Skip to content

Privacy

KaraTube is a karaoke queue built on top of the official YouTube APIs. This page describes exactly what it stores, why it stores it, and what you can demand of us under the GDPR.

Last updated: 11 August 2026

Who is responsible for your data

KaraTube is built and operated by Cristian MESINA, trading as Devmox (“Devmox”, “we”). Devmox is the data controller for the personal data described on this page, within the meaning of Article 4(7) of the General Data Protection Regulation (EU) 2016/679.

Data protection questions and requests go to privacy+karatube@demox.page. There is no separate Data Protection Officer; that address reaches the developer directly.

What KaraTube stores

Profile metadata
Your Google account id, email address, name and avatar URL, plus an optional display name you choose. Used to sign you in and label you in rooms and shared playlists.
Saved playlists and items
Playlist titles, descriptions, visibility, and for each track the YouTube video id, title, channel name, thumbnail URL and duration.
Queues
Your personal Play Next queue while you are signed in. Anonymous queues live only in your browser's localStorage and are never sent to the server unless you choose to migrate them after signing in.
Rooms and queue actions
Rooms you host or join, the display name you use in a room, songs you submit, approvals and skips, and reactions. Room membership records include a last-seen timestamp so the host can see who is present.
Favorites, history and song notes
Videos you favorite, tracks you play, and any personal notes you attach to a song. Playback history is off unless you switch it on in Settings — new accounts record nothing until you ask them to.
Recent searches
Your last 12 search terms, so the search page can offer them back — and only if you switch that on in Settings, which is off by default. Turning it off again deletes the ones already stored, and you can clear them at any time from the search page.
OAuth tokens
When you connect YouTube, Google's access and refresh tokens are stored server-side in the accounts table. The grant is read-only, so the token cannot modify your YouTube account even in principle. Tokens are never sent to your browser and are excluded from all application logs.
YouTube import history
A record of every playlist import KaraTube performed on your behalf, including what was requested and what YouTube returned. This is your audit trail.
Access journal
For each request the server handles: the time, the HTTP method, the status, the name of the route (never the address itself, so a room name or a share link is not recorded), your internal account id, a rotating one-way fingerprint of your IP address, the network prefix that address belongs to, and an approximate location derived from it — country, region and city at most. It never contains your email address, your full IP address, search terms, query strings or anything you typed.
Security journal
A much smaller record of events that matter for security: signing in and out, a failed sign-in and why it failed, a request that was refused, sustained hammering of an endpoint, and changes to your account including its deletion. These entries additionally carry your full IP address, your email address and your browser's user-agent string, because on those events the address and the account are precisely what has to be identifiable. Those two values are encrypted as they are written, under a key whose other half is held offline: our hosting provider, our log collector and anyone reading the logs day to day see only ciphertext, and connecting an entry to you is a deliberate act by someone holding that key.
Usage and performance measurement
Only if you say yes, and it is off until you do. Two measurement scripts then run. One counts visits: which page, the site you arrived from, your browser, device type and operating system, and an approximate location — country, region and city, the same limit the journals keep to. The other records how quickly pages loaded and responded, with the page, your browser, device, connection speed and country. Neither sets a cookie of any kind. The visit counter identifies you by a hash derived from the request itself, which is discarded after 24 hours; your IP address is not stored. The page address is reduced to its route name before it is sent — a shared playlist is reported as "/playlist/[shareSlug]", never with the actual link, and query strings and anything after a # are removed — so neither script receives a share link, a room name, or anything you typed. Neither is used to build a profile, to advertise, or to make any decision about you, and turning it off stops the collection immediately.

Why we are allowed to store it

Under the GDPR every use of your data needs a legal basis. These are the ones KaraTube relies on.

Performance of a contract — Article 6(1)(b)
Creating and running your account, storing your playlists, queues, favorites and song notes, and hosting or joining rooms. Without this data the service cannot be provided to you at all.
Consent — Article 6(1)(a)
Everything here is optional and off until you actively agree. Connecting your YouTube account with the read-only scope: you give that consent on Google's own screen, it is asked for only when you first use the feature, and you can withdraw it at any time from your Google account permissions page. Usage and performance measurement: you are asked once, on your first visit, refusing is one tap and the same size as agreeing, and the switch further down this page turns it off again whenever you like. And playback history and recent searches, each its own switch in Settings, each off until you turn it on — they exist to make the app remember what you were doing, which is a convenience you should get to decline. Withdrawing any of them does not affect what happened while it was on, though switching searches off also deletes the terms already saved.
Legitimate interests — Article 6(1)(f)
Keeping the service usable and safe: caching and rate limiting to stay inside YouTube's API quota, and the two journals described above — kept strictly to secure the service, prevent fraud and abuse, investigate incidents, and audit what happened. We have documented the balancing test for this purpose in our internal operating note: the logging is limited, proportionate, short-lived, not used for analytics or marketing, and necessary to protect the service from abuse and account compromise. Those journals are never used for product analytics, profiling or marketing; doing so would need a separate legal basis, and we have not taken one. Measurement, where you have agreed to it, is a separate system on a separate basis — it never reads the journals, and the journals never feed it.
Legal obligation — Article 6(1)(c)
Handling and recording data protection requests, and responding to lawful requests from an authority or a rights holder.

