Privacy policy
Effective October 10, 2026
BopLift helps you transfer Spotify playlists to YouTube. This policy explains the information the app accesses, how it uses that information, and your choices.
Information we access and store
- Connected accounts: provider account identifiers, display names, authorization tokens, refresh tokens, and token expiration times. Google sign-in requests profile and email access; the app uses the provider account identifier and display name and generates an internal account address rather than storing your provider email address.
- Playlist information: Spotify playlist identifiers, playlist names, track titles, artists, track identifiers, and source order. Playlist artwork may be displayed from Spotify-provided image URLs.
- YouTube information: search results and video metadata used to find matches, selected video identifiers and titles, and destination playlist identifiers.
- Your activity in the app: transfer settings, visibility choices, progress, timestamps, error reports, and any matches you choose to save. We also store the policy version you accepted and the time of acceptance, plus timestamps needed to process disconnection and deletion requests.
- Technical information: essential session cookies and operational request logs. The hosting provider processes network information, including IP addresses, to deliver and protect the service.
How we use information
We use this information to sign you in, link your service accounts, read the playlists you select, search for matching YouTube videos, create and populate your destination playlists, show transfer progress, remember your saved matches, and diagnose service failures. Refresh tokens let the app complete background work without asking you to sign in for every request.
BopLift uses YouTube API Services. Its access to Google and YouTube data is used to provide the playlist features you request. The app does not use your music or account data to train AI models, sell personal information, or target advertisements.
Sharing and service providers
When you transfer a playlist, song and artist search queries and your selected destination details are sent to Google/YouTube. Spotify receives requests to read your playlists. Your access tokens are sent only to the corresponding provider to authorize requests. BopLift is hosted by Fly.io, which processes app data and operational logs as part of hosting.
The page loads fonts from Google Fonts, and playlist artwork can load from provider image servers. Those servers receive ordinary browser connection information when your browser requests their resources. Links to Spotify, YouTube, and Google open services governed by their own policies. The app has no advertising or analytics integration.
Your destination playlists are private by default. If you select public or unlisted visibility, YouTube makes them available according to that setting. Information may also be disclosed when required by applicable law.
Storage and security
Account records, transfer history, and saved matches are stored in the app's database. Access and refresh tokens are encrypted before database storage. App credentials and encryption keys are held separately in the hosting platform's secret store. Connections to the app use HTTPS. Access is restricted to operating and supporting the service; no security measure provides an absolute guarantee.
Retention and deletion
Transfer history and saved matches expire 28 days after creation and are removed by an hourly cleanup. Reusing a saved match does not extend its retention. Connected-account tokens are stored while access remains authorized and needed. We check Google authorization at least daily while the maintenance worker is operating. When Google reports that authorization has expired or been revoked, we block the connection and schedule removal of the associated app data.
You can remove an individual saved match from Saved matches. In Privacy & data, you can disconnect a service or delete your BopLift account. Disconnecting YouTube blocks new requests immediately, asks Google to revoke authorization, and removes your transfer history and saved matches. Disconnecting Spotify blocks new Spotify requests and removes that local connection. Account deletion removes all connections, transfer records, saved matches, and your BopLift account. Work already sent to a provider may finish or leave a partial playlist.
Deleting data from BopLift does not delete playlists or videos on YouTube or alter your Spotify playlists. Manage or delete those directly with the relevant service. App records are normally removed within minutes, after a short delay for in-flight requests to finish. Google revocation failures are retried; access remains blocked during retries, and retained local credentials and account records are removed within six days. New database snapshots are retained for one day, so deleted information may remain in backups until those snapshots expire. Deletion requests are handled within seven calendar days, including the backup retention window. Minimal operational logs record request times and internal record identifiers so deletions can be reapplied before a backup is returned to service.
Revoke provider access
You can revoke BopLift's Google access through Google account permissions and Spotify access through Spotify account apps. Revoking Google access stops future authorized requests; our periodic authorization check detects revoked or expired Google access and schedules deletion of associated transfer history and saved matches. Spotify revocation stops authorized Spotify requests; use Privacy & data or contact us to remove stored app records.
Provider policies
See the Google Privacy Policy, YouTube Terms of Service, and Spotify Privacy Policy for those services' practices.
Contact and updates
You can also request deletion by email. We may ask you to verify account ownership before processing a request. For privacy questions, complaints, or account and data-deletion requests, email privacy@boplift.com.
Changes to this policy will appear on this page with an updated effective date. Material changes to how the app uses your information will be explained before that new use begins.