Skip to content

Cookie Policy

Effective Date: March 18, 2026 · Last Updated: August 23, 2026

This Cookie Policy explains how Lumitone, a Deruvish Labs LLC service (lumitone.io) uses cookies. In short: Lumitone sets none of its own. Two third parties do set cookies on their own domains, and the one that matters is described below, because it happens without you clicking anything.

1. What We Use

Without an account, Lumitone sets no cookies at all. If you sign in (optional), we set one strictly necessary session cookie on lumitone.io that keeps you signed in; it holds your session token, nothing else, is never used for tracking, and is removed when you sign out. Everything else in the list below belongs to a third party on its own domain:

  • Stripe, only if you start a checkout, and only on Stripe's own pages. These are strictly necessary for payment security and fraud prevention.
  • Spotify, but only after you ask for a player. A results page shows a Load Spotify player button next to a track and loads nothing from Spotify until you activate it. Scrolling the whole list does not contact Spotify. When you do activate one, an iframe from open.spotify.com is loaded for that track, and from that point Spotify can make requests and set cookies on its own domains, including a sp_t identifier we can neither see nor read. At most one player is loaded at a time: opening another closes the first, and you can close the open one. Closing a player does not delete cookies Spotify may already have set.
  • Apple, but only if you use Import from Apple Music on the music input page. Nothing is loaded from Apple until you click it. Clicking loads Apple's MusicKit script from Apple's servers and opens Apple's own sign-in window; during that flow Apple can make requests and set cookies on its own domains under Apple's own policies. Your listening data is read once, in your browser, and the sign-in token never leaves it. If you never click the button, no request to Apple is made.

We describe this plainly rather than calling the site cookie-free, because activating a player is a real third-party load. If you would rather it never happens, do not activate a player; the track names, artists and albums are all readable without one, and blocking third-party cookies also stops the cookies while the rest of the page keeps working.

SourcePurposeLifetime
Lumitone (lumitone.io)Session cookie, only after you sign in (strictly necessary). Nothing without an account.Until you sign out; refreshed while you use the site
Stripe (during checkout)Payment security and fraud prevention on Stripe's own pagesPer Stripe's cookie policy
Spotify player (only if you activate one)Set by Spotify once you load a player for a track; nothing before that. Includes sp_t, a Spotify identifierPer Spotify's cookie policy
Apple (only if you start an Apple Music import)Set by Apple on its own domains during the sign-in and authorization flow you start by clicking Import from Apple Music; nothing before thatPer Apple's cookie policy

A few things are kept in your browser's sessionStorage (not a cookie), only for the duration of the tab: your song/artist picks, so the results page can read them; the free result computed from a Letterboxd export you upload, so cancelling a payment or reloading does not lose it; and a small purchase-attempt record (an attempt counter and the id of a checkout you walked away from), so a retried payment reuses the same checkout instead of opening a second one. None of these are sent anywhere except with the requests you make, and all of them are destroyed when the tab closes.

2. What We Do NOT Use

  • No tracking cookies. We do not track your behavior, on our site or across other websites.
  • No advertising cookies, no ad networks, no marketing pixels. The only third parties that touch your browser are the two named in section 1, and neither is there to advertise to you.
  • No analytics cookies. We do measure which steps of the site get used, but that measurement is first-party and cookie-free: it uses a random id held in sessionStorage that disappears when you close the tab. See section 2.4 of the Privacy Policy. We run no third-party analytics trackers of any kind.
  • We do not use cookies to store your analysis data, your queries, or your browsing history. Recommendation activity is never written to a cookie. What we do and do not keep on the server is listed row by row in section 6 of the Privacy Policy.

3. Cookie Lifetimes

Our only cookie is the sign-in session cookie, and it ends when you sign out. Everything else we keep in your browser (sessionStorage: picks, an uploaded export's free result, the purchase-attempt record) is cleared automatically when you close the tab. Third-party cookies set by Stripe or embedded players follow those providers' own lifetimes and policies.

4. Managing Cookies

You can delete or block cookies at any time through your browser settings. Blocking third-party cookies stops the Spotify and Apple cookies described in section 1 from being set. It will also break Stripe checkout, the inline previews, and the Apple Music import. Everything else on the site, including the recommendations themselves and the links out to Spotify and Letterboxd, keeps working.

5. Changes to This Policy

We may update this Cookie Policy from time to time. Material changes are indicated by the "Last Updated" date above.

6. Contact

Questions about this policy: [email protected]