Data protection
Privacy policy
Plain-language notice for anyone who browses ScoreBear, unlocks a soundtrack, connects TIDAL or Apple Music, or votes for a title request.
Last updated: 28 July 2026
Who is responsible
ScoreBear is operated by Bifrost Bridge Studio (the data controller).
Contact: hello@bifrostbridge.studio
What we collect
- Buyer email — when you pay for a title unlock via Stripe, together with the Stripe checkout session ID and which title you unlocked.
- Title requests — the search text and optional IMDb ID you upvote, plus a vote count. Curators move requests through a wanted → curating → processed queue.
- Wish notify email — optional. If you choose “Email me when it’s online” after a 👍, we store that address only to tell you when that soundtrack is published. You can skip this.
- Unlock cookie — a signed browser cookie that stores your buyer email and which titles you have unlocked on this device (approximately one year), so we can restore access and honor purchases.
- TIDAL connection cookies— access and refresh tokens, token expiry, and your TIDAL country code, stored in your browser only while you connect TIDAL for playlist push (about 30 days, or until you disconnect). Short-lived cookies are also used during the OAuth login flow. We call TIDAL's profile API for country code; we do not store your TIDAL email or profile in our database.
- Apple Music (MusicKit)— when you choose Push to Apple Music, Apple's MusicKit runs in your browser. Your Apple Music user token stays on your device for that session; we mint a short-lived developer token on our server so MusicKit can talk to Apple. We do not store your Apple Music library or user token in our database.
- Local device storage — small
localStorageentries remembering which titles you have already upvoted and which notify opt-ins you saved in this browser. - Catalog search — when you search for titles, the query is sent to OMDb (IMDb data) to return results. Search queries are not stored as a search history in our database.
- Usage analytics — aggregated, anonymized page-view data via Vercel Web Analytics (for example page path, referrer, approximate location at country/region/city level, browser, OS, and device type). Visitors are identified only by a short-lived hash derived from the request (not a cookie); that hash is discarded after about 24 hours. We do not use this to identify you as a person or to track you across other websites.
We do not create user accounts or passwords. We do not store payment card numbers — Stripe handles card data.
Why we use it
- Contract — to fulfill a one-time unlock, restore purchases on another device, and provide playlist export / TIDAL and Apple Music push for titles you paid for.
- Consent — connecting your TIDAL or Apple Music account for playlist push, and optional email notify when a wanted title goes live.
- Legitimate interests — operating title-request voting, catalog search, understanding aggregated site traffic so we can improve the product, and basic security of our APIs and hosting.
Who we share with
We use service providers that process data on our behalf (subprocessors):
- Stripe — payments and customer email at checkout
- Neon — database hosting for unlocks and title requests
- Vercel — application hosting (including typical request logs such as IP address and user agent) and Vercel Web Analytics for cookie-free, aggregated traffic statistics
- TIDAL — OAuth and playlist API when you choose to connect
- Apple — MusicKit / Apple Music API when you choose Push to Apple Music
- Resend — transactional email when you opt in to “notify me when it’s online” (and only then)
- OMDb — title search when you use catalog search
Poster images may load from third-party image hosts (for example IMDb/Amazon CDNs) when results include a poster URL. We do not sell personal data.
Cookies and local storage
We only set cookies that are necessary for the service: unlock memory and TIDAL authentication (including short-lived OAuth helpers). We also use browser localStorage for vote deduplication.
We use Vercel Web Analytics, which does not set analytics cookies and does not store a persistent identifier on your device. We do not use advertising cookies or cross-site advertising trackers. If that changes, we will update this policy and ask for consent where required.
How long we keep it
- Unlock records — until you ask us to delete them, or the product no longer needs them to honor your purchase.
- Title-request votes — until they are no longer needed for curation, or you ask us to remove a specific request where we can identify it.
- Wish notify emails — until we have notified you that the title is live, you ask us to delete the address, or the request is no longer needed for curation.
- Unlock cookie — about one year, or until you clear site data.
- TIDAL cookies — about 30 days, or until you disconnect / log out or clear site data. OAuth helper cookies expire within minutes.
- Vote
localStorage— until you clear site data for this origin. - Vercel Web Analytics visitor hash — discarded after about 24 hours; we only see aggregated statistics, not a browsable history of your session.
Stripe keeps payment records under its own legal obligations; we cannot erase those from Stripe on your behalf.
Your rights
If you are in the EU/EEA (and in many other places), you can ask us to access, correct, export, or delete personal data we hold about you, and to object to certain processing.
Email hello@bifrostbridge.studio from the address you used at checkout. We aim to reply within a few days (and within 30 days at most).
Delete my data
There is no account login. To erase what we store, email hello@bifrostbridge.studio with subject line Delete my data and the email address involved.
We will:
- Delete unlock / entitlement records for that email
- Delete wish-notify subscriptions for that email (title-request vote counts are anonymous and usually cannot be attributed to you)
- Ask you to clear this site's cookies and
localStorage(and disconnect TIDAL) on your devices
After deletion you will need to purchase again to unlock paid titles on a new browser.
Children
ScoreBear is not directed at children under 16. We do not knowingly collect their personal data.
Changes
If we change how we handle data in a material way, we will update this page and the “Last updated” date above.