Privacy.
What stays in your browser, what leaves it and when, who holds it, for how long, and how to take any of it back. This page describes what the site does, read from the code that does it. When the code changes, this page changes with it.
Crate has no accounts and sets no cookies. Your reading mode, your want list, your crate and your preferences live in this browser's storage. Four things can leave it, each only on its own terms: a connection to a music service you choose to make, a seed you choose to send, an email-alerts subscription you choose to start, and anonymous read-counts you can switch off. Questions about any of it: privacy@cratescenes.com.
Everything personal is kept in this browser's local storage under keys that start with crate.: the theme you picked, the records you want, the crate you built by connecting a source, the choices you made while connecting, and the date you agreed to the terms. None of it is copied anywhere unless you send it, below. Settings' Remove everything clears it, and so does clearing this site's data in your browser.
When you connect Discogs, Spotify or Last.fm, your browser talks to that service directly. Crate's pages never see your password. What comes back, your collection or your saved albums or your loved tracks, is matched against the corpus in this browser and stored here.
- Discogs reads a public collection by username, or a CSV you export yourself.
- Spotify, by sign-in, opens Spotify's own page and asks only for the permissions the boxes you ticked need:
user-library-readfor saved albums and liked songs,playlist-read-privatefor playlists, anduser-top-readfor your most-played tracks. The grant Spotify returns is kept in this browser so a later re-sync can run without asking again; removing the import removes it. The sign-in also lives on your Spotify account until you revoke it there, under Spotify's Manage apps. - Spotify, by file, reads a Liked Songs export you made yourself at exportify.net, the YourLibrary.json file from Spotify's own data download, or both together. From YourLibrary.json it reads saved albums and liked songs and nothing else; the rest of that download is never asked for. The file is read in this browser and never uploaded.
- Last.fm reads a public profile by username. No sign-in.
Settings has a Remove import button for each source. It deletes what was imported and the grant that fetched it, and withdraws anything you sent that carried that source (below). Your library on the service is untouched either way.
Settings offers a send button that shares a scrubbed copy of your crate with the atlas, so that scenes people own records from can be written next. Nothing is sent until you press it, and pressing it is agreeing to what this section says. What leaves is shown to you in full before it goes: record identities and counts from each connected source, Spotify included if you connected it, with usernames, filenames and dates removed, first in your browser and again on arrival. A disconnected source is never sent. It carries a random id your browser made, not you, and is never joined to read-counts.
- Where: stored with Cloudflare, Crate's host. The site's operator copies seeds to their own machine to count demand, with scripts.
- Looked up: to learn each record's styles and the year it first came out (a reissue bought last year can be a record from 1979), those scripts look up its artist and title on two public music databases, Discogs and MusicBrainz, one record at a time, the way anyone searching them would. A lookup carries the artist and title and nothing else: not the seed's id, not anything that names you, not which seed it came from. The answers stay on the operator's machine with the seed.
- Never given: no seed, and no record from one, is given to an AI model or to anyone not named on this page. Writing the atlas uses counts summed across seeds, such as how many records a style has, never a row.
- How long: 12 months from your last send, then deleted automatically.
- Deleting it sooner: Settings, Seed the atlas, Withdraw my donation. Removing or disconnecting a source that was in it withdraws it at once, and so does Remove everything. The operator's copy follows within five days.
If you ask Crate to email you when a new scene is written about records you own, two things are stored with Cloudflare until you unsubscribe: the address you gave, and a scrubbed copy of your crate in the same shape as a seed — no username, no filename, nothing you did not import. An address that is never confirmed is deleted after a day. The copy exists to be matched against each new scene; it is refreshed when your crate changes, refreshed without a source you remove or disconnect, and deleted with the subscription when nothing is left to match. Mail goes out through Resend, which sees the address and the mail, as any mail service must. Every mail carries a one-click unsubscribe; using it, or the Unsubscribe button in Settings, deletes the address and the stored copy together, and changes nothing in your browser. The mails carry no tracking pixel, and their one link carries no per-person token: it says only that it came from a mail, the same word for everyone.
The site counts reads: which pages get read, for how long, whether a listen link was followed, whether a search found nothing. The writing queue uses these to know what is read. The counts are anonymous by construction, are kept by Cloudflare's analytics store, and are deleted by it after three months.
- No cookies and no persistent identifiers. Nothing is stored that could recognise you on a later visit.
- One random token lives for the length of a tab and dies with it, so that the pages of one visit can be read in order. It is never written to lasting storage.
- One bit says whether a crate exists in the browser. Never its contents.
- Your address is not stored. The country the request came from is kept, coarsely.
- A search that finds nothing sends the words you typed, folded to plain lowercase, so that a missing scene can be noticed. Nothing else about the search is kept.
- A link from one of Crate's own mails or from its Instagram profile says only that it came from there — one word, the same for everyone, never a token that could name you.
If your browser sends Global Privacy Control or Do Not Track, nothing is counted, without you touching anything. Otherwise Settings, under Reading data, switches counting off in this browser.
- Cloudflare hosts the site and stores seeds (12 months), email-alerts subscriptions (until you unsubscribe) and read-counts (three months).
- Resend sends the alert mails, and sees the address and the mail.
- Discogs and MusicBrainz are asked the artist and title of records in seeds, one lookup at a time, with nothing that names you or your seed (above).
- Anthropic: Crate's pages are drafted with the help of Claude, Anthropic's AI model. Nothing from a reader's crate is given to it; it sees counts summed across seeds, never a record.
- Nobody else. Nothing is sold, nothing is shared for advertising, and there is no advertising.
Crate sets no cookies, its own or anyone else's, and keeps what it keeps in local storage as described above. Like any web page, some parts of Crate come from other hosts, and each of those hosts sees the request that fetches them: the typefaces from Google Fonts, the map library and its tiles on the Explorer, and the Spotify or Bandcamp player on a scene page when you scroll to it. A player is Spotify's or Bandcamp's own page inside Crate's, and runs under their privacy terms, which may include their cookies. Crate sends none of your data to any of them. The site tells browsers which hosts it may talk to and no others.
The new-scenes feed is a file. Subscribing to it happens in your reader, and Crate learns nothing about who subscribes. The podcast is hosted on Spotify, under Spotify's terms.
- Remove an import, and anything sent that carried it: Settings, the source's row, Remove import.
- Withdraw a seed: Settings, Seed the atlas, Withdraw my donation.
- Stop the email alerts and delete the stored copy: the Unsubscribe link in any alert, or Settings, Email alerts, Unsubscribe.
- Revoke Crate's Spotify sign-in at Spotify too: spotify.com, Manage apps.
- Stop being counted: Settings, Reading data. Or send Global Privacy Control.
- Everything at once: Settings, Remove everything. It clears this browser and deletes the seed and the alerts subscription on Crate's side. Clearing this site's data in your browser clears the browser only: a seed then expires on its own, and an alerts subscription ends with the Unsubscribe link in any mail.
- Anything else, or a question: privacy@cratescenes.com.
The writing, the design and the code of this site are © Crate Scenes, from the first sealed scene onward, and all rights in them are reserved. The facts they rest on — who made which record, where and when — belong to nobody and you are free to take them. Quote a passage with a link to the page it came from and you have done everything asked; reproduce a scene or the site's design wholesale and you have not. Record and artist names are their owners'.
The terms of use, including the terms Spotify requires of anyone connecting it, are on their own page, and this page is part of them.
Dated 2026-10-05 and changed only alongside the code it describes. Corrections to the writing go where all corrections go, the errata on the Contents page.