Statiks app iconStatiks

Privacy center

Privacy Policy

How Statiks handles Spotify data, listening history imports, purchases, analytics, crash diagnostics, and your GDPR rights.

Last updated August 14, 2026

01

Controller

The controller responsible for the processing of personal data in Statiks is:

Anton Sarg, sole proprietor, Pichlacker 2/2, 6161 Natters, Austria. Email: anton@statiks.app.

02

What Statiks Does

Statiks is an app for Spotify listening statistics. You can connect your Spotify account to view your top tracks, top artists, top albums, recently played music, and other statistics.

With Statiks Plus, you can also import your Spotify Extended Streaming History as a ZIP file. After a successful import, Statiks uses it to create long-term statistics, trends, timelines, and listening patterns.

03

Data Processed by Statiks

When you sign in with Spotify, Statiks processes your internal Statiks user ID, Spotify ID, Spotify display name, Spotify access token and refresh token, and technical login and authentication data.

Spotify access tokens are stored in encrypted form. Statiks uses them to provide app features, for example to retrieve your recently played tracks or show your Spotify top lists.

Statiks normally does not store your Spotify email address.

04

Music and Listening History Data

To display your statistics, Statiks processes data about your Spotify usage, including tracks, artists, albums, Spotify IDs, track names, artist names, album names, cover images, listening timestamps, estimated or imported playback duration, whether a track was likely skipped, top lists, and ranking data.

Statiks retrieves your recently played tracks from Spotify and stores listening events in your Statiks account. The backend may also periodically query connected Spotify accounts so that your statistics remain up to date.

05

Spotify History Import with Statiks Plus

If you use Statiks Plus, you can upload your Spotify Extended Streaming History as a ZIP file.

In particular, Statiks processes the uploaded ZIP file, JSON files from your Spotify export, track URIs, track names, artist names, album names, playback timestamps, playback duration, skip information or derived skip values, import status, progress, error codes, and import summaries.

Podcast or episode entries are skipped during import where they are recognized as such.

The ZIP file is stored and processed on the Statiks server. If the import fails, the ZIP file is deleted. If the import succeeds, the ZIP file may be kept until you delete the import or your account.

You can delete your import in the app. This deletes the stored import ZIP and the listening events created from that import.

06

Spotify Playlist Features

If you create a playlist through Statiks or add a track to a Spotify playlist, Statiks sends the data required for that action to Spotify, such as the playlist name, playlist visibility, Spotify track URIs, and Spotify playlist ID.

Statiks uses this data only to perform the requested action on Spotify. Payment data and private Spotify passwords are not processed for this purpose.

07

Statiks Plus and Purchases

Statiks uses RevenueCat to manage App Store and Google Play purchases.

This may include processing your internal Statiks user ID as the RevenueCat App User ID, product ID, entitlement ID, purchase status, store, platform, environment, subscription expiration date, transaction IDs, and RevenueCat webhook data.

Payments are handled by the Apple App Store or Google Play. Statiks does not receive credit card data or complete payment data.

08

Product Analytics

Statiks may use optional product analytics with PostHog. This analytics helps understand which features are used and whether actions are successful.

This may include processing your internal Statiks user ID, app version, platform, opened screen or tab, selected time ranges or filters, Plus status, whether a history import has been completed, technical error types, HTTP status codes, and request IDs for API errors.

Statiks does not send Spotify tokens, email addresses, track names, artist names, album names, playlist names, or raw Spotify payloads to PostHog.

In regions where consent is required, product analytics is activated only after your consent. You can change your decision in the settings.

09

Contextual Advertising

Statiks may use Unity Ads to show ads in the app.

Statiks only shows contextual, non-personalized ads. This means ads are selected based on the app context rather than on a personalized advertising profile or your Spotify listening history.

Statiks does not send Spotify tokens, email addresses, track names, artist names, album names, playlist names, raw Spotify payloads, or imported Spotify history files to Unity Ads for advertising.

Unity Ads may process technical ad-delivery data, such as device and app information, approximate location derived from IP address, ad interaction data, identifiers or privacy signals where applicable, and fraud-prevention or aggregated reporting data. Unity processes this data under its own privacy documentation: https://unity.com/legal/privacy-policy.

10

Crash Reports and Error Diagnostics

Statiks uses Firebase Crashlytics to detect and fix crashes and technical errors.

