Legal
Privacy Policy
What Chord Lens collects, what it keeps, who sees it, and why. We have kept it as short as we can.
The short version.
Signing in is optional in the extension and required for the Studio. When you sign in with Google, we keep your name, email address, profile picture and Google account ID.
When you ask for a chart, we record which video, when, your IP address and browser, and your account if you are signed in. The Studio's History page shows you your own list.
The Studio records how it is used, such as opening a song or splitting it, so we can improve it. Those records never include lyrics, chords, file names or anything you type.
Stems you split are made on your own device and kept in your browser, not on our server.
We don't sell your data, and we don't use it for advertising.
YouTube. Chord Lens uses YouTube API Services. This site embeds videos using YouTube API Services; when you play an embedded video, YouTube and Google may collect data under the Google Privacy Policy. By using the YouTube features on this site you agree to the YouTube Terms of Service.
You can remove Chord Lens's access to your Google account at any time on Google's security settings page. To ask about deleting your account and data, email [email protected] and we'll respond.
Who runs Chord Lens
Chord Lens is an independent project. It is not affiliated with, sponsored by, or endorsed by YouTube or Google. For any question about this policy or your data, write to [email protected].
Your account
You sign in with Google. We ask Google only for your basic profile, and we receive:
- your name, email address (and whether Google has verified it) and profile picture;
- your Google account ID, which is how we recognise you next time.
We store those with the date your account was created and the time you last signed in. Chord Lens never sees your Google password, and it gets no access to your YouTube account, your watch history, your email or any other Google service.
Each time your sign-in is renewed, which is about every 15 minutes while you use Chord Lens, we keep a session record: a scrambled (hashed) copy of the sign-in token, when it was issued and when it expires, and your IP address and browser at that moment. Earlier session records are kept too. The website keeps you signed in with two cookies, cl_access (15 minutes) and cl_refresh (30 days), plus a short-lived cookie that protects the sign-in itself. They are needed for sign-in and are used for nothing else. The extension keeps its sign-in tokens in its own storage instead.
Signing out ends the current session on that device and clears its sign-in cookies or tokens. Your other devices stay signed in. Signing out does not delete your account, your history or earlier session records.
Revoking access. You can remove Chord Lens from your Google account on Google's security settings page. That withdraws the permission you gave Chord Lens; it does not delete what we already hold. To ask about deleting that, write to us (see Your choices).
Charts and your history
When you ask for a chart, in the extension or the Studio, we send our server the YouTube video's ID. The server makes the chart, or reuses one it already has. Charts are stored by video, and everyone who opens the same video gets the same chart.
Every chart request is recorded with:
- the video ID and the time;
- your IP address and browser (its user-agent string), and which site or app the request came from;
- a request ID, and whether a chart was served and how it was made;
- your account, if you are signed in.
The first request that causes a video to be analysed is also kept with that video's chart, with the same details. We use these records to run the service, stop abuse and understand how Chord Lens is used. The Studio's History page shows you the charts you looked up while signed in, and only you can see your own list.
Audio
To make a chart, our server may retrieve the audio of the YouTube video you chose. It analyses it and deletes the audio when it is done. Some charts come from music services without any audio being retrieved.
To split a song into stems, or to change its key or tempo, the Studio needs the song's audio in your browser. Our server retrieves it, sends it to you, and deletes its own copy once it has been sent. The extension does the same when you use its Stems tab. We record each of these requests with the video ID, the time, your IP address and browser, and your account if you are signed in.
Chord Lens never uses your microphone and never captures your screen.
Files you upload
In the Studio you can open an audio file from your computer. To find its chords, the file is sent to our server, which deletes it as soon as it has read the chords. We do not keep the file or its name. We record that an upload was charted, whether it worked and how long it took, with your account, IP address and browser.
The chart that comes back is kept in your browser, not on our server. Splitting an uploaded file happens on your device, as below.
Splitting stems
Splitting a song into drums, bass, vocals and the rest is done on your own device, using your browser and your graphics hardware (WebGPU). No audio is sent to us to do it.
