Legal
Privacy policy
This policy explains how the TrueTrack browser extension handles information while identifying potential AI-generated music on Spotify.
Last updated: August 5, 2026
1. The extension's single purpose
TrueTrack has one narrow purpose: to check the Spotify track page you open for signs of AI-generated music and display a small indicator beside the stream count. The extension only handles information needed to provide, secure, and maintain that feature.
2. Information the extension processes
When you open an individual Spotify track page, TrueTrack processes:
- The Spotify track identifier contained in that page's URL.
- The track's detection result, including whether AI signals were found, the probability, and the likely AI type when available.
- Limited technical request data, such as IP address and request time, used for security, abuse prevention, and rate limiting.
The extension reads the stream-count element only to place the indicator in the correct location. It does not transmit that element, your Spotify credentials, account details, playlists, complete listening history, or general browsing history.
3. Why the extension needs its permissions
- Spotify page access: lets TrueTrack recognize an individual track page and place the indicator beside its stream count.
- Storage: saves detection results locally in your browser so revisiting a track does not require another network request.
- API host access: allows the extension to securely send the Spotify track identifier to
https://apiv2.istruetrack.comand receive the result.
TrueTrack does not request access to your browser history, tabs, microphone, camera, contacts, precise location, or Spotify login.
4. How information is used and shared
The Spotify track identifier is sent over HTTPS to the TrueTrack API. The API uses SH Labs to analyze the track's available audio and return a detection result. TrueTrack may use infrastructure providers, including Railway and MongoDB infrastructure where applicable, to host the API and store cached results.
These providers receive information only when necessary to deliver, secure, or maintain the extension's disclosed feature. We do not sell extension data, share it with data brokers, or use it for advertising, profiling, credit decisions, or unrelated purposes.
5. Storage and retention
Detection results are cached in your browser using chrome.storage.local.
You can remove this local data by uninstalling the extension or clearing its stored data.
Results may also be stored with the Spotify track identifier in TrueTrack's shared server
cache so the same public track does not need to be analyzed repeatedly. Successful track
results may be retained because the recording does not change; unavailable-audio results
are rechecked periodically.
Security and rate-limit data is retained only as reasonably needed for those operational purposes.
6. Chrome Web Store Limited Use disclosure
TrueTrack's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
We limit extension data to providing or improving TrueTrack's single purpose and related security and reliability needs. We transfer it only when necessary to provide that purpose, comply with law, or protect against abuse. Humans do not read extension user data except with explicit consent, when required for security or legal compliance, or when data is aggregated and anonymized for permitted internal operations.
7. Website audio checks
The optional audio-upload checker on the TrueTrack website is separate from the browser extension. Audio you deliberately upload is held temporarily, provided to the detection service to complete your requested analysis, and removed from TrueTrack's temporary storage when the check finishes or times out.
8. Security
Information sent by the extension is transmitted over HTTPS. We use access controls, limited permissions, rate limiting, and other reasonable safeguards. No internet service, however, can guarantee absolute security.
9. Your choices and rights
You can stop all extension processing by disabling or uninstalling TrueTrack. You may also contact us to ask about your information or request deletion where applicable. Because cached Spotify results are associated with a public track identifier rather than a user account, we may need details from you to locate a particular record.
10. Changes and contact
If the extension's data practices materially change, we will update this policy and provide any notice or consent required by the Chrome Web Store policies and applicable law. Questions, privacy requests, or complaints can be sent to hello@istruetrack.com.