Last updated 10 August 2026
This policy covers the hosted Chordia service at chordia.dev, operated by the Chordia project. Chordia is also free software that anyone can run themselves. If you use somebody else’s Chordia instance, this policy does not apply to it — whoever runs that instance decides how it handles your data.
Your audio files never reach our servers. Not as an upload, not as a cache, not in transit. When you press play, your device connects directly to your own library server over an encrypted connection and the audio flows between those two machines. We are not on that path and cannot be.
What we do hold is the account and the record around it: who you are, who you have shared with, and what you have listened to.
Your account. Email address, handle, display name, and a hashed password. If you sign in with Discord, we store your Discord account ID so we can recognize you next time. If you set an avatar, we store the image. If you turn on two-factor authentication, we store the secret needed to verify your codes.
Your sessions. A record of each signed-in device so you can see and revoke them, including the browser and platform that device reported. We do not store the IP address of a session.
Your library directory. The name and network address of each library server you pair, and the fingerprint of its TLS certificate so your devices can verify they are talking to the right machine. We store no file paths and no contents.
Catalog metadata. When your library syncs, it sends us the descriptive metadata for your collection: artist, album and track names, durations, track numbers, release dates, and cover artwork. This is what makes search, playlists and your listening history work across devices. It is metadata about the recordings, never the recordings.
Your listening history. Every play is recorded against your account with the track, the time, and the playlist or album it came from. This is what the insights and Wrapped-style pages are built on. You can switch it off in Settings, and doing so stops new events being recorded.
Your social graph and library shares. Friend relationships, follows, blocks, and which of your libraries you have granted to which people.
What you have made. Playlists, liked and hidden tracks, pinned items, and your settings, including the privacy audiences that control who can see your profile, your history and your playlists.
Administrative records. Actions taken by instance administrators — moderation and configuration changes — are written to an audit log so those actions are accountable.
To do its job, Chordia talks to a small number of outside services. Each one receives only what is described here.
We do not sell your data, and we do not share it with advertisers. There is no advertising on Chordia.
Chordia sets one cookie, to remember your chosen language. Your sign-in tokens and interface preferences are kept in your browser’s local storage rather than in cookies, which means they stay on your device and are not sent along with every request. There are no advertising or tracking cookies.
Export everything. Settings has a data export that returns your account, your playlists, your social graph and your full listening history in a machine-readable form.
Delete everything. Deleting your account from Settings removes it and the data described above. Your music is unaffected: it was never ours, and it is still on your own server exactly where you left it.
Control what others see. Each of your profile, your listening history, your playlists and your follows has its own audience setting, from private through to public. Playlists default to private and the rest default to friends-only.
Stop recording history. Turning off history recording in Settings stops new plays being stored.
Account data, listening history and everything you have created are kept for as long as your account exists, because that is the point of them — a listening history is only useful if it goes back. They are removed when you delete your account, and from our backups within 30 days of that.
The hosted service runs on servers in the United States, and our email and error-reporting providers process data there too. If you are in the UK or the EU, that means your data is handled outside it. If you run Chordia yourself, your data is wherever you put it.
Chordia is not directed at children under 13, and we do not knowingly create accounts for them.
If this policy changes in a way that affects what we collect or who receives it, we will update the date at the top of this page and tell account holders by email before the change takes effect.
Questions, requests, or a correction to something on this page: privacy@chordia.dev.