How long it is kept

Rooms and room activity
Rooms expire 12 hours after creation by default. A scheduled sweep deletes expired rooms together with their membership records, submissions and reactions.
Account, playlists, favorites and notes
Kept until you delete the item, or until your account goes. Individually they have no timer on purpose: they are the library you came here to build, and expiring a setlist you assembled last summer would be worse for you than keeping it. The account itself is deleted after two years with no sign-in, and everything in it goes with it — Settings shows the date we are counting from, and signing in is all it takes to reset the clock. We do not email a warning first, and would rather say so than let you assume one is coming; the period is deliberately long for that reason.
Playback history
13 months from the moment a track is played, after which a scheduled sweep deletes the entry automatically. Sooner if you delete individual entries or clear the whole history. Nothing is recorded at all unless you have switched playback history on.
Recent searches
Nothing is recorded unless you switch it on. When it is on, only the last 12 terms are kept at any time and each is deleted 6 months after you searched it. Switching it off deletes them immediately, and you can clear them yourself from the search page.
YouTube import history
6 months, then deleted automatically. It exists so you can see what KaraTube did on your behalf, and that question stops being asked long before the entry expires.
Sign-in sessions
A session lasts 30 days. Expired session records are deleted by the same scheduled sweep rather than lingering.
Connected YouTube tokens
Kept until you disconnect YouTube in KaraTube, revoke access in your Google account, or delete your account.
Caches and rate-limit counters
Search caches and rate-limit counters expire automatically within minutes to hours and are keyed to a request, not to a profile.
Access journal
90 days, then deleted automatically. The one-way fingerprint of your IP address is re-keyed every 7 days, so entries older than a week can no longer be linked to each other by address even before they are deleted.
Usage and performance measurement
Nothing is collected at all unless you have agreed. The visitor hash that avoids double-counting is discarded after 24 hours and is never kept as an identifier. What remains is aggregate counts, held by the measurement provider for a reporting window of one month on the plan this deployment runs on. Turning the switch off stops collection at once; it does not retroactively remove counts already aggregated, because after aggregation there is nothing left that points at you.
Security journal
6 months, then deleted automatically. That is the period the CNIL recommends for security and audit trails; a longer window would need a specific documented reason, and there is not one. These entries outlive the deletion of your account — see the erasure right below.

The retention periods above are stamped in the application on every log line. In practice, the platform that collects the logs must enforce the deletion schedule; otherwise the hosting default would determine the real retention. We have documented the operator controls for that deployment in the project’s data-protection operations note.

Who else processes it

KaraTube does not sell your data, share it for advertising, or use it for automated decision-making or profiling. Beyond that, it is handled only by the categories of service provider needed to run the app:

Cloud application hosting
Serves the app, runs its scheduled jobs, derives the approximate location from your IP address, and collects and expires the two journals described above.
Managed database hosting
Stores accounts, playlists, queues, rooms, history and notes.
Managed cache and rate limiting
Holds short-lived search caches, rate-limit counters and live room state.
Usage and performance measurement
Counts visits and records page load timings, but only for visitors who have agreed. Receives nothing at all from anyone who has not.
Google / YouTube
Sign-in, the YouTube Data API v3, and the embedded IFrame Player. Google is an independent controller for the data it collects through the embedded player and through your Google account.

Some of these providers operate outside the European Economic Area, principally in the United States. Where that happens, transfers rely on the safeguards in Chapter V of the GDPR — the European Commission's Standard Contractual Clauses, and where applicable the EU–US Data Privacy Framework. If you want the specific providers and regions behind those categories for the deployment you use, ask at privacy+karatube@demox.page and we will tell you.

Your GDPR rights

If you are in the EU or the UK, the rights below are yours by law. In practice we honour them for everyone, wherever you are.

Access
Get a copy of the personal data KaraTube holds about you (Article 15). Settings has a Download my data button that produces the whole thing as one JSON file, immediately and without asking us. It excludes your stored Google tokens on purpose: those are live credentials to your account and are not safe to put in a file on your disk.
Rectification
Correct anything inaccurate. Most of it — display name, playlists, notes — you can edit yourself (Article 16).
Erasure
Have your account and its data deleted (Article 17). Settings has a delete button that does it immediately and without asking us; email the privacy address if you would rather we did it, or if you cannot reach your account. One exception, and we would rather state it than let you discover it: entries already written to the security journal — sign-ins, failed sign-ins, refused requests, the deletion itself — are kept for their full 6 months and carry your email address and IP. Article 17(3) allows this where erasure would defeat the purpose the data was collected for, and a security trail that any account holder could erase on request would protect nobody. Nothing new is written about you afterwards, and the entries expire on schedule.
Restriction
Ask that processing be paused while a complaint or a correction is being resolved (Article 18).
Portability
Receive your data in a structured, machine-readable format (Article 20). The same Download my data button covers this — JSON, one file, everything. Individual playlists can also be exported on their own as JSON or CSV.
Objection
Object to processing based on legitimate interests, including history and recent searches (Article 21). For the security journal, we rely on compelling legitimate interests and do not offer a general opt-out because the logs are necessary to keep the service secure, investigate abuse and preserve an audit trail.
Withdraw consent
Disconnect YouTube at any time, in KaraTube or from your Google account permissions page. Withdrawal does not affect processing that already happened (Article 7(3)).
Complain
Lodge a complaint with your local data protection supervisory authority if you think something is wrong (Article 77). You are welcome — but not required — to raise it here first.

To exercise any of them, email privacy+karatube@demox.page from the address you signed in with, or tell us which account you mean. We reply within one month, as Article 12(3) requires; if a request is unusually complex we will tell you inside that month and explain the delay. There is no charge for a reasonable request.

Google permissions

Signing in asks for the minimum: your basic profile and email address, so KaraTube can create your account and show you who is signed in.

The YouTube permission (youtube.readonly scope) is requested separately, only at the moment you first choose to list the playlists you own. It is read-only: KaraTube cannot create, edit or delete anything in your YouTube account. If you never use that feature, KaraTube never asks for it, and declining still leaves search, queues, local playlists, rooms and public-URL imports fully working.

You can revoke KaraTube's access at any time from your Google account permissions page. KaraTube will fall back to public search and local playlists.

Cookies and local storage

KaraTube sets no advertising cookies, and no cookie of any kind for measurement. It uses a session cookie and a CSRF token cookie to keep you signed in securely, and a short-lived cookie identifying you inside a room you have joined — all strictly necessary for something you asked for, so none of them needs consent.

Usage and performance measurement is the one thing here that is not necessary, so it is the one thing you are asked about. It is off until you agree, it sets no cookie and stores nothing on your device, and the switch below turns it off again at any time. Your answer itself is remembered in localStorage — that is what stops the question being asked twice.

Usage and performance measurement

Off unless you turn it on. When it is on, KaraTube counts visits and records how quickly pages load. It is never used to build a profile, to advertise, or to decide anything about you.

Your theme preference, and any queue you build before signing in, are kept in your browser's localStorage and never leave your device unless you choose to migrate that queue to your account. Clearing site data removes them.

The video player is embedded from YouTube's privacy-enhanced host (youtube-nocookie.com), which holds Google's cookies back until you actually play something — open a room and never press play, and you pick none up. The name oversells it: once a video plays, Google sets cookies under its own control. See the third parties section below.

Your controls

  • Turn playback history and recent searches on or off individually in Settings. Both are off unless you turn them on; while playback history is off no history rows are written at all, and turning searches off also deletes the ones already saved.
  • Download everything KaraTube holds about you from Settings, as one JSON file.
  • Delete individual history entries or clear your whole history.
  • Clear your recent searches from the search page.
  • Turn usage and performance measurement on or off with the switch in the cookies section above, or in Settings. It is off unless you turned it on.
  • Delete a playlist, room or favorite at any time; deleting removes the stored rows, including any share link.
  • Delete your account from Settings. It removes your user record and everything that references it, including playlists, queues, rooms you host, favorites, history and stored OAuth tokens. Security journal entries already written are the one exception, and expire on their own within 6 months. Email privacy+karatube@demox.page if you would rather we did it.

What KaraTube never does

  • It does not download, proxy, re-stream or modify YouTube videos.
  • It does not extract audio or attempt to remove vocals.
  • It does not scrape YouTube pages; all data comes from official APIs.
  • It does not write to your YouTube account at all. KaraTube holds only a read-only grant, so this is enforced by Google rather than by our own restraint.
  • It does not log OAuth tokens, secrets, session cookies, request bodies, query strings or what you searched for.
  • It does not put your email address or your full IP address in the ordinary access journal. Both appear only on the security events listed above — signing in, a failed sign-in, a refused request, a change to your account.
  • It does not derive a precise location. IP-based geolocation stops at the city; coordinates are published by the hosting platform on every request and are deliberately not read.
  • It does not sell your data or share it with advertisers.

Children

KaraTube is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, write to privacy+karatube@demox.page and it will be deleted.

Third parties

Playing a video loads YouTube's embedded player. KaraTube embeds it from youtube-nocookie.com, so nothing is set until you press play; from that point the player sets its own cookies and is governed by Google's privacy policy, not by this one. KaraTube also uses the YouTube API Services, and by using KaraTube you also agree to the YouTube Terms of Service.

How to contact the developer

KaraTube is run by one person, so it helps to use the right address:

  • privacy+karatube@demox.page — anything about your data: access, correction, deletion, portability, objection, withdrawing consent, complaints about how data is handled, or a security or privacy vulnerability you have found.
  • legal@demox.page — anything legal: copyright and trademark notices, licensing enquiries, misuse of the KaraTube name or code, and formal correspondence. See the Terms for who owns what.

Changes to this policy

If this policy changes, the date at the top changes with it. Material changes — a new purpose, a new category of data, a new processor — will be announced in the app before they take effect, and where the law requires consent, we will ask for it rather than assume it.

May we measure how KaraTube is used and how fast it loads? It is off unless you say yes, it never affects what the app does, and you can change your mind at any time on the privacy page.