This may include processing your internal Statiks user ID, app version, device and operating system information, crash logs, technical error information, and the time of the crash.

This data is used to improve the stability and security of the app.

11

Share Cards and Photo Access

When you save a Share Card, Statiks requests access to your photo library so the image can be saved there.

When you share a Share Card, sharing is handled through your device’s share function or the app you choose. The data processed by the destination app is governed by that app’s own privacy policy.

12

Support Contact

If you contact Statiks by email, Statiks processes the data you voluntarily send, such as your email address, the content of your message, technical details you include yourself, and the time of the communication.

This data is used to respond to your request.

13

Technical Data and Server Operation

The Statiks backend is operated on a Hetzner server in Germany.

When accessing the app and API, technical data may be processed, such as IP address, date and time of access, requested API endpoint, HTTP method, HTTP status code, request ID, request duration, user agent or device information where technically transmitted, and error and security logs.

This data is processed to provide the app, identify errors, prevent abuse, and ensure the security of the service.

14

Legal Bases

Depending on the purpose, processing is based on the following legal bases:

Performance of a contract or pre-contractual measures under Art. 6(1)(b) GDPR, where processing is necessary to provide Statiks, manage your account, perform Spotify features, or provide Statiks Plus.

Consent under Art. 6(1)(a) GDPR, where you consent to product analytics or connect Spotify through the login flow.

Legitimate interests under Art. 6(1)(f) GDPR, especially for security, error analysis, abuse prevention, server operation, app improvement, and showing contextual, non-personalized ads.

Legal obligations under Art. 6(1)(c) GDPR, where data is required for statutory retention obligations.

15

Recipients and Service Providers

Statiks may transmit personal data to the following categories of recipients: hosting provider Hetzner in Germany; Spotify where required for login, Spotify data retrieval, and playlist features; RevenueCat for managing Statiks Plus and purchase status; Apple App Store and Google Play for purchase processing; PostHog for optional product analytics; Unity Ads / Unity for contextual, non-personalized advertising; Firebase Crashlytics / Google for crash reports; email providers if you contact us by email; and technical service providers where required for operation, security, or maintenance.

Some providers may process data outside the EU or EEA. Where required, this is done on the basis of appropriate safeguards, such as adequacy decisions or standard contractual clauses.

16

Retention Period

Statiks stores personal data only for as long as necessary for the respective purposes.

Account data is stored for as long as your Statiks account exists. Spotify tokens are stored for as long as your Spotify account is connected to Statiks or your Statiks account exists. Listening history data is stored for as long as your account exists or until you remove it by deleting an import or your account.

Import ZIP files are deleted if the import fails. If the import succeeds, they may remain stored until you delete the import or your account. Technical logs are stored only as long as necessary for operation, security, and error analysis. Purchase and RevenueCat data is stored as long as required for Plus access, evidence, troubleshooting, and legal obligations. Statiks does not store personalized advertising profiles. Ad-related data processed by Unity Ads is retained by Unity according to Unity’s own retention rules. Support emails are stored as long as necessary to process your request and any follow-up questions.

17

Account Deletion

You can delete your Statiks account in the app.

This deletes your account, stored Spotify connection data, authentication tokens, stored listening history data, and import file to the extent they are associated with your account.

Certain data may be stored for longer if legally required or necessary to defend, assert, or document claims.

18

Your Rights

Under the GDPR, you have in particular the right of access, rectification, deletion, restriction of processing, data portability, objection to certain processing, withdrawal of consent with effect for the future, and complaint to a data protection supervisory authority.

You can contact anton@statiks.app at any time to exercise these rights.

If you are in Austria, you can also contact the Austrian Data Protection Authority at https://www.dsb.gv.at.

19

Requirement to Provide Data

You are not required to provide Statiks with any data. However, without certain data, the app cannot function or can function only in a limited way.

Without a Spotify connection, Statiks cannot display Spotify statistics. Without a Spotify Extended Streaming History ZIP, Statiks Plus cannot create long-term statistics from your complete Spotify listening history.

20

Automated Decision-Making

Statiks does not make automated decisions that produce legal effects concerning you or similarly significantly affect you.

Statiks may derive statistics, rankings, trends, listening patterns, and profile labels from your listening history data. These are used only for display within the app.

21

Changes to This Privacy Policy

Statiks may update this privacy policy if the app, data processing, or legal requirements change. The current version is available at https://statiks.app/privacy.