Privacy
Last updated: 2026-09-10
This page describes the data the current WOKE1 service uses, where it goes, and the choices available to you.
WOKE1 is operated by George Drag.
What WOKE1 collects
- Beta invites. An invite request stores the email you submit, an optional name, and the submission time. A SHA-256 value of the lowercased email prevents duplicates. The private beta accepts at most 200 unique invite records. A SHA-256 value of the request IP and aggregate counters enforce one-hour request limits.
- Anonymous recipient identity. A bomb visit receives a random UUID in a Secure, SameSite=Lax, httpOnly cookie and a readable marker cookie. The Redis record stores declared Apple Music, Spotify, YouTube, Amazon Music, and Tidal flags, unlock state, creation time, and an optional pass time. It contains no account, password, IP address, user-agent, or geolocation.
- Bomb links. A shared bomb record contains an opaque ID, an artist ID, and its creation time, with no creator reference. Anonymous visitor IDs can also appear temporarily in creation-limit counters.
- Stations and credentials. A station record stores its station ID, call-sign, creation and key-rotation times, and SHA-256 credential hashes. WOKE1 returns the raw station key and session access token to the station client; Redis indexes credentials and session records by their hashes and stores session timing.
- Linked Spotify source and listening history. A linked station stores authorization timestamps, OAuth refresh and access tokens, source health, current and recent playback observations, and bounded listening history. That history includes play times plus track and artist IDs, names, durations, and Spotify links. To link a station, WOKE1 requests only current playback, playback state, and recently played permissions, not Spotify profile or email permissions. The iOS app separately requests Spotify and Apple Music playback-control permissions on the device. Those playback-control credentials stay on the device.
- Music and presentation records. WOKE1 stores artist and track identifiers, artwork and links, identity and catalog lookup results, media records, source URLs, and generated artist presentations. This data describes music and station listening, not a recipient profile.
- Analytics and browser-loaded media. When analytics is configured, Umami counts pageviews. A pageview includes the page path, referrer, screen size, and language. Umami derives location and device information. WOKE1 uses these pageviews for aggregate traffic statistics. WOKE1 also sends explicit install and share events, including install choice outcomes and share modes. Browsers also request Spotify artwork, YouTube thumbnails and embeds, and Apple preview media directly when those surfaces load or play.
- Operational data and iOS diagnostics. Application logs contain bounded failure and status details and sometimes station or artist identifiers. Invite emails, invite names, and raw credentials are excluded from those logs. The iOS app sends crash and session diagnostics to Sentry.
How we use it
WOKE1 uses this data to operate and personalize the service; link and poll an authorized Spotify source; assemble music and media pages; generate artist editorial content; enforce rate and capacity limits; measure install and share flows; compile aggregate traffic statistics; secure and diagnose the service; and send station-health alerts.
WOKE1 does not sell personal data.
Who receives data
- Spotify. WOKE1 performs OAuth authorization and token exchange, then makes authorized playback and history API requests. Browsers directly request Spotify-hosted artwork and open user-chosen Spotify links.
- Apple Music. Server catalog lookups send ISRCs or Apple artist and song IDs with a developer token. Browsers directly request Apple-hosted previews and open user-chosen Apple links.
- YouTube/Google. Server feed and API requests send channel identifiers, candidate handles or usernames, artist search text, and an API key where configured. Thumbnails load from YouTube, and playing a video connects the browser to youtube-nocookie.com.
- MusicBrainz. Server identity lookups send ISRCs, Spotify artist URLs, or MusicBrainz IDs with WOKE1's contactable User-Agent.
- Wikidata. Server identity lookups send MusicBrainz IDs or Wikidata QIDs with WOKE1's User-Agent.
- Anthropic. WOKE1 sends artist identifiers, names, images and links; identity anchors; played track names; neighboring artists; listening signal; research results; and source URLs to generate cached artist presentations. Recipient identity and invite details are not sent in that generation request.
- Vercel. Vercel hosts and serves WOKE1, and processes visitors' IP addresses and browser details to serve the site.
- Upstash. Upstash provides Redis storage for invite, visitor, bomb, station, source credential, playback and history, artist and media, cache, limiter, and operational records.
- Umami. When configured, it receives page paths, referrers, screen sizes, and languages, derives location and device information, and receives explicit install and share event names and properties.
- ntfy. It receives station-health alert titles and bodies only.
- Sentry. It receives iOS crash and session diagnostics.
- User-chosen external destinations. Music-service and artist-site links send the browser to the selected external site, which handles that request under its own policy.
YouTube API Services
WOKE1 uses YouTube API Services to find and show artists' music videos through the embedded YouTube player. When you play a video, YouTube may place cookies or use similar storage on your device. This is governed by Google's Privacy Policy. If you choose to watch one of those videos, your use of the embedded player is subject to Google's Privacy Policy and the YouTube Terms of Service.
WOKE1 has no YouTube sign-in and requests no access to your YouTube account. The Google security settings are provided only as general information for managing access to your Google account, not as a way to revoke access from WOKE1.
WOKE1 stores video IDs and public video metadata. It is refreshed or removed over time. If you want WOKE1's stored YouTube data deleted, email support@vance.digital.
How long we keep it
- Invite request-limit counters expire after one hour.
- A recipient identity record expires 180 days after its last successful read or write.
- A station access token expires after one day. Its Redis session record expires after eight days.
- Eligible third-party source responses are cached for six hours. Spotify and Apple Music API responses are excluded from that cache.
- Playback history is bounded by a configured play cap, with a default of 100,000 plays.
When the source does not establish a shorter period, records are kept until deleted or no longer needed. This includes invite and bomb records, linked-source data, artist and media records, operational logs, analytics, and crash records.
Your choices and deletion
You can delete the anonymous visitor record. WOKE1 removes the valid Redis record and expires both visitor cookies.
An authenticated station deletion invalidates the station and its sessions, permanently retires its call-sign, and attempts to purge linked source credentials, access tokens, playback state, and history. If cleanup fails after the station is retired, unreachable source keys can remain for later reclamation rather than disappearing synchronously.
For an invite or privacy request, use the contact below.
Contact
Email support@vance.digital.