What we collect and why
Last Updated : 13 September 2026
We collect personal information about you when you register for an account, create or modify your profile, set preferences, and sign-up for our Services. For example, for us to communicate with you, you are asked to provide us personal information that will be used to identify you such as your email address. The exact personal data we will collect depends on the type of service plan you sign up for and whether or not you use a third party service (such as Spotify) to sign up and use our Services.
We collect information about your activity using our Services, which we use to allow playlist creators to gain information about your track and accept/reject it. The activity information may include music/tracks you search for and listen to, user location, username, social pages linked on Spotify, user subscription type on Spotify, number of Spotify followers, artists you follow.
Data you collect from your own audience
The sections below concern data that you, as a Citaurus user, gather from your own audience through the Services – as distinct from the data we collect about you, which is described above.
As used in these Terms, “End User” means a user or potential user of your products or services, and “End User Data” means the data about your End Users (including any End User personally identifiable information) that you input or submit to the Services directly or via providing us with access to your Third Party Accounts. As a Registered User, you can use the marketing platform features of the Services (“Marketing Service”) to generate landing pages containing your User Content (each a “Landing Page”) to engage your target audience and capture information via social networking services such as Facebook, Twitter, Spotify, etc. (each, an SNS). You are responsible for your use of the Marketing Service.
Access to your End User Data. In order for us to retrieve your End User Data from your Third Party Account, you agree to provide us with the requisite security permissions, software interfaces to your business applications on such Third Party Accounts and any other information requested by us. We are not responsible or liable for any Third Party Accounts or any products or services (including End User Data) accessed from such Third Party Accounts on your behalf. You will indemnify us from any liability arising from accessing any End User Data from any of your Third Party Accounts.
You are the Controller of End User Data. You (and not Citaurus Records) determine what End User Data (including any personally identifiable information) is received and stored by Citaurus Records via your use of the Services. You agree to publish and abide by an appropriate privacy policy that is compliant with the applicable laws (including privacy and data security laws applicable to you) and that adequately describes the collection, use and sharing of End User Data by you and your use of third party service providers like Citaurus Records Music Voting. You further agree to comply with all laws applicable to your information collection, use and sharing practices including relating to your use of the Marketing Service, Messaging Service and Advertising Service, and if required by applicable laws you agree to obtain any appropriate consents from End Users in this regard.
Users can create Contest Landing Page to engage their audience. Please refer to our feature pages for more information on each type of Landing Page here. For each Landing Page, you will need to enter information regarding your product, offer, or content along with other selections within the Marketing Service to generate your Landing Page.
Consumers will be able to engage and interact with your Landing Pages and Citaurus Records Music Voting will collect certain personally identifiable information (“PII”) from these Consumers in connection with such engagement and interaction and will share this PII with you, the Registered User who created the Landing Pages. You agree that you will only use this PII as described in our Privacy Policy and that you will only interact with those Consumers who have agreed and consented to such interaction with you.
We receive information about you when you or your administrator integrate or link a third-party service with our Services as follows. (i) If you create an account or log into the Services using your Spotify credentials, we may receive your name and email address as permitted by your Spotify profile settings in order to authenticate you. (ii) You or your administrator may also integrate our Services with other service providers you use, such as to allow you to access, store, share and edit certain content from a third-party through our Services. (iii) You may authorize our Services to access, display and store files from a third-party document-sharing service within the Services interface. (iv) You may authorize our Services to sync a playlist so that you can easily connect with our Services. (v) You may authorize our Services to access, display and modify data from a third-party email service provider such as Mailchimp within the Services interface. The information we receive when you link or integrate our Services with a third-party service depends on the settings, permissions and privacy policy controlled by that third-party service. You should always check the privacy settings and notices in these third-party services to understand what data may be disclosed to us or shared with our Services.
Types of Data Collected
Personal Data: While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you ("Personal Data"). Personally identifiable information may include, but is not limited to:
E-mail address (anonymous not public)
Your Spotify full name
heard songs and playlists
your supported artists and playlists
your nationality
Reviews of songs
Access tokens for the services you connect — Spotify, and optionally Last.fm, Meta, X and TikTok — so that counting, scheduled publishing and the daily reading of figures keep working while your browser is closed
Your listening history, if you connect Last.fm — including tracks that have nothing to do with Citaurus (see below)
The public figures of your own TikTok videos, if you connect TikTok — views, likes, comments and shares, read once a day (see below)
Access to your Spotify account and your playlists
You sign in to Citaurus with Spotify. During that sign-in, Spotify asks you to approve a specific list of permissions, and we receive only what you approved there. What we do with it:
Your Spotify profile (user ID, display name, country, profile picture) — this is your Citaurus account. Your Spotify user ID is our internal key for everything that belongs to you.
Your playlists — so that you can register a playlist with Citaurus and manage the songs on it.
What you are currently playing — read periodically while you are listening, in order to recognise which playlist a play belongs to. Without this, a play cannot be credited to the right playlist. This does not require Spotify Premium; it is read access only.
We store your Spotify access token
Citaurus stores the access token (and the refresh token that renews it) that Spotify issues when you sign in. This is necessary because two things have to keep working while your browser is closed:
Recognising which playlist you are listening to. A play happens whether or not you have Citaurus open; if we could only look while you are on our website, almost nothing would ever be credited correctly.
Keeping registered playlists in step with Spotify, so that songs which a curator has added or removed are reflected here.
The token is stored on our servers, transmitted only to Spotify, and never passed to anyone else. It grants exactly the permissions you approved and nothing beyond them.
Where we do act on your account, we do so only on your instruction. Adding a song to a playlist, following an artist or a playlist, and reordering or removing songs on a playlist you own happen when you trigger them in Citaurus, or when you run the curator tools on your own playlist. We never touch playlists belonging to other people, we do not follow anything on your behalf without you asking, and we do not read your private data beyond the list above.
You can withdraw this access at any time at spotify.com/account/apps. The stored token stops working immediately. To have it deleted from our side as well, write to info@citaurus.com.
Connecting your Last.fm account
Connecting Last.fm is entirely optional, and Citaurus works without it. It exists because Spotify stopped supplying listening history to applications in July 2026 — since then, Last.fm is the reliable way for your listening to be counted, and it works with a free Spotify account as well.
When you connect it, we store your Last.fm username and the session key that Last.fm issues, and we then retrieve your recently played tracks about twice an hour. For each play we store the artist, the track title, the album, the time it was played and the cover image supplied by Last.fm.
Please be aware of what this means: Last.fm reports everything you listen to, not only music that is on Citaurus. Roughly half of what arrives here has no connection to this platform. Those entries cannot be counted for anything and are used only to determine whether a play belongs to a registered song. Plays that cannot be matched are deleted after a short period; plays that were counted are kept as the record of what earned a placement.
We only read. We never scrobble anything to your Last.fm account, never mark tracks as loved, and never change anything there. You can sever the connection at any time on your Citaurus profile under “Connections”, and revoke it from Last.fm's side under Settings → Applications.
Connecting your X (Twitter) account
Also optional. If you connect X, we store the access token, the refresh token, your X user ID and your handle, so that posts you create or schedule in Citaurus can be published — including at a time you set while your browser is closed. We also cache the mentions of your account that we display to you inside Citaurus.
We publish only what you have created and released yourself. We do not read your direct messages, your followers, or your timeline beyond the mentions shown to you. If the connection expires, we notify you by email and ask you to reconnect; we do not deactivate anything on your account.
Connecting your TikTok account
Also optional, and part of our PRO features. Citaurus works without it. We only access a TikTok account after you have gone through TikTok's own login dialog and approved the listed permissions there, and you can withhold any individual permission without losing the rest.
When you connect TikTok, we store the access token and refresh token that TikTok issues, your TikTok user identifier, and your public profile details — display name, username, profile picture, profile link, and, if you granted that permission, your follower count, your total number of likes and the number of videos on your account.
Once a day we then retrieve the videos on your own account and store, for each of them, the video identifier, its title and description, the cover image, the link to the video, its length, when it was posted, and its public performance figures: views, likes, comments and shares. We keep those figures as a daily record, because a single number tells you how large a video once was, while the history tells you whether it is still being served.
We only read, and only from your own account. Citaurus never posts to TikTok, never comments, never sends messages and never changes anything on your account — it is technically unable to do so. We do not receive your direct messages, your follower list, your watch history, or the identity of the individual people who viewed or interacted with your videos. We also do not receive anything about videos posted by other people, including videos by others that use your music.
This data is stored on our servers in the European Union, in records tied to your Citaurus account. It is shown to you and to Citaurus staff, and to nobody else: we do not sell it, do not use it for advertising of our own, do not build profiles from it, and do not pass it to any third party. Access tokens issued by TikTok expire on their own — the access token after 24 hours, and the underlying permission after one year — after which the connection stops working until you reconnect. If it expires, we notify you by email and ask you to reconnect; we do not deactivate anything on your account.
You can sever the connection at any time using the “Disconnect” function on your Citaurus profile. Doing so immediately and permanently deletes the stored tokens, your TikTok profile details and every video figure we collected. You can equally revoke the connection from TikTok's side, in the TikTok app under Settings and privacy, in the section where security and connected app permissions are managed. If you would rather ask us directly, or want confirmation that the deletion has taken place, write to info@citaurus.com.
Connecting your Facebook and Instagram accounts
Connecting a Meta account is entirely optional. Citaurus works without it, and you can disconnect at any time (see “Disconnecting and deleting your Meta data” below). We only access a Meta account after you have gone through Facebook's own login dialog and approved the listed permissions there.
When you connect a Meta account, we receive and store the following, and nothing else:
Your basic Facebook profile (name and Facebook user ID) — so that we can show you which account is connected.
The list of Facebook Pages you manage (page ID, page name, and the access token belonging to that Page) — so that you can choose the Page you want to publish to. Where a Page is not held directly by your personal account but through a Meta Business Manager, we also read the list of businesses and the Pages they own or manage, for the sole purpose of finding those Pages.
The Instagram Business account linked to a Page (Instagram ID, username, profile picture) — so that you can publish to Instagram.
Page and Instagram statistics (follower counts, reach, profile views, and per-post engagement figures for content published through Citaurus) — shown to you inside Citaurus so that you can see how a post performed. These are aggregate figures about your own account; we do not receive the identity of the individual people who saw or interacted with your posts.
Posts you create in Citaurus — the text, image or video, the chosen target and the scheduled time, so that a scheduled post can be published at the time you set.
We publish to your Page or Instagram account only when you actively trigger it, or at a time you have scheduled yourself. We never post on your behalf otherwise, and we do not read your private messages, your friends list, your personal timeline, or content belonging to other people.
Advertising tools
If you use the advertising features of Citaurus, we additionally access, with your prior permission, the advertising accounts you have access to on Meta (account ID, name, currency, account status), the advertising pixels contained in those accounts, and the advertising campaigns created through Citaurus together with their performance figures (impressions, clicks, cost, and results). We use this solely to prepare a campaign for you, to show it to you before it starts, and to report back on it afterwards.
No campaign is ever started without your explicit confirmation. Everything Citaurus creates on Meta is created in a paused state; only your confirmation activates it, and only then is any money spent. The advertising budget is charged by Meta to your own advertising account under your own payment method — Citaurus never receives, holds, or processes your payment details.
Where this data is stored and for how long
All of the above is stored on our servers in the European Union, in database records tied to your Citaurus account. Access tokens are stored so that scheduled publishing keeps working after you close your browser; they are transmitted only to Meta and never passed to anyone else. Access tokens issued by Meta expire on their own, typically after 60 days, after which the connection stops working until you reconnect.
We keep this data for as long as your Meta account remains connected. We do not sell it, we do not use it for advertising of our own, we do not use it to build profiles of you, and we do not share it with any third party other than Meta itself, which is where it came from.
Disconnecting and deleting your Meta data
You can sever the connection at any time using the “Disconnect” function on your Citaurus profile. Doing so immediately and permanently deletes the stored Meta profile data, the list of your Pages and Instagram accounts, all associated access tokens, and your saved publishing target. This works even if your PRO subscription has already expired — losing PRO must never stop you from revoking access.
You can equally revoke the connection from Meta's side, under Settings → Apps and Websites on Facebook. Meta then notifies us automatically, and we delete the same data without any further action on your part. If you would rather ask us directly, or want confirmation that the deletion has taken place, write to info@citaurus.com.
Tracking pixels on public artist pages
Artists using our PRO features may place their own tracking pixel (Meta, Google, TikTok or X) on their public Citaurus artist page in order to measure their own promotional activity. Where an artist has done so, that provider's script runs on that artist page and may set cookies and transmit information about your visit — such as the page viewed and your IP address — to that provider, under that provider's own privacy policy and outside our control. This affects only individual public artist pages, never the rest of Citaurus. The artist who placed the pixel is responsible for it and for obtaining any consent required in their jurisdiction.
Cookie Policy
Last Updated : 13 September 2026
This Cookie Policy explains how Citaurus Records (Austria) use cookies and similar technologies to recognize you when you visit our Site at www.citaurus.com (the “Site”). It explains what these technologies are and why we use them, as well as your rights to control our use of them. For more information about your personal information, please see the Privacy Policy above.
WHAT IS A COOKIE?
A cookie is a small data file that is placed on your device when you visit a website. Cookies are widely used in order to make websites work or to work more efficiently, as well as to provide reporting information. A cookie may have unique identifiers and reside, among other places, on your device, in emails we send to you, and on the Site.
Cookies may be set by Citaurus Records or third-parties that perform services on our behalf. Cookies enable features or functionality in connection with our Site, for example, advertising, interactive content, and analytics. Cookies created by certain third-parties can recognize your device when you visit our Site and also when you visit certain other websites.
We may use other technologies similar to cookies like web beacons, which are sometimes called “tracking pixels” or “clear gifs”. These are tiny graphic files that contain a unique identifier that enable us to recognize when someone has visited our Site or opened an email that we have sent them. In many instances, these technologies are reliant on cookies to function properly, and so declining cookies will impair their functioning.
WHY DO WE USE COOKIES?
We Use Cookies for Several Reasons . Some are required for technical reasons in order for our Site to operate. Others provide a better experience on our Site by remembering some of your activities on the Site (including through our plug-ins, widgets, and embedded content). Other cookies enable more relevant advertising and better analytics.
Essential Cookies . Some cookies are required to enable you to navigate throughout our Site. For example, to identify you as being logged into the Site or to make sure you connect to the right service on our Site when we make any changes to the way our Site works.
Cookies for Features and Services . Some cookies provide a better experience on our Site. For example, without cookies to remember some of your settings and activities on our Site, you would not be able to [for example: once you've connected via Spotify's API we keep you logged in till you've logged out of Spotify to save time logging in on every visit].
Cookies for Analytics and Personalization . Some cookies collect information about how you use the Site to help us improve how our Site is being used, and to help us understand what may interest you and personalize your experience accordingly. These cookies, for example:
Generate statistics on how the Site is used, including to measure any errors that occur or to obtain data on the number of users of the Site that have viewed a product
Test different designs for the Site
Help us track email response rates, identify when our emails are viewed, and track whether our emails are forwarded
Collect or transmit information about you, such as your browser type and search preferences, and your use of the Site or third-party sites that incorporate part of the Site
Third-Party Cookies. We work with analytics service providers, advertising partners, and advertising networks that may have access to your device information which is anonymous data. In other words, third parties do not collect information such as your name, contact details or other personal information.
HOW CAN I CONTROL COOKIES?
You can amend or "opt out" of the collection of information created through cookies or other technology by actively managing the settings on your browser or mobile device. If you choose to reject cookies, your access to some functionality and areas of our Site may be restricted.
Our Site does not support Do Not Track settings (“DNT”) at this time. DNT is a privacy preference you can set in your web browser to indicate that you do not want certain information about your Site visits collected across Sites when you have not interacted with that service on a page. For more information about how to control cookies, please see “More About Cookies”.
CHANGES AND UPDATES TO THE COOKIE POLICY
We may update this Cookie Policy from time to time in order to reflect, for example, changes to the cookies we use or for other operational, legal or regulatory reasons. Please therefore re-visit this Cookie Policy regularly to stay informed about our use of cookies and related technologies.
QUESTIONS
If you have any questions about our use of cookies or other technologies, please
email us.
MORE INFORMATION ABOUT ANALYTICS
Our Site uses Google Analytics, a web analysis service from Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). Google Analytics uses cookies text files that are stored on your device and make it possible to analyze how you utilize the site. The information generated by the cookie (including the IP address) is transferred and stored on a Google server located in the United States.
Google uses the information on our behalf to evaluate how the Site is used, create reports about the activities on the Site for the site operators, and to perform additional services regarding Site and internet utilization.
Further you can prevent the collection and processing of cookie created data relating to your utilization of the Site (including your IP) via Google by downloading and installing the browser-plugin available under the following link https://tools.google.com/dlpage/gaoptout?hl=en .
You can refuse the use of Google Analytics by clicking on the following link. An opt-out cookie will be set on the device, which prevents the future collection of your data when visiting this Site: For more information on Google Analytics and Google’s privacy practices, please review their privacy policy at https://www.google.com/policies/privacy/
Further information concerning the terms and conditions of use and data privacy can be found at
http://www.google.com/analytics/terms/gb.html
or at
https://www.google.de/intl/en_uk/policies/ .
MORE INFORMATION ABOUT COOKIES
You can learn more about cookies at
www.allaboutcookies.org , Network Advertising Initiative at
www.networkadvertising.org.