MTMTME
Privacy policy
Last updated 20 September 2026
MTMTME (“the service”) is a small, independent website for keeping a record collection and writing about it. This policy explains what it collects, why, who else ends up seeing anything, and how to get it back or have it deleted. It is written to be read, not to be survived.
1. Who is responsible
MTMTME is run by Simon Curd, an individual, as a personal project. For the purposes of UK data protection law he is the data controller for the personal data described here.
Contact: simoncurd@gmail.com. A postal address can be provided on request where the law requires one.
2. What is collected
There are three kinds of data here, and no others.
Your account
Signing in is done through Google. When you sign in, Google tells the service your email address, your name and the web address of your profile picture, and gives it a stable identifier for your Google account. Those are stored, together with the date you first signed in and the last date you used the service. No password is ever seen or stored — there isn't one.
What you put in
The records on your shelf and everything attached to them: title, artist, year, genre, which catalogue the details came from, the cover image (a link to the catalogue's image, or the picture itself if you uploaded one for a record you added by hand), your rating, the age you say you were, which tracks you starred, and the notes you write — with the date each note was written and last edited.
Notes are free text. Whatever you choose to put in them is stored as written, so treat them as you would a private notebook kept on someone else's shelf.
Technical
- A session record for each browser you sign in from: an expiry date, and the browser's self-description (its “user agent” string, e.g. Safari on macOS). The sign-in cookie itself is not stored — only an irreversible hash of it, so a copy of the database cannot be used to walk into an account.
- Ordinary server logs kept by the hosting provider, which include IP addresses and requested URLs. These are used to keep the service running and to investigate faults and abuse.
There is no analytics, no advertising, no tracking pixel, no fingerprinting, no third-party script of any kind, and nothing is sold, rented or shared for marketing.
3. Why, and on what legal basis
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Creating your account and signing you in | Performance of a contract — you asked for an account |
| Storing your collection and notes and showing them back to you | Performance of a contract — that is the service |
| Keeping the service up, secure, and free of abuse; fixing faults | Legitimate interests — running a service safely |
| Answering you when you get in touch | Legitimate interests — replying to correspondence |
Your data is never used to build a profile of you, to make automated decisions about you, or to advertise anything.
4. Cookies
One cookie, and it is strictly necessary: the one that keeps you signed
in after you have signed in. It holds a random token and nothing else,
it is HttpOnly and (over HTTPS) Secure, and it
expires. Signing out deletes it and ends the session.
Because the service sets no analytics or advertising cookies, there is no consent banner to click through. Your browser also keeps a few small preferences on your own device — which view you last used, for instance. Those never leave your browser.
5. Who else is involved
The service is deliberately small, and the list of other parties is short.
| Who | What they see, and why |
|---|---|
| Sign-in. Google authenticates you and tells the service your email, name and profile picture. Google's own handling of your account is governed by Google's privacy policy. | |
| The hosting provider | Runs the server and the database on which everything above is stored, under a contract that permits them to process it only to provide that hosting. |
|
Music catalogues Apple, Deezer, MusicBrainz |
When you search for an album, or view one, your browser contacts these services directly to fetch results, tracklists and cover images. They therefore see your IP address and what you searched for, as any website you visit would. They are not told who you are, and they receive none of your notes. |
Nobody else is given access. Data may be disclosed if the law requires it — a court order, for example — and that is the only other case.
6. Where the data is
The service is hosted on infrastructure that may be located in the United Kingdom, the European Economic Area or the United States, depending on the hosting region in use. Google operates globally. Where personal data leaves the UK, it is protected by the safeguards UK law recognises — an adequacy decision, or standard contractual clauses with the UK addendum.
7. How long it is kept
- Your collection and notes: until you delete them, or until your account is deleted.
- Your account: until you ask for it to be deleted. Accounts that have not been used for a long time may be deleted after reasonable notice to the email address on the account.
- Sessions: they expire on their own, and are deleted when you sign out.
- Server logs: kept for a short period by the hosting provider — typically days to a few weeks — then discarded.
Deleting a record deletes its notes with it. Deleting your account deletes the account, its records, its notes, its starred tracks and its sessions. Backups, if any exist, roll over in the ordinary course and are not used to restore deleted accounts.
8. Your rights
Under UK GDPR you have the right to ask for a copy of your data, to have it corrected, to have it deleted, to restrict or object to how it is used, and to receive it in a portable form. You can exercise most of these yourself, immediately:
- A copy, in a portable form: use Export collection (.json) in the menu. It contains your records, notes, favourites and ages.
- Correction and deletion of content: edit or delete any note or record from the album page.
- Deleting the account itself: email simoncurd@gmail.com from the address on the account and it will be done, normally within seven days and in any case within one month.
There is no charge for any of this. If you are unhappy with how your data has been handled, please say so first — but you also have the right to complain to the Information Commissioner's Office, ico.org.uk, or to your local supervisory authority.
9. Security
Traffic is served over HTTPS. Sign-in cookies are stored hashed rather
than in the clear, are marked HttpOnly so scripts cannot
read them, and expire. Every request for a collection is checked
against the account that made it, so one account cannot read another's
records. There is no password to steal because there are no passwords.
No service can promise perfect security, and this one is honest about being a personal project rather than a company with a security team. If you find a problem, please report it to the address below and it will be taken seriously.
10. Children
The service is not aimed at children and is not intended for use by anyone under 13. If you believe a child has created an account, get in touch and it will be removed.
11. Changes
If this policy changes, the date at the top changes with it. A change that materially affects how your data is used will be announced by email to the address on your account before it takes effect.
12. Contact
Questions, requests, complaints and bug reports all go to the same place: simoncurd@gmail.com.