In the Studio, the stems and the song's original audio are saved in your browser's storage on this computer, for the account that made them, until you delete them. Signing out does not delete them; they are shown only to the same account when it signs in again on this browser. They never go to our server, and we cannot see them. Clearing your browser's site data for this site removes them.
In the extension, stems aren't saved.
Studio activity
The Studio sends us a record of what happens in it, so we can see which features are used and where things go wrong. Each record holds:
- what happened, such as opened a song, split finished, changed key or saved a loop, and when;
- the song's YouTube video ID, or, for an uploaded file, an ID worked out from the file's contents (a fingerprint, not its name), and small details such as the new key, how many stems, or how long something took;
- your account if you are signed in, or else a random ID this browser keeps; a random ID for the visit; and your IP address and browser.
They never include lyrics, chords, file names or text you type. Where you name something, such as a loop, a section or a folder, only the name's length is sent. These records are read only by the Chord Lens team, for our own reports. They are not shared with anyone and are never sold.
In your browser
The website and the Studio keep some things in your browser's local storage so they are where you left them: the theme, the sidebar and your layouts; display settings such as key, capo and Simplify; recent songs, loops, library folders and tags; the random browser ID above; and the stems and upload charts described above. The extension keeps its settings, the key and speed you chose for recent videos, loops you saved, and a list of videos it found no chords in. None of this is sent to us except as described on this page.
To remove it, clear this site's data in your browser, or uninstall the extension from chrome://extensions.
The extension
The extension runs only on YouTube pages. When you press Chords, or ask for lyrics or stems, it sends our server the video's ID, a key that identifies the Chord Lens extension (the same for everyone), and, if you have signed in, a token for your account. Like any request on the internet, it also reaches us with your IP address and browser, and it is recorded as described above.
Signing in to the extension is optional, and nothing is locked behind it. Changing a song's key or tempo happens in your browser; nothing about it is recorded or sent. The extension never touches your microphone, your screen, other websites, or your YouTube account.
Other services we use
- YouTube. The Studio plays videos in YouTube's embedded player (from
youtube-nocookie.com) and shows video thumbnails from YouTube (i.ytimg.com). When the Studio shows a YouTube video, YouTube receives the request and may set cookies and collect data under the Google Privacy Policy. Your Google profile picture is loaded from Google. - Google Analytics counts visits to this website and the Studio, and to our Chrome Web Store listing. It sets its own cookies and receives your IP address, from which it works out a rough location. What comes back to us is aggregate: how many visits, which pages, roughly which country, what kind of device, and which site referred you. To stay out of it, use Google's browser opt-out add-on or a content blocker; Chord Lens works the same either way. The extension sends nothing to Google Analytics.
- Cloudflare delivers this website and our server's answers, and sees each request to do that.
- Music services. To find lyrics, song sections and some charts, our server may look a video up with third-party music services. Only the video goes with that request, never anything about you.
- Buy Me a Coffee. Links to it are ordinary links. If you follow one, its own privacy policy applies.
Server logs
Like every web server, ours keep access logs: IP address, time, the page or address requested, the response and the browser. They exist to keep the service running and stop abuse, and they are deleted after 14 days.
How long we keep things
We don't delete records on a schedule, and there is no set time limit. That covers your account; your chart history, audio requests, Studio activity and session records; the details kept with a chart you were the first to request (your IP address, browser and account); and records of requests made while signed out. Charts are kept by video, because they describe a song, not you. What is in your browser stays until you delete it.
Sharing
We do not sell, rent or trade your data, and we don't share it with advertisers or data brokers. The only other parties that handle it are the services listed above, for the reasons given there. We would disclose data only if the law required us to.
Your choices
- See your history on the Studio's History page.
- Ask about deleting your data. Email [email protected] from the address on your account to ask about deleting your account and data, or about what we hold about you, and we'll respond.
- Revoke Google access on Google's security settings page.
- Clear what is in your browser by deleting stems in the Studio, clearing this site's data, or uninstalling the extension.
Children
Chord Lens is not directed at children under 13, and we don't knowingly collect data from them. If you believe a child under 13 has signed in, write to us and we'll respond.
Changes to this policy
If what Chord Lens collects changes, this page changes with it, and the date at the top is updated. Material changes will also be noted in the extension's Chrome Web Store listing.