Privacy.

What stays in your browser, what leaves it and when, who holds it, for how long, and how to take any of it back. This page describes what the site does, read from the code that does it. When the code changes, this page changes with it.

The short version

Crate has no accounts and sets no cookies. Your reading mode, your want list, your crate and your preferences live in this browser's storage. Four things can leave it, each only on its own terms: a connection to a music service you choose to make, a seed you choose to send, an email-alerts subscription you choose to start, and anonymous read-counts you can switch off. Questions about any of it: [email protected].

What stays here

Everything personal is kept in this browser's local storage under keys that start with crate.: the theme you picked, the records you want, the crate you built by connecting a source, the choices you made while connecting, and the date you agreed to the terms. None of it is copied anywhere unless you send it, below. Settings' Remove everything clears it, and so does clearing this site's data in your browser.

Connecting a source

When you connect Discogs, Spotify or Last.fm, your browser talks to that service directly. Crate's pages never see your password. What comes back, your collection or your saved albums or your loved tracks, is matched against the corpus in this browser and stored here.

Settings has a Remove import button for each source. It deletes what was imported and the grant that fetched it, and withdraws anything you sent that carried that source (below). Your library on the service is untouched either way.

Sending a seed

Settings offers a send button that shares a scrubbed copy of your crate with the atlas, so that scenes people own records from can be written next. Nothing is sent until you press it, and pressing it is agreeing to what this section says. What leaves is shown to you in full before it goes: record identities and counts from each connected source, Spotify included if you connected it, with usernames, filenames and dates removed, first in your browser and again on arrival. A disconnected source is never sent. It carries a random id your browser made, not you, and is never joined to read-counts.

Email alerts

If you ask Crate to email you when a new scene is written about records you own, two things are stored with Cloudflare until you unsubscribe: the address you gave, and a scrubbed copy of your crate in the same shape as a seed — no username, no filename, nothing you did not import. An address that is never confirmed is deleted after a day. The copy exists to be matched against each new scene; it is refreshed when your crate changes, refreshed without a source you remove or disconnect, and deleted with the subscription when nothing is left to match. Mail goes out through Resend, which sees the address and the mail, as any mail service must. Every mail carries a one-click unsubscribe; using it, or the Unsubscribe button in Settings, deletes the address and the stored copy together, and changes nothing in your browser. The mails carry no tracking pixel, and their one link carries no per-person token: it says only that it came from a mail, the same word for everyone.

Read-counts

The site counts reads: which pages get read, for how long, whether a listen link was followed, whether a search found nothing. The writing queue uses these to know what is read. The counts are anonymous by construction, are kept by Cloudflare's analytics store, and are deleted by it after three months.

If your browser sends Global Privacy Control or Do Not Track, nothing is counted, without you touching anything. Otherwise Settings, under Reading data, switches counting off in this browser.

Who holds what
Cookies, and what the page itself loads

Crate sets no cookies, its own or anyone else's, and keeps what it keeps in local storage as described above. Like any web page, some parts of Crate come from other hosts, and each of those hosts sees the request that fetches them: the typefaces from Google Fonts, the map library and its tiles on the Explorer, and the Spotify or Bandcamp player on a scene page when you scroll to it. A player is Spotify's or Bandcamp's own page inside Crate's, and runs under their privacy terms, which may include their cookies. Crate sends none of your data to any of them. The site tells browsers which hosts it may talk to and no others.

Feeds and the podcast

The new-scenes feed is a file. Subscribing to it happens in your reader, and Crate learns nothing about who subscribes. The podcast is hosted on Spotify, under Spotify's terms.

Taking it back
Rights

The writing, the design and the code of this site are © Crate Scenes, from the first sealed scene onward, and all rights in them are reserved. The facts they rest on — who made which record, where and when — belong to nobody and you are free to take them. Quote a passage with a link to the page it came from and you have done everything asked; reproduce a scene or the site's design wholesale and you have not. Record and artist names are their owners'.

The terms of use, including the terms Spotify requires of anyone connecting it, are on their own page, and this page is part of them.

Dated 2026-10-05 and changed only alongside the code it describes. Corrections to the writing go where all corrections go, the errata on the Contents page.

© 2026 Crate Scenes · text and design all rights reserved · quotation with a link is welcome