in is used for nothing else, and it is independent of which music service you use, so a Spotify user can have a shared counter without ever granting a YouTube permission.
You can either name a spreadsheet you already have, or ask the app to make one. If you
ask it to, it creates a new spreadsheet file in your Google Drive,
named for this app and containing only the counter's two empty tabs and their header
rows. That is the one file it creates; it is yours, it appears in your Drive like any
other, and you can rename, move or delete it whenever you like — deleting it simply
turns the shared counter off. No extra permission is involved: the same
spreadsheets scope above is what allows it, and no Drive permission is
asked for, so nothing outside Google Sheets is reachable at all.
To be exact about that scope, because Google's consent screen is blunt about it: it says the app may see, edit, create and delete all your spreadsheets, and that is genuinely what the permission covers — Google offers no narrower one that can also create a file. What the app actually does with it is fixed in code you can read: it creates the one counter spreadsheet, and afterwards reads and writes only the spreadsheet whose id is in your settings. It never lists your spreadsheets and never opens one you did not name.
Each liked track gets one row on the Likes tab: an identifier for your
music-service account, the identifier of the track, the count, whether the first count
was backfilled, and the time. If the follow-artist action is on, on either device, it also adds
a row to the ArtistTracks tab pairing the track's identifier with the
artist's identifier, so it can tell when an artist reaches the threshold. No song
titles, no artist names, no listening history, no personal profile. If no spreadsheet
is configured, the counter stays entirely local and no Google sign-in is asked for.
What is never done
- No analytics, telemetry, crash reporting or advertising SDK of any kind.
- No data is sold, rented or shared with third parties.
- The maintainer has no access to your account, your tokens or your listening history.
Third-party services
When you connect an account, your data is handled by that service under its own terms. This application uses YouTube API Services; by using it you also accept the YouTube Terms of Service, and Google's handling of your information is described in the Google Privacy Policy. For Spotify, see the Spotify Privacy Policy.
Revoking access and deleting data
- Google / YouTube — revoke at myaccount.google.com/permissions.
- Spotify — revoke at spotify.com/account/apps.
- Everything on the device — disconnecting the service in the app
deletes its stored tokens. Uninstalling the app (or deleting
~/.like_spotify/on desktop) removes the settings, the log and the local counters. - The shared counter — its rows live in your own spreadsheet, so deleting them is deleting rows, or the sheet itself. Nobody else has a copy.
Because the project holds no data about you, there is nothing for the maintainer to delete on your behalf.
Children
The app is not directed at children under 13 and collects nothing from anyone.
Changes
If this policy changes, the new version is published on this page with a new effective date, and the change is recorded in the project's commit history.
Contact
Questions about this policy: open an issue at github.com/Osasuwu/like-current-song/issues, or email petrkudr2@gmail.com. Suspected security problems should go through a private advisory, as described in SECURITY.md, rather than a public issue.