YOUR EMAIL STAYS PRIVATE

Privacy, in plain language.

MelodyMeter uses your email to verify ownership before counting a rating. Verification emails are transactional: we do not use your address for a mailing list or marketing.

What we keep

The voting database stores a server-keyed identifier derived from your normalized email, your scores, and their submission time. Public pages show averages and counts, never email addresses or voter identifiers. This identifier is pseudonymous rather than anonymous.

Your email is passed to Resend to deliver the confirmation link. Email delivery services may retain delivery records under their own policies. We do not store raw addresses in the voting database or include them in application logs.

Verification and sessions

Verification links expire after 30 minutes and can be used once. Expired pending submissions are removed within 24 hours. A private session cookie keeps your verified identity active on this browser for 30 days. It lets you rate more songs without receiving an email for each one.

On your device

Favorites, cached rating snapshots, and unfinished score drafts stay in your browser. Drafts do not include your email. Clearing site data removes them. The app caches public pages and assets for offline reading, and never caches verification requests or private API responses.

Keeping votes useful

Cloudflare Turnstile helps protect submissions from automated abuse. The server applies request limits using short-lived keyed identifiers. Invalid votes may be excluded, and their removal updates the public averages.

Local testing

In local development, confirmation messages appear in a local test inbox and no email is sent. The test inbox and verification bypass are disabled when the app is configured for its public domain.