Last updated 20 August 2026
This policy covers the hosted Chordia service at chordia.dev, operated by the Chordia project. Chordia is also free software that anyone can run themselves. If you use somebody else’s Chordia instance, this policy does not apply to it. Whoever runs that instance decides how it handles your data.
Your audio files never reach our servers. Not as an upload, not as a cache, not in transit. When you press play, your device connects directly to your own library server over an encrypted connection, and the audio flows between those two machines.
What we hold is your account and the activity attached to it: who you are, who you have shared with, and what you have listened to.
Your account. Email address, handle, display name, and a hashed password. If you sign in with Discord, we store your Discord account ID so we can identify your account on your next sign-in. If you set an avatar, we store the image. If you turn on two-factor authentication, we store the secret needed to verify your codes.
Your sessions. A record of each signed-in device, so you can review and revoke them. Each record holds the browser and platform that device reported. It does not include an IP address.
Your library directory. The name and network address of each library server you pair, and the fingerprint of its TLS certificate, so your devices can confirm they are talking to the right machine. That is the whole of it: the directory holds no folder paths from inside your library, and nothing about the files in it.
Catalog metadata. When your library syncs, it sends us the descriptive metadata for your collection: artist, album and track names, durations, track numbers, release dates, and cover artwork. This is what makes search, playlists and your listening history work across devices. It is metadata about the recordings, never the recordings.
Your listening history. Every play is recorded against your account with the track, the time, and the playlist or album it came from. This is what your listening statistics are built on. You can switch it off in Settings, which stops new events being recorded.
Your social graph and library shares. Friend relationships, follows, blocks, and which of your libraries you have granted to which people.
What you have made. Playlists, liked and hidden tracks, pinned items, and your settings, including the privacy audiences that control who can see your profile, your history and your playlists.
Administrative records. Moderation and configuration changes made by instance administrators are written to an audit log, so those actions are accountable.
To do its job, Chordia talks to a small number of outside services. Each one receives only what is described here.
We do not sell your data, and we do not share it with advertisers.
Chordia sets one cookie, to remember your chosen language. Your sign-in tokens and interface preferences are kept in your browser’s local storage rather than in cookies, which means they stay on your device and are not sent along with every request. There are no advertising or tracking cookies.
Export everything. Settings has a data export. It gives you a single JSON file holding your account, your playlists, your social graph and your complete listening history, in a form you can open and read yourself.
Delete everything. Deleting your account from Settings removes it and the data described above. Your music is unaffected. It was never on our servers, and it remains on yours.
Control what others see. Each of your profile, your listening history, your playlists and your follows has its own audience setting, from private through to public. Playlists default to private and the rest default to friends-only.
Stop recording history. Turning off history recording in Settings stops new plays being stored.
Account data, listening history and everything you have created are kept for as long as your account exists. They are deleted when you delete your account, and removed from our backups within 30 days of that.
The hosted service runs on servers in the United States, and our email and error-reporting providers process data there too. If you are in the UK or the EU, that means your data is handled outside it. If you run Chordia yourself, your data is wherever you put it.
Chordia is not directed at children under 13, and we do not knowingly create accounts for them.
If this policy changes in a way that affects what we collect or who receives it, we will update the date at the top of this page and tell account holders by email before the change takes effect.
Questions, requests, or a correction to something on this page: privacy@chordia.dev.