
Last updated: 22 April 2026
This page lists every cookie, local-storage key, and similar technology that growyour.music sets on your device, who set it, what it does, and how long it lasts. It is the companion document to our Privacy Policy and the Subprocessors list.
You can change your cookie choices at any time via the "Cookies" link in our footer, which re-opens the cookie preferences modal.
Sec-GPC: 1 header, we automatically treat it as an opt-out of the sale/sharing of personal information and disable marketing cookies for that session.| Name | Vendor | Purpose | Duration |
|---|---|---|---|
| next-auth.session-token | NextAuth.js (first-party) | Authenticated session identifier. Required for login to work. | 30 days |
| next-auth.csrf-token | NextAuth.js (first-party) | CSRF protection for authentication flows. | Session |
| __twr_csrf | growyour.music (first-party) | Double-submit CSRF token for state-changing API requests. | Session |
| cc_cookie | vanilla-cookieconsent (first-party) | Stores your cookie-preference choices so we do not re-prompt on every visit. | 182 days |
| gpc_optout | growyour.music (first-party) | Persists a Global Privacy Control opt-out signal detected from the Sec-GPC request header. | 365 days |
| paddle_* (set by Paddle.js when a checkout opens) | Paddle (Paddle.com Market Limited) | Checkout session continuity and card-fraud scoring on payment pages. Set by our merchant of record, only on pages where a checkout is opened. | Session to 1 year |
| __stripe_mid / __stripe_sid | Stripe | Fraud prevention on payment pages. Fallback provider during the Paddle changeover. | 1 year / session |
| Name | Vendor | Purpose | Duration |
|---|---|---|---|
| ph_* (e.g. ph_phc_<token>_posthog) | PostHog | Product analytics (anonymous visitor id, session id, feature-flag evaluation). Only loaded after analytics consent. | 1 year |
| Name | Vendor | Purpose | Duration |
|---|---|---|---|
| _fbp | Meta (Facebook) | Meta Pixel attribution for ad campaigns. Only loaded after marketing consent and only when we are running active ad campaigns. | 90 days |
| _fbc | Meta (Facebook) | Click-ID for Meta ads conversion tracking. | 90 days |
| _ttp | TikTok | TikTok Pixel attribution. Only loaded after marketing consent. | 13 months |
| reddit_uid | Reddit Ads | Reddit conversion tracking. Only loaded after marketing consent. | 2 years |
When you upload an audio demo we compute a Chromaprint / AcoustID hash of the track. That hash is used to detect duplicate uploads inside the platform and to check the recording against the public MusicBrainz / AcoustID database for copyright matches.
These hashes are technical content signatures of the audio file — not voiceprints, not biometric identifiers of a natural person. They cannot be used to identify or re-identify you. They are stored for up to 7 years from upload, aligned with copyright limitation periods, then purged automatically by a scheduled job.
The rationale for this classification is documented in our compliance log (see docs/compliance/decisions.md CD-001 and CD-002 in our public source repository).
Questions about this page? Email privacy@growyour